Loading

Manage network security in the Azure Native Service

You can restrict access to Elastic Cloud Hosted deployments created through the Azure Native Service by applying network security policies. Policies include IP filters and private connections.

This page covers how to create and associate those policies from the Azure portal Traffic Filter page.

Where you manage the Elastic-side policies depends on the hosting type:

Policy type Elastic Cloud Hosted Elastic Cloud Serverless
IP filters Azure portal Traffic Filter or Elastic Cloud Console. Changes sync between the two surfaces. Elastic Cloud Console only. The Azure portal Traffic Filter page does not support Serverless policies yet.
Private Link private connection policy Azure portal Traffic Filter or Elastic Cloud Console. Changes sync between the two surfaces. Elastic Cloud Console only. The Azure portal Traffic Filter page does not support Serverless policies yet.

For Elastic Cloud Console steps that apply to both Elastic Cloud Hosted and Serverless, refer to Manage IP filters in ECH or Serverless and Private connectivity with Azure Private Link.

Policies you create in the Azure portal appear in the Elastic Cloud Console under Network security, labeled Created from Azure. Policies created in the Elastic Cloud Console also appear in the Azure portal list. Linking or unlinking in either place updates the association.

Microsoft also documents this page in Manage settings for your Elastic resource.

To create a private connection policy, you must first create the private endpoint and DNS records in Azure, and then create the policy in the Azure portal.

Follow the steps to create your private endpoint and DNS entries in Azure. This procedure creates the private endpoint and DNS records using regional service aliases and private hosted zone names.

After you create the private endpoint and DNS records in Azure, you can create the private connection policy in the Azure portal.

  1. In the Azure portal, open your Elastic resource, then select Elastic Cloud Resource Configuration > Traffic Filter.

  2. Select Add.

  3. Enter a filter name.

  4. Set Filter Type to Private Link.

  5. Choose how to identify the private endpoint:

  6. Create the filter.

  7. Select the new filter in the list, then select Link so the status shows Linked for this deployment.

The policy must be in the same region as the deployment. Policies from other regions can appear in the list but remain Not Linked on this resource.

Create and link an IP filter from the Azure portal to allowlist IPv4 addresses or CIDR blocks.

  1. In the Azure portal, open your Elastic resource, then select Elastic Cloud Resource Configuration > Traffic Filter.
  2. Select Add.
  3. Enter a filter name.
  4. Set Filter Type to IP filtering rule set.
  5. Add the IPv4 addresses or CIDR blocks to allow.
  6. Create the filter.
  7. Select the filter, then select Link.

The policy must be in the same region as the deployment. Policies from other regions can appear in the list but remain Not Linked on this resource.

Remove a policy from this deployment, or delete it from your organization, in the Azure portal.

  1. In the Azure portal, open your Elastic resource, then select Elastic Cloud Resource Configuration > Traffic Filter.
  2. To stop a policy from applying to this deployment, select it and choose Unlink. The policy remains available in your organization.
  3. To delete a policy, unlink it from all deployments first, then select Delete.