This is a collection of errors (and corresponding troubleshooting tip) at various stages across the different scenarios during the deployment.
Verify Network connectivity status. If the status is not healthy review DNS, VPN/Routing, Firewall/NVA design considerations for Internal vs External mode.
Validate routing to the backend API, review NSGs and if firewall /NVA IP needs to be whitelisted
HTTP/1.1 500 Internal Server Error
content-length: 111
content-type: application/json
vary: Origin
"statusCode": 500,
"message": "Internal server error",
"activityId": "cd71e1f2-28a5-4c28-8b72-368278afcbda"}
Validate routing to the backend API (in this case is not routable from on-premises resulting in this error
lastError: { "elapsed": 20039, "source": "request-forwarder", "path": "forward-request\forward-request", "reason": "BackendConnectionFailure", "message": "connection timed out:", "section": "backend" }, errors: [
Review http and https settings on the APIM Web service URL
HTTP/1.1 302 Moved Temporarily
Backend service responded with a redirect.
Validate self-hosted gateway is attached to an API
"statusCode": 404,
"message": "Resource not found"
Verify that a valid certificate is installed
[Error]2021-08-29T12:47:23.554 [Error], exception: System.Net.Http.HttpRequestException: Response status code does not indicate success: 503 (Service Unavailable).
at System.Net.Http.HttpResponseMessage.EnsureSuccessStatusCode()
Check app gw health, probe test, http/https settings on the APIM
<title>502 Bad Gateway</title>
<h1>502 Bad Gateway</h1>
Review firewall rules
HTTP/1.1 470 Unknown
content-length: 165
content-type: text/plain; charset=utf-8
vary: Origin
HTTP request from172.16.6.6:50748 Url: Action: Deny. Norule matched. Proceeding with default action
Default domain in external mode fails because the return traffic gets assymetric. Use custom domain when you have a firewall/NVA in the design.
Error: connect ETIMEDOUT
Verify firewall/NVA causing assymetric routing issue
Failed to connect to management endpoint
Failed to connect to management endpoint at for a service deployed in a virtual network. Make sure to follow guidance at
Verfiy that management endpoint is reachable and DNS resolution works
GET http://https//
Error: getaddrinfo ENOTFOUND https
▶Request Headers
User-Agent: PostmanRuntime/7.28.4
Accept: */*
Postman-Token: ce4b4d65-ab47-4232-a99a-468ec01c586b
Accept-Encoding: gzip, deflate, br
Potential Issue: NSG on the APIM or Backend API subnet
GET http://http//
Error: getaddrinfo ENOTFOUND http
HTTP/1.1 400 Bad Request
content-length: 213
content-type: application/json
vary: Origin
"error": "A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond"}
Missing subscritpion Key
"statusCode": 401,
"message": "Access denied due to invalid subscription key. Make sure to provide a valid key for an active subscription."
Verify backend API is routable
docker logs 92 --follow
IpAddress:, timeGenerated: 09/03/2021 11:09:11, region: nn-eastus, correlationId: 287cc23d-984e-4490-a05c-de8abecb4229, method: GET, url:, responseCode: 500, responseSize: 259, cache: none, apiId: self-hosted-api, operationId: get-all-user, apimSubscriptionId: all-api-subscription, clientProtocol: HTTP/1.1, apiRevision: 1, clientTlsVersion: 1.2, lastError: {
"elapsed": 20018,
"source": "request-forwarder",
"path": "forward-request\\forward-request",
"reason": "BackendConnectionFailure",
"message": "connection timed out:",
"section": "backend"
}, errors: [
"elapsed": 20018,
"source": "request-forwarder",
"path": "forward-request\\forward-request",
"message": "connection timed out:",
"section": "backend"
Review CORS polciy setting.
Since the browser initiates the request, it requires Cross-Origin Resource Sharing (CORS) enabled on the server. Learn more.