Share via

Azure firewall Active -Passive mode similar like PA

AzurePro 80 Reputation points
2025-03-11T06:34:06.4433333+00:00

I want to setup Azure firewall 2 instance. 1 is node is active and 1 node is passive. i cant find any such scenarios on internet having such design with failover.

Azure Firewall
Azure Firewall

An Azure network security service that is used to protect Azure Virtual Network resources.


1 answer

Sort by: Most helpful
  1. Praveen Bandaru 11,550 Reputation points Microsoft External Staff Moderator
    2025-03-11T13:26:56.9866667+00:00

    Hello AzurePro

    I understand that you want to set up an Azure firewall with two instances: one active and one passive.

    • Azure Firewall does not inherently support an Active-Passive high availability mode like Palo Alto (PA) firewalls. However, you can achieve a similar result using Azure Firewall with Availability Zones.
    • Azure Firewall is a fully managed service that supports zone-redundant deployment, distributing traffic across multiple availability zones.
    • This ensures high availability but operates in an Active-Active mode rather than Active-Passive.
    • Check the document for more understanding High availability
    • And also, availability Zones can only be configured during deployment. You can't configure an existing firewall to include Availability Zones.

    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.    

    If you have any other questions or are still running into more issues, let me know in the "comments" and I would be happy to help you.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.