Issue Accessing Azure File Share via VPN Point-to-Site with Private Endpoint

Jamal Nguyen 0 Reputation points
2025-11-15T06:14:20.5833333+00:00

Hi,

I have anissue and need your help.

When I connects using the P2S VPN to my Azure File Share, I can reach the VNet range (10.0.0.0/16), but I cannot resolve the Private Endpoint DNS name to the private IP. nslookup mystorageaccount.file.core.windows.net returns a public IP (20.x.x.x) or times-out instead of its private IP which belongs to subnet 10.0.0.0/24, I ensure my P2S VPN working correctly because I also tried successfully connecting to a VM belonging to subnet 10.0.0.0/24.

And I'm wondering whether China computers are able to access my Azure File Share via P2S VPN.

Thank you.

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
{count} votes

2 answers

Sort by: Most helpful
  1. Q&A Assist
    2025-11-15T06:14:33.3+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    It seems that you are experiencing issues with DNS resolution for your Azure File Share when connected via a Point-to-Site (P2S) VPN. Here are some steps to troubleshoot this issue:

    1. Check Private Endpoint Configuration: Ensure that the private endpoint for your Azure File Share is correctly configured and associated with the correct virtual network and subnet. The private endpoint should be in the same virtual network that your P2S VPN connects to.
    2. DNS Configuration: When you create a private endpoint, a private DNS zone is typically created or updated. Make sure that your virtual network is linked to the private DNS zone. This allows the DNS resolution to point to the private IP address of the endpoint instead of the public IP.
    3. Use Correct DNS Name: When performing the nslookup, ensure you are using the correct private DNS name format, which is mystorageaccount.privatelink.file.core.windows.net. This should resolve to the private IP address associated with the private endpoint.
    4. Test DNS Resolution: You can use the Resolve-DnsName cmdlet in PowerShell to test the DNS resolution from within an Azure VM in the same VNet. This can help confirm if the private DNS setup is functioning correctly.
         Resolve-DnsName -Name "mystorageaccount.privatelink.file.core.windows.net"
      
    5. Firewall and Network Security Group (NSG) Rules: Check if there are any firewall or NSG rules that might be blocking access to the private endpoint from your P2S VPN.

    Regarding your question about access from China, it is generally possible for computers in China to access Azure services via VPN, but there may be additional considerations regarding network policies, latency, and compliance with local regulations.

    If you continue to face issues, consider reaching out to Azure support for more detailed assistance.


    References:

    0 comments No comments

  2. Ravi Varma Mudduluru 3,550 Reputation points Microsoft External Staff Moderator
    2025-11-17T09:37:21.1733333+00:00

    Hello @Jamal Nguyen

    Thanks for reaching out to Microsoft Q&A.

    In your situation, I see that you’re unable to resolve the private IP using the P2S VPN, and it’s resolving the public IP instead. This appears to be a DNS issue.

    To resolve the issue, you can use a private endpoint and add a host entry on your local machine with the Private Endpoint IP and the Storage Endpoint.

    enter image description here

    10.0.0.5    venkatstoragetestdemo.file.core.windows.net
    
    

    When I tried to access the file share without a host entry, I also faced the same issue.

    enter image description here

    The issue was resolved after adding the host entry on the local machine.

    enter image description here

    Azure file share is accessible from P2S VPN

    enter image description here

    Reference document: https://learn.microsoft.com/en-us/azure/storage/files/storage-files-networking-overview#tunneling-traffic-over-a-virtual-private-network-or-expressroute

    Kindly let us know if the above helps or you need further assistance on this issue.

    Please "Accept the Answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.