Azure Firewall and Inbound Filtering documentation

Adriano López 20 Reputation points
2024-09-01T00:17:04.18+00:00

Hi! I have a question about the Azure Firewall documentation and the Knowledge Check section.

The documentation (although it does not explicitly say otherwise) focuses on the fact that the Azure Firewall service is not suitable for filtering inbound HTTP/S traffic. However, in the Knowledge Check section it points out that it is.

It is likely that it is a misinterpretation or that the documentation is indeed a bit confusing, to clear up doubts I prefer to share it with the community

Documentation

Azure Firewall provides inbound protection for non-HTTP/S protocols (such as RDP, SSH, and FTP), outbound network-level protection for all ports and protocols, and application-level protection for outbound HTTP/S.

Knowledge Check - Requirement

Network security. You need to filter HTTP(S) traffic from Azure to on-premises, and filter traffic outbound to the internet.

Knowledge Check - Correct Answer

Azure Firewall Correct. Azure Firewall can filter HTTP(S) traffic from Azure to on-premises and outbound to the internet.


In addition, other documentation for the service also mentions the same

Does Azure Firewall support inbound traffic filtering? Azure Firewall supports inbound and outbound filtering. Inbound protection is typically used for non-HTTP protocols like RDP, SSH, and FTP protocols. For inbound HTTP and HTTPS protection, use a web application firewall such as Azure Web Application Firewall.

adding that Azure Web Application Firewall is among the possible answers in the Knowledge Check section, but specifies it as an incorrect answer.

Thanks in advance for the help!

AL

This question is related to the following Learning Module

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
674 questions
Azure Training
Azure Training
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.Training: Instruction to develop new skills.
1,707 questions
0 comments No comments
{count} votes

Accepted answer
  1. Marcin Policht 25,290 Reputation points MVP
    2024-09-01T00:46:10.16+00:00

    The knowledge check deals with OUTBOUND (to on-premises and the internet) filtering of HTTP/HTTPS traffic - which Azure Firewall supports. The limitation regarding HTTP/HTTPS traffic applies to INBOUND traffic


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.