Skip to content

Commit db9d3b4

Browse files
authored
Sync release-hotfixes with main
Sync release-hotfixes with main
2 parents 668a87e + 21c2d77 commit db9d3b4

12 files changed

+101
-63
lines changed

AKS-Arc/aks-hci-network-system-requirements.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: AKS enabled by Azure Arc network requirements
33
description: Learn about AKS network prerequisites.
44
ms.topic: overview
5-
ms.date: 11/19/2024
5+
ms.date: 04/23/2025
66
author: sethmanheim
77
ms.author: sethm
88
ms.reviewer: abha
@@ -64,6 +64,9 @@ Regardless of the option you choose, you must ensure that the IP addresses alloc
6464

6565
Proxy settings in AKS are inherited from the underlying infrastructure system. The functionality to set individual proxy settings for Kubernetes clusters and change proxy settings isn't supported yet. For more information on how to set proxy correctly, see [proxy requirements for Azure Local](/azure/azure-local/manage/configure-proxy-settings-23h2).
6666

67+
> [!WARNING]
68+
> You cannot update incorrect proxy settings after you deploy Azure Local. If the proxy is misconfigured, you must redeploy Azure Local.
69+
6770
## Firewall URL exceptions
6871

6972
Firewall requirements for AKS have been consolidated with Azure Local firewall requirements. See [Azure Local firewall requirements](/azure/azure-local/concepts/firewall-requirements) for list of URLs that need to be allowed to successfully deploy AKS.

azure-local/concepts/firewall-requirements.md

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,25 @@ For a consolidated list of endpoints for Japan East that includes Azure Local, A
6565
For a consolidated list of endpoints for South Central US that includes Azure Local, Arc-enabled servers, ARB, and AKS, use:
6666
- [Required endpoints in South Central US for Azure Local](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/SouthCentralUSEndpoints/southcentralus-hci-endpoints.md)
6767

68+
## Firewall requirements for OEMs
69+
70+
Depending on the OEM you are using for Azure Local you may need to open additional endpoints in your firewall.
71+
72+
DataON required endpoints for Azure Local deployments
73+
- [DataOn required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/DataOn/DataOnAzureLocalEndpoints.md)
74+
75+
Dell required endpoints for Azure Local deployments
76+
- [Dell required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/Dell/DellAzureLocalEndpoints.md)
77+
78+
HPE required endpoints for Azure Local deployments
79+
- [HPE required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/HPE/HPEAzureLocalEndpoints.md)
80+
81+
Hitachi required endpoints for Azure Local deployments
82+
- [Hitachi required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/Hitachi/HitachiAzureLocalEndpoints.md)
83+
84+
Lenovo required endpoints for Azure Local deployments
85+
- [Lenovo required endpoints](https://github.com/Azure/AzureStack-Tools/blob/master/HCI/OEMEndpoints/Lenovo/LenovoAzureLocalEndpoints.md)
86+
6887
## Firewall requirements for additional Azure services
6988

7089
Depending on additional Azure services you enable for Azure Local, you may need to make additional firewall configuration changes. Refer to the following links for information on firewall requirements for each Azure service:

azure-local/concepts/physical-network-requirements.md

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -141,11 +141,13 @@ If your switch isn't included, contact your switch vendor to ensure that your sw
141141
|----- |---| :-: | :-: | :-: | :-: |
142142
| [S41xx series](https://www.dell.com/en-us/learn/assets/shared-content~data-sheets~en/documents~dell-emc-networking-s4100-series-spec-sheet.pdf) <br>(10 GbE)|SmartFabric OS10.5.4 or later |&check;| &check;| &check;| &check; |
143143
| [S52xx series](https://www.delltechnologies.com/resources/en-us/asset/data-sheets/products/networking/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SmartFabric OS10.5.4 or later |&check;| &check;| &check;| &check; |
144-
| [S5232F series](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
145-
| [S5248F series](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
146-
| [S5296F series](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
147144
| [S54xx series](https://www.delltechnologies.com/asset/en-us/products/networking/technical-support/dell-emc-powerswitch-s5448f-on-spec-sheet.pdf) <br>(25, 100 GbE)|SmartFabric OS10.5.4 or later |&check;| &check;| &check;| &check; |
148-
| [S5448F series](https://www.delltechnologies.com/asset/en-my/products/networking/technical-support/dell-emc-powerswitch-s5448f-on-spec-sheet.pdf) <br>(25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
145+
| [S5232F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
146+
| [S5248F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
147+
| [S5296F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
148+
| [S5448F](https://www.delltechnologies.com/asset/en-my/products/networking/technical-support/dell-emc-powerswitch-s5448f-on-spec-sheet.pdf) <br>(25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
149+
| [Z9432F](https://www.delltechnologies.com/asset/en-us/products/networking/technical-support/dell-emc-powerswitch-z9432f-spec-sheet.pdf) <br>(10, 25, 100, 400 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
150+
| [Z9664F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell-powerswitch-z9664f-on-spec-sheet.pdf) <br>(10, 25, 100, 400 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
149151

