How do I block replication traffic passing through Azure NSv?

Description

If you are using an NSv  firewall to control outbound network traffic from VMs, the appliance might get throttled if all the replication traffic passes through the NSv. We recommend creating a network service endpoint in your virtual network for "Storage" so that the replication traffic does not go to the NSv.


Note that:

  • Azure's default system route for Azure VM replication is 0.0.0.0/0.
  • Typically, NSv deployments also define a default route (0.0.0.0/0) that forces outbound Internet traffic to flow through the NSv. The default route is used when no other specific route configuration can be found.
  • The same limitation also applies when using default routes for routing all Azure VM traffic to on-premises deployments.

Resolution


1. Creating Network Service Endpoint for Storage Under Home | Virtual Networks | [Your Virtual Network].

  • Select your Azure virtual network and click on 'Service endpoints'.

Image

 


2. Click Add and select ‘Microsoft Storage ‘ under ‘Service and Subnets should be selected as Select All and click ‘Add’.

 

Image

This will re-route the storage traffic away from Sonicwall NSv firewall.

Related Articles

  • Remediation Playbook
    Read More
  • How To change the SSO PSK
    Read More
  • How do I SSH into a SonicWall NSv Azure using SSH key pair?
    Read More
not finding your answers?
was this article helpful?