Azure Network Security Demo Lab Environment with new updates. v2.1
A new version of the Azure Network Security lab demo environment is now available in our GitHub Repository. As a result of the constant need to validate different architectures and the increasing additional features in our Network security suite (Azure Firewall, Web Application Firewall and DDOS Standard protection), the new demo lab when deployed, allow more feature tests to be validated.
This lab environment contains the recently GA Azure Firewall premium with Firewall Manager and Azure Frontdoor Premium.
This new lab also provides the following on deployment:
- Script to generate Self-signed certificate
- VM with Bastion Access
- Azure Keyvault integration
Lab owners will be able to use this lab to validate different architectures without the need to deploy individual components that may not be required for their specific scenario. This lab can then be removed by deleting the Resource group containing the resources.
Example POC scenarios that users of this lab may be looking to validate include:
- Azure Firewall with Frontdoor and App Gateway plus Virtual Machines and Web App – This is one of the common scenarios that may be broken into deployment types based on network requirements such as preserving public IP addresses, inbound traffic inspection etc. More on the different architectures in this post
- App Gateway plus Webapp – Application behavior with different WAF custom rules and WAF tuning. Example scenarios may tht you are looking to customize rule sets and validate the new improvements in Azure WAF for Application Gateway.
- Azure Premium Firewall and Virtual machines – Azure Firewall is encouraged when protecting your Azure Virtual Desktop deployments by passing all traffic through Azure firewall. This is also covered extensively in a previous post here.
- Azure Firewall with Bastion – Azure Firewall can be used with Azure Bastion to restrict access as a security measure to improve security of backend resources. Bastion provides secure RDP and SSH connectivity to all of the VMs in the virtual network in which it is provisioned More on Accessing virtual machines behind Azure Firewall with Azure Bastion
- Azure DDOS Protection – Utilize the standard DDOS protection option in the demo lab to observe the response to volumetric attacks in a controlled environment
- Azure Firewall Premium for intermediate Certificate Authority – In production environment, Enterprise PKI is often used to generate certificates. Azure Firewall Premium may be used to manage Intermediate CA certificate. More information on using Azure Firewall to manage certs can be found in this doc.
There are different scenarios that may require a quick and ready lab testing such as IDPS validation, TLS inspection, Azure Firewall detection in Sentinel, Rule Processing Logic, Web Categories testing, automations among others.
The earlier version 2.0 which contains the old demo lab environment will be maintained and made available for the rest of the year. This may be useful for customers looking to try out Azure Firewall standard migration to the new SKU and other legacy tests. We are excited to make this environment available to the community and are looking forward to your feedback.
For more information on Azure Network Security training, see the Network Security Ninja training.
Watch videos on:
New Detections, Hunting Queries and Response Automation in Azure Firewall Solution for Sentinel
Azure Premium Firewall - Deep Dive
Published on:
Learn moreRelated posts
IPv6 Adoption: Enhancing Azure WAF on Front Door
The transition to IPv6 is a significant step for enterprise corporations, reflecting the evolution of internet technology and the need for a l...
Azure WAF’s Bot Manager 1.1 and JavaScript Challenge (Preview): Navigating the Bot Threat Terrain
Introduction Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...
Private IP DNAT Support (Preview) and Scenarios with Azure Firewall
Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...
Getting Started with Azure DDoS Protection REST API: A Step-by-Step Guide
REST API is a cornerstone in the management of resources on Azure, providing a streamlined and efficient approach for executing create, read, ...
Monitoring Azure DDoS Protection Mitigation Triggers
Monitoring Azure DDoS Protection Mitigation Triggers In today’s digital landscape, Distributed Denial of Service (DDoS) attacks pose a signifi...
Azure WAF’s Bot Manager 1.1 and JavaScript Challenge: Navigating the Bot Threat Terrain
Introduction Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...
Utilizing Azure DDoS Protection Workbook for DDoS attack traffic Analysis
In today's digital age, the security of applications, servers, and networks is paramount. One of the most significant threats to this security...
Independent Configuration of Size Enforcement and Inspection Limits in Application Gateway WAF
Introduction In the constantly changing world of cybersecurity, both flexibility and effective security are essential for safeguarding ...
Private IP DNAT Support and Scenarios with Azure Firewall
Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...
Monitoring traffic flows in Azure Firewall using Virtual Network Flow Logs
Azure Firewall is a managed service designed to protect your Azure Virtual Network resources, providing advanced threat protection and advance...