150152
> [!NOTE]
151153
> Guest RDMA requires both Compute (Standard) and Storage.
@@ -155,11 +157,13 @@ If your switch isn't included, contact your switch vendor to ensure that your sw
155157
|----- |---| :-: | :-: | :-: | :-: |
156158
| [S41xx series](https://www.dell.com/en-us/learn/assets/shared-content~data-sheets~en/documents~dell-emc-networking-s4100-series-spec-sheet.pdf) <br>(10 GbE)|SmartFabric OS10.5.4 or later |&check;| &check;| &check;| &check; |
157159
| [S52xx series](https://www.delltechnologies.com/resources/en-us/asset/data-sheets/products/networking/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SmartFabric OS10.5.4 or later |&check;| &check;| &check;| &check; |
158-
| [S5232F series](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
159-
| [S5248F series](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
160-
| [S5296F series](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
161160
| [S54xx series](https://www.delltechnologies.com/asset/en-us/products/networking/technical-support/dell-emc-powerswitch-s5448f-on-spec-sheet.pdf) <br>(25, 100 GbE)|SmartFabric OS10.5.4 or later |&check;| &check;| &check;| &check; |
162-
| [S5448F series](https://www.delltechnologies.com/asset/en-my/products/networking/technical-support/dell-emc-powerswitch-s5448f-on-spec-sheet.pdf) <br>(25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
161+
| [S5232F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
162+
| [S5248F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
163+
| [S5296F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell_emc_networking-s5200_on_spec_sheet.pdf) <br>(10, 25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
164+
| [S5448F](https://www.delltechnologies.com/asset/en-my/products/networking/technical-support/dell-emc-powerswitch-s5448f-on-spec-sheet.pdf) <br>(25, 100 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
165+
| [Z9432F](https://www.delltechnologies.com/asset/en-us/products/networking/technical-support/dell-emc-powerswitch-z9432f-spec-sheet.pdf) <br>(10, 25, 100, 400 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
166+
| [Z9664F](https://www.delltechnologies.com/asset/en-in/products/networking/technical-support/dell-powerswitch-z9664f-on-spec-sheet.pdf) <br>(10, 25, 100, 400 GbE)|SONiC 4.5.0 or later |&check;| &check;| &check;| &check; |
163167

164168
> [!NOTE]
165169
> Guest RDMA requires both Compute (Standard) and Storage.

azure-local/deploy/deployment-azure-arc-gateway-overview.md

Lines changed: 28 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Overview of Azure Arc gateway for Azure Local, version 23H2 (preview)
33
description: Learn what is Azure Arc gateway for Azure Local, version 23H2 (preview).
44
author: alkohli
55
ms.topic: how-to
6-
ms.date: 04/10/2025
6+
ms.date: 04/23/2025
77
ms.author: alkohli
88
ms.service: azure-local
99
---
@@ -89,37 +89,36 @@ Unsupported scenarios for Azure Local include:
8989

9090
## Azure Local endpoints not redirected
9191

92-
As part of the Azure Local version 2411.1 preview update, the endpoints from the table are required and must be allowlisted in your proxy or firewall to deploy the Azure Local instance. These version 2408 and 2411 endpoints are not redirected via the Arc gateway:
92+
The endpoints from the table are required and must be allowlisted in your proxy or firewall to deploy the Azure Local instance:
9393

