Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

Register now to learn Fabric in free live sessions led by the best Microsoft experts. From Apr 16 to May 9, in English and Spanish.

Reply
Anonymous
Not applicable

Ports to be opened for on-premise gateway

on-prem-data-gateway-how-it-works.png

Hi,

I have gone through the link on-premises gateway configuration and the architecture above.

But I m still not clear on configurations necessary and here are my questions:

1. Gateway communicates with Azure Service Bus on outbound ports TCP 443 (default), 5671, 5672, 9350 thru 9354.

Is it sufficient to open outbound ports for the domain names specified?

*.download.microsoft.com, *.powerbi.com, *.analysis.windows.net, *.login.windows.net, *.servicebus.windows.net, *.frontend.clouddatahub.net, *.core.windows.net, login.microsoftonline.com, *.msftncsi.com, *.microsoftonline-p.com

 

2. It is mentioned to white list Microsoft Azure Data Center IP List and that these addresses are updated weekly.

a) Depending on the region where power BI data is located, should I open outbound ports for each of IP ranges?

b) Which protocol and port number is used for this communication b/w Gateway and Azure Service Bus?

c) If IP addresses change weekly, isn't it required to involve n/w team on a weekly basis? Is there any work-around?

 

3. For defining the firewall rules, the n/w team is insisting on specifying "What destination exactly would you like to reach"

Firewall is located b/w Server where Power BI gateway is installed and the Azure Servive Bus/ Cloud. Your inputs on any of the questions asked would be very much appreciated as we have been stuck with the issue since several days.

 

Untitled.png

Thank you.

1 ACCEPTED SOLUTION
v-haibl-msft
Employee
Employee

@Anonymous

 

1. Currently, the gateway will communicate with Azure Service Bus using the IP address in addition to the fully qualified domain name. It may be not sufficient to just open outbound ports for the domain names.

 

2.

a) I think yes.
b) TCP 443 (default), 5671, 5672, 9350 thru 9354.
c) Yes. It seems that no workaround is available now.

 

Best Regards,

Herbert

View solution in original post

2 REPLIES 2
v-haibl-msft
Employee
Employee

@Anonymous

 

1. Currently, the gateway will communicate with Azure Service Bus using the IP address in addition to the fully qualified domain name. It may be not sufficient to just open outbound ports for the domain names.

 

2.

a) I think yes.
b) TCP 443 (default), 5671, 5672, 9350 thru 9354.
c) Yes. It seems that no workaround is available now.

 

Best Regards,

Herbert

Anonymous
Not applicable

Thanks @v-haibl-msft

Helpful resources

Announcements
Microsoft Fabric Learn Together

Microsoft Fabric Learn Together

Covering the world! 9:00-10:30 AM Sydney, 4:00-5:30 PM CET (Paris/Berlin), 7:00-8:30 PM Mexico City

PBI_APRIL_CAROUSEL1

Power BI Monthly Update - April 2024

Check out the April 2024 Power BI update to learn about new features.

April Fabric Community Update

Fabric Community Update - April 2024

Find out what's new and trending in the Fabric Community.

Top Solution Authors
Top Kudoed Authors