An Azure service that provides a hybrid, multi-cloud management platform for APIs.
The external APIM instance establishes a new outbound connection to the backend External Service API. This means the external APIM's own outbound IP addresses are used as the source of the traffic. Azure API Management (APIM) acts as a reverse proxy and gateway. When the Azure Function App calls the external APIM, APIM terminates that connection and then initiates a completely new outbound TCP/HTTP connection to the backend External Service API.
Effectively, the External Service API will see the external APIM outbound IP address as the client/source IP, not the original Function App's IP address - so this one should be whitelisted.
For confirmation, refer to https://docs.azure.cn/en-us/api-management/api-management-howto-ip-addresses
When a request is sent from API Management to a public (internet-facing) backend, a public IP address will always be visible as the origin of the request.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin