With Azure Firewall Premium, application rules can filter on the complete URL path rather than just the FQDN as in Standard. Network rules don't offer it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains URL filtering in context, with comparison tables and the common traps.
Terms in this definition
- Azure Firewall Premium
Top Azure Firewall SKU, which builds on Standard with IDPS, TLS inspection, URL filtering and web categories; using those features requires a firewall policy on the Premium tier.
- FILTER
Returns just those rows of a table that meet a condition. In CALCULATE it handles conditions too complex for a Boolean filter argument, though a Boolean filter is faster whenever one will work.
- Deployment modes
The two ways ARM can deploy: Incremental, the default, creates or updates what the template lists and ignores everything else; Complete also removes resource group contents absent from the template.
- URL
The web address of a resource, on which URL-based routing relies.
- PATH
Parent-child hierarchies in DAX rely on this function. For each row it builds one delimited text value listing the IDs of the row's ancestors, top level first and ending with the row's own ID, which PATHITEM, PATHLENGTH and friends can then pick apart.
- FQDN
The full DNS name of a host, zone included, for example www.contoso.com.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
Related terms
- Application rule
Azure Firewall rule type that controls outbound HTTP, HTTPS and MSSQL traffic according to the destination FQDN, with full URL filtering requiring Premium. DNAT and network rules are evaluated before it.