Azure Firewall Rule Conf

alsavi1984 21 Reputation points


I have questions about network rule creation as I have doubts about it.

Which type of source addresses are allowed? Could I configure different ip address separated with commas, different CIDR ranges or a mixture of its?

Then in the Destination Addresses field could I use a mixture of CIDR nets and Ip addresses?

I will be very grateful If you could help with it.


Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
603 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. suvasara-MSFT 10,026 Reputation points

    @alsavi1984 , Yes, you can configure a single IP address or IP's separated with commas. Incase of adding address range you can select IP group option. An IP Group can have a single IP address, multiple IP addresses, or one or more IP address ranges.

    The following IPv4 address format examples are valid to use in IP Groups:

    Single address:
    CIDR notation:
    Address range:


    Note: IP Groups are not currently available in Azure national cloud environments.

    The same goes with destination address field as you have option to select IP group.


    Reference Doc


    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    0 comments No comments

  2. alsavi1984 21 Reputation points

    Thank you Suvahara.

    My question was related about using different single ips plus network ranges. I think it is possible.

    The problem here it's about creating more than 100 hundreds ipgroups. I will expect that MSN could solve it.

    Kind Regards