9494
| Endpoint # | Required endpoint | Component |
9595
| -- | -- | -- |
96-
| 1 | `http://go.microsoft.com:443` | Arc registration |
97-
| 2 | `http://login.microsoftonline.com:443` | Arc registration |
98-
| 3 | `http://<region>.login.microsoft.com:443` | Arc registration |
99-
| 4 | `http://download.microsoft.com:443` | Arc registration |
100-
| 5 | `http://management.azure.com:443` | Arc registration |
101-
| 6 | `http://gbl.his.arc.azure.com:443` | Arc registration |
102-
| 7 | `http://<region>.his.arc.azure.com:443` | Arc registration |
103-
| 8 | `http://dc.services.visualstudio.com:443` | Arc registration |
104-
| 9 | `https://<region>.obo.arc.azure.com:8084` | AKS extensions |
105-
| 10 | `http://<yourarcgatewayId>.gw.arc.azure.com:443` | Arc gateway |
106-
| 11 | `http://<yourkeyvaultname>.vault.azure.net:443` | Azure Key Vault |
107-
| 12 | `http://<yourblobstorageforcloudwitnessname>.blob.core.windows.net:443` | Cloud Witness Storage Account |
108-
| 13 | `http://files.pythonhosted.org:443` | Microsoft On-premises Cloud/ARB/AKS |
109-
| 14 | `http://pypi.org:443` | Microsoft On-premises Cloud/ARB/AKS |
110-
| 15 | `http://raw.githubusercontent.com:443` | Microsoft On-premises Cloud/ARB/AKS |
111-
| 16 | `http://pythonhosted.org:443` | Microsoft On-premises Cloud/ARB/AKS |
112-
| 17 | `http://ocsp.digicert.com` | Certificate Revocation List for Arc extensions |
113-
| 18 | `http://s.symcd.com` | Certificate Revocation List for Arc extensions |
114-
| 19 | `http://ts-ocsp.ws.symantec.com` | Certificate Revocation List for Arc extensions |
115-
| 20 | `http://ocsp.globalsign.com` | Certificate Revocation List for Arc extensions |
116-
| 21 | `http://ocsp2.globalsign.com` | Certificate Revocation List for Arc extensions |
117-
| 22 | `http://oneocsp.microsoft.com` | Certificate Revocation List for Arc extensions |
118-
| 23 | `http://dl.delivery.mp.microsoft.com` | Windows Update |
119-
| 24 | `http://*.tlu.dl.delivery.mp.microsoft.com` | Windows Update |
120-
| 25 | `http://*.windowsupdate.com` | Windows Update |
121-
| 26 | `http://*.windowsupdate.microsoft.com` | Windows Update |
122-
| 27 | `http://*.update.microsoft.com` | Windows Update |
96+
| 1 | `http://login.microsoftonline.com:443` | Arc registration |
97+
| 2 | `http://<region>.login.microsoft.com:443` | Arc registration |
98+
| 3 | `http://management.azure.com:443` | Arc registration |
99+
| 4 | `http://gbl.his.arc.azure.com:443` | Arc registration |
100+
| 5 | `http://<region>.his.arc.azure.com:443` | Arc registration |
101+
| 6 | `http://dc.services.visualstudio.com:443` | Arc registration |
102+
| 7 | `https://<region>.obo.arc.azure.com:8084` | AKS extensions |
103+
| 8 | `http://<yourarcgatewayId>.gw.arc.azure.com:443` | Arc gateway |
104+
| 9 | `http://<yourkeyvaultname>.vault.azure.net:443` | Azure Key Vault |
105+
| 10 | `http://<yourblobstorageforcloudwitnessname>.blob.core.windows.net:443` | Cloud Witness Storage Account |
106+
| 11 | `http://files.pythonhosted.org:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
107+
| 12 | `http://pypi.org:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
108+
| 13 | `http://raw.githubusercontent.com:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
109+
| 14 | `http://pythonhosted.org:443` | Not required starting with 2504 new deployments. Microsoft On-premises Cloud/ARB/AKS |
110+
| 15 | `http://ocsp.digicert.com` | Certificate Revocation List for Arc extensions |
111+
| 16 | `http://s.symcd.com` | Certificate Revocation List for Arc extensions |
112+
| 17 | `http://ts-ocsp.ws.symantec.com` | Certificate Revocation List for Arc extensions |
113+
| 18 | `http://ocsp.globalsign.com` | Certificate Revocation List for Arc extensions |
114+
| 19 | `http://ocsp2.globalsign.com` | Certificate Revocation List for Arc extensions |
115+
| 20 | `http://oneocsp.microsoft.com` | Certificate Revocation List for Arc extensions |
116+
| 21 | `http://crl.microsoft.com/pkiinfra` | Certificate Revocation List for Arc extensions |
117+
| 22 | `http://dl.delivery.mp.microsoft.com` | Windows Update |
118+
| 23 | `http://*.tlu.dl.delivery.mp.microsoft.com` | Windows Update |
119+
| 24 | `http://*.windowsupdate.com` | Windows Update |
120+
| 25 | `http://*.windowsupdate.microsoft.com` | Windows Update |
121+
| 26 | `http://*.update.microsoft.com` | Windows Update |
123122

