Azure Firewall Policy Analytics: "rules with multiple IP addresses"

Robbert K 21 Reputation points
2024-11-19T09:40:20.1366667+00:00

We started using Policy Analytics and I have the following issue:

The 'Rules with multiple IP addresses' the pane on the Insights tab shows '6 rules with more than 10 source IPs'. When I click on 'See recommendations' I get a list of over 50 recommendations. This is not what I expect when clicking on the recommendations link.

Where can I see what 6 rules this recommendation is about? And can this confusing part of the UI be corrected?

User's image

User's image

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
693 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 47,571 Reputation points Microsoft Employee
    2024-11-19T11:04:17.3366667+00:00

    @Robbert K ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you are using Policy Analytics in Azure Firewall.

    Can you please elaborate what is the recommendation you are expecting?

    • The screenshot you shared is partial
    • From the Policy Analytics video available here : https://www.microsoft.com/en-us/videoplayer/embed/RE57NCC?postJsllMsg=true,
      • User's image
      • I see RuleName, RuleCollection, RuleGroup as well
    • Are you concerned about the multiple/duplicate entries for each Rule?
      • I assume there are multiple entries based on the number of IPs
      • Once you create an IP group for a single Rule, it should not be popping up in this table.

    If you have any suggestions for the UI/Recommendations, please consider requesting the feature in Azure Feedback Hub.

    All the feedback shared in these forums are monitored and reviewed by the Microsoft engineering teams responsible for building Azure.

    Please let us know if we can be of any further assistance here.

    Thanks,

    Kapil


    Please Accept an answer if correct.

    Original posters help the community find answers faster by identifying the correct answer.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.