Azure Firewall High Latency

Azra Akil 40 Reputation points
2023-10-25T13:30:53.87+00:00

I have a firewall setup of standard SKU type what is the recommended latency probe recommended for standard SKU.

If it reaches the maximum latency how we can resolve?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
567 questions
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
84 questions
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 22,941 Reputation points Microsoft Employee
    2023-10-25T20:55:32.87+00:00

    @Azra Akil

    Thank you for reaching out.

    Based on your questions above.

    I have a firewall setup of standard SKU type what is the recommended latency probe recommended for standard SKU.

    I think you can explore the option of using AZFW Latency Probe,

    This metric measures the overall or average latency of Azure Firewall in milliseconds. Administrators can use this metric for the following purposes:

    • Diagnose if Azure Firewall is the cause of latency in the network.
    • Monitor and alert if there are any latency or performance issues, so IT teams can proactively engage.
    • There may be various reasons that can cause high latency in Azure Firewall. For example, high CPU utilization, high throughput, or a possible networking issue.

    This metric doesn't measure end-to-end latency of a given network path. In other words, this latency health probe doesn't measure how much latency Azure Firewall adds.

    • When the latency metric isn't functioning as expected, a value of 0 appears in the metrics dashboard.
    • As a reference, the average expected latency for a firewall is approximately 1 ms. This may vary depending on deployment size and environment.
    • The latency probe is based on Microsoft's Ping Mesh technology. So, intermittent spikes in the latency metric are to be expected. These spikes are normal and don't signal an issue with the Azure Firewall. They're part of the standard host networking setup that supports the system.

    You can check this metric on in Metrics section on Azure Portal.

    User's image

    If it reaches the maximum latency how we can resolve?

    If there is a spike in the latency, it can be caused due high CPU utilization, high throughput, or a possible networking issue. In case of high CPU utilization or high throughput you can migrate your firewall to premium SKU which offers higher scalability as described here.

    Although in case you observe high latency for a prolonged period, it is recommended to create a support request as a support engineer can take a look at the backend logs and help pin-point the issue.

    Hope this helps! Please let me know if you have any additional questions. Thank you!


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful