Persistent Azure App Service to Azure SQL pre-login timeout (SqlException -2) despite successful DNS, TCP and firewall checks

Lyubomir Shumantov 0 Reputation points
2026-09-23T09:04:19.7333333+00:00

I have a Linux ASP.NET Core App Service using Microsoft.Data.SqlClient to connect to an Azure SQL Database through a system-assigned Managed Identity. Both resources are located in Sweden Central.

The application readiness endpoint persistently returns HTTP 503 / Unhealthy because the database connection times out before any SQL command is executed.

Observed exception:

Exception: Microsoft.Data.SqlClient.SqlException

Number: -2

State: 0

Class: 11

Failure stage: SqlConnection.Open / pre-login

SQL command execution: not reached

A correlated failure occurred during this exact UTC window:

2026-09-23T06:20:38.4668729Z–2026-09-23T06:20:55.7567144Z

The following checks have already been completed:

The App Service is Running on Linux.

The Azure SQL Database Resource Health status was Available.

The SQL Server FQDN is correct.

DNS resolution succeeds.

TCP port 1433 is reachable.

Azure SQL public network access is enabled.

The App Service outbound address is covered by an Azure SQL firewall rule.

The system-assigned Managed Identity is enabled and matches the expected identity.

The database external principal was transactionally repaired and all post-verification checks passed.

The principal has the expected roles and effective CONNECT permission.

VNet integration is present and Route All is disabled.

No relevant Azure Activity Log events were found during the correlated window.

One App Service restart did not resolve the problem.

The connection policy was initially Default.

A controlled change from Default to Proxy was tested to eliminate a possible Redirect-port dependency.

With Proxy confirmed as effective, the readiness endpoint still returned HTTP 503.

The connection policy was subsequently rolled back and verified as Default.

No test configuration remains.

The Azure guided troubleshooter categorized the failure as:

“Connection Timeout Expired. The timeout period elapsed while attempting to consume the pre-login handshake acknowledgement.”

However, the available telemetry does not prove whether the failure is inside the App Service outbound stack, the SQL gateway/pre-login layer, TLS negotiation, SNAT/proxy handling, or another platform component.

Could a Microsoft/Azure engineer please advise:

Can the Azure SQL gateway/pre-login telemetry be correlated with the exact UTC window above?

Did the SQL gateway receive a connection attempt from the App Service during that window?

If no attempt reached the gateway, which App Service outbound diagnostics can identify where the connection stopped?

Are there known App Service-to-Azure SQL pre-login issues in Sweden Central affecting Linux App Service or Microsoft.Data.SqlClient?

Which additional sanitized platform diagnostic would distinguish an App Service outbound failure from an Azure SQL gateway/TLS failure?

No access tokens, connection strings, subscription IDs, tenant IDs, principal identifiers, IP addresses, or raw application data are included.

Azure SQL Database
0 comments No comments

1 answer

Sort by: Newest
  1. Praveen Sreeram 11 Reputation points
    2026-09-23T10:30:55.28+00:00

    A SqlException (-2) during the pre-login handshake indicates that the App Service is able to reach the Azure SQL endpoint, but the SQL connection is timing out before authentication is completed.

    Since DNS resolution, TCP 1433 connectivity, and the SQL firewall have already been verified, I would check the following:

    SQL connection policy – If Azure SQL is using Redirect (the default for many Azure-to-Azure connections), the client may need connectivity to the redirect ports 11000–11999. A network device, NSG, Azure Firewall, or UDR blocking this traffic can result in a pre-login timeout. As a diagnostic, test with the Proxy connection policy.

    App Service SNAT exhaustion – Check App Service → Diagnose and solve problems → SNAT Port Exhaustion. If the application is creating many outbound SQL connections instead of reusing connection pools, SNAT exhaustion can cause intermittent connection/pre-login timeouts.

    VNet/Private Endpoint/DNS configuration – If the App Service uses VNet Integration or Azure SQL Private Endpoint, verify that *.database.windows.net resolves to the intended endpoint and that the complete network path is allowed.

    1. SqlClient/TLS – Make sure the application is using a current Microsoft.Data.SqlClient version and a supported .NET runtime if you are using .Net?

    In this scenario, I would first investigate SQL Redirect connectivity and App Service SNAT exhaustion, as both can cause a pre-login timeout even when TCP 1433 appears to be working.

    If this answer helped resolve the issue, please consider accepting it as the answer so it can help others facing the same problem.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.