Content
Exposing web servers to internet in Azure
Hello Team, I'm working on an architecture for one of our customers, The customer need to host his web server on Azure (CMS web server), the web server need to be exposed to internet I have some questions about the frontal connection of the web…


Geo-location policy in WAF blocks wrong address
We use application gateway with app gateway WAF policy enabled. A custom policy is the geo-location filter, which is blocking everything not originating from white-listed countries. It's been working for years, today it suddenly started blocking our…


How to get all firewall rules with all the properties via Azures Resource Graph?
Hi, I need help with proper formulation of a query that would give me all firewall rules with all properties so it can be saved as a CSV file. All rules from a particular directory.


Will my outbound connection from a VM timeout in 4mins if it not configured behind an azure firewall?
My VM is having a publicIP associated with it. It initiates a connection with a server in internet. but with 4 minutes of inactivity the connection times out and I dont receive the packets from my server. I see an 'idle timeout' setting for publicIP…
why some Azure FW rules should be re-save to continue to function otherwide the traffic is denied
why some Azure FW rules should be re-save to continue to function otherwide the traffic is denied? I have to click on the ... 3 dots next to the rule and click on save for the rule to start to function and allow the matching traffic otherwise the traffic…


Cannot connect to VM using RDP after setting up firewall for public ip of VM and VM public ip as none
I have followed the learn steps to set up firewall and configure it for public and when i tried to connect using public IP , the connection failed using public IP. I followed steps provided here:…


TLS Inspection not working.
TLS Inspection with auto-generate new certification feature in Azure Firewall Premium does not work. The document followed was as follows.…


Forcing VPN-to-ER through the firewall
Hi, I want to ask about the below scenario. I want to inspect the traffic between the region via firewall. I want to know that the UDR attached to the GWs mark in red are legitimate or not, when i create them the type in effective route of VM NIC…


Website Hosted on Azure || L7 Protection
We are looking to migrate a website to Azure and protect from DDoS and Layer 7 attacks. Moreover, and since the website will be accessed globally, we are looking to take advantage of an SDN Solution. As a result, I guess that Azure Front Door will be the…


How to promote Virtual Network Gateway Routes between to different Route Servers in different Regions.
If I have a Virtual Network Gateway on Azure East with a Site-to-Site (IPSEC) Connection to access some VM's in AWS, how can I promote these routes from the Route Server on East Region to the Route Server on the West Region so my NVA's on the East and…


SCALING OF AZURE FIREWALL
Is it possible to scale azure firewall instances manually?


How to avoid successful SSH Brute Force Attack
Daily I receive alerts for "Successful SSH Brute Force Attack". I have the active SSH service but in a another port than the default TCP/22. I have Azure Firewall that protects my server at the network level. The origin of SSH Brute Force…


Require solution to allow specific traffic from Firewall to the internet and deny rest all.
I want to allow specific websites from my firewall to the internet and deny rest all. I have added all required websites to application rules (as allow) under Firewall Policy, however if I add a network rule to deny all, it will block all the traffic…


How to connect my Azure firewall with VPN gateway
I have a VPN gateway configured in Azure to redirect an external call via that. I wanted to redirect continue this redirection which requires Azure firewall filtration too. Now my VM is call a URL call https://abcd.xyz.com/asd/ , this is resolving to…


I want to delete all resources from the account, but an error appear
Account status: Free Azure account, 30-day period expired, account disabled. Please let me know if my disable account on azure accumulates costs? or During the period when the account is disabled, can payments be accumulated? Are payments required for…


can we connect to spoke vnet by passing two virtual hub?
Hello everyone, I'm a bit stuck on a routing case. we have two virtual hubs, each with its own VPN gateway and Firewall. we also have two spokes which are located behind different hubs. Hubs are connected to each other with vnet to vnet VPN connection.…


Through tag, shutdown and start the firewall in Aazure?
According to the title, I would like to know if there is a way to turn off and on a firewall through tags, I need to configure it with this specification, making the schedule. Thanks


KQL - Azure Firewall - specific rule without duplicates
Hi, I'm pretty inexperienced with KQL and I'm struggling with preparing athe query I need. Goal: identify all hits on the Azure firewall for a specific rule, ideally excluding duplicates Azure does provide a built-in query like this: // Network rule log…


Add network rule on Azure firewall policy with Bash scripting
Creating rule collection 'Local-Traffic-policy'. (AzureFirewallPolicyAndRuleCollectionsConflict) Request parameter Firewall Policy FirewallPolicy and Rule Collection NetworkRuleCollections cannot coexist for the Azure Firewall…


SFTP Services
Dear All, We need to set up an SFTP solution that has a gateway and IP blacklist function. However, the public traffic passes through Azure Firewall, due to the DNAT on the firewall the client IP is removed. This hinders the blacklist functionality as…

