Azure Firewall policy rule sets (2024)

  • Article

Firewall Policy is a top-level resource that contains security and operational settings for Azure Firewall. You can use Firewall Policy to manage rule sets that the Azure Firewall uses to filter traffic. Firewall policy organizes, prioritizes, and processes the rule sets based on a hierarchy with the following components: rule collection groups, rule collections, and rules.

Azure Firewall policy rule sets (1)

Rule collection groups

A rule collection group is used to group rule collections. They're the first unit that the firewall processes, and they follow a priority order based on values. There are three default rule collection groups, and their priority values are preset by design. They're processed in the following order:

Rule collection group namePriority
Default DNAT (Destination Network Address Translation) rule collection group100
Default Network rule collection group200
Default Application rule collection group300

Even though you can't delete the default rule collection groups nor modify their priority values, you can manipulate their processing order in a different way. If you need to define a priority order that is different than the default design, you can create custom rule collection groups with your wanted priority values. In this scenario, you don't use the default rule collection groups at all and use only the ones you create to customize the processing logic.

Rule collection groups contain one or multiple rule collections, which can be of type DNAT, network, or application. For example, you can group rules belonging to the same workloads or a virtual in a rule collection group.

For rule collection group size limits, see Azure subscription and service limits, quotas, and constraints.

Rule collections

A rule collection belongs to a rule collection group, and it contains one or multiple rules. They're the second unit processed by the firewall and they follow a priority order based on values. Rule collections must have a defined action (allow or deny) and a priority value. The defined action applies to all the rules within the rule collection. The priority value determines order the rule collections are processed.

There are three types of rule collections:

  • DNAT
  • Network
  • Application

Rule types must match their parent rule collection category. For example, a DNAT rule can only be part of a DNAT rule collection.

Rules

A rule belongs to a rule collection, and it specifies which traffic is allowed or denied in your network. They're the third unit that the firewall processes and they don't follow a priority order based on values. The processing logic for rules follows a top-down approach. The firewall uses defined rules to evaluate all traffic passing through the firewall to determine whether it matches an allow or deny condition. If there's no rule that allows the traffic, then the traffic is denied by default.

Our built-in infrastructure rule collection processes traffic for application rules before denying it by default.

Inbound vs. outbound

An inbound firewall rule protects your network from threats that originate from outside your network (traffic sourced from the Internet) and attempts to infiltrate your network inwardly.

An outbound firewall rule protects against nefarious traffic that originates internally (traffic sourced from a private IP address within Azure) and travels outwardly. This is usually traffic from within Azure resources being redirected via the Firewall before reaching a destination.

Rule types

There are three types of rules:

  • DNAT
  • Network
  • Application

DNAT rules

DNAT rules allow or deny inbound traffic through one or more firewall public IP addresses.You can use a DNAT rule when you want a public IP address to be translated into a private IP address. The Azure Firewall public IP addresses can be used to listen to inbound traffic from the Internet, filter the traffic and translate this traffic to internal resources in Azure.

Network rules

Network rules allow or deny inbound, outbound, and east-west traffic based on the network layer (L3) and transport layer (L4).
You can use a network rule when you want to filter traffic based on IP addresses, any ports, and any protocols.

Application rules

Application rules allow or deny outbound and east-west traffic based on the application layer (L7).You can use an application rule when you want to filter traffic based on fully qualified domain names (FQDNs), URLs, and HTTP/HTTPS protocols.

Next steps

  • Learn more about Azure Firewall rule processing: Configure Azure Firewall rules.
Azure Firewall policy rule sets (2024)
Top Articles
Income Statement Analysis: How to Read an Income Statement
Munger's own system of human psychology - Charlie Munger Investing Lessons by Equitymaster
7 C's of Communication | The Effective Communication Checklist
Craigslist Houses For Rent In Denver Colorado
Inducement Small Bribe
Dricxzyoki
Craftsman M230 Lawn Mower Oil Change
St Petersburg Craigslist Pets
Fully Enclosed IP20 Interface Modules To Ensure Safety In Industrial Environment
Fusion
Costco in Hawthorne (14501 Hindry Ave)
Southland Goldendoodles
Regular Clear vs Low Iron Glass for Shower Doors
More Apt To Complain Crossword
Fool’s Paradise movie review (2023) | Roger Ebert
Connect U Of M Dearborn
Mail.zsthost Change Password
Amc Flight Schedule
Mflwer
Video shows two planes collide while taxiing at airport | CNN
Parentvue Clarkston
Cocaine Bear Showtimes Near Regal Opry Mills
Morristown Daily Record Obituary
Long Island Jobs Craigslist
Maxpreps Field Hockey
Del Amo Fashion Center Map
1964 Impala For Sale Craigslist
Pipa Mountain Hot Pot渝味晓宇重庆老火锅 Menu
Syracuse Jr High Home Page
The Hoplite Revolution and the Rise of the Polis
Gabrielle Enright Weight Loss
One Credit Songs On Touchtunes 2022
Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
2012 Street Glide Blue Book Value
Ticketmaster Lion King Chicago
Chuze Fitness La Verne Reviews
Elizaveta Viktorovna Bout
Body Surface Area (BSA) Calculator
What Is Kik and Why Do Teenagers Love It?
Aita For Announcing My Pregnancy At My Sil Wedding
Janaki Kalaganaledu Serial Today Episode Written Update
Sofia With An F Mugshot
The Wait Odotus 2021 Watch Online Free
Yakini Q Sj Photos
Mychart University Of Iowa Hospital
26 Best & Fun Things to Do in Saginaw (MI)
La Qua Brothers Funeral Home
60 Days From August 16
Okta Login Nordstrom
Powah: Automating the Energizing Orb - EnigmaticaModpacks/Enigmatica6 GitHub Wiki
Ics 400 Test Answers 2022
Ocean County Mugshots
Latest Posts
Article information

Author: Pres. Carey Rath

Last Updated:

Views: 6009

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Pres. Carey Rath

Birthday: 1997-03-06

Address: 14955 Ledner Trail, East Rodrickfort, NE 85127-8369

Phone: +18682428114917

Job: National Technology Representative

Hobby: Sand art, Drama, Web surfing, Cycling, Brazilian jiu-jitsu, Leather crafting, Creative writing

Introduction: My name is Pres. Carey Rath, I am a faithful, funny, vast, joyous, lively, brave, glamorous person who loves writing and wants to share my knowledge and understanding with you.