124123
## Restrictions and limitations
125124

azure-local/deploy/download-23h2-software.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@ author: alkohli
55
ms.author: alkohli
66
ms.topic: how-to
77
ms.service: azure-local
8-
ms.date: 04/21/2025
8+
ms.date: 04/23/2025
99
---
1010

11-
# Download version 23H2 operating system for Azure Local deployment
11+
# Download operating system for Azure Local deployment
1212

1313
[!INCLUDE [hci-applies-to-23h2](../includes/hci-applies-to-23h2.md)]
1414

@@ -27,6 +27,7 @@ Before you begin the download of the software from Azure portal, ensure that you
2727
- [Pay-as-you-go](https://azure.microsoft.com/pricing/purchase-options/pay-as-you-go/) subscription with credit card.
2828
- Subscription obtained through an Enterprise Agreement (EA).
2929
- Subscription obtained through the Cloud Solution Provider (CSP) program.
30+
- At a minimum, you'll need **Reader** access at the subscription level.
3031

3132
- Register the Microsoft Azure Stack HCI resource provider. For more information, see [Register your machines and assign permissions for Azure Local deployment](deployment-arc-register-server-permissions.md).
3233

azure-local/includes/hci-download-vhdx.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ author: alkohli
33
ms.author: alkohli
44
ms.service: azure-local
55
ms.topic: include
6-
ms.date: 10/11/2024
6+
ms.date: 04/22/2025
77
---
88

99

@@ -12,9 +12,9 @@ SDN uses a VHDX file containing either the Azure Stack HCI or Windows Server ope
1212
> [!NOTE]
1313
> The version of the OS in your VHDX must match the version used by the Azure Local Hyper-V machines. This VHDX file is used by all SDN infrastructure components.
1414
15-
To download an English-language version of the VHDX file, see [Download the operating system from the Azure portal](../deploy/download-23h2-software.md). Make sure to select **English VHDX** from the **Choose language** dropdown list.
15+
[Download an English-language version of the VHDX file](https://aka.ms/PVvxVBVCVVC).
1616

17-
Currently, a non-English VHDX file isn't available for download. If you require a non-English version, download the corresponding ISO file and convert it to VHDX using the `Convert-WindowsImage` cmdlet. You must run this script from a Windows client computer. You'll probably need to run this script as Administrator and modify the execution policy for scripts using the `Set-ExecutionPolicy` command.
17+
Currently, a non-English VHDX file isn't available for download. If you require a non-English version, [download the corresponding ISO file](../deploy/download-23h2-software.md) and convert it to VHDX using the `Convert-WindowsImage` cmdlet. You must run this script from a Windows client computer. You'll probably need to run this script as Administrator and modify the execution policy for scripts using the `Set-ExecutionPolicy` command.
1818

1919
The following syntax shows an example of using `Convert-WindowsImage`:
2020

0 commit comments

Comments
 (0)