US .gov websites blocking Azure IP's

We have a few clients in AVD where .gov sites are blocking pretty much all Azure IP's.  We've tried static on a NAT Gateway, different regions, etc.. same result.  For one client we ended up doing a site-to-site VPN with a proxy on the client's office Sophos XG firewall. That client's local firewall is now being replaced and SonicWall does not support that feature. 
 We have looked at a few different proxy services and so far, none of them support using it for .gov sites.

Curious how anyone else is dealing with this.

 

Thanks!

0

Comments (2 comments)

0
Avatar
Dave Stephenson

I know I've seen that kind of behavior with some sites (Reddit, YouTube, etc.) requiring a login to access the sites from an Azure IP, but never being blocked all together like that.

You could reach out to those individual .gov agencies to get your Public IP whitelisted, but that may take a while.

Another alternative would be to configure a firewall (Azure FireWall, SonicWall virtual appliance, etc.) in Azure and route your internet traffic through to the on-prem network. (see Azure Firewall forced tunneling | Microsoft Learn)

It could be potentially pretty difficult to setup, but if that's what the customer needs, it might be worth it.

0
Avatar
Phil Long

Jay Edlin  Hi Jay, not sure if you found a legitimate awnser to this but I have seen many websites, not just government sites, filter blocks of Azure (and maybe other datacenter) IP addresses.  

It does tend to be bank websites or other personal informational type sites but I have seen it happen with very random websites.  A client cant access a website from their session host but can from thier local machine in thier office.  I can check the website from another clients session host in the same region and its blocked but sometime NOT blocked from a completely different region (different block of IPs).  I have even gone as far as to run an Onion browser in the same session host and was able to browser to the site successfully. 

I have tried submitting requests to webhosts to get an ALLOW added for the clients IP but that usually goes nowhere.  Sometimes you might get lucky and pull an IP for a new Public IP and NAT Gateway that is outside the scope of the website blocking list but if its government sites they probably have a pretty broad list of IPs.  

   
I know thats not an awnser to your issue but “you are not alone” 

Please sign in to leave a comment.