Can you create your own custom IDPS Signatures/Rules
Is there a way to create custom IDPS signatures like with mainstream NGFW providers (Palo Alto, Fortinet, Checkpoint, Snort etc.) for the Azure Firewall Premium? Thanks
Pass Client IP to the webserver behind Azure Firewall
Is it possible to Pass Client IP to the webserver behind Azure Firewall, need to obtain the original client IP's which connect to my webserver behind the azure firwall
Azure Firewall
Need to get the source IP of the client who is connecting from outside to my webserver behind a Azure Firewall NAT rule
Point-to-Site VPN protected by Azure firewall from the outside
Hello, I am wondering how I could configure the hub to route traffic as follows: p2s tunnels over the internet -> azure FW - > vpnGateway - > AzureFW -> vnet subnets (and back to p2s clients the same way) tia
Azure Firewall Log Query - Src and Dst IP Only
Hi folks - newbie here so excuse me - don't worry i'll stop asking basic qtns here very soon [hopefully] Can I please ask someone to share script to run query for defined source / destination IP only only. So in other words, show me all flow with the…
Avoiding Preflight calls
I have frontend react app deployed in Az CDN and backend in Az App service. How can I avoid CORS issue i.e. avoiding preflight calls? Please suggest a solution.
How to set up a multi-spoke virtual network in Azure Firewall
Can you tell us how to configure multiple-spoke virtual networks in Azure Firewall when you adopt a hub-spoke network topology in Azure?
Cannot Delete Azure Firewall
Hi Folks, I am not able to delete azure firewall, error: Failed to delete the Azure Firewall 'AZFW01'. Error: Azure Firewall AZFW01 failed to dereference Firewall Policy…
Hub & Spoke with Azure Firewall - Integrating External Businesses
Hi, I need to find a solution to integrate external businesses into our Azure Hub & Spoke environment with an Azure Firewall. By external businesses I am meaning businesses that we own as a group but are not connected to our normal MPLS network. I…
Assigning external IP to subnets
I am looking into the functionality of Azure in comparison to our existing on prem firewall. Currently we have a batch of external IPs broken up and assigned to one of the vnets on our firewall. i.e. Subnet 1 uses External IP 1 to go out to the…
Is there a way to restrict SSH access to Azure VMs by country instead of a specific IP range?
We are looking for a way to improve the security of remote access. Our teams with SSH access are only in a few countries. Restricting the SSH source country or even city would be the ideal strategy, which is clearer, simpler and more flexible than a…
Route all Virtual Gateway P2S traffic through Azure Firewall
I'm trying to set up a firewall between a P2S Virtual Gateway connection and the remainder of my Azure network but having trouble figuring out how to set it up. As a simplified architecture, I have two VNets "hub" and "spoke" and…
Azure Firewall Health and SNAT Ports usage shows unavailable after 3 days.
Azure Firewall Health and SNAT Ports usage shows unavailable after 3 days. Earlier, SNAT was 0% and Health state was 100%. What could have gone wrong. Probably I was enabling log analytics for this Firewall that day. Tried to remove it to rule that…
Azure Firewall Network Rule for O365 - Error "Invalid argument: 'Malformed IP address: 2603:1006:1400::'"
Hi Community Just wondering if I'm completely off-the-mark here and someone can provide insights from experience. While configuring Azure Firewall Network rule for Office 365 IP Address ranges as suggested here-->…
Hub spoke architecture public access
Hello I am hoping to get a conformation about a best practice concearning the hub spoke architecture. We have a hub spoke architecture. It has a expressroute connection between the onprem network and Azure. The er gateway is in the hub network, so is…
Azure +Cisco Meraki+Azure route server
Hello, Do we have any approved pattern for Cisco Meraki on Azure with Azure route server and PA firewall? We have a Hub n Spoke topology in 2 region and in each region we have Meraki+ARS+PA firewall. Have someone attempted something likethis? Any…
Azure Advisor - Virtual Network should be protected by Azure Firewall
Azure Advisor is suggesting that we protect our virtual network by Azure Firewall (Low alert) but in the process of doing this, it is asking us for Public IP address . This is risky, why would we want to have poke a hole to have a Public IP address. …
Target FQDNs in application rules
According to this https://learn.microsoft.com/en-us/azure/firewall/firewall-faq Azure fw supports: TargetURL www.contoso.com/test When I try adding this it won't allow me to. However I can enter wildcard .contoso.com but not contoso.com/ Any…
Why azure firewall (premium) deny'ing 443 traffic
We deployed Azure Firewall Premium in AzureFirewallSubnet subnet (10.100.0.128/25 ) I am seeing 443 traffic being denied, see the attached screen capture. How can know more about this traffic? Below is the screen capture of our…
What are premium firewall options like IDS/IPS/TLS inspection based on ?
Is it a solution completely build by Microsoft or is based on other NGFW from vendors like PaloAlto, Cisco (Snort) and the likes?