Upgrade to Premium Azure Firewall SKU

Son 80 Reputation points
2024-05-01T07:47:57.3666667+00:00

Hi,

We are planning on upgrading our standard Azure FW SKU to a premium SKU soon using the upgrade function in the portal.

The premium SKU introduces IDPS, I was just curious as to whether that is enabled by default once you upgrade or if it is something you turn on afterwards at your choice? I am assessing the risks involved with the upgrade and whether there is potential for traffic to suddenly be blocked as a result of introducing the feature.

If anyone has any other pointers for the upgrade and things to watch out for it would be great if you could share that!

Thanks

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
681 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,509 questions
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 49,586 Reputation points Microsoft Employee
    2024-05-01T12:18:40.2133333+00:00

    Hello @Son ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you are planning to upgrade your Standard SKU Azure Firewall to Premium SKU using the easy upgrade feature and have some queries regarding the same.

    The premium SKU introduces IDPS, I was just curious as to whether that is enabled by default once you upgrade or if it is something you turn on afterwards at your choice?

    IDPS is not enabled by default.

    I've tested this by upgrading a Standard SKU Azure Firewall to Premium using the Change SKU option:

    User's image

    You can enable it and start with IDPS Alert mode before you enable Alert + Deny mode, while ensuring optimal performance for your Azure Firewall.

    Below are some documents that you can follow for best practices:

    https://learn.microsoft.com/en-us/azure/firewall/firewall-best-practices

    https://learn.microsoft.com/en-us/azure/well-architected/service-guides/azure-firewall

    If anyone has any other pointers for the upgrade and things to watch out for it would be great if you could share that!

    Performance is a consideration when migrating from the standard SKU. IDPS and TLS inspection are compute-intensive operations. The premium SKU uses a more powerful VM SKU, which scales to a higher throughput comparable with the standard SKU. Microsoft recommends customers perform full-scale testing in their Azure deployment to ensure the firewall service performance meets your expectations.

    https://learn.microsoft.com/en-us/azure/firewall/firewall-performance

    https://learn.microsoft.com/en-us/azure/firewall/firewall-best-practices

    The easiest way to change your Azure Firewall SKU with no downtime is to use the Change SKU feature.

    Refer: https://learn.microsoft.com/en-us/azure/firewall/easy-upgrade

    NOTE: Even though the above migration feature has no downtime, it is advised that you should always perform any upgrade/downgrade operations during off-business hours and scheduled maintenance times.

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.