Skip to content

Commit b0d1275

Browse files
Add new afs.azure.net sync and discovery endpoints
Adding afs.azure.net regional sync and discovery endpoints, as well as adjusting wording to favor the afs.azure.net domain as one.microsoft.com is on the deprecation path for sync.
1 parent 15956d4 commit b0d1275

File tree

1 file changed

+21
-20
lines changed

1 file changed

+21
-20
lines changed

articles/storage/files/storage-sync-files-firewall-and-proxy.md

Lines changed: 21 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -95,38 +95,39 @@ The following table describes the required domains for communication:
9595
| **Microsoft PKI** | https://www.microsoft.com/pki/mscorp/cps<br><http://ocsp.msocsp.com> | https://www.microsoft.com/pki/mscorp/cps<br><http://ocsp.msocsp.com> | Once the Azure File Sync agent is installed, the PKI URL is used to download intermediate certificates required to communicate with the Azure File Sync service and Azure file share. The OCSP URL is used to check the status of a certificate. |
9696
9797
> [!Important]
98+
> When allowing traffic to &ast;.afs.azure.net, traffic is only possible to the sync service. There are no other Microsoft services using this domain.
9899
> When allowing traffic to &ast;.one.microsoft.com, traffic to more than just the sync service is possible from the server. There are many more Microsoft services available under subdomains.
99100
100-
If &ast;.one.microsoft.com is too broad, you can limit the server's communication by allowing communication to only explicit regional instances of the Azure Files Sync service. Which instance(s) to choose depends on the region of the storage sync service you have deployed and registered the server to. That region is called "Primary endpoint URL" in the table below.
101+
If &ast;.afs.azure.net or &ast;.one.microsoft.com is too broad, you can limit the server's communication by allowing communication to only explicit regional instances of the Azure Files Sync service. Which instance(s) to choose depends on the region of the storage sync service you have deployed and registered the server to. That region is called "Primary endpoint URL" in the table below.
101102
102103
For business continuity and disaster recovery (BCDR) reasons you may have specified your Azure file shares in a globally redundant (GRS) storage account. If that is the case, then your Azure file shares will fail over to the paired region in the event of a lasting regional outage. Azure File Sync uses the same regional pairings as storage. So if you use GRS storage accounts, you need to enable additional URLs to allow your server to talk to the paired region for Azure File Sync. The table below calls this "Paired region". Additionally, there is a traffic manager profile URL that needs to be enabled as well. This will ensure network traffic can be seamlessly re-routed to the paired region in the event of a fail-over and is called "Discovery URL" in the table below.
103104
104105
| Cloud | Region | Primary endpoint URL | Paired region | Discovery URL |
105106
|--------|--------|----------------------|---------------|---------------|
106-
| Public |Australia East | https:\//kailani-aue.one.microsoft.com | Australia Southeast | https:\//tm-kailani-aue.one.microsoft.com |
107-
| Public |Australia Southeast | https:\//kailani-aus.one.microsoft.com | Australia East | https:\//tm-kailani-aus.one.microsoft.com |
107+
| Public |Australia East | https:\//australiaeast01.afs.azure.net<br>https:\//kailani-aue.one.microsoft.com | Australia Southeast | https:\//tm-australiaeast01.afs.azure.net<br>https:\//tm-kailani-aue.one.microsoft.com |
108+
