FREE STUDY NOTES · AZ-700

How NSG rules are evaluated: priorities, default rules and stateful flows

Rule order, the default rules, and what happens to a flow between subnets and to return traffic.

From Ultra Transcenders AZ-700 by Tony Rough (publishing soon)

Before you design any rule set, you need to know which rules apply to a flow, in which direction, and what the platform allows before you write anything yourself.

Direction, statefulness and scope

Common trap: Treating an outbound rule on the destination’s NSG as if it could block (or allow) inbound traffic - NSG rules only apply in their own direction, so for traffic arriving at a subnet only the destination NSG’s inbound rules count (and the source’s outbound rules on the way out).

Default rules

A new flow leaves a source subnet, where the source NSG's outbound rules are checked, and arrives at the destination subnet NSG. There, inbound rules are read lowest priority number first: two custom rules don't match, AllowVnetInBound matches and allows the flow, and the rules below it are never read. The destination NSG's outbound rules don't apply to this flow, and return traffic is allowed because NSGs are stateful.
Figure 13.1: Which NSG rules decide an incoming flow, and in what order

Get the whole book

This note is one section of Ultra Transcenders AZ-700: Designing and Implementing Microsoft Azure Networking Solutions, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free AZ-700 glossary · All AZ-700 study notes

More AZ-700 study notes