Loading...

Announcing New Monitoring and Scaling Updates in Azure Firewall

Announcing New Monitoring and Scaling Updates in Azure Firewall

We are pleased to introduce some new features and improvements for the service today. These features include capabilities that enhance the monitoring and scalability of your Azure Firewall:

 

  • Flow Trace logs are now generally available.
  • Autoscaling based on the number of connections is now generally available.
  • Parallel IP Group update support is now in public preview.

 

Azure Firewall is a cloud-native firewall as a service offering that enables customers to centrally govern and log all their traffic flows using a DevOps approach. The service supports both application and network-level filtering rules and is integrated with the Microsoft Threat Intelligence feed to filter known malicious IP addresses and domains. Azure Firewall is highