{"id":5516,"date":"2017-03-23T12:00:07","date_gmt":"2017-03-23T16:00:07","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/azuregov\/?p=5516"},"modified":"2017-03-23T12:00:07","modified_gmt":"2017-03-23T16:00:07","slug":"setting-up-vnet-integration-in-app-services-using-powershell","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/setting-up-vnet-integration-in-app-services-using-powershell\/","title":{"rendered":"Setting up VNET integration in App Services using Powershell"},"content":{"rendered":"<p>One of the capabilities in the Web Apps Service is placing your Azure resources in a non-internet routable network that you can control access to. These networks can be connected to your on-premise networks using VPN technologies. For example, with VNET integration you can enable access from your web app to resources running on a virtual machine in your Azure virtual network. <strong>\u00a0<\/strong>It is important to note that this will not isolate your WebApp from the internet, but rather enable it and other resources to operate within the integrated VNET.<\/p>\n<p>We will be enabling the UI\u00a0 aspect of this feature in the upcoming months. In the meantime, here is information on how to enable VNET integration via PowerShell:<\/p>\n<p>To begin, we&#8217;ll be referencing a slightly modified version of the script found in <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service-web\/app-service-vnet-integration-powershell\">this<\/a> article describing how to enable VNET integration in ARM\u00a0 and ASM\u00a0 through PowerShell. We&#8217;re going to focus on ARM for this implementation.<\/p>\n<p>First, you&#8217;ll need a copy of the script \u2013 very slightly modified to enable compatibility with Azure Government. Below is a copy of this script which you can save locally to get started. Once complete, open and run the script and you will be presented with a series of prompts. These prompts will guide you through the actual integration of your VNET with minimal effort as shown below.<\/p>\n<p><a href=\"https:\/\/msdnshared.blob.core.windows.net\/media\/2017\/03\/AzureGovVNETIntegration.txt\">azuregovvnetintegration<\/a> (script)<\/p>\n<p><strong>Step <\/strong><strong>1<\/strong><strong> &#8211; Log In<\/strong><\/p>\n<p><a href=\"https:\/\/blogs.msdn.microsoft.com\/azuregov\/?attachment_id=5525\"><img decoding=\"async\" width=\"562\" height=\"383\" class=\"aligncenter size-full wp-image-5525\" alt=\"1\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/148.png\" \/><\/a><\/p>\n<p><strong>Step <\/strong><strong>2<\/strong><strong> &#8211; Enter in the configuration data for your web app, and select a VNET Configuration option<\/strong><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"315\" height=\"262\" class=\"aligncenter size-full wp-image-5535\" alt=\"2\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/230.png\" \/><\/a><\/p>\n<p><strong>Step <\/strong><strong>3<\/strong><strong> &#8211; If you select to a create a new VNET, you will be prompted to review the proposed configuration. Select NO to accept the defaults.<\/strong><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"626\" height=\"268\" class=\"aligncenter size-full wp-image-5545\" alt=\"3\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/322.png\" \/><\/a><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"286\" height=\"113\" class=\"aligncenter size-full wp-image-5555\" alt=\"4\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/414.png\" \/><\/a><\/p>\n<p><strong>Step <\/strong><strong>4<\/strong><strong> &#8211; After selecting the VNET configuration options, the script will begin integrating the VNET and creating the appropriate VNET Gateway, shown above<\/strong><\/p>\n<p><em>\u00a0<a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"634\" height=\"213\" class=\"aligncenter size-full wp-image-5556\" alt=\"5\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/513.png\" \/><\/a><\/em><\/p>\n<p>Note: At this point, take a coffee break. The gateway can and will take up to an hour to finalize and complete.\u00a0 Once this is done you should be rewarded with no errors and a clean \u201cFinished!\u201d message as shown below.<\/p>\n<p>With the script execution complete, you\u2019ll want to test to ensure your integration was successful. This is as simple as creating a new VM on the same VNET to ensure connectivity is established using a built-in tool (TCPPing.exe).<\/p>\n<p><strong>Step <\/strong><strong>5<\/strong><strong> &#8211; Finished with the integration, continue for verification and testing<\/strong><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"343\" height=\"192\" class=\"aligncenter size-full wp-image-5565\" alt=\"6\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/612.png\" \/><\/a><\/p>\n<p><strong>Step <\/strong><strong>6<\/strong><strong> &#8211; Ensure your VNET has a subnet you can put add a VM to by creating a new subnet if needed.<\/strong><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"628\" height=\"472\" class=\"aligncenter size-full wp-image-5575\" alt=\"7\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/79.png\" \/><\/a><\/p>\n<p><strong>Step <\/strong><strong>7<\/strong><strong> &#8211; Deploy a new VM and confirm the Private IP is accurately assigned to the subnet you just made, as shown above.<\/strong><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"937\" height=\"485\" class=\"aligncenter size-full wp-image-5585\" alt=\"8\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/810.png\" \/><\/a><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><\/a><\/p>\n<p>Once your VM has been deployed you can then log into the KUDU console for debugging your Webapp. This can be found by adding .scm to your webapps URL, for example: <u>&lt;yourwebappname&gt;<strong>.scm.<\/strong>azurewebsites.us<\/u> .\u00a0 Navigate to the CMD Debug Console and utilize the TCPPING.exe tool to execute your test.<\/p>\n<p>IMPORTANT: Please ensure you specify a listening port for the TCPPing test. By default TCPPing will leverage port :80 which is not set to respond on a freshly provisioned VM. I\u2019ve demonstrated using :3389, which is the default RDP port for Windows, and will generally be responsive for Windows VMs.<\/p>\n<p><strong>Step <\/strong><strong>8<\/strong><strong> &#8211; Finally, log in to your WebApps KUDU Debug console and attempt to ping your VM<\/strong><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/\"><img decoding=\"async\" width=\"725\" height=\"618\" class=\"aligncenter size-full wp-image-5595\" alt=\"9\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/43\/2019\/03\/98.png\" \/><\/a><\/p>\n<p>Please refer to <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/app-service-web\/web-sites-integrate-with-vnet\">this<\/a> article for more information on VNET integration.<\/p>\n<p>We welcome your comments and suggestions to help us continually improve your Azure Government experience. To stay up to date on all things Azure Government, be sure to subscribe to our <a href=\"https:\/\/blogs.msdn.microsoft.com\/azuregov\/feed\/\">RSS feed<\/a> and to receive emails, click \u201cSubscribe by Email!\u201d on the <a href=\"https:\/\/blogs.msdn.microsoft.com\/azuregov\/\">Azure Government Blog<\/a>. To experience the power of Azure Government for your organization, sign up for an <a href=\"https:\/\/azuregov.microsoft.com\/trial\/azuregovtrial\">Azure Government Trial<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the capabilities in the Web Apps Service is placing your Azure resources in a non-internet routable network that you can control access to. These networks can be connected to your on-premise networks using VPN technologies. For example, with VNET integration you can enable access from your web app to resources running on a [&hellip;]<\/p>\n","protected":false},"author":1791,"featured_media":20423,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6,25],"tags":[55,462,591],"class_list":["post-5516","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-connectivity","category-portalpreview","tag-app-services","tag-powershell","tag-vnet-integration"],"acf":[],"blog_post_summary":"<p>One of the capabilities in the Web Apps Service is placing your Azure resources in a non-internet routable network that you can control access to. These networks can be connected to your on-premise networks using VPN technologies. For example, with VNET integration you can enable access from your web app to resources running on a [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/5516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/1791"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=5516"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/5516\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/20423"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=5516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=5516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=5516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}