NAT and NAT Gateway in Azure

Поділитися
Вставка
  • Опубліковано 7 сер 2024
  • A walkthrough of how NAT works in Azure and how the new NAT Gateway can be leveraged. Rounded off with a demo!
  • Наука та технологія

КОМЕНТАРІ • 71

  • @henriquealexandreh
    @henriquealexandreh 2 роки тому

    Objective and concise explanation. Thanks a mil John. Have a lovely weekend!

  • @VijayKumar-id9vy
    @VijayKumar-id9vy 3 роки тому +2

    Hey John, This video is useful and clear to understand. Thank you for making this video.

  • @sruthireddy1979
    @sruthireddy1979 Рік тому

    Thank you so much John .. you explain very well with depth yet simple way... You are a great trainer 👍

  • @SynysterGuitarX
    @SynysterGuitarX Рік тому +1

    As always, very good explanation John! We actually are going to use the NatGw and this video will clear up alot of questions. 👍🏻

  • @prashanth4899
    @prashanth4899 4 роки тому +1

    Premium quality explanation.
    Love to watch your videos.

  • @maciejpakulski1182
    @maciejpakulski1182 2 роки тому

    As always, super high quality content. Thanks !

  • @johnashby8461
    @johnashby8461 4 роки тому

    Great overview! The AZ explanation is excellent.

  • @user-bn1sl1us2d
    @user-bn1sl1us2d 4 роки тому +1

    Thanks for the demo and lecture.

  • @iamdedlok
    @iamdedlok 3 роки тому +1

    John, my man, you are a legend. Thank you so much. Best video on the internet to explain Azure NAT/NAT Gateway. Your videos alone makes youtube premium worth it.

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +4

      Great but I have no advertising on my videos anyway. You don’t need premium :)

    • @iamdedlok
      @iamdedlok 3 роки тому +1

      @@NTFAQGuy Fantastic ;-) More kudos to you!

  • @stuartwilliams7103
    @stuartwilliams7103 2 роки тому

    Thanks John a very useful recap on NAT Gateway

  • @angellopez6687
    @angellopez6687 2 роки тому

    This tutorial is just excellent. Thanks John!!

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      You're very welcome!

  • @JS-vl5gd
    @JS-vl5gd 3 роки тому +3

    Great tech videos as always, John! By the way, the 172 ip range goes from 172.16.x.x to 172.31.x.x The 172.12.x.x would be a public ip address. I don't know that much it's just that that range was hammered into my head last week that now I can tell the private ip ranges from the public ones! Keep up the good work!

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +4

      Yep sometimes my brain does strange things :) thanks

  • @sambhavpandey
    @sambhavpandey 2 роки тому

    Very nicely explained Azure NAT. thank you.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому +1

      Glad it was helpful!

  • @chrisadams27
    @chrisadams27 Рік тому

    Great video, thank you!

  • @david1dinan
    @david1dinan 4 роки тому

    Great explanation.

  • @DANISHAAMIR786
    @DANISHAAMIR786 4 роки тому +1

    Hi, I love to watch your videos. Great work. Can you please make a video explaining azure Load balancer with multiple frontend and also cosmos db logical and physical partition key concept.
    Thanks.

  • @MassaKingWOfficial
    @MassaKingWOfficial 2 роки тому

    Oh shit, feels like I timed traveled lol
    I'm so used to the new video format that this video hit me different when my browser was done rendering it
    😁

  • @nareshgb1
    @nareshgb1 5 місяців тому

    great video.

  • @deepeshshah8095
    @deepeshshah8095 3 роки тому

    Hey John, once again awesome video. Can you please cover one video for VWan Hub please.

  • @sajidshamir
    @sajidshamir 4 роки тому

    nice work..

  • @MMTheWGA
    @MMTheWGA 4 роки тому +1

    Thanks John, very clearly explained from the ground up! Thought you would be using BING for the IP address search, not Goog....!! :-P

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +4

      hehe. I did try bing first but it does not show your IP if you just ask that question and instead I would have had to use a site like whatismyip that then shows a bunch of adverts. This was the lesser evil ;-)

  • @yuhechen7258
    @yuhechen7258 4 роки тому

    Very useful.

  • @therockfaith
    @therockfaith 3 роки тому

    you are awesome :)
    Thanks a lot

  • @maxsnts
    @maxsnts 4 роки тому

    How does this behave in the case of traffic that opens a connection one way and expects the remote peer to open a connection back, like passive FTP connections for instance?

  • @yahorsinkevich4451
    @yahorsinkevich4451 3 роки тому +1

    Nice! Thank you! Wondering why there is no private NAT Gateways :) To do the same kind of thing but withing VNET

  • @jimmy9297
    @jimmy9297 3 роки тому

    #JohnSavill , I am always a fan of your great videos, your dedication and discipline towards the work :) . Keep posting, keep sharing

  • @suzukisamurai99
    @suzukisamurai99 3 роки тому

    Great video! John.. quick question: i need to have a subnet spanning multiple AZs with computer resources on multiple AZs. In this case should i have just 1 regional NAT gateway instead of multiple zonal gateways?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому +1

      if subnet is spanning AZs then yes you would go regional but realize thats not the same as zone-redundant and you have no visibility into how its implemented. Your safest is to have separate subnets per AZ with zonal gateway or don't use nat gateway and use standard load balancer with NAT rules.

