The API Management VNet mode where the gateway can be reached solely through a private IP address.
Also called APIM VNet mode.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Internal in context, with comparison tables and the common traps.
Terms in this definition
- API Management
Azure's API gateway, where policies like rate limits, quotas, ip-filter and validate-jwt are defined once and apply to every API. Production VNet injection is offered in the Premium tier.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Private IP address
An address taken from a subnet of a virtual network and used to talk within that network, to linked networks and to on-premises sites. The internet can't reach it.
Related terms
- Accessibility level
Whether a Container Apps environment is reachable publicly or only privately, fixed when the environment is made. With external, its virtual IP sits on a public address; with internal, an internal load balancer in your own virtual network holds it.
- BGP peer IP
IP address from which each router runs its BGP session. Azure allocates one to a VPN gateway when BGP is switched on, and you record the internal address of your on-premises router in the local network gateway.
- ClusterIP
Kubernetes' default Service type; it is given an internal address from the service CIDR and can be reached only from within the cluster.
- ClusterIP Service
Standard Kubernetes Service type: pods behind it get one fixed internal IP address that only things running within the cluster can reach.
- Container Apps environment
Boundary that groups Azure Container Apps for security, isolation and networking; decisions about workload profiles versus Consumption only, a custom VNet, and internal or external access can't be changed after creation.
- CoreDNS
AKS's default cluster DNS, running as pods in kube-system, that resolves internal names and enables service discovery; its service IP can only be reached within the cluster.
- DNAT rule
Azure Firewall rule, evaluated before any other, that maps a public IP and port on the firewall to an internal IP and port, with the translated traffic allowed automatically.
- EEEU
SharePoint's built-in group of all internal users, guests excluded. Anything shared with it, such as a public site or item, is open to the whole organisation and may appear in Microsoft 365 Copilot answers.