In Azure Firewall, these rules filter on protocol, port, IP address or service tag, plus FQDN once DNS proxy is on. Evaluation order puts them after DNAT and ahead of application rules.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Network rule in context, with comparison tables and the common traps.
Terms in this definition
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- FILTER
Returns just those rows of a table that meet a condition. In CALCULATE it handles conditions too complex for a Boolean filter argument, though a Boolean filter is faster whenever one will work.
- Service tag
A set of IP prefixes for an Azure service, kept up to date by Microsoft (such as AzureKeyVault or Storage, with optional regional variants), that can be used as the source or destination in NSG rules.
- FQDN
The full DNS name of a host, zone included, for example www.contoso.com.
- DNS proxy
Azure Firewall policy option under which clients send DNS queries to port 53 on the firewall's private IP, and the firewall passes them on to its own DNS servers (Azure DNS by default). FQDN-based network rules need it, and on-premises resolvers may forward to it.
- DNAT
Destination NAT. Inbound packets get a new target address, letting an outside IP map to a workload inside. On NSX this requires an active-standby gateway.