Skip to content
Tech Master Tech Master

OneStopTechnical Forum

  • Books
  • AI
  • Networking
  • Windows
  • Linux
  • Cloud
  • Mac
  • Active Directory
  • Azure
  • Cloud
  • Exchange
  • M365
  • Server 2025
  • Storage
  • Vsphere
  • Website
  • Database
  • Security
  • Knowledge Base
  • VPN
Tech Master
Tech Master

OneStopTechnical Forum

Azure firewall and firewall rules

blog.payperitem.com, April 16, 2025April 18, 2025

Azure Firewall is a cloud-native, managed network security service provided by Microsoft Azure. It acts as a stateful firewall as a service, designed to protect Azure Virtual Network (VNet) resources. It allows you to control both inbound and outbound traffic using defined rules and is fully integrated with Azure Monitor for logging and analytics.


🔥 Key Features of Azure Firewall:

  • Stateful inspection: Remembers the state of active connections and uses that to determine whether traffic is allowed.
  • High availability: Built-in high availability and auto-scaling.
  • Threat intelligence: Uses Microsoft Threat Intelligence feeds to deny traffic from known malicious IPs/domains.
  • Application FQDN filtering: Rules based on Fully Qualified Domain Names (FQDNs).
  • Integration with Azure services: Works well with Azure Monitor, Sentinel, and other tools.
  • Supports hybrid networks: Can inspect traffic between on-prem and cloud via VPN or ExpressRoute.

🛡️ Azure Firewall Rule Types:

Azure Firewall rules are grouped into rule collections, and they can be of the following types:

1. Network Rules

Used for L3/L4 traffic filtering based on:

  • Source IP
  • Destination IP
  • Protocol (TCP/UDP/ICMP)
  • Port

📌 Example:
Allow traffic from 10.0.0.0/24 to 192.168.1.1 on TCP port 443.


2. Application Rules

Used for L7 HTTP/S traffic filtering based on:

  • FQDN (e.g., *.microsoft.com)
  • HTTP methods
  • TLS inspection (if enabled)

📌 Example:
Allow outbound access to www.office365.com over HTTPS.


3. NAT Rules (DNAT)

Used to translate public IP traffic to private IPs behind the firewall.

  • Supports inbound traffic redirection.

📌 Example:
Public IP 20.50.10.5:443 → Private IP 10.0.1.5:443


📚 Rule Collection Structure:

Each rule collection has:

  • Name
  • Priority (lower number = higher priority)
  • Action (Allow/Deny/Redirect)
  • Rules (the actual rules themselves)

