DNS Private Resolver
Azure DNS Private Resolver answers DNS queries from outside Azure-provided DNS with the answers a virtual network would get, private zones included. The Azure Enterprise Baseline runs one in the hub so that VPN clients, the firewall's DNS proxy and, through forwarding, other networks resolve the platform's private names.
What it does
Azure-provided DNS (168.63.129.16) answers only from inside a virtual network. A DNS Private Resolver bridges that gap with two kinds of endpoint in delegated subnets: an inbound endpoint, an IP address that any client able to reach the network can query, and an outbound endpoint, through which a forwarding ruleset sends queries for chosen domains to other DNS servers, such as an on-premises resolver. A ruleset takes effect in the virtual networks linked to it. Each endpoint is billed per hour.
How BuiltForProd uses it
The dns-resolver unit in acme-core-network creates acme-eus2-network-dnspr in the hub, behind enable_dns_private_resolver in network.hcl, which is on by default (about $365 a month for both endpoints at about $0.25 per endpoint-hour, as the comments state).
| Part | Where | Used by |
|---|---|---|
| Inbound endpoint | snet-dns-inbound, at a fixed address | The hub's DNS server setting, so point-to-site VPN clients receive it; the firewall's DNS proxy; on-premises conditional forwarders |
| Outbound endpoint | snet-dns-outbound | The forwarding ruleset, when one is defined |
| Forwarding ruleset | linked to the hub | forwarding_rules in the unit, empty by default: one entry per domain and target resolver |
A fixed address. The inbound endpoint takes the fifth address of snet-dns-inbound (Azure reserves the first four), which the ipam unit computes from the address plan and publishes (10.9.19.4 in the default plan). Because the address is known before the resolver exists, the hub network can name it as its DNS server and the Azure Firewall policy can point its DNS proxy at it in the same deployment. The contract publishes it as network--dns-resolver-ip.
Why it matters. A VPN client's DNS is not Azure-provided DNS, so without the resolver it could not resolve kv-acme-eus2-prd-plat.vault.azure.net to the private endpoint behind it. Through the inbound endpoint, the client gets the answer from the central Private Link zones the hub is linked to. The firewall's DNS proxy, on the Standard and Premium SKUs, resolves through the same address, so FQDN rules see the same answers as the workloads. The spokes and the runner network do not need it: they use Azure-provided DNS and their own zone links.
With the switch off, the unit creates nothing, the hub keeps Azure-provided DNS and the firewall policy has no DNS proxy.
Terms you will see
| Term | Meaning |
|---|---|
| Inbound endpoint | The resolver's IP address that clients outside Azure DNS query. |
| Outbound endpoint | The resolver's path to other DNS servers. |
| Forwarding ruleset | Rules that send queries for a domain to chosen target resolvers. |
| DNS proxy | The firewall feature that forwards clients' DNS queries to a configured server. |
| Azure-provided DNS | The default resolver at 168.63.129.16 inside every virtual network. |
Where to read more
- Azure Enterprise Baseline overview for the hub network and its cost switches.
- VPN Gateway for the clients that depend on the resolver.
- Hub-and-spoke networking for shared services in the hub.