An Azure relational database service.
A SqlException (-2) during the pre-login handshake indicates that the App Service is able to reach the Azure SQL endpoint, but the SQL connection is timing out before authentication is completed.
Since DNS resolution, TCP 1433 connectivity, and the SQL firewall have already been verified, I would check the following:
SQL connection policy – If Azure SQL is using Redirect (the default for many Azure-to-Azure connections), the client may need connectivity to the redirect ports 11000–11999. A network device, NSG, Azure Firewall, or UDR blocking this traffic can result in a pre-login timeout. As a diagnostic, test with the Proxy connection policy.
App Service SNAT exhaustion – Check App Service → Diagnose and solve problems → SNAT Port Exhaustion. If the application is creating many outbound SQL connections instead of reusing connection pools, SNAT exhaustion can cause intermittent connection/pre-login timeouts.
VNet/Private Endpoint/DNS configuration – If the App Service uses VNet Integration or Azure SQL Private Endpoint, verify that *.database.windows.net resolves to the intended endpoint and that the complete network path is allowed.
- SqlClient/TLS – Make sure the application is using a current
Microsoft.Data.SqlClientversion and a supported .NET runtime if you are using .Net?
In this scenario, I would first investigate SQL Redirect connectivity and App Service SNAT exhaustion, as both can cause a pre-login timeout even when TCP 1433 appears to be working.
If this answer helped resolve the issue, please consider accepting it as the answer so it can help others facing the same problem.