Azure firewall migration from third party firewall
prasantc
936
Reputation points
I am planning to migrate from a third party firewall to Azure firewall. Without much downtime
- Currently, all UDR points to third party firewall appliance hosted in Azure
- I have setup a firewall and empty policy in Azure
- I am will be importing rules from CSV
- Once the policy is ready, I will secure the hub using existing policy and deploy the new firewall created by secured hub. Repurpose the public IP of old AZ firewall to the new firewall deployed from hub and delete old firewall.
- Enable routing intent on the secured hub
- peered one of the test subscription and test subscription vvnets to VWAN.
- Test all traffic from test subscription.
- Start peering other subscription to VWAN.
Only thing I am worried about is step 5. Which will enable all default summary route of all RFC1918 IP address for both internet and internal traffic pointed Azure firewall. With this setup would it be possible only to peer test subscription for initial test and route all remaining subscription UDR traffic to third party firewall?
Sign in to answer