Azure

Azure Relay: No Inbound Ports Needed

How the cloud reaches a server it is not allowed to connect to.

What you'll learn

  • How the cloud reaches an on-prem service with no inbound port
  • Why the private side dials out to a rendezvous point instead
  • When Relay beats a VPN, and when a queue beats both
Azure 10 steps 32 seconds views

Was this useful?

Share

Understand it one step at a time

The short runs these in order in about 32 seconds. Here they are written out — pick any step to jump the short straight to it.

1 Step 1 of 10

Your ERP is behind the firewall

The cloud app needs live stock levels right now. The ERP system that actually has them sits on a private 10.x address in a Chennai datacenter.

Frequently asked questions

How does Azure Relay reach an on-premises service without an open inbound port?
The on-premises (private) side makes the outbound connection to a rendezvous point in Azure — the cloud side never initiates an inbound connection, so no firewall rule needs to be opened for it.
When would you use Relay instead of a VPN?
Relay suits reaching a single specific on-prem service without standing up full network-level connectivity. When more than a request/response link is needed, or the two sides don't need to be online at the same time, a VPN or a queue can be the better fit.

Free app · no app store

These are built for a phone

Every short is drawn at full portrait height, the shape a phone already is. Installed, it opens full-bleed with no address bar across the top — and the whole library reads offline.

How it works

Read deeper on Azure

Twenty seconds gets the shape of an idea across. These go into how it behaves in production.

More shorts

Get new posts by email

New technical articles, Azure AI and GitHub Copilot updates, and upcoming events. No spam, unsubscribe anytime.

navigate open