An Azure network security service that is used to protect Azure Virtual Network resources.
Firewall blocking port 9000 traffic to 10.255.0.x across multiple tenants
I am seeing ongoing firewall blocks on port 9000 across two different managed tenants and wanted to check if this pattern is expected platform behavior or if anyone has insights into it.
Here are the details from our firewall logs stretching back over the last month:
Tenant A: Traffic is originating from an Azure SQL Managed Instance subnet and attempting to route toward 10.255.0.x on port 9000, which is being actively blocked by the firewall.
Tenant B: We are observing continuous traffic coming from everywhere (external/random sources) attempting to send to that exact same IP address (10.255.0.x) and port (9000), which is also being blocked by the firewall.
Are these port 9000 patterns recognised internal platform probes, telemetry, or typical background scanning noise? Any guidance from the community or MVPs would be greatly appreciated.