Holds Azure Firewall settings and rules in one resource that can be attached to multiple firewalls in different hubs and regions. Available as Standard or Premium.
Also called Azure Firewall policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Firewall policy in context, with comparison tables and the common traps.
Terms in this definition
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
Related terms
- Azure Firewall Premium
Top Azure Firewall SKU, which builds on Standard with IDPS, TLS inspection, URL filtering and web categories; using those features requires a firewall policy on the Premium tier.
- DNS proxy
Azure Firewall policy option under which clients send DNS queries to port 53 on the firewall's private IP, and the firewall passes them on to its own DNS servers (Azure DNS by default). FQDN-based network rules need it, and on-premises resolvers may forward to it.
- join/action permission
Network Contributor has this Azure RBAC action but Reader does not. It allows an identity to attach one resource to another, such as associating a firewall with a subnet, public IP or firewall policy.
- Parent firewall policy
Base Azure Firewall policy inherited by child policies. NAT rules do not flow down, network and application rule collections from the parent always override the child's, and firewalls in any region can use it.
- Rule collection group
Top-level container in an Azure Firewall policy for rule collections. Priorities order the groups and collections of the same type, yet DNAT rules are always processed before network rules, and network before application rules.
- Set-AzFirewallPolicy
Cmdlet in Az.Network used to update an Azure Firewall policy.