Short for next-generation firewall: a third-party network virtual appliance which, when built into a Virtual WAN hub, can be chosen as where routing intent sends traffic. Each hub supports only a single integrated NVA.
Also called next-generation firewall.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains NGFW in context, with comparison tables and the common traps.
Terms in this definition
- NVA
Network virtual appliance, a VM from a third party acting as a firewall, router or other network device.
- Virtual WAN
A networking service built around hubs that Microsoft manages. The Basic type handles only site-to-site VPN; Standard brings in ExpressRoute, point-to-site and full transit.
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Routing intent
With this Virtual WAN feature, a hub forces private traffic, internet traffic or both through a security solution inside it (Azure Firewall, an NGFW NVA or a SaaS offering). Branch-to-branch and hub-to-hub traffic is then inspected without hand-built route tables.
- NVA in the hub
A partner appliance, whether SD-WAN, NGFW or both, placed straight into a Virtual WAN hub where it runs BGP with the hub router. Each hub can hold only one.
Related terms
- Internet traffic routing policy
On a Virtual WAN hub, this routing intent setting makes Azure Firewall, a third-party next-generation firewall or a SaaS security product the single exit for traffic heading to the internet, by advertising a default route to everything attached. A hub may carry one such policy plus one private traffic policy.