Ability to add port ranges to DNAT rule

Dan 176 Reputation points
2020-09-14T08:50:43.617+00:00

Hi,

Is it possible to add a range of ports to a DNAT rule with Azure firewall? We currently have a machine that required a large range of UDP ports to be open, and adding individual rules for each port will be rather unmanageable.

Thanks

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
570 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Bastiaan 6 Reputation points
    2021-05-15T09:20:35.01+00:00

    This really blows my mind. It's very common to have port ranges in DNAT situations. For example, we need to add an pasive FTP server. This requires an range of at least 1000 ports. We are now adding them as single rules, but this is so time consuming. Please add ranges like with NAT and NSG's.

    The description of the field is "Destination Ports" while you have only one. :-(

    1 person found this answer helpful.

  2. suvasara-MSFT 10,006 Reputation points
    2020-09-14T13:21:00.273+00:00

    Greetings,

    You should be able to add multiple ports with a comma separation while creating a NAT rule in the Azure Firewall.

    24440-image.png

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    Best regards,
    Subhash


  3. Thomas, Philip 1 Reputation point
    2020-11-13T22:46:38.797+00:00

    Just have to ask @suvasara-MSFT , what is the recommended way of handling DNAT's that require a range of ports?

    0 comments No comments