Bilješka
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati da se prijavite ili promijenite direktorije.
Pristup ovoj stranici zahtijeva provjeru vjerodostojnosti. Možete pokušati promijeniti direktorije.
This article describes the networking requirements for deploying Azure Arc resource bridge in your enterprise.
General network requirements
The lowest network bandwidth validated for deployment of Arc resource bridge is 100 Mbps. If your network bandwidth is slower, you might experience problems with deployment.
Arc resource bridge communicates outbound securely to Azure Arc over TCP port 443. If the appliance needs to connect through a firewall or proxy server to communicate over the internet, it communicates outbound by using the HTTPS protocol.
Generally, connectivity requirements include these principles:
- All connections are TCP unless otherwise specified.
- All HTTP connections use HTTPS and SSL/TLS with officially signed and verifiable certificates.
- All connections are outbound unless otherwise specified.
To use a proxy, verify that the agents and the machine performing the onboarding process meet the network requirements in this article.
Inbound connectivity requirements
To deploy and maintain Arc resource bridge, the management machine, appliance VM IPs, and control plane IPs need to communicate through the following ports. Ensure these ports are open and that traffic doesn't go through a proxy.
Important
During onboarding, provide two IP addresses for the Arc Resource Bridge appliance VMs - either as a range or as two individual IPs. For successful deployment, operations, and upgrades:
- Ensure the management machine, appliance VM IPs, and control plane IPs can communicate over the required ports listed in the following table.
- Don't route traffic through a proxy for these connections.
| Service | Port | IP/machine | Direction | Notes |
|---|---|---|---|---|
| SSH | 22 | appliance VM IPs and Management machine |
Bidirectional | Management machine connects outbound to the appliance VM IPs. Appliance VM IPs must allow inbound connections. |
| Kubernetes API server | 6443 | appliance VM IPs and Management machine |
Bidirectional | Management machine connects outbound to the appliance VM IPs. Appliance VM IPs must allow inbound connections. |
| SSH | 22 | control plane IP and Management machine |
Bidirectional | Used for deploying and maintaining the appliance VM. |
| Kubernetes API server | 6443 | control plane IP and Management machine |
Bidirectional | Management of the appliance VM. |
| HTTPS | 443 | private cloud control plane address and Management machine |
Management machine needs outbound connection. | Communication with private cloud (ex: VMware vCenter address and vSphere datastore). |
| Kubernetes API server | 6443, 2379, 2380, 10250, 10257, 10259 | appliance VM IPs (to each other) |
Bidirectional | Required for appliance VM upgrade. Ensure all appliance VM IPs have outbound connectivity to each other over these ports. |
| HTTPS | 443 | private cloud control plane address and appliance VM IPs |
appliance VM IPs need outbound connection. | Communication with private cloud (ex: VMware vCenter address and vSphere datastore). |
Outbound connectivity requirements
Note
For Arc-enabled VMware vSphere, this requirement doesn't apply if you use Azure Arc gateway (preview). Azure Arc gateway for Arc-enabled VMware vSphere (preview) reduces the firewall and proxy URL allow list requirements. For more information, see Arc-enabled VMware vSphere - Support Matrix.
The following firewall and proxy URLs must be on the allow list in order to enable communication from the management machine, Arc resource bridge VM (initially deployed), Arc resource bridge VM 2 (upgrade creates a new VM using a different VM IP), and Control Plane IP to the required Arc resource bridge URLs.
Important
When onboarding Arc Resource Bridge, you must provide two IP addresses for the appliance VMs. Specify these IP addresses as either:
- A range of IPs
- Two individual IPs (one for each VM)
To ensure successful upgrades, all appliance VM IPs must have outbound access to the required URLs. Ensure these URLs are on the allow list in your network.
