I don’t know what is happenning when I make the firewall rule "allow-frontend-to-backend-fwr" the target is the backend-sa and the filter is the frontend-sa with icmp protocol, when I try to do a ping from a frontend instance to a backend instance is not possible to stablish a connection. Anybody had the same issue?
I had the same issue as well. So the second time around I created my instance groups with network tag The weird thing is that I used the network tags as the target in the firewall rule and then got it working. Then I deleted the firewall rule with the network tag and recreated it with the service accounts and then it was working.
Conclusion: it either is a glitch or the service accounts might need some time to propagate.