# Trace the Azure source-address requirement when RHEL updates fail through a central proxy

> Why might a RHEL VM reach the internet through an on-premises proxy but still fail to reach Azure RHUI?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-389-trace-the-azure-source-address-requirement-when-rhel-updates-fail-through-a/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:27+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why might a RHEL VM reach the internet through an on-premises proxy but still fail to reach Azure RHUI?

## Potentially affected

RHEL PAYG VMs using Azure-hosted Red Hat Update Infrastructure with centralized outbound traffic.

## DSE recommendation

Review the update traffic's actual egress path before changing repositories or disabling validation.

## Article

## Source facts

Azure-hosted RHUI restricts access to VMs in Azure datacenter IP ranges. Microsoft warns that sending all VM traffic through an on-premises proxy may require user-defined routes for RHUI, covering every RHUI address. RHEL PAYG images are configured for this update infrastructure; golden BYOS images instead need Subscription Manager or Satellite. These are different update-source arrangements, not interchangeable troubleshooting defaults. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/workloads/redhat/redhat-rhui).

## Applicability

Use this check when a RHEL PAYG VM’s repository requests fail after an egress or proxy change. Confirm the actual image and repository configuration before treating the problem as an Azure RHUI connectivity incident.

## DSE recommendation

Review the update traffic’s actual egress path before changing repositories or disabling validation. Ask the network owner to trace where the request leaves the environment and compare the routing and filtering configuration with the current official endpoint list. Have the Linux owner confirm which update source the VM is intended to use. Review any route change through normal network controls.

## Verification

From a representative affected VM, test the configured repository path after the approved change and inspect the resulting package-manager evidence. Confirm that all required RHUI destinations are covered, not just the address that happened to answer one test. Record the effective route and sanitized outcome without repository credentials. Leave the issue open if ordinary web access succeeds but the intended update operation still fails.

## Official references

[Microsoft Learn: Red Hat Update Infrastructure for Azure RHEL VMs](https://learn.microsoft.com/en-us/azure/virtual-machines/workloads/redhat/redhat-rhui). Source reviewed September 9, 2026.

## Primary reference

- Name: Red Hat Update Infrastructure - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/workloads/redhat/redhat-rhui
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Trace the Azure source-address requirement when RHEL updates fail through a central proxy,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-389-trace-the-azure-source-address-requirement-when-rhel-updates-fail-through-a/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