Firewall/Proxy URL allow list
| Service | Port | URL | Direction | Notes |
|---|---|---|---|---|
| DNS servers | 53 | Your DNS server IPs | Management machine and appliance VM IPs need outbound connection. | Network connectivity to the DNS servers specified during deployment to resolve required service endpoints. |
| SFS API endpoint | 443 | msk8s.api.cdp.microsoft.com |
Management machine & Appliance VM IPs need outbound connection. | Download product catalog, product bits, and OS images from SFS. |
| Resource bridge (appliance) image download | 443 | msk8s.sb.tlu.dl.delivery.mp.microsoft.com |
Management machine & Appliance VM IPs need outbound connection. | Download the Arc Resource Bridge OS images. |
| Microsoft Container Registry | 443 | mcr.microsoft.com |
Management machine & Appliance VM IPs need outbound connection. | Discover container images for Arc Resource Bridge. |
| Microsoft Container Registry | 443 | *.data.mcr.microsoft.com |
Management machine & Appliance VM IPs need outbound connection. | Download container images for Arc Resource Bridge. |
| Windows NTP Server | 123 | time.windows.com |
Management machine & Appliance VM IPs (if Hyper-V default is Windows NTP) need outbound connection on UDP | OS time sync in appliance VM & Management machine (Windows NTP). |
| Azure Resource Manager | 443 | management.azure.com |
Management machine & Appliance VM IPs need outbound connection. | Manage resources in Azure. |
| Microsoft Graph | 443 | graph.microsoft.com |
Management machine & Appliance VM IPs need outbound connection. | Required for Azure RBAC. |
| Azure Resource Manager | 443 | login.microsoftonline.com |
Management machine & Appliance VM IPs need outbound connection. | Required to update ARM tokens. |
| Azure Resource Manager | 443 | *.login.microsoft.com |
Management machine & Appliance VM IPs need outbound connection. | Required to update ARM tokens. |
| Azure Resource Manager | 443 | login.windows.net |
Management machine & Appliance VM IPs need outbound connection. | Required to update ARM tokens. |
| Resource bridge (appliance) Dataplane service | 443 | *.dp.prod.appliances.azure.com |
Appliance VMs IP need outbound connection. | Communicate with resource provider in Azure. |
| Resource bridge (appliance) container image download | 443 | *.blob.core.windows.net, ecpacr.azurecr.io |
Appliance VM IPs need outbound connection. | Required to pull container images. |
| Managed Identity | 443 | *.his.arc.azure.com |
Appliance VM IPs need outbound connection. | Required to pull system-assigned Managed Identity certificates. |
| Microsoft events data service | 443 | v20.events.data.microsoft.com |
Appliance VM IPs need outbound connection. | Send diagnostic data from Windows. |
| Log collection for Arc Resource Bridge | 443 | linuxgeneva-microsoft.azurecr.io |
Appliance VM IPs need outbound connection. | Push logs for Appliance managed components. |
| Microsoft open source packages manager | 443 | packages.microsoft.com |
Appliance VM IPs need outbound connection. | Download Linux installation package. |
| Custom Location | 443 | sts.windows.net |
Appliance VM IPs need outbound connection. | Required for Custom Location. |
| Azure Arc | 443 | guestnotificationservice.azure.com |
Appliance VM IPs need outbound connection. | Required for Azure Arc. |
| Diagnostic data | 443 | gcs.prod.monitoring.core.windows.net |
Appliance VM IPs need outbound connection. | Periodically sends Microsoft required diagnostic data. |
| Diagnostic data | 443 | *.prod.microsoftmetrics.com |
Appliance VM IPs need outbound connection. | Periodically sends Microsoft required diagnostic data. |
| Diagnostic data | 443 | *.prod.hot.ingest.monitor.core.windows.net |
Appliance VM IPs need outbound connection. | Periodically sends Microsoft required diagnostic data. |
| Diagnostic data | 443 | *.prod.warm.ingest.monitor.core.windows.net |
Appliance VM IPs need outbound connection. | Periodically sends Microsoft required diagnostic data. |
| Azure service bus | 443 | *.servicebus.windows.net |
Appliance VM IPs need outbound connection. Outbound WebSocket (wss://) connections must be allowed. | Enables secure control channel. |
| Azure CLI | 443 | *.blob.core.windows.net |
Management machine needs outbound connection. | Download Azure CLI Installer. |
| Arc Extension | 443 | *.web.core.windows.net |
Management machine needs outbound connection. | Download Arc resource bridge extension. |
| Azure Arc Agent | 443 | *.dp.kubernetesconfiguration.azure.com |
Management machine needs outbound connection. | Dataplane used for Arc agent. |
| Python package | 443 | pypi.org, *.pypi.org |
Management machine needs outbound connection. | Validate Kubernetes and Python versions. |
| Azure CLI | 443 | pythonhosted.org, *.pythonhosted.org |
Management machine needs outbound connection. | Python packages for Azure CLI installation. |
Note
The URLs listed here are required for Arc resource bridge only. Other Arc products (such as Arc-enabled VMware vSphere) might have additional required URLs. For details, see Azure Arc network requirements.
Designated IP ranges for Arc resource bridge
When you deploy Arc resource bridge, specific IP ranges are reserved exclusively for the Kubernetes pods and services within the appliance VM. These internal IP ranges must not overlap with any configuration inputs for the resource bridge, such as IP address prefix, control plane IP, appliance VM IPs, DNS servers, proxy servers, or vSphere ESXi hosts. For details on the Arc resource bridge configuration, refer to the system requirements.
Note
Designated IP ranges within the resource bridge don't affect Azure resources. However, they must not overlap with any IP ranges in the AVS environment or the Arc-enabled VMware environment (including management and workload networks).
| Service | Designated IP range |
|---|---|
| Arc resource bridge Kubernetes pods | 10.244.0.0/16 |
| Arc resource bridge Kubernetes services | 10.96.0.0/24 |
SSL proxy configuration
Important
Arc Resource Bridge supports only direct (explicit) proxies, including unauthenticated proxies, proxies with basic authentication, SSL terminating proxies, and SSL passthrough proxies.
If you use a proxy, you must configure the Arc Resource Bridge to use the proxy to connect to Azure services.
To configure the Arc resource bridge with a proxy, provide the proxy certificate file path when you create the configuration files.
The format of the certificate file is Base-64 encoded X.509 (.CER).
Only pass the single proxy certificate. If you pass a certificate bundle, the deployment fails.
The proxy server endpoint can't be a
.localdomain.The proxy server must be reachable from all IPs within the IP address prefix, including the control plane and appliance VM IPs.
When you deploy the Arc resource bridge behind an SSL proxy, only two certificates are relevant:
SSL certificate for your SSL proxy (so that the management machine and appliance VM trust your proxy FQDN and can establish an SSL connection to it)
SSL certificate of the Microsoft download servers. This certificate must be trusted by your proxy server itself, as the proxy is the one establishing the final connection and needs to trust the endpoint. Non-Windows machines might not trust this second certificate by default, so you might need to ensure that it's trusted.
To deploy the Arc resource bridge, you need to download images to the management machine and then upload them to the on-premises private cloud gallery. If your proxy server throttles download speed, you might not be able to download the required images (~3.5 GB) within the allotted time (90 minutes).
Exclusion list for no proxy
If you're using a proxy server, use the following table to configure the noProxy settings and exclude these addresses from the proxy.
| IP Address | Reason for exclusion |
|---|---|
| localhost, 127.0.0.1 | Localhost traffic |
| .svc | Internal Kubernetes service traffic (.svc) where .svc represents a wildcard name. This entry is similar to saying *.svc, but none is used in this schema. |
| 10.0.0.0/8 | Private network address space |
| 172.16.0.0/12 | Private network address space - Kubernetes Service CIDR |
| 192.168.0.0/16 | Private network address space - Kubernetes Pod CIDR |
| .contoso.com | You might want to exempt your enterprise namespace (.contoso.com) from being directed through the proxy. To exclude all addresses in a domain, add the domain to the noProxy list. Use a leading period rather than a wildcard (*) character. In the sample, the address .contoso.com excludes addresses prefix1.contoso.com, prefix2.contoso.com, and so on. |
The default value for noProxy is localhost,127.0.0.1,.svc,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16. While these default values work for many networks, you might need to add more subnet ranges or names to the exemption list. For example, you might want to exempt your enterprise namespace (.contoso.com) from being directed through the proxy. Add that namespace by specifying the value in the noProxy list.
Important
When listing multiple addresses for the noProxy settings, don't add a space after each comma to separate the addresses. The addresses must immediately follow the commas.
Internal port listening
The appliance VM is configured to listen on the following ports. These ports are used exclusively for internal processes and don't require external access:
- 8443 – Endpoint for Microsoft Entra Authentication Webhook
- 10257 – Endpoint for Arc resource bridge metrics
- 10250 – Endpoint for Arc resource bridge metrics
- 2382 – Endpoint for Arc resource bridge metrics
Next steps
- To learn more about requirements and technical details, see the Azure Arc resource bridge overview.
- To learn about security configuration and considerations, see security configuration and considerations for Azure Arc resource bridge.
- To view troubleshooting tips for networking issues, see troubleshooting tips for networking issues.