Azure Firewall: lack of service tag: Internet / allow access to the Internet on the specific port
Hi all, I tried to use service tag "Internet" on the Azure Firewall but I see that it's not available in this product (https://learn.microsoft.com/en-us/azure/virtual-network/service-tags-overview#available-service-tags) Case Environment 2…
Difficulty Identifying Edited Rules in Azure Firewall Logs via KQL
Hello, community! I'm having trouble identifying specific changes to Azure Firewall rules through KQL (Kusto Query Language). After modifying certain firewall rules, I can see that edits have occurred through the firewall’s logs tab (where it shows a…
closed ports 443 and 80 on all my VM's
my firewall is open for all inbound ports in order to troubleshoot the issue but I am still having that my only two ports is closed 443 and 80 only but all other ports are open in all my VM's . I have a peering network between two VNET is this where came…
Site to Site VPN Connection
I have configured site to site VPN as per the Microsoft documentation. We have created: Vnet Vnet Gateway Local network gateway Connection We have configured with all the client's requirement. We are seeing connection status: Unknown We have also created…
How can I get sorted Hit count in the Traffic Flows tab in Azure Firewall Policy Analytics?
Hi, we are planning a larger network change and to prepare for that we want to make sure we are aware of the most common traffic patterns within our network. Thus, we turned to Azure Firewall Policy Analytics as it could be a great tool to better…
Need to find Top talkers from Azure Firewall network Logs
I want a KQL query and configuration settings which can give me Azure firewall network rule logs with column having details for SentBytes and received bytes details for each packet.
How to effectively tune Azure WAF without exhausting too many resources
We have Azure WAF rules in prevention mode in both Azure Front Door and APIM gateway. We are facing this issue for a long term due to so many false positives blocking requests from our end users, frustrating us and users as there is no predictive…
On premise network routing to internet via azure s2s
I have a test device that works on us internet only. we are the organization working for US clients. So to make the device work for test purpose we need to route all traffic from device via azure to internet. How can we do that please help me to find me…
Is there a need to configure any port on Firewall for Azure Arc inbound connectivity?
I want to know whether AzureArc extensions like AMA, WAC, ESU, HybridWorker etc need any inbound ports to be opened on Firewall? The outbound connectivity is public via the internet. Nothing configured for Inbound specifically. A lot of these extensions…
How to find azure firewall rules using KQL
Hi Team, We are currently having an azure firewall in place and also diagnostic settings are enabled to log the information in Log Analytics Workspace. However, when I run the below query I'm not getting any results: AzureActivity | where…
Unable to bypass network traffic through firewall, if private link is configured for storage account.
I have a firewall configured in subnet x in my vnet. I also have an aks cluster launched in the same vnet, within subnet y. I have configured a private endpoint for a storage account, and am trying to access the same from my aks subnet, which is…
Trying to open ldap port on azure fw but it just plain wont open
Hi everyone, please excuse my lack of knowledge here as I am trying to learn as I go. I have a Synology NAS device at my office that I would like to connect with my Azure Ad so that I can pass authentication for sharing permissions to the NAS. I am…
How do I configure an inbound NAT rule in Azure Firewall to point at an Azure Container App?
The instructions to filter inbound traffic uses a Virtual Machine with a private IP address. If I set up a Container Apps Environment with a subnet and a Container App with VNet only ingress, the Container App replica doesn't have a private IP available.…
Azure Firewall DNS Proxy & DNS Private Resolver
I am trying to achieve a setup where I have the following main components. Hub vnet 10.0.0.0/23 This has a VPN connection to on-premises This has a Azure Firewall Shared services vnet 10.0.3.0/24 This has DNS Private Resolver With inbound and…
When to use Azure WAF or Azure Firewall ?
Hi Folks, Can anyone here please share some thoughts and comments of when to use Azure WAF or Azure Firewall? I have already existing Azure ExpressRoute so my Azure VMs can ping my OnPremise servers, and vice versa. My purpose here is to be able to…
Azure Firewall Migration to vWAN Hub
I have a question regarding migrating/replacing Azure Firewall (in this case standard Firewall) in a hub-and-spoke network, and replacing with a Azure secured VWAN hub. I have looked at the following migration guide which includes secured WAN:…
How to create a Routing table between my Azure firewall to Azure SD-WAN Vmx
Hello we have a Vnet name Vnet-SD-WAN and Below are subnets in Vnet 10.170.0.0/22 and Sd-wan Vmx subnet - 10.170.1.0/28 Azurefirewall subnet -10.170.3.0/26 Azure Application gateway : 10.170.3.64/26 Network flow in below way …
Azure firewall logging traffic in a hub-and-spoke network
Hi, A similar sort of setup and query to this thread here, however I have a more specific question: https://learn.microsoft.com/en-us/answers/questions/1322184/azure-firewall-traffic-logging-for-route-based-vpn We have Azure Firewall logging all traffic…
Azure Firewall Logical Unit and Throughput
Hello Experts, Would like to know throughput for single logical unit of Azure Firewall 'Standard' and single logical unit of Azure Firewall 'Premium' , if it is same or different. As per following Azure URL -…
Azure Firewall rule limits
Hello, In our environment it is expected to reach the rule limits (20,000 unique source/destinations in network rules) and i know if i exceeded the limits this might impact my performance. Now i need to know what my options will be if i need more rules…