I have an Azure hub-and-spoke deployment with two Application Gateway v2 instances in the hub: one for public traffic and one for internal traffic. Both have private and public frontend IPs configured, and their backend resources are located in peered spoke VNets. The backend for one gateway is an Azure Storage static website exposed through a private endpoint. The Application Gateway backend pool uses the storage hostname, but requests currently return 502 Bad Gateway. The Application Gateway subnets and storage spoke use routes through an internal NVA. Do I need a private endpoint for Application Gateway itself, or should VNet peering and correct routing allow it to reach the storage private endpoint? What DNS, host header, listener, or routing settings should I verify?
3 Answers
Application Gateway does not need its own private endpoint. Its v2 instances make outbound connections from the ApplicationGatewaySubnet, so reaching a private endpoint in a peered spoke should work as long as peering, NSGs, UDRs, and the NVA allow the traffic in both directions. Confirm that the gateway subnet can resolve the storage hostname to the private endpoint IP and that the NVA is not blocking or asymmetrically routing the connection.
Check the Application Gateway listener and routing rule separately from the backend configuration. The listener should match the client-facing hostname, while the backend HTTP settings and health probe should target the storage endpoint's expected hostname. Review whether the storage static website endpoint supports the private endpoint subresource and the exact protocol being used; a private endpoint for one Storage service subresource does not automatically expose every other endpoint.
A 502 usually means the backend health probe cannot complete, so check the backend health view first. Verify the private DNS zone is linked to the hub VNet, or that the hub DNS forwarders can resolve the storage hostname to the private endpoint address. Also make sure the probe uses the correct protocol, port, hostname, and path. If HTTPS is used, the backend hostname and certificate name must match.
Using the storage hostname as the backend address is generally preferable to using the private IP, but the probe may need an explicit host header. The frontend hostname such as app.example.local is not automatically the correct host header for the storage backend.

Since the gateways are in the hub and the backend is in a spoke, validate the effective routes and NSG flow logs from the ApplicationGatewaySubnet. A route through the NVA needs a valid return path as well; otherwise the backend health probe can fail even when the destination appears reachable.