Container Apps UDR to virtual appliance not applied for specific private prefix

Jaime da Cruz Silva Júnior 0 Reputation points
2026-10-07T13:14:43.4466667+00:00

Azure Container Apps Workload Profiles environment integrated to a custom VNet. A route table is associated with the infrastructure subnet, with 10.30.0.0/24 -> VirtualAppliance 10.20.10.4.

A Container Apps Job can establish TCP connectivity directly to the NVA private IP (10.20.10.4:22); the NVA observes the traffic SNATed to the Container Apps subnet (10.20.60.x). However, when the Job connects to 10.30.0.1:40005, the connection times out and a packet capture on the NVA shows no SYN arriving, despite the UDR. The NVA forwards correctly to the remote network for other sources.

Is a specific-prefix UDR to a third-party virtual appliance supported for outbound traffic from Container Apps Workload Profiles, or is a default route (0.0.0.0/0) required? How can we validate effective routing for the managed Container Apps data plane?

Azure Container Apps
Azure Container Apps

An Azure service that provides a general-purpose, serverless container platform.

0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.