NSG的默认规则如下。
入站:
+-----------------------------------+----------+--------------------+-------------+-----------------+------------------+----------+--------+
| Name | Priority | Source IP | Source Port | Destination IP | Destination Port | Protocol | Access |
+-----------------------------------+----------+--------------------+-------------+-----------------+------------------+----------+--------+
| ALLOW VNET INBOUND | 65000 | VIRTUAL_NETWORK | * | VIRTUAL_NETWORK | * | * | ALLOW |
| ALLOW AZURE LOAD BALANCER INBOUND | 65001 | AZURE_LOADBALANCER | * | * | * | * | ALLOW |
| DENY ALL INBOUND | 65500 | * | * | * | * | * | DENY |
+-----------------------------------+----------+--------------------+-------------+-----------------+------------------+----------+--------+出站:
+-------------------------+----------+-----------------+-------------+-----------------+------------------+----------+--------+
| Name | Priority | Source IP | Source Port | Destination IP | Destination Port | Protocol | Access |
+-------------------------+----------+-----------------+-------------+-----------------+------------------+----------+--------+
| ALLOW VNET OUTBOUND | 65000 | VIRTUAL_NETWORK | * | VIRTUAL_NETWORK | * | * | ALLOW |
| ALLOW INTERNET OUTBOUND | 65001 | * | * | INTERNET | * | * | ALLOW |
| DENY ALL OUTBOUND | 65500 | * | * | * | * | * | DENY |
+-------------------------+----------+-----------------+-------------+-----------------+------------------+----------+--------+如果与此NSG关联的虚拟机打开internet浏览器并导航到某个网站,如何将该网站返回给该虚拟机?
据我所知,允许出站流量,但只允许来自VNET或LB的流量返回。
虚拟机是否会发出HTTP请求,该请求将命中目标服务器,并将响应发送回虚拟机,最终会被NSG阻止?
发布于 2019-09-13 14:33:14
因为允许出站流量-连接已建立,且数据包正在使用已建立的连接。NSG阻止创建新连接,不接触现有连接。
https://stackoverflow.com/questions/57918334
复制相似问题