Configure Azure Firewall in a Virtual WAN hub

A secured hub is an Azure Virtual WAN hub with Azure Firewall. This article walks you through the steps to convert a virtual WAN hub to a secured hub by installing Azure Firewall directly from the Azure Virtual WAN portal pages.

Before you begin

The steps in this article assume that you've already deployed a virtual WAN with one or more hubs.

To create a new virtual WAN and a new hub, use the steps in the following articles:

Important

Virtual WAN is a collection of hubs and services made available inside the hub. The user can have as many Virtual WAN per their need. In a Virtual WAN hub, there are multiple services like VPN, ExpressRoute etc. Each of these services is automatically deployed across Availability Zones except Azure Firewall, if the region supports Availability Zones. To deploy an Azure Firewall with Availability Zones (recommended) in a Secure vWAN Hub, this article must be used.

View virtual hubs

The Overview page for your virtual WAN shows a list of virtual hubs and secured hubs. The following figure shows a virtual WAN with no secured hubs.

Screenshot showing the Overview page for an Azure Virtual WAN.

Convert to secured hub

  1. On the Overview page for your virtual WAN, select the hub that you want to convert to a secured hub.

  2. Once in the hub properties, select on Azure Firewall and Firewall Manager under the "Security" section on the left:

    Screenshot showing Azure Virtual WAN Hub properties.

  3. Select on Next: Azure Firewall button at the bottom of screen:

    Screenshot showing [Select virtual hubs] step in the conversion flow

  4. Select the Azure Firewall properties and status desired, then complete the wizard up to the Review + confirm tab:

    [Azure Firewall] step in the conversion flow

Note

As reported at the beginning of the article, the procedure described in this article will not permit the usage of Availability Zones for Azure Firewall.

  1. After the hub has been converted to a secured hub, Azure Firewall status will be reported as in the image below:

    Screenshot showing end result of the conversion flow.

View hub resources

From the virtual WAN Overview page, select the secured hub. On the hub page, you can view all the virtual hub resources, including Azure Firewall.

To view Azure Firewall settings from the secured hub, select on Azure Firewall and Firewall Manager under the "Security" section on the left:

Screenshot showing Azure Virtual WAN status view in Firewall Manager.

Usage of Availability Zones for Azure Firewall in the Azure Virtual WAN Hub, can be checked accessing the security properties of the hub, as shown in the screenshot below:

Screenshot showing Availability Zones property in Virtual WAN secured hub.

Configure additional settings

To configure additional Azure Firewall settings for the virtual hub, select the link to Azure Firewall Manager. For information about firewall policies, see Azure Firewall Manager.

Screenshot showing Secured Hub overview with Manage Security Provider.

To return to the hub Overview page, you can navigate back by clicking the path, as shown by the arrow in the following figure.

Screenshot showing how to return to the Overview page.

Upgrade to Azure Firewall Premium

At any time, it's possible to upgrade from Azure Firewall Standard to Premium following these instructions. This operation will require a maintenance window since some minimal downtime will be generated.

Next steps

For more information about Virtual WAN, see the FAQ.