Azure firewall migration from third party firewall

prasantc 936 Reputation points
2024-05-06T22:05:01.7366667+00:00

I am planning to migrate from a third party firewall to Azure firewall. Without much downtime

  1. Currently, all UDR points to third party firewall appliance hosted in Azure
  2. I have setup a firewall and empty policy in Azure
  3. I am will be importing rules from CSV
  4. Once the policy is ready, I will secure the hub using existing policy and deploy the new firewall created by secured hub. Repurpose the public IP of old AZ firewall to the new firewall deployed from hub and delete old firewall.
  5. Enable routing intent on the secured hub
  6. peered one of the test subscription and test subscription vvnets to VWAN.
  7. Test all traffic from test subscription.
  8. Start peering other subscription to VWAN.

Only thing I am worried about is step 5. Which will enable all default summary route of all RFC1918 IP address for both internet and internal traffic pointed Azure firewall. With this setup would it be possible only to peer test subscription for initial test and route all remaining subscription UDR traffic to third party firewall?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
692 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.