Mid-level Azure Firewall SKU: it filters with application and network rules, can block known-bad addresses using threat intelligence and acts as a DNS proxy. Inspecting TLS traffic and IDPS are Premium-only.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure Firewall Standard in context, with comparison tables and the common traps.
Terms in this definition
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- SKU
The size or tier of a service, for example a VM size or the Premium tier of ACR.
- Threat intelligence-based filtering
Uses Microsoft's threat intelligence feed to flag traffic involving known malicious domains and IP addresses. Every Azure Firewall SKU can raise alerts; only Standard and Premium can block the traffic as well.
- DNS proxy
Azure Firewall policy option under which clients send DNS queries to port 53 on the firewall's private IP, and the firewall passes them on to its own DNS servers (Azure DNS by default). FQDN-based network rules need it, and on-premises resolvers may forward to it.
- TLS
Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.
- IDPS
Signature-based intrusion detection and prevention in Azure Firewall Premium, which raises alerts on or blocks harmful traffic. It only takes effect with a Premium policy attached.