  • @SecurityMadeSimple
    @SecurityMadeSimple 3 роки тому

    what an absolute awesome video a major light bulb moment 😂

  • @dunx182
    @dunx182 3 роки тому

    Thanks for the great video. Out of interest (and completely off topic), how many Ironmans have you done?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      15 fulls. Hopefully another 5 in 2021 if COVID allows :)

  • @Kavinnathcse
    @Kavinnathcse 3 роки тому

    Excellent tutorial.. for ipv6 we have Egress-only internet gateways in aws. Is there similar services in azure?

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      For regular internet egress you don’t need a special gateway in azure unless you want it. It is natively available. I cover this in the azure networking lesson of the masterclass.

  • @maltek6457
    @maltek6457 2 роки тому +1

    Is the NAT Gateway compatible with an Azure Firewall?
    For now I have setup the Azure Firewall for inbounrd traffic but if I want to use it for outbound in the future aswell do I bypass the Firewall if I use a NAT Gateway?

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому +1

      Docs discuss their default behavior. docs.microsoft.com/en-us/azure/firewall/integrate-with-nat-gateway

  • @josephmathew9662
    @josephmathew9662 4 роки тому

    Can nat gateway replace az firewall for outbound network traffic if for a budget friendly architecture?

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      not sure about budget replacement :-) but you can certainly use nat gateway to facilitate outbound however realize azure firewall has a lot of other capabilities. Depends on what you need.

  • @maxsnts
    @maxsnts 4 роки тому +2

    Not to be pedantic, but the private space at 172 starts at 16 does it not? making 172.12 a public address?

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому

      Quite right, whoops :) too many numbers in my head :)

    • @maxsnts
      @maxsnts 4 роки тому

      @@NTFAQGuy Happens to everyone.
      Good luck for Ironman!

  • @1234croydon
    @1234croydon 4 роки тому +2

    Hi.. great video as always John. I have a query about usage of Nat gateway public ip with function app. I have a function app which is vnet integrated (regional) and its associated to a subnet. This subnet is attached to a NAT gateway which has a public ip. The problem I am trying to solve is by default the outbound ip of a function app is a list of possible ip’s which could potentially change and the api provider will need to whitelist the new IP. I tried the above setup but the outbound request still originated from the function app listed ip and not the nat gateway is. Hopefully this question made sense. If not please let me know I will try to rephrase it😊

    • @NTFAQGuy
      @NTFAQGuy  4 роки тому +1

      I'm afraid I've not tried that configuration. I'd have to set that up but not something have cycles to do right now, sorry :-(

    • @bazookaman3
      @bazookaman3 4 роки тому +2

      Vnet integration, by default, only sends outbound traffic to your vnet that is RFC1918. Try the application setting for WEBSITE_VNET_ROUTE_ALL as described here docs.microsoft.com/en-us/azure/app-service/web-sites-integrate-with-vnet . I’m wondering if nat gateway will pick up the traffic after that?

    • @1234croydon
      @1234croydon 4 роки тому

      BazookaMan3 i did try that setting. Unfortunately that still picked the function app ip and not Nat gateway :(

  • @MuhammadWaqas-gr4gg
    @MuhammadWaqas-gr4gg 2 роки тому

    Hello John, What i got is, even if we deploy a VM in seperate AZ and NAT Gateway in another AZ but VM subnet is associated with NAT gateway.....in that case VM traffic will also route through Nat Gateway...however this is not good approach...m i right????

  • @IvanIvanov-kn5oz
    @IvanIvanov-kn5oz 2 роки тому

    If you have a session coming from outside to the public address of the VM, which path the return traffic will take?? through NAT gateway?? They are using different public addresses and you won`t be able to establish a session. Is there any kind of source NAT when session is coming from outside to public address of the VM??

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому

      Return uses same path as ingress

  • @prasadpandit5735
    @prasadpandit5735 3 роки тому

    Hi... Can you please let me know how to remove NAT gateway from the subnet using Azure powershell

    • @NTFAQGuy
      @NTFAQGuy  3 роки тому

      that is covered in the docs. just search for remove nat gateway azure powershell

  • @mike9611
    @mike9611 2 роки тому

    When using the NAT Gateway resource is the outbound public IP only for your networks that use it? Pretty sure the answer is yes. I just want to be sure that I am the only one using that outbound IP for setting up policies for restrictions to other resources in azure and elsewhere based upon IP.
    I imagine if I don't use this or some similar resource to restrict outbound to the public internet that it uses a shared public IP that would not be as useful to use for restricting traffic.

    • @mike9611
      @mike9611 2 роки тому

      And thank you for all the amazing videos! I have learned so much in a very short time thanks to you.

    • @NTFAQGuy
      @NTFAQGuy  2 роки тому +1

      Yes. Only subnets connected

  • @MrJ0SH81
    @MrJ0SH81 3 роки тому

    Skip right to NAT Gateways here 9:33