Built-in NSG inbound rule at priority 65000 that admits anything from the VirtualNetwork service tag, which also covers peered VNets.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AllowVNetInBound in context, with comparison tables and the common traps.
Terms in this definition
- Default security rules
Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
- Priority
Routing method in Traffic Manager for active/passive failover: traffic goes to whichever healthy endpoint has the highest priority.
- Service tag
A set of IP prefixes for an Azure service, kept up to date by Microsoft (such as AzureKeyVault or Storage, with optional regional variants), that can be used as the source or destination in NSG rules.
Related terms
- ICMP
The protocol behind ping, distinct from both UDP and TCP. Between peered VNets, the default
AllowVnetInBoundNSG rule permits it.