Azure Firewall unable to update existing rules.
The save button when modifying a existing Azure Firewall Policy rule is not working on Azure portal, I've tried different browsers. It's throwing a error in the browser developer console. How to fix this?
Azure Firewall
how to allow my IP to access the RDP using port 3389
our customer who is using our software asked us to block RDP access to the server from anywhere, as a part of their security measurements, the step i took was to allow secured access to the server only on port 3389, so now the RDP is not accessible from…
Azure Firewall
Azure firewall behind AGW
Hi All, we want to configure azure firewall behind application gateway to translate further to project specific spoke Internal AGW. Internet client -> HUB Public application gateway -> HUB Azure firewall -> Spoke Internal Application gateway. …
Azure Firewall
Azure Firewall — geo (country/region) filtering support & maintaining IP allow/deny lists
Hi Team, Could you please confirm the current stance and best practices around geo filtering with Azure Firewall? Geo filtering support I don’t see a geolocation/country operator in Azure Firewall rule docs (NAT/Network/Application). Can you confirm…
Azure Firewall
Enabling MARS (Multiple Active Result Sets) in Azure Sql Connection string results in failure with Private Endpoints/Azure Firewall
We have an app service running from UK South, that talks to an Azure Sql Database over in North Europe. We have vnet integration on the app service on a virtual network in UK South, the private endpoints vnet/subnet resides on North EU and requests are…
Azure SQL Database
Azure Private Link
Azure Firewall
Azure firewall application rule doesn't work
Dear team, I have Azure policy as below: Rule collection group 1: Priority = 9999 Application rule: Allow access google, priority = 11003 Rule collection group 2: Priority = 50000 Network rule: Allow full https, priority = 50002 Diagnostic…
Azure Firewall
Azure Firewall to secure LDAPS
Hello, I would like some assistance please. I have Server 2022 configured with LDAPS and I would like to configure Azure Firewall to secure inbound LDAPS with FQDN / IP ranges. I have Workspace ONE UEM and would like to integrate SAML / Entra ID but…
Azure Firewall
Error while accessing a RDP app through azure app proxy
When I download my RDP file through the application proxy URL, it gives me the following error. Please help.
Azure Firewall
Azure Firewall DNAT issues
Hello everyone, We have a firewall on our environment. We need to expose an SFTP server to some specific public IP addresses. We have created a DNAT rule to expose port 22 and translate to port 22 to the SFTP server. If we try to do a test connection…
Azure Firewall
AVD outbound web access, different outbound public IPs.
Hi Basically I would like outbound AVD web traffic to use different public IPs. We already have Azure basic firewall, AVD subnet has a route out to Azure Firewall. The documentation suggests that if you add multiple public IPs to Azure Firewall that a…
Azure Firewall
Azure Firewall blocking access to Power BI blob storage endpoint despite Network Rule allowing Storage service tag
Sub: Azure Firewall blocking access to Power BI blob storage endpoint despite Network Rule allowing Storage service tag We have a Hub-Spoke topology with all VM traffic routed through Azure Firewall. A SHIR VM in the hub subnet must access Power BI…
Azure Firewall
How to configure to block suspicious IP address in Azure web service
Hello, Recently we had lots of 404 error in the Azure web service. Errors came from several IP addresses (4 .227.36.9, 20.78.102.199, 172.190.142.176) and it pointed to Microsoft in IP look up. But I think it's not really the Microsoft IP. How can I…
Azure Firewall
Add new Public IPs in Azure Firewall
Hello, I get this messages when I add new IPs in the Azure Firewall. Can you help to identify the cause of this ? Thanks
Azure Firewall
Azure private endpoint doesn't work with Azure firewall
Dear team I have network topology Hub vnet: 10.150.0.0/20 Azure firewall subnet with private IP: 10.150.0/4 Azure firewall management subnet Gateway subnet Peering with DB vnet UDR with route table 1 (RT1): 10.160.18.0/23 via next hop 10.150.0/4,…
Azure Firewall
Azure Firewall Telnet Behaviour
Hello everyone, I have a strange behavior in Azure Firewall. Traffic from ip 192.168.1.1 to example.com is denied by default on port 443. The traffic from 192.168.1.1 pass through the firewall. If I execute the command telnet example.com 433 it works…
Azure Firewall
Cannot allocate IP from prefix to Azure Firewall
I have an existing IP Prefix with a /28 range. (Standard SKU) I have an existing Azure firewall (PremiumSku) Both are in the same region. I have previously allocated IP's from the prefix to the Firewall Public IP's, however, I am not able to do that…
Azure Firewall
What is the subnet for *.msftauth.net and *.msftauth.net ?
The application under test has multi factor authentication enabled. This functionality is working as expected. We have recently created a virtual machine which will be used for running load tests. When we open the application from this VM in particular,…
Microsoft Security | Microsoft Entra | Microsoft Entra ID
Azure Firewall
Azure Security Architecture Design - Need Expert Guidance
Azure Security Architecture Design - Need Expert Guidance Hi, I'm designing a secure architecture for a web application hosted on Azure Kubernetes Service (AKS) and would appreciate insights on my current design and some specific questions I…
Azure Firewall
How to avoid record "SNI TLS extension was missing." on Logs Analytic workspace of Firewall?
On Logs Analytic workspace of Firewall, I have a lots of records with ActionReason_s as "SNI TLS extension was missing.", and these cost make the cost so high (99% of records come from this). However, the record only have SourceIP, I don't see…
Azure Firewall
Configuring BGP with Dual ISP on Fortinet Firewall in Azure Active-Passive Mode
Hi Team, Having two ISPs terminating at a single Fortinet firewall, VPN connections to the Fortinet have been established using both ISP IPs, and BGP is enabled. However, routes from Azure are not appearing in the Fortigate. The Virtual Network Gateway…