Does Azure APIM preserve the client source IP or use its own outbound IP when forwarding requests to a backend

Apurva Pathak 960 Reputation points
2026-09-21T14:38:58.1566667+00:00

I have the following architecture:

Frontend --> APIM (Internal API) --> Azure Function App --> APIM (External API) --> External Service

The Azure Function App calls an API exposed through a second Azure API Management (APIM) instance. That APIM authenticates with the backend External Service API.

I'm trying to determine which component should be considered the source of traffic for firewall/IP whitelisting purposes.

When the Function App sends a request to APIM, and APIM subsequently forwards the request to External Service API:

  1. Does APIM establish a new outbound connection to the backend and use its own outbound IP addresses?
  2. Will External Service API see the APIM outbound IP as the client IP, or the original Function App outbound IP?
  3. For backend IP whitelisting, should the External Service API team whitelist the APIM outbound IPs or the Function App outbound IPs?

Any Microsoft documentation confirming the expected behaviour would be appreciated.

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.

0 comments No comments

Answer accepted by question author
Marcin Policht 109.6K Reputation points MVP Volunteer Moderator
2026-09-21T14:53:30.55+00:00

The external APIM instance establishes a new outbound connection to the backend External Service API. This means the external APIM's own outbound IP addresses are used as the source of the traffic. Azure API Management (APIM) acts as a reverse proxy and gateway. When the Azure Function App calls the external APIM, APIM terminates that connection and then initiates a completely new outbound TCP/HTTP connection to the backend External Service API.

Effectively, the External Service API will see the external APIM outbound IP address as the client/source IP, not the original Function App's IP address - so this one should be whitelisted.

For confirmation, refer to https://docs.azure.cn/en-us/api-management/api-management-howto-ip-addresses

When a request is sent from API Management to a public (internet-facing) backend, a public IP address will always be visible as the origin of the request.


If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

hth

Marcin

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.