You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure公网负载均衡器NAT规则搭配NSG的RDP端口访问问题排查

Hey Alex, let's break down your Azure setup and the likely issues you're hitting with Network Watcher's IP Flow Verify tool.

Core Misunderstanding in Your NSG Rules

First, a critical point about Azure Load Balancer (LB) NAT rules: when an external client connects to your LB's static PIP on port 12345, the LB forwards that traffic to your VM's private IP (10.2.2.2) on port 3389. However, the source IP seen by your NSGs is the client's original public IP, not the LB's PIP. This is why your current rules aren't working as expected.

Let's break down the problems with your existing NSG config:

  • Subnet NSG Rule 100: You've set the source to the LB's PIP, but actual traffic comes from client IPs—this rule will never match incoming RDP traffic.
  • Subnet NSG Rule 120: Targets IP 10.1.2.4 (not your VM's 10.2.2.2) and specifies source port 12345 (client traffic uses random source ports, not 12345). This rule is irrelevant to your setup.
  • VM NIC NSG Rule 100: Again, you're using the LB's PIP as the source, which doesn't align with real traffic sources.
Fixed NSG Configuration Recommendations

You need to create explicit allow rules that match the actual traffic flow. Here are two valid approaches:

Add a high-priority allow rule to your subnet NSG:

  • Priority: 90 (higher than your existing rules to ensure it's evaluated first)
  • Source: Internet (or restrict to specific client IP ranges for better security)
  • Source port range: * (clients use random source ports)
  • Destination: 10.2.2.2/32 (your VM's private IP)
  • Destination port range: 3389
  • Protocol: TCP
  • Action: Allow

Option 2: VM NIC-Level NSG

If you prefer to manage rules directly on the VM's NIC, use the same rule parameters as above—just apply it to the VM's NSG instead of the subnet's.

Correct IP Flow Verify Test Parameters

To validate the fix, run IP Flow Verify with these settings:

  • Direction: Inbound
  • Target IP: 10.2.2.2 (your VM's private IP)
  • Target port: 3389
  • Source IP: Your local client's public IP (the one you'd use to connect via RDP)
  • Source port: * (or any random port like 50000)
  • Protocol: TCP

This test should now show "Allowed" once your new NSG rule is in place.

Remember: Azure NSGs have a default inbound rule that denies all Internet traffic, so you must explicitly allow the traffic you need.

内容的提问来源于stack exchange,提问作者AlexB

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:18:22