AzureFW HA failure behavior

Glenn Hunter 125 Reputation points Microsoft Employee
2024-02-08T13:01:08.04+00:00

My customer has a couple of questions around the behavior of AFW in a failure scenario. I have investigated doc’s and Q&A and haven’t found any good answer. Could you please provide some detailed input to the following questions.  Scenario:
Azure FW is deployed (Service employs HA across AZs) MS/Azure gets a problem in one of the availability zones for some reason, 1: AFW Layer 4 configuration: is there a disruption to the data flow to the backend servers when changing AFW? 2: AFW Layer 7 configuration: How is the AZFW session state been handled, are they stateful sessions on all backend servers or are the sessions broken? 3: AFW Layer 7 with TLS inspection configuration: How is the AZFW session state been handled, are they stateful sessions on all backend servers or are the sessions broken? Many thanks

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
674 questions
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 26,216 Reputation points Microsoft Employee
    2024-02-12T19:42:54.5033333+00:00

    @Glenn Hunter

    Just sharing the response received from the product regarding this question here for community benefit.

    Based on the questions above

    1: AFW Layer 4 configuration: is there a disruption to the data flow to the backend servers when changing AFW? 

    In case the firewall is deployed in 3 zones, zone aligned ones, meaning explicitly chosen all 3 zones during creating, then the firewall instances on the VM’s with the zone down will stop working, those connections will stop and the others operating vms will take them as they come again.

    2: AFW Layer 7 configuration: How is the AZFW session state been handled, are they stateful sessions on all backend servers or are the sessions broken?

    The sessions are stateful, hence the sessions on the VM’s that went down during one of the zones will be broken and need to be reestablished.

    3: AFW Layer 7 with TLS inspection configuration: How is the AZFW session state been handled, are they stateful sessions on all backend servers or are the sessions broken?

     same as above.

    Hope this helps!


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.