    We are looking to design a Remote Network Connection for our vendors to connect to vendor-devices/applications running in our corporate network, we already have a hybrid connection between on-premise and azure so we would like to create a Jump host (DMZ ?) in azure which will talk to our vendor applications deployed in corporate network . Is this a good idea ? Rationale behind this , we will be migrating all our applications (except those vendor devices) to azure so in the long term this will be a feasible solution. I know there is an azure bastion PaaS available but that work's within the vnet and cannot be used to connect to on-premise servers? what are the pros and cons of creating a hardened bastion server in azure for the purpose of granting external people access to the application running in corporate network? what are the best practices around this ? Anyone has any thoughts on this please

    Sunday, November 22, 2020 9:43 AM