Azure Firewall policy option under which clients send DNS queries to port 53 on the firewall's private IP, and the firewall passes them on to its own DNS servers (Azure DNS by default). FQDN-based network rules need it, and on-premises resolvers may forward to it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains DNS proxy in context, with comparison tables and the common traps.
Terms in this definition
- Firewall policy
Holds Azure Firewall settings and rules in one resource that can be attached to multiple firewalls in different hubs and regions. Available as Standard or Premium.
- DNS
The system that turns names into addresses. In Azure, private endpoints depend on private DNS zones, which are queried through 168.63.129.16.
- Azure DNS
Family of Azure services for hosting and resolving DNS, covering public zones, private zones and DNS Private Resolver; you can't register domain names through it.
Related terms
- Azure Firewall Standard
Mid-level Azure Firewall SKU: it filters with application and network rules, can block known-bad addresses using threat intelligence and acts as a DNS proxy. Inspecting TLS traffic and IDPS are Premium-only.
- Network rule
In Azure Firewall, these rules filter on protocol, port, IP address or service tag, plus FQDN once DNS proxy is on. Evaluation order puts them after DNAT and ahead of application rules.