Content
Internet Routing via Azure Firewall
Hell All. We have a hub and spoke set up within Azure, within our hub resides our azure firewall and a express route gateway. The hub has 2 spoke vnets peered, each subnet within the peered vnet, has a UDR with a entry 0.0.0.0/0 pointing to the private…

Azure Firewall blocking traffic from Virtual Network Gateway
Hello All! We have a VPN (Site-to-site) connecting our customers On-Prem network with our Azure environment. In this Azure environment we have a VNet containing two VMs. This VNet has an Azure Firewall associated to it. In the Firewall rules, we have…

Azure Firewall Manager GUI peered vnet icon
This is from Azure Firewall Manager / Virtual Network GUI. What's the difference between green and blue icon?
path "/SUBSCRIPTIONS/5B0F54C4-6B83-44E7-A71F-E02E4C5CEFDC/RESOURCEGROUPS/HUB-NETWORK-EASTUS-RG/PROVIDERS/MICROSOFT.NETWORK/AZUREFIREWALLS/AZUREFIREWALL_SHD-HUB-EASTUS-VHUB"
We got security alert ,please suggest of the activity which kind of activity is it ? alert details is mentioned below path…

Alternative choice of Checkpoint firewall in Azure.
Hello experts! I am working on the Checkpoint firewall and managing Azure resources. But I wanted to know if we can use the functionalities of Checkpoint firewall in Azure Firewall as I wanted to keep only one portal to manage everything from Azure…
How to manage firewall public ips for secure virtual hub?
Hi all, I've created a virtual hub in my environment, and now I'm trying to make it a secure virtual hub by adding an Azure Firewall instance. For the firewall I want to use two public ips that I have created previously. From looking at the…
WAF exclusion rules alternatives
Hello, Can anyone help me with this. We enabled WAF rules for my Azure app services and two rules are blocking the below request (920230 - Multiple URL Encoding Detected, 931130 - Possible Remote File Inclusion (RFI) Attack: Off-Domain…
Managing ACR access via Azure Firewall Manager
Hi, I'm trying to create a solution where all Azure services (AKS, AKV, ASQL, ACR, etc.) can only be accessed if the client is connected using Azure VPN Gateway. I have already managed to connect AKS from a different VNET to only be accessed privately…

Backup up network settings of Azure for virtual routers/firewalls
Hi Guys, I have a few firewalls and routers set up in Azure. The firewalls and routers are locked down to a specific group (Security group) and also their configurations are backup daily. While Azure portal allows system, storage, virtual and security…
931100- Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link exclusion rules
Hello, Can anyone help me with this. We enabled WAF rules for my Azure app services and facing one issue with the rule "931100- Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link". Because of above rule i am getting the…

When to use Azure WAF or Azure Firewall ?
Hi Folks, Can anyone here please share some thoughts and comments of when to use Azure WAF or Azure Firewall? I have already existing Azure ExpressRoute so my Azure VMs can ping my OnPremise servers, and vice versa. My purpose here is to be able to…

Azure WAN and P2S VPN Forced Tunneling
I have setup Azure WAN with a secured hub(Azure Firewall). WAN also has a P2S VPN which am successfully able to connect to. I understand forced tunneling was not an option before Azure VWAN, but now can i do forced tunneling for my P2S clients and give…
TLS Inspection not working.
TLS Inspection with auto-generate new certification feature in Azure Firewall Premium does not work. The document followed was as follows.…
Azure P2S VPN for Remote Workers
Hello, I would like to know if there is an alternative to a forced tunnel VPN through Virtual WAN in Azure. We have an external company that needs to access one of our Azure Virtual Desktops. We use the azure remote desktop app that uses 365 credentials…

Azure secured hub with cross tenant Vnet peering
Hello, I am facing one challenge in Azure networking and I am really trying to figure it out but without luck at the moment. I have configured secured virtual hub in vWAN (Virtual WAN + Virtual hub + Azure Firewall). Thing is that there is…


I want to delete all resources from the account, but an error appear
Account status: Free Azure account, 30-day period expired, account disabled. Please let me know if my disable account on azure accumulates costs? or During the period when the account is disabled, can payments be accumulated? Are payments required for…
Add network rule on Azure firewall policy with Bash scripting
Creating rule collection 'Local-Traffic-policy'. (AzureFirewallPolicyAndRuleCollectionsConflict) Request parameter Firewall Policy FirewallPolicy and Rule Collection NetworkRuleCollections cannot coexist for the Azure Firewall…
Create Network firewall rule with Azure Powershell
Hi, I am trying to create Azure network firewall rule with PowerShell terminal. My all script is right according to Azure Documentation and get this error. I already update Az Module and other updates. kindly help me for these issues. Here I paste error…
any any allow rule on azure firewall
Hi MS, I have a secured HUB and my firewall has ANY-ANY allow rule. The inbound and outbound traffic is protected via NSGs. So are there any risks of having an ANY ANY allow rule or any best practices I should follow?
Cannot connect to an external server using a ShrewSoft VPN from an Azure windows machine
I am trying to connect to an external server (IP address x.y.z.0.1) using a ShrewSoft VPN client. But I always get "negotiation timeout occurred". When I try to do the same thing from my personal machine (outside of Azure VM), I am able to set…
