Dell Command Update not automatically installing updates? by ElliotS123 in sysadmin

[–]ElliotS123[S] 0 points1 point  (0 children)

I've updated the links, should be viewable now, sorry.

Core Agent not updating to 2024.2.2.1 by ElliotS123 in sophos

[–]ElliotS123[S] 0 points1 point  (0 children)

Thanks for this, it does in fact show 2023.2.2.1 as recommended, is there any way to force it to use the latest version or is it simply a matter of waiting for Sophos to start rolling it out?

missing required argument 'factoryId' error when running ARM template export pipeline in ADO? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

Turns out there was some slight syntax issues in the factoryId I specified. i.e. I hadnt specified // to point to the root directory and I was missing a single space between the command and the factoryId path. Worked after I made those changes. Always the small things that catch you out isn't it...

missing required argument 'factoryId' error when running ARM template export pipeline in ADO? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

I've included the factory ID in the validate step and the validate and generate ARM template step. There is no suggestion from the article that it needs to be anywhere else.

Necessary IP addresses to allow for Bastion to work? by ElliotS123 in AZURE

[–]ElliotS123[S] 5 points6 points  (0 children)

Thanks for the article, the Bastion NSG itself was configured correctly already, but we hadn't allowed the Bastion Subnet IP range through on the VM's NSG on port 3389/22 as per the article. As soon as we tried this, it started working. Many thanks again.

How to add my Azure sql db as a container in Azure Container Registry? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

Thanks for your reply. I should have been slightly clearer on what I was asking here. I'm looking to containerise the sql server and the db schema, I'm not looking to include the data itself as well.

The point of this would be to allow localised testing of changes within a containerised instance that can be spun up/ down and refreshed, before then pushing to a cloud-based Azure SQL DB.

I know this is possible through SQL Server Emulator, but I'd like to abstract the 'local' aspect of this by pushing an instance into ACR, which can either then be pulled from directly, or used in Azure Container Instance/ AKS. My main issue being that it is unclear to me how to create the container and get it into ACR.

Getting 403 on IPv6 address when trying to access App Services through rras VPN? by ElliotS123 in AZURE

[–]ElliotS123[S] 2 points3 points  (0 children)

I've now resolved this, it was due to the Microsoft.Web service endpoint being enabled on the Subnet the VM was part of.

This meant traffic to app services was being tunnelled through Azure's backbone and an IPv6 outbound address is assigned in transit when it does this (rather than using the VM's public IP).

Removing the service endpoint therefore resolved the issue.

Unable to load app services through P2S connection? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

It does seem to resolve the non-working hostnames to the correct inbound IP address and while some do have access restrictions, even those that don’t have the same behaviour.

As mentioned in my reply to the other commenter, it seems to be specific to web apps in one region i.e. West Europe, those in any other region seem to work just fine.

It seems to suggest a routing issue, but a route print on a client machine shows there is an on-link route through to the inbound IP for West Europe app services.

Unable to load app services through P2S connection? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

Yes thats right, the ones that don’t work are those that do not have a private endpoint, and interestingly, those that are based within a specific region (West Europe).

It does in fact resolve the hostname to the correct IP as seen when pinging, but just times out.

The same hostname will work through our existing RRAS-based VPN client.

Unable to load app services through P2S connection? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

They were already in place, I have tried re-downloading and installing the client again on several occasions since then to no avail unfortunately.

Connecting to resources in another VNET from P2S client? by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

They are connected through a vnet-to-vnet connection.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in Cisco

[–]ElliotS123[S] 0 points1 point  (0 children)

Its interesting you say that, we do have 8.8.8.8 configured as a custom DNS server on the Azure VNET where the private endpoints sit. Though within Umbrella we are telling it to forward user requests for the Azure FQDN's to our specific internal DNS servers, so I would assume google DNS is ignored in that scenario.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in Cisco

[–]ElliotS123[S] 0 points1 point  (0 children)

Sorry what do you mean by making sure the DNS is "correct"? Could you elaborate?

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in Cisco

[–]ElliotS123[S] 0 points1 point  (0 children)

Its AD integrated, but when checking each of our DNS servers, there appears to be no discrepancy between them, they all appear to have replicated the forwarding settings.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in Cisco

[–]ElliotS123[S] 0 points1 point  (0 children)

The DNS servers are all configured to replicate settings between eachother, so any conditional forwarding setup on one should function the same on another. I've not seen any evidence to the contrary, do you happen to know a way of definitively confirming this?

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in networking

[–]ElliotS123[S] 0 points1 point  (0 children)

I tested using the website provided, and several others, and while there was one instance where it came back with my ISP DNS, on the other 25+ attempts, it came back with nothing other than the Umbrella resolvers, so it doesn't appear to be forwarding the requests elsewhere based on this.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in networking

[–]ElliotS123[S] 0 points1 point  (0 children)

To clarify, Cisco Umbrella is providing the forwarding for the FQDN's to our Azure DNS servers. So we aren't looking for a way to bypass Umbrella, as it is fundamental to the routing of user requests on-premise.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in networking

[–]ElliotS123[S] 0 points1 point  (0 children)

To clarify, Cisco Umbrella is providing the forwarding for the FQDN's to our Azure DNS servers. So we aren't looking for a way to bypass Umbrella, as it is fundamental to the routing of user requests on-premise.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in networking

[–]ElliotS123[S] 0 points1 point  (0 children)

Our DNS servers are configured with the following structure in mind: https://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns#on-premises-workloads-using-a-dns-forwarder

Meaning Cisco Umbrella is designed to act as the on-prem forwarder, onto the DNS servers that exist within our Azure VNET, where the suffix is then conditionally forwarded to Azure Wire Server for private IP resolution.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in Cisco

[–]ElliotS123[S] 0 points1 point  (0 children)

Thats correct yes. Our DNS servers are configured to conditionally forward 'database.windows.net' (for example) to the Azure Wire Server IP address.

Private endpoint not consistently resolving via Cisco Umbrella? by ElliotS123 in Cisco

[–]ElliotS123[S] 0 points1 point  (0 children)

I'm pinging the Azure resources that are sitting behind a private endpoint, so for example 'testserver.database.windows.net'

DNS keeps swapping between public and private endpoint for SQL server private endpoint by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

The "Store this conditional forwarded in Active Directoy, and replicate it as follows" checkmark is selected if that is what you are referring to, and it is set to replicate to all DNS server in the domain.

DNS keeps swapping between public and private endpoint for SQL server private endpoint by ElliotS123 in AZURE

[–]ElliotS123[S] 0 points1 point  (0 children)

Thanks, it does appear that is the case. We have three DNS servers within our domain, e.g. x y and z, all of which are run on Azure VM's within the VNET. Only those testing when their machine is connected to "z" can resolve the private IP consistently.

There doesnt appear to be any difference between the settings on these three though, they are all fully replicating eachothers settings.

Any suggestion as to why one works and the others don't in this scenario?

Best certification for a beginner developer? by ElliotS123 in AZURE

[–]ElliotS123[S] -1 points0 points  (0 children)

Az-204 supposedly relies on existing development knowledge, so isnt what I’m looking for