Azure Firewall rule type that controls outbound HTTP, HTTPS and MSSQL traffic according to the destination FQDN, with full URL filtering requiring Premium. DNAT and network rules are evaluated before it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Application rule in context, with comparison tables and the common traps.
Terms in this definition
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- HTTP
Hypertext Transfer Protocol, which sends data in clear text; VCF interfaces and APIs instead use HTTPS.
- HTTPS
Secure HTTP, wrapped in TLS. VCF products serve their web UIs and REST APIs this way on 443.
- FQDN
The full DNS name of a host, zone included, for example www.contoso.com.
- URL filtering
With Azure Firewall Premium, application rules can filter on the complete URL path rather than just the FQDN as in Standard. Network rules don't offer it.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
- DNAT
Destination NAT. Inbound packets get a new target address, letting an outside IP map to a workload inside. On NSX this requires an active-standby gateway.
Related terms
- Parent firewall policy
Base Azure Firewall policy inherited by child policies. NAT rules do not flow down, network and application rule collections from the parent always override the child's, and firewalls in any region can use it.