Hello,
Welcome to Microsoft Q&A, thank you for asking your question.
You should set the Application Gateway's backend pool to the Azure Firewall's private IP address. This setup ensures that all incoming traffic passes through the Application Gateway and is then forwarded to the Azure Firewall for inspection before reaching your web applications within the Virtual Network (VNet).
- Navigate to your Azure Firewall instance in the Azure Portal.
- Locate the private IP address assigned to the firewall within its dedicated subnet (
AzureFirewallSubnet
).
For more information on the architecture and best practices, please have a look into the below link.
Please Upvote and Accept the answer if it helps!!