Network connection deny issue: can the windows operating system VM connect with private IP and public IP through 80,443 port if use windows VNet product together?

rain purple 340 Reputation points
2026-05-30T10:58:35.6233333+00:00

Hello, support team:

Is there anybody using windows **2025** operating system VM and try to connect them in the **same subnet** or **peering subnet** located in the same subscription through 80 or 443 port?

I try for more than six months, and then cannot solve this issue, also I send a support ticket to Azure portal support team, and now, don't know who takes response for this issue together.

Is there anyone try to fix it by yourself successfully?

or it's a very complex and professional issue that needs a very higher level engineer (that we cannot connect them with a fresh user role?) to fix it? 

Thanks a lot!

Have a good working week and relaxing weekend!

fresh user from Azure portal

Azure Virtual Machines
Azure Virtual Machines

An Azure service that is used to provision Windows and Linux virtual machines.

0 comments No comments

Answer accepted by question author

AI answer

2026-05-30T10:58:55.1333333+00:00

Yes, Windows Server/Windows client VMs in the same subnet or in peered subnets can communicate over ports 80 and 443 using both private IPs and (when exposed) public IPs, as long as network filtering and OS firewalls allow it.

For this scenario, the key checks are:

  1. Verify NSG rules on subnet and NIC
    • Go to the VM → Networking → check the Network security group on both the subnet and the NIC.
    • Ensure there is an Allow rule for:
      • Direction: Inbound
      • Protocol: TCP
      • Destination port ranges: 80 (for HTTP) and/or 443 (for HTTPS)
      • Source: the other VM’s IP, subnet range, or Any
      • Priority: lower number (higher priority) than any deny rules
    • A typical rule to allow HTTP from anywhere is:
      • Source: Any
      • Source port ranges: Any
      • Destination: IP of the VM, subnet, or Any
      • Destination port ranges: 80
      • Protocol: TCP
      • Action: Allow
      • Priority: 100
    • If NSGs are associated with both the subnet and the NIC, the port must be open in both NSGs for traffic to reach the VM.
  2. Check effective security rules
    • In the Azure portal, open the VM → Networking → select the NIC → Effective security rules.
    • Confirm there is no higher-priority Deny rule blocking ports 80 or 443.
  3. Use Network Watcher to test traffic
    • Use IP flow verify to test if traffic is allowed or denied and which rule is responsible.
    • Example (CLI) for testing inbound RDP (adapt similarly for ports 80/443):
           az network watcher test-ip-flow \
             --direction Inbound \
             --protocol TCP \
             --local 10.0.0.4:80 \
             --remote 10.0.1.4:* \
             --vm <vm-resource-id> \
             --nic <nic-name>
      
    • The result shows whether traffic is allowed or denied and which NSG rule is applied.
  4. Confirm OS-level configuration
    • On Windows VMs, ensure Windows Firewall allows inbound TCP 80/443.
    • Ensure the web service (IIS, custom app, etc.) is listening on 80/443 on the correct IP (usually bound to “All Unassigned” or the specific private IP).
  5. Validate IP configuration inside the VM
    • Do not manually assign the public IP inside the OS.
    • If setting a static IP in the OS, ensure it matches the private IP assigned to the NIC in Azure.
    • Run ipconfig /all inside the VM and verify the primary private IP matches the NIC’s primary IP.
  6. For peered VNets
    • Ensure VNet peering is configured to allow traffic between VNets and that no user-defined routes or NSGs block ports 80/443.
    • Use Connection troubleshoot in Network Watcher to test connectivity between source and destination VMs and see which NSG rule or configuration is causing issues.

If all these checks are correct, Windows VMs (including newer versions) in the same or peered subnets can communicate over ports 80 and 443 using private IPs, and via public IPs if inbound rules are explicitly opened.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.