Azure Relay: No Inbound Ports Needed
How the cloud reaches a server it is not allowed to connect to.
What you'll learn
- How the cloud reaches an on-prem service with no inbound port
- Why the private side dials out to a rendezvous point instead
- When Relay beats a VPN, and when a queue beats both
Share this passage
Drawing…
Understand it one step at a time
The short runs these in order in about 32 seconds. Here they are written out — pick any step to jump the short straight to it.
Your ERP is behind the firewall
The cloud app needs live stock levels right now. The ERP system that actually has them sits on a private 10.x address in a Chennai datacenter.
Frequently asked questions
- How does Azure Relay reach an on-premises service without an open inbound port?
- The on-premises (private) side makes the outbound connection to a rendezvous point in Azure — the cloud side never initiates an inbound connection, so no firewall rule needs to be opened for it.
- When would you use Relay instead of a VPN?
- Relay suits reaching a single specific on-prem service without standing up full network-level connectivity. When more than a request/response link is needed, or the two sides don't need to be online at the same time, a VPN or a queue can be the better fit.
Free app · no app store
These are built for a phone
Every short is drawn at full portrait height, the shape a phone already is. Installed, it opens full-bleed with no address bar across the top — and the whole library reads offline.
Read deeper on Azure
Twenty seconds gets the shape of an idea across. These go into how it behaves in production.
-
AI Bot Attacks on a Mobile App Login, and How Azure Stops Them
A script tries 8,000 passwords a minute against your login API at 3am. Rate limiting, smart lockout and Defender for Cloud make speed the losing move.
-
Azure Key Vault Explained: The One Secret Tutorials Never Remove
Moving every secret into Key Vault leaves exactly one behind: the credential that opens the vault. A managed identity is what removes it.
-
How to Secure a Mobile API on Azure in Five Steps, in the Right Order
HTTPS only, authentication, authorization, secrets and monitoring: five steps to secure a mobile API on Azure, and why the order carries most of the value.
More shorts
-
Azure
Money debited. Order failed.
10 steps · 56s
-
Azure
One tap. Two orders.
10 steps · 57s
-
Azure
1.6 million downloads. One photo.
10 steps · 58s
Get new posts by email
New technical articles, Azure AI and GitHub Copilot updates, and upcoming events. No spam, unsubscribe anytime.