Tests a simulated flow against each applicable Virtual Network Manager security admin rule and NSG rule, then gives allow or deny with the deciding rule. Scale sets and ICMP are supported.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains NSG diagnostics in context, with comparison tables and the common traps.
Terms in this definition
- Flow
The unit of work inside a Lakeflow pipeline that takes data from a source, transforms it and lands it in a destination like a streaming table. Streaming flows either append or update, and
CREATE FLOWlets you declare a flow apart from the table it feeds. - VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Security admin rule
A rule from Azure Virtual Network Manager that takes effect ahead of NSG rules. Its action is Deny (blocks whatever NSGs say), Always allow (bypasses NSGs) or Allow (hands traffic on for NSG evaluation).
- Default security rules
Built-in NSG rules at priorities 65000-65500: AllowVnetInBound, AllowAzureLoadBalancerInBound and DenyAllInBound, plus AllowVnetOutBound, AllowInternetOutBound and DenyAllOutBound. Removal is impossible; custom rules at 100-4096 take precedence.
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
- ICMP
The protocol behind ping, distinct from both UDP and TCP. Between peered VNets, the default
AllowVnetInBoundNSG rule permits it.