Create a Post

Outbound internet access not working on Azure VMSS scale set

We have an Azure VMSS scale set deployed with an internal and external load balancer. We are having issues getting internal hosts to access the internet. I created a HIDE NAT as follows:

Original src=, Original dest=ANY, Original service=ANY

Translated src=VMSS firewall object (HIDE)

I also have a policy rule permitting both the original src and the scale set access to ANY dest on ANY port


When I try to go to the Internet form host I see the traffic come into the vmss on eth1 and leave on eth0 (translated) but I get no return traffic from the Internet.

Is there something additional (besides the HIDE NAT) that we need to configure on the VMSS? Or is the issue outside the VMSS (in Azure).

0 Kudos
3 Replies
This widget could not be displayed.