Wilfried Woivré

Cloud Solution Architect - MVP Microsoft Azure

Azure - Service IPs

Categories : Azure Azure

One of the requests that often comes up on Azure is that of setting up NSGs or firewalls in order to secure our assets in the Cloud. In recent years, Microsoft has done a remarkable job of providing capabilities such as Service Endpoints and Service Tags which are popularized by everyone. Now not all services have these features.

If you do a search on the internet you will find this page: Azure IP Range and Service Tags

If you download this document you will find a JSON file that you can parse to find the information you need. However, Azure datacenters are acquiring new capacities day after day, and as a result new IPs may appear in this file, it is therefore updated very regularly by Microsoft.

Before there was only this file, and even before it was XML, that we had to recover on a regular basis, then parse it then inject it into our NSG configurations.

Now, this mechanism is much simpler, because there is the command Get-AzNetworkServiceTag in Powershell, or az network list-service-tags in CLI to help you.

Below in Powershell, here is how to recover the IPs of the Azure Batch management nodes for the West Europe region:

  • 1st step *: Retrieve all the values for our region
PS C:\Users\wilfr> $allTags = Get-AzNetworkServiceTag -Location westeurope
PS C:\Users\wilfr> $allTags

Name         : Public
Id           : /subscriptions/e7bd1bb5-e9af-49c7-b5aa-ac09992fdfeb/providers/Microsoft.Network/serviceTags/Public
Type         : Microsoft.Network/serviceTags
Cloud        : Public
ChangeNumber : 65
Values       : {ApiManagement, ApiManagement.AustraliaCentral, ApiManagement.AustraliaCentral2, ApiManagement.AustraliaEast...}
  • 2nd step *: Filter only on the desired service
PS C:\Users\wilfr> $serviceName = "BatchNodeManagement.WestEurope"
PS C:\Users\wilfr> $serviceTag = $allTags.Values | Where { $_.Name -eq $serviceName }
PS C:\Users\wilfr> $serviceTag

Name             : BatchNodeManagement.WestEurope
System Service   : BatchNodeManagement
Region           : westeurope
Address Prefixes : {,,,}
Change Number    : 1
  • 3rd and last step *: Retrieve our Ips
PS C:\Users\wilfr> $serviceTag.Properties.AddressPrefixes

And here it remains only to put them in your NSG or in your Firewall configuration according to your network topology.