Top-level container in an Azure Firewall policy for rule collections. Priorities order the groups and collections of the same type, yet DNAT rules are always processed before network rules, and network before application rules.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Rule collection group in context, with comparison tables and the common traps.
Terms in this definition
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Firewall policy
Holds Azure Firewall settings and rules in one resource that can be attached to multiple firewalls in different hubs and regions. Available as Standard or Premium.
- DNAT
Destination NAT. Inbound packets get a new target address, letting an outside IP map to a workload inside. On NSX this requires an active-standby gateway.
Related terms
- Azure Firewall rule collection
Set of rules of a single type (DNAT, network or application) that share one action and one priority and sit within a rule collection group. Priority only decides order among collections of the same rule type.