| Public |Australia Southeast | https:\//australiasoutheast01.afs.azure.net<br>https:\//kailani-aus.one.microsoft.com | Australia East | https:\//tm-australiasoutheast01.afs.azure.net<br>https:\//tm-kailani-aus.one.microsoft.com |
108109
| Public | Brazil South | https:\//brazilsouth01.afs.azure.net | South Central US | https:\//tm-brazilsouth01.afs.azure.net |
109-
| Public | Canada Central | https:\//kailani-cac.one.microsoft.com | Canada East | https:\//tm-kailani-cac.one.microsoft.com |
110-
| Public | Canada East | https:\//kailani-cae.one.microsoft.com | Canada Central | https:\//tm-kailani.cae.one.microsoft.com |
111-
| Public | Central India | https:\//kailani-cin.one.microsoft.com | South India | https:\//tm-kailani-cin.one.microsoft.com |
112-
| Public | Central US | https:\//kailani-cus.one.microsoft.com | East US 2 | https:\//tm-kailani-cus.one.microsoft.com |
113-
| Public | East Asia | https:\//kailani11.one.microsoft.com | Southeast Asia | https:\//tm-kailani11.one.microsoft.com |
114-
| Public | East US | https:\//kailani1.one.microsoft.com | West US | https:\//tm-kailani1.one.microsoft.com |
115-
| Public | East US 2 | https:\//kailani-ess.one.microsoft.com | Central US | https:\//tm-kailani-ess.one.microsoft.com |
110+
| Public | Canada Central | https:\//canadacentral01.afs.azure.net<br>https:\//kailani-cac.one.microsoft.com | Canada East | https:\//tm-canadacentral01.afs.azure.net<br>https:\//tm-kailani-cac.one.microsoft.com |
111+
| Public | Canada East | https:\//canadaeast01.afs.azure.net<br>https:\//kailani-cae.one.microsoft.com | Canada Central | https:\//tm-canadaeast01.afs.azure.net<br>https:\//tm-kailani.cae.one.microsoft.com |
112+
| Public | Central India | https:\//centralindia01.afs.azure.net<br>https:\//kailani-cin.one.microsoft.com | South India | https:\//tm-centralindia01.afs.azure.net<br>https:\//tm-kailani-cin.one.microsoft.com |
113+
| Public | Central US | https:\//centralus01.afs.azure.net<br>https:\//kailani-cus.one.microsoft.com | East US 2 | https:\//tm-centralus01.afs.azure.net<br>https:\//tm-kailani-cus.one.microsoft.com |
114+
| Public | East Asia | https:\//eastasia01.afs.azure.net<br>https:\//kailani11.one.microsoft.com | Southeast Asia | https:\//tm-eastasia01.afs.azure.net<br>https:\//tm-kailani11.one.microsoft.com |
115+
| Public | East US | https:\//eastus01.afs.azure.net<br>https:\//kailani1.one.microsoft.com | West US | https:\//tm-eastus01.afs.azure.net<br>https:\//tm-kailani1.one.microsoft.com |
116+
| Public | East US 2 | https:\//eastus201.afs.azure.net<br>https:\//kailani-ess.one.microsoft.com | Central US | https:\//tm-eastus201.afs.azure.net<br>https:\//tm-kailani-ess.one.microsoft.com |
116117
| Public | Japan East | https:\//japaneast01.afs.azure.net | Japan West | https:\//tm-japaneast01.afs.azure.net |
117118
| Public | Japan West | https:\//japanwest01.afs.azure.net | Japan East | https:\//tm-japanwest01.afs.azure.net |
118119
| Public | Korea Central | https:\//koreacentral01.afs.azure.net/ | Korea South | https:\//tm-koreacentral01.afs.azure.net/ |
119120
| Public | Korea South | https:\//koreasouth01.afs.azure.net/ | Korea Central | https:\//tm-koreasouth01.afs.azure.net/ |
120121
| Public | North Central US | https:\//northcentralus01.afs.azure.net | South Central US | https:\//tm-northcentralus01.afs.azure.net |
121-
| Public | North Europe | https:\//kailani7.one.microsoft.com | West Europe | https:\//tm-kailani7.one.microsoft.com |
122+
| Public | North Europe | https:\//northeurope01.afs.azure.net<br>https:\//kailani7.one.microsoft.com | West Europe | https:\//tm-northeurope01.afs.azure.net<br>https:\//tm-kailani7.one.microsoft.com |
122123
| Public | South Central US | https:\//southcentralus01.afs.azure.net | North Central US | https:\//tm-southcentralus01.afs.azure.net |
