Azure Firewall Service Tag AzureCloud

Wieser Philipp 20 Reputation points
2024-04-12T09:18:32.43+00:00

Hi

We're in the implementing phase of Azure vWAN combined with Azure Firewall and Azure Firewall Policies. We've configured a network rule which allows the port 80 and 443 to the service tag "AzureCloud" which should include all IP ranges from all Azure Datacenters and Services. However, this rule does not seem to be working and we have to break down the rules in to multiple service tags to allow communication to certain Azure services. Is this a known limitation for this service tag?
The tag overview can be found here: https://video2.skills-academy.com/en-us/azure/virtual-network/service-tags-overview#available-service-tags

Best Regards

Philipp

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
600 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 39,446 Reputation points Microsoft Employee
    2024-04-12T11:08:17.4233333+00:00

    @Wieser Philipp ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to make use of the "AzureCloud" tag with Azure Firewall and you notice certain IPs/FQDNs are not covered by this tag.

    • Can you provide an example?
    • Of which particular service or IP is getting blocked by the Azure Firewall?
    • A IP (along with port) would help me repo your environment.

    Cheers,

    Kapil

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful