What you get once Azure Firewall Manager places Azure Firewall, or a SECaaS partner, inside a Virtual WAN hub. Putting a NAT gateway, WAF or Front Door in front is not enough to count.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Secured virtual hub in context, with comparison tables and the common traps.
Terms in this definition
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
- Azure Firewall Manager
Service for administering Azure Firewall policies centrally, letting child policies inherit from a parent across subscriptions and regions.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- Security partner provider
A third-party SECaaS offering, such as Zscaler, that Azure Firewall Manager deploys into a Virtual WAN hub to filter traffic bound for the internet. It connects via the hub's VPN gateway and turns the hub into a secured hub.
- Virtual WAN
A networking service built around hubs that Microsoft manages. The Basic type handles only site-to-site VPN; Standard brings in ExpressRoute, point-to-site and full transit.
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
- NAT gateway
Gives a subnet managed, outbound-only SNAT through static public IPs and is Microsoft's preferred explicit outbound option. Unsolicited inbound connections are never accepted.
- Web Application Firewall
Protection at layer 7 from OWASP Top 10 threats like XSS and SQL injection, available on Application Gateway or Front Door.
Related terms
- Zscaler
Through Azure Firewall Manager, this security partner provider can be deployed in a secured virtual hub.