123-
| Public | South India | https:\//kailani-sin.one.microsoft.com | Central India | https:\//tm-kailani-sin.one.microsoft.com |
124-
| Public | Southeast Asia | https:\//kailani10.one.microsoft.com | East Asia | https:\//tm-kailani10.one.microsoft.com |
125-
| Public | UK South | https:\//kailani-uks.one.microsoft.com | UK West | https:\//tm-kailani-uks.one.microsoft.com |
126-
| Public | UK West | https:\//kailani-ukw.one.microsoft.com | UK South | https:\//tm-kailani-ukw.one.microsoft.com |
124+
| Public | South India | https:\//southindia01.afs.azure.net<br>https:\//kailani-sin.one.microsoft.com | Central India | https:\//tm-southindia01.afs.azure.net<br>https:\//tm-kailani-sin.one.microsoft.com |
125+
| Public | Southeast Asia | https:\//southeastasia01.afs.azure.net<br>https:\//kailani10.one.microsoft.com | East Asia | https:\//tm-southeastasia01.afs.azure.net<br>https:\//tm-kailani10.one.microsoft.com |
126+
| Public | UK South | https:\//uksouth01.afs.azure.net<br>https:\//kailani-uks.one.microsoft.com | UK West | https:\//tm-uksouth01.afs.azure.net<br>https:\//tm-kailani-uks.one.microsoft.com |
127+
| Public | UK West | https:\//ukwest01.afs.azure.net<br>https:\//kailani-ukw.one.microsoft.com | UK South | https:\//tm-ukwest01.afs.azure.net<br>https:\//tm-kailani-ukw.one.microsoft.com |
127128
| Public | West Central US | https:\//westcentralus01.afs.azure.net | West US 2 | https:\//tm-westcentralus01.afs.azure.net |
128-
| Public | West Europe | https:\//kailani6.one.microsoft.com | North Europe | https:\//tm-kailani6.one.microsoft.com |
129-
| Public | West US | https:\//kailani.one.microsoft.com | East US | https:\//tm-kailani.one.microsoft.com |
129+
| Public | West Europe | https:\//westeurope01.afs.azure.net<br>https:\//kailani6.one.microsoft.com | North Europe | https:\//tm-westeurope01.afs.azure.net<br>https:\//tm-kailani6.one.microsoft.com |
130+
| Public | West US | https:\//westus01.afs.azure.net<br>https:\//kailani.one.microsoft.com | East US | https:\//tm-westus01.afs.azure.net<br>https:\//tm-kailani.one.microsoft.com |
130131
| Public | West US 2 | https:\//westus201.afs.azure.net | West Central US | https:\//tm-westus201.afs.azure.net |
131132
| Government | US Gov Arizona | https:\//usgovarizona01.afs.azure.us | US Gov Texas | https:\//tm-usgovarizona01.afs.azure.us |
132133
| Government | US Gov Texas | https:\//usgovtexas01.afs.azure.us | US Gov Arizona | https:\//tm-usgovtexas01.afs.azure.us |
@@ -137,9 +138,9 @@ For business continuity and disaster recovery (BCDR) reasons you may have specif
137138
138139
**Example:** You deploy a storage sync service in `"West US"` and register your server with it. The URLs to allow the server to communicate to for this case are:
139140
140-
> - https:\//kailani.one.microsoft.com (primary endpoint: West US)
141-
> - https:\//kailani1.one.microsoft.com (paired fail-over region: East US)
142-
> - https:\//tm-kailani.one.microsoft.com (discovery URL of the primary region)
141+
> - https:\//westus01.afs.azure.net (primary endpoint: West US)
142+
> - https:\//eastus01.afs.azure.net (paired fail-over region: East US)
143+
> - https:\//tm-westus01.afs.azure.net (discovery URL of the primary region)
143144
144145
### Allow list for Azure File Sync IP addresses
145146
Azure File Sync supports the use of [service tags](../../virtual-network/service-tags-overview.md), which represent a group of IP address prefixes for a given Azure service. You can use service tags to create firewall rules that enable communication with the Azure File Sync service. The service tag for Azure File Sync is `StorageSyncService`.

0 commit comments

Comments
 (0)