Up to 1,000 rules sending named domains to target IPs, bound to an outbound endpoint of a DNS Private Resolver and linked to same-region VNets, which needn't peer with the resolver's VNet. 168.63.129.16 can't be a target.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DNS forwarding ruleset in context, with comparison tables and the common traps.
Terms in this definition
- Outbound endpoint
Endpoint of DNS Private Resolver, placed in a dedicated subnet, that forwards queries outside Azure as a forwarding ruleset directs. Having no listening IP, it cannot serve as a rule's destination.
- DNS
The system that turns names into addresses. In Azure, private endpoints depend on private DNS zones, which are queried through 168.63.129.16.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- 168.63.129.16
Special platform address (WireServer) through which Azure delivers the VM agent channel, built-in DNS, DHCP and load balancer health probes. Traffic to it must stay open, or those platform functions stop working.