Search code examples
azurecloudvpnazure-vpnhybrid-cloud

Azure Bastion for Hybrid Cloud Environment


Is there any way to use Azure Bastion to connect to on-prem systems as well as Azure virtual machines? I have a hybrid cloud environment where some key machines are on-prem and some are Azure VMs. The Azure VNet is extended with a VPN tunnel so the azure VMs can talk to the on-prem machines. In Googling my question, I was not able to find much...

  • The official page for Azure Bastion describes it as '''Azure Bastion is provisioned directly in your Virtual Network (VNet) and supports all VMs in your Virtual Network (VNet)'''
  • This page talks about hybrid envrionments https://blog.ahasayen.com/introducing-azure-bastion/ , saying: '''You might also have some sort of hybrid connectivity with your on-premises network and when you are outside the office, you use point to site VPN to securely access your VNET, which is the ideal situation.'"
  • I am aware of Azure Arc which is currently in preview. Would something like that be appropriate to make this work?

My overall questions are:

  • Am I totally barking up the wrong tree here? Is my understanding off?
  • Is it possible to use Azure Bastion to access an on-prem server on an extended VNet?

Thanks in advance!


Solution

  • This is now possible via the new capabilities introduced in Azure Bastion Standard Tier.

    https://learn.microsoft.com/en-us/azure/bastion/connect-ip-address