Understanding the Differences Between Azure Firewall and the VM-Series (2024)

Microsoft recently announced the Azure Firewall (in public preview) as an optional set of extra cost security features that would be deployed in conjunction with Azure Network Security Groups. Key features include:

  • A stateful firewall as a service that provides outbound control over traffic based on port, protocol and/or by manually whitelisting the fully qualified domain name, or FQDN (i.e., www.github.com).
  • Built-in high availability with unrestricted cloud scalability; fully integrated with Azure Monitor for logging and analytics.
  • Price based on each Azure Firewall instance deployed plus bandwidth consumed.

More info can be found here: https://azure.microsoft.com/en-us/services/azure-firewall/

Whereas Network Security Groups are required to enable an Azure VNet, both the VM-Series and Azure Firewall are optional, and as such, customers and partners should understand how they can improve their security posture.

Key VM-Series Differentiators

The VM-Series differs from Azure Firewall by providing customers with a broader, more complete set of security functionality that, when combined with security automation, can help ensure workloads and data on Azure are protected from threats. Specific VM-Series differentiators include:

  • Can be deployed to protect traffic flows in all directions, not just outbound – including inbound, outbound, and east-west.
  • Bi-directional control over applications (web-based and otherwise) not ports, resulting in a threat footprint reduction for improved security and compliance.
  • For allowed traffic, policies can prevent data exfiltration and threats, including vulnerability exploits, known and unknown malware.
  • Granular control over web-based developer resources with PAN-DB URL Filtering – blacklist known malicious categories; whitelist specific developer resource URLs and/or categories.
  • Automation features such as dynamic address groups, external dynamic lists, and HTTP log forwarding to dynamically drive policy updates and ensure that developer environments are protected at the speed of the cloud.
  • Consistent security policies and enforcement across private cloud and public cloud environments.

A more specific comparison can be found in the table below.

General FeaturesVM-Series on AzureAzure Network Security GroupsAzure

Firewall

IP/Port/Protocol-based securityXXX
Port ranges used within policyXXX
Source and/or destination within policyXXX
CIDR-based rulesXXX
ACL-like features within a policyXXX
Security applied after traffic enters Resource GroupXXX
Drop vs. deny distinction within a policyX
Next-Generation Firewall Features
Policy-based identification and control over thousands of applications; create custom applications; manage unknown traffic based on policyXWeb apps only based on whitelisted FQDN
Policy-based, bi-directional SSL decryption and inspection; per-policy SSH controlX
Bi-directional control of traffic based on country or geographic regionX
QoS: policy-based traffic shaping (priority, guaranteed, maximum) per application, per user, per tunnel, based on DSCP classificationX
Zone-based network segmentation and protectionX
TCP protocol validation, ensuring that standard three-way handshake is validX
Additional Features
Threat Prevention: Prevent known threats (vulnerability exploits, malware and botnets), block polymorphic malwareX
Advanced Malware Protection (WildFire®): Detect potential malware, detonate, analyze and automatically deliver protectionsX
URL Filtering: Control access to web resources based on category and/or specific URL; prevent access to known malicious sites and credential phishing sitesXBased on whitelisted FQDN only
File and Data Filtering: Bi-directional control over unauthorized file and data transferX
Contextual Threat Intelligence (AutoFocus™): Context around attacks, adversaries and campaigns, including targeted industriesX
Policy Automation: Tagging to automate policy updates, ingest third-party data directly into policyX
Centralized Management and Visibility: Single pane of glass delivers aggregated logging and event correlation; actionable insight into traffic and threatsX
Mobile Security (GlobalProtect™): Extend policy to remote users and devicesX
Integration with Azure Security Command Center: Gain more complete visibility into Azure account security statusXXX
Scale Out Architectures: Integration with load balancing for scalability and availabilityXXX
Understanding the Differences Between Azure Firewall and the VM-Series (2024)
Top Articles
How to Get a $100k Business Loan for Your Growing Company
Why Retro Style Is Making A Comeback - FasterCapital
Tyson Employee Paperless
Nyu Paralegal Program
Mackenzie Rosman Leaked
Culver's Flavor Of The Day Wilson Nc
Lost Ark Thar Rapport Unlock
EY – все про компанію - Happy Monday
Arrests reported by Yuba County Sheriff
Craigslist/Phx
Craigslist Pets Southern Md
Nioh 2: Divine Gear [Hands-on Experience]
Buff Cookie Only Fans
Dr. med. Uta Krieg-Oehme - Lesen Sie Erfahrungsberichte und vereinbaren Sie einen Termin
Panorama Charter Portal
Vanessawest.tripod.com Bundy
Vrachtwagens in Nederland kopen - gebruikt en nieuw - TrucksNL
Skip The Games Fairbanks Alaska
Marine Forecast Sandy Hook To Manasquan Inlet
Busted News Bowie County
Free Personals Like Craigslist Nh
kvoa.com | News 4 Tucson
Keshi with Mac Ayres and Starfall (Rescheduled from 11/1/2024) (POSTPONED) Tickets Thu, Nov 1, 2029 8:00 pm at Pechanga Arena - San Diego in San Diego, CA
Sam's Club Gas Price Hilliard
Parent Management Training (PMT) Worksheet | HappierTHERAPY
Xfinity Outage Map Lacey Wa
Forager How-to Get Archaeology Items - Dino Egg, Anchor, Fossil, Frozen Relic, Frozen Squid, Kapala, Lava Eel, and More!
1987 Monte Carlo Ss For Sale Craigslist
Netherforged Lavaproof Boots
Reborn Rich Ep 12 Eng Sub
Edict Of Force Poe
Hisense Ht5021Kp Manual
Bimmerpost version for Porsche forum?
Austin Automotive Buda
Tiny Pains When Giving Blood Nyt Crossword
2007 Jaguar XK Low Miles for sale - Palm Desert, CA - craigslist
Lamont Mortuary Globe Az
Mychart University Of Iowa Hospital
Eat Like A King Who's On A Budget Copypasta
Studentvue Calexico
Unblocked Games - Gun Mayhem
Conan Exiles Colored Crystal
Dragon Ball Super Card Game Announces Next Set: Realm Of The Gods
Meet Robert Oppenheimer, the destroyer of worlds
Headlining Hip Hopper Crossword Clue
Who Is Nina Yankovic? Daughter of Musician Weird Al Yankovic
The Hardest Quests in Old School RuneScape (Ranked) – FandomSpot
Itsleaa
Sunset On November 5 2023
Latest Posts
Article information

Author: Duncan Muller

Last Updated:

Views: 5812

Rating: 4.9 / 5 (79 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Duncan Muller

Birthday: 1997-01-13

Address: Apt. 505 914 Phillip Crossroad, O'Konborough, NV 62411

Phone: +8555305800947

Job: Construction Agent

Hobby: Shopping, Table tennis, Snowboarding, Rafting, Motor sports, Homebrewing, Taxidermy

Introduction: My name is Duncan Muller, I am a enchanting, good, gentle, modern, tasty, nice, elegant person who loves writing and wants to share my knowledge and understanding with you.