Azure Firewall scale in issue

asked 2023-01-16T11:26:07.0233333+00:00
Pratik Shinde 1 Reputation point

Hello Team,

We are having issue with Azure firewall premium where AZFW scale out as throughput hits > 2gbps. throughput is moving from 2gbps to 6 gbps for few minutes and then came back to < 1.5 gbps. After that Scale in may starts.
But after few minutes/hrs if throughput hits again over 2gbps then what is the exact action taken by AZFW.? Does is perform scale out action or it continues with scale in operation which is on-going?

In this case, we are loosing session and connections for a long time. Also want to know about session persistence and TCP reset is enabled or not by default in AZFW.

Thank you !!

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
331 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
1,171 questions
Azure Virtual Machine Scale Sets
Azure Virtual Machine Scale Sets
Azure compute resources that are used to create and manage groups of heterogeneous load-balanced virtual machines.
216 questions
{count} votes

1 answer

Sort by: Most helpful
  1. answered 2023-01-16T12:44:20.29+00:00
    KapilAnanth-MSFT 8,891 Reputation points Microsoft Employee

    @Pratik Shinde

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to know more about Azure Firewall Scaling, Session Persistence and TCP Reset.

    Breaking the average throughput changes,

    2 Gbps to 6 Gbps - Scale Out

    6 Gbps to 1.5 Gbps - Scale In

    1.5 Gbps to 2 Gbps - Scale Out

    It should take about 10 to 15 minutes to inorder to notice the effective scale out.

    For a scale in, it should take about 1.5 minutes.

    P.S:

    • The above calculations (numbers) hold for Standard AzFW.
    • For Premium AzFW, the initial Max bandwidth is upto 18 Gbps and scale out should start only at 10.8 average bandwidth (i.e, 60%)
    • User's image

    Wrt Session Persistence and TCP Reset,

    Refer : How does Azure Firewall handle VM instance shutdowns during Virtual Machine Scale Set scale in (scale down) or fleet software upgrades?

    User's image

    Hope this helps.

    Thanks,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    No comments