Azure backup for vms - traffic not going to our firewall

Mohan Venkata Durgarao Y 40 Reputation points
2026-09-28T15:48:45.41+00:00

Hi ,

We recently enabled backup for all of our azure vms. One rsv per subscription which has one vnet only. All our backup data is not going through our firewall and going through azure backbone. Is there a way to divert traffic to our firewall

Thanks

Mohan

Azure Virtual Network
Azure Virtual Network

An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Stanislav Zhelyazkov 29,826 Reputation points MVP Volunteer Moderator
    2026-09-29T05:47:37.2133333+00:00

    Hi,

    It is not possible to pass the backup traffic through Azure Firewall or other firewall. "Azure VM backup: All the required communication and data transfer between storage and Azure Backup service happens within the Azure network without needing to access your virtual network. So back up of Azure VMs placed inside secured networks don't require you to allow access to any IPs or FQDNs.". The traffic does not passes through the vnet so you cannot use things like UDR (user-defined routes) to route it. Even if it was possible wouldn't be recommended as that most likely will cause throttle and latency issues.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-28T15:48:59.36+00:00

    For Azure VM backup, the backup traffic does not go through the virtual network or Azure Firewall. The data transfer between the VM disks, storage, and the Recovery Services vault happens on the Azure backbone network.

    Because of that, there isn’t a supported way to force standard Azure VM backup traffic through a firewall in the VNet.

    Key points:

    1. Azure VM backup doesn’t require allowing IPs or FQDNs in the VNet for backup traffic.
    2. The communication and data transfer stay within Azure’s internal network.
    3. If the goal is to inspect or control backup traffic with a firewall, that model doesn’t apply to VM-level Azure Backup.
    4. Private endpoints are relevant for workloads such as SQL Server on Azure VM, SAP HANA on Azure VM, and MARS/on-premises servers, where secure network connectivity to the Recovery Services vault is needed.

    If the requirement is specifically to send backup-related traffic through a firewall, that applies to some workload backups inside VMs, not to Azure VM backup itself.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.