NSG vs Azure Firewall vs WAF: which one filters what

Three Azure services all "block traffic", but at different layers and in different places. What each one inspects, how they fit together, and three exam traps.

By Tony Rough

  • AZ-700
  • AZ-104
  • SC-500
  • networking
  • security
  • exam traps

A network security group, Azure Firewall and a web application firewall can all stop traffic, so exam scenarios offer all three as answers. They aren’t alternatives: each looks at a different part of the traffic, in a different place.

The one-line difference

Network security groups: the subnet door

An NSG is a list of allow and deny rules matched on the five-tuple: source, source port, destination, destination port and protocol. Rules have a priority from 100 to 4096, lower numbers first, and processing stops at the first match. Default rules (priority 65000 and up) allow traffic within the virtual network and out to the internet, and deny other inbound traffic.

An NSG can’t read a domain name, a URL or the content of a request.

Azure Firewall: the central checkpoint

Azure Firewall is a firewall as a service, with built-in high availability, for east-west and north-south traffic. For production, Microsoft recommends a hub-and-spoke design: the firewall in its own hub virtual network, workloads in peered spokes.

It only sees traffic sent to it, so each workload subnet needs a route table with a user-defined route for 0.0.0.0/0, next hop Virtual appliance, at the firewall’s private IP address.

Rules come in three kinds: DNAT (inbound, to a private server), network (addresses, ports, service tags) and application (FQDN filtering for HTTP/S and MSSQL). Network rules can use FQDNs for other protocols, such as SSH, if DNS proxy is on.

The three SKUs:

Don’t confuse those routes with the firewall’s own forced tunnelling, which sends its internet-bound traffic on to an on-premises device and needs the Firewall Management network interface.

WAF: the web bouncer

A WAF inspects HTTP and HTTPS requests arriving at a web app. You’ll meet it on Application Gateway (regional) and Azure Front Door (at Microsoft’s global edge). A WAF policy holds:

Detection mode only logs matches; prevention mode blocks them. Microsoft suggests running a new WAF in detection mode briefly first, to find false positives.

How they combine

A typical design layers all three: a WAF on Front Door or Application Gateway in front of the web tier, Azure Firewall in the hub with a user-defined route on each spoke subnet, and NSGs on the spoke subnets, kept short with ASGs and service tags.

Three traps

  1. A WAF doesn’t filter outbound or non-web traffic. Controlling which websites your VMs can reach is a job for Azure Firewall application rules.
  2. Inbound TLS inspection isn’t a Firewall Premium feature. Premium inspects outbound and east-west TLS; for inbound, Microsoft points you to WAF on Application Gateway.
  3. Detection mode doesn’t block anything. If attacks must be stopped, the policy must be in prevention mode. And on Front Door, managed rule sets need the Premium tier: Standard supports custom rules only.

Pick it in five seconds

You need… Choose
Allow or deny ports between subnets or VMs NSG (with ASGs and service tags)
Restrict outbound traffic to named websites (FQDNs) Azure Firewall application rules
One central inspection point for every spoke Azure Firewall in the hub, plus UDRs
Decrypt and inspect outbound HTTPS, or IDPS Azure Firewall Premium
Block SQL injection or XSS against a web app WAF on Application Gateway or Front Door
Log web attacks without blocking yet WAF in detection mode

Go deeper

The AZ-700 study guide gives each service its own chapter: NSGs (chapter 13), Azure Firewall (chapter 14) and WAF (chapter 15). The SC-500 study guide covers them in chapters 7, 9 and 12, and the AZ-104 study guide covers NSGs, ASGs and service tags in chapter 12. Facts checked against Microsoft Learn on 8 October 2026.

The books in this post

Never miss a free Kindle weekend

An email when an Ultra Transcenders book is free on Kindle, and when a new book comes out. Sign up and you also get the free exam-day checklist: booking, ID, the online check-in and what to expect on the day.

We'll email you to confirm first. A few emails a month at most, no spam, unsubscribe any time. The list is run by Kit; see the privacy notice.

More from the blog

All posts