Azure Firewall SNAT one-to-one

Anonymous
2025-05-29T07:57:25.27+00:00

Hello,

I have an Azure firewall configured with one public IP address. But I need to do a SNAT one-to-one for a particular server that must has another public IP address in addition to the already configured public IP address of the AZ FW.

This feature is available on AZ FW?

Regards,

Rogerio.

Azure Firewall
Azure Firewall

An Azure network security service that is used to protect Azure Virtual Network resources.


Answer accepted by question author
Anonymous
2025-05-29T08:17:12.6666667+00:00

Hi @Ferreira, Rogério

It sounds like you're looking to configure a one-to-one SNAT for a specific server in your Azure Firewall setup, allowing it to use a different public IP address alongside the existing one.

Currently, Azure Firewall supports SNAT but it typically SNATs all outbound traffic to its public IP address. In projects with multiple public IP addresses, any public IP can be chosen for outbound connections, and it doesn’t support individual SNAT setups for distinct servers directly.

However, if you need a more granular setup, you might want to consider integrating an Azure NAT Gateway. Here's how it could help you out:

Use NAT Gateway: You can associate a NAT Gateway with your virtual network/subnet alongside the Azure Firewall. This gateway allows for multiple public IP addresses and can allocate SNAT ports dynamically for outbound connections, giving you greater flexibility.

Configuration: Once a NAT Gateway is associated with the Azure Firewall subnet, all outbound internet traffic will utilize the public IP addresses of the NAT Gateway for SNAT. However, the selection of which public IP is used for each session is randomized, meaning you can’t explicitly assign a single public IP to a specific internal server.

Limitations: If a one-to-one mapping is critical, you may need to look into using a Load Balancer or another architecture as NAT Gateway doesn't provide static IP assignment per server for outbound traffic.

For detailed steps on how to integrate a NAT Gateway with Azure Firewall, you can refer to this documentation.

If the "one-to-one SNAT" requirement is specifically for inbound traffic and then outbound responses related to an application (e.g., a web server), you might consider using a Standard Load Balancer with outbound rules. This can expose a public IP and manage connections to backend servers. However, this is for application-specific scenarios, not general outbound internet access from a server.


Your feedback is important so please take a moment to click 'Accept answer'.

If you still have questions, please let us know what is needed in the comments so the question can be answered.

Was this answer helpful?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.