Subnet (minimum /26) set aside for the management NIC of Azure Firewall; that NIC must have a public IP address of its own and a default route to the internet.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AzureFirewallManagementSubnet in context, with comparison tables and the common traps.
Terms in this definition
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- NIC
Network interface card, the network interface of a VM; NSGs can be associated with it.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- Public IP address
Resource in Azure for an IPv4 or IPv6 address routable on the internet, attached to a NIC, firewall, gateway, load balancer or Bastion host. Allocation, zone support and default security depend on its SKU.
- Default route
The 0.0.0.0/0 route matching any destination. Advertised by on-premises routers through BGP on ExpressRoute private peering (Microsoft peering won't do), it sends internet traffic from connected VNets back on-premises.
Related terms
- Firewall Management NIC
A second Azure Firewall interface, in AzureFirewallManagementSubnet with a public IP of its own, carrying management traffic. Forced tunnelling requires it; an existing firewall gains one after a stop and restart.
- Forced tunnelling
Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (
AzureFirewallManagementSubnetand a management public IP) for it.