    Azure Cloud Security #100GbE#100GbECloudNetworking#10GbE#40GbE#5GUPF#AdaptiveResync#AdaptiveResyncNVMe#AF_XDP#AIArbitrage#AIClusterOptimization#AIInferenceonFPGA#AIModelParallelism#AIonGPUs#AIQuantTrading#AMDMPGPU#AnsibleAutomation#AnsibleForVMware#ApacheFlinkPerformance#AWSNitro#AWSVMwareCloud#Azure#AzureVMwareSolution#BareMetalCloudTuning#BareMetalServer#BatchedInferenceOptimization#BladeServers#BSOD#CacheTiering#CentOS#CephHighPerformance#CiscoACI#CiscoACIAnsible#CiscoHyperFlex#CiscoMDS#CiscoNexus#CiscoUCS#CiscoVPC#CiscoVXLAN#CloudComputing#CloudHosting#CloudMigration#CloudNative5G#Colocation#ColumnarStorageTuning#CompressionOptimization#Containerization#CUDAonVMware#CyberSecurity#CyberSecurity #WindowsSecurity #PrivacyMatters #Firewall #EndpointSecurity#DataCenter#DataCenterNetworking#DDoSProtection#DebianServer#Deduplication#DeepLearningHFT#DeepLearningInfra#DellCompellent#DellIDRAC#DellIDRACAPI#DellOpenManage#DellPowerEdge#DellPowerMax#DellPowerStore#DellUnityXT#DellVxRail#DirectFlash#DirectMarketAccess (DMA)#DirectX#DistributedTrainingInfra#DPDK#DPDKTelcoOptimizations#DPUPassthrough#DPUvsFPGA#DruidRealTimeAnalytics#DVS#DynamicCongestionControl#eBPFNetworking#EdgeAIOptimization#EdgeComputing#EnterpriseIT#ESXi#ESXiAdaptiveResync#ESXiNUMAOptimization#ESXiQueueDepth#ESXiRDMA#ESXiTuning#ETLPerformanceOptimization#FCBufferCredits#FCNPIV#FCoE#FCoEPerformance#FCPortChannel#FibreChannel#FibreChannelZoning#Firewall#FPGAforAI#FPGAforHFT#GameOptimization#GlobalEdgeRouting#GoogleCloudVMwareEngine#GPUDirectStorage#GPUPassthrough#HardenedServer#HLSforFPGA#HPC#HPCforAI#HPE3PAR#HPEAlletra#HPEGen10Plus#HPEiLO#HPEiLOAutomation#HPEInfoSight#HPEOneView#HPEPrimera#HPEProLiant#HPEStoreOnce#Hyperscale#HyperscaleLoadBalancing#HyperscaleMultiTenantSecurity#HyperV#IDSIPS#InfiniBandAI#InfrastructureAsCode#IntelFPGAAcceleration#IntelSPDK#IntrusionDetection#IOPSOptimization#IOTailLatency#iSCSI#iSCSIJumboFrames#ITInfrastructure#ITPro#JuniperNetworks#K8sMultiCloud#KafkaUltraLowLatency#KernelBypassNetworking#KubernetesCluster#KVM#LatencyArbitrageInfra#LatencyFix#LinuxServer#LUNQueueDepth#ManagedHosting#MarketDataFeedOptimization#MarketMakingAI#MellanoxConnectXPerformance#MellanoxGPUDirect#MellanoxNetworking#MellanoxRoCE#Microsegmentation#Microservices#MIGonNVIDIA#MultiAccessEdgeComputing#NASStorage#NetAppAFF#NetAppAnsibleModules#NetAppFAS#NetAppFlexGroup#NetAppMetroCluster#NetAppONTAP#NetAppSnapMirror#Networking#NeuralAccelerators#NeuralNetworkBacktesting#NFVAcceleration#NSXT#NVGPUPassthrough#NVIDIABlueField#NVMe#NVMeLatencyBenchmark#NVMeoF#NVMeoFPerformance#NVMeOverFabric#NVMePolling#NVMeQueueDepth#NVMeTCPPerformance#NVSwitchTuning#O-RANOptimization#OnChipNetworking#OpenStack#OptanePMem#P4ProgrammableNIC#PCGaming#PCIssues#PensandoDPU#PersistentMemoryRDMA#PFCforRoCE#PicoSecondPrecision#PipelinedCompute#PowerShell#ProgrammableNICs#Proxmox#PureEvergreen#PureFlashArray#PureStorage#PureX90#PyTorchXLA (Accelerated Linear Algebra for PyTorch)#QoSStorage#RAID#RDMA#RDMAonDPU#RDMAOptimization#RDMAoverEthernet#RDMAQueueDepthTuning#RDMAStorage#RedHat#ReinforcementLearningForTrading#SANStorage#SentimentAnalysisTrading#Server#ServerlessPerformanceTuning#ServerRoom#ServerSecurity#SIEM#SIEMSolutions#SOC2Compliance#SRIOV#SRIOVNetworking#SSDServers#StorageClassMemory#StorageIOControl#StorageTiers#StreamingDataOptimization#StreamProcessingAI#SubMicrosecondTrading#SysAdmin#SysAdminLife#TaskScheduler#TCPBypass#TechSupport#TelcoEdgeAI#TensorFlowXRT#Terraform#TerraformMultiCloud#TerraformVMware#TickToTradeOptimization#TinyMLPerformance#UbuntuServer#UltraLowLatencyFPGA#vCloudDirector#VectorizedQueryExecution#VFIO#vGPUPassthrough#VMDirectPathIO#vMotion#VMware#VMwareHCX#VMwarePowerCLI#VMwarePVRDMA#VMwareSmartNIC#VPSHosting#vRANPerformanceTuning#vSANDeduplication#vSANPerformance#vSANResyncImpact#vSphere#vSphereMultiCloud#vSphereOptimization#WindowsAutomation#WindowsDebugging#WindowsFix#WindowsGaming#WindowsServer#WriteAmplification#WriteBackCaching#XilinxAlveo#XilinxSmartNIC#ZeroCopyNetworking#ZeroLatencyInference#ZeroTrustArchitecture#ZFSPerformanceTuning

    Post navigation

    Previous post
    Next post

    Related Posts

    Windows 10/11 Hardening Checklist

    April 29, 2025April 29, 2025

    1. OS and Software Updates 2. Account and Credential Hardening 3. BitLocker and Disk Encryption 4. Windows Defender and Security Features 5. Firewall and Network Protection 6. Remote Access Hardening 7. Application Control 8. Browser Hardening 9. Device and Hardware Security 10. Privacy and Telemetry 11. Advanced Policies (Group Policy…

    Read More

    Windows NPS (RADIUS) with Palo Alto Networks firewalls

    April 11, 2025April 11, 2025

    Integrating Windows NPS (RADIUS) with Palo Alto Networks firewalls lets you centralize VPN and admin authentication via Active Directory. Here’s a full deep-dive for both GlobalProtect VPN and admin GUI/CLI login with RADIUS + optional MFA. 🔁 Integration Overview 🧱 Windows NPS Configuration 1. Add Palo Alto as a RADIUS…

    Read More

    🔐 Forgotten Passwords & Login Issues: Deep Dive

    April 8, 2025April 8, 2025

    🔐 Forgotten Passwords & Login Issues: Deep Dive 🧠 Start with Context Questions to ask: 💻 1. Local OS Login (macOS / Windows / Linux) 🔧 macOS 🔧 Windows 🔧 Linux ☁️ 2. Cloud Accounts / SaaS (Microsoft 365, Google, AWS, etc.) 🖥️ 3. Servers: ESXi, vCenter, Linux, AD DC,…

    Read More

    Recent Posts

    • List of AD Schema Versions
    • OldNewExplorer Free Download For Windows 11, 10, 8 and 7 [Latest Version]
    • How to Get the Classic (old) Context Menu on Windows 11
    • BitLocker Recovery Keys
    • Active Directory and Server hardening

    Recent Comments

    No comments to show.
    June 2025
    M T W T F S S
     1
    2345678
    9101112131415
    16171819202122
    23242526272829
    30  
    « May    
    Log in
    ©2025 Tech Master | WordPress Theme by SuperbThemes
    • Login
    • Sign Up
    Forgot Password?
    Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.
    body::-webkit-scrollbar { width: 7px; } body::-webkit-scrollbar-track { border-radius: 10px; background: #f0f0f0; } body::-webkit-scrollbar-thumb { border-radius: 50px; background: #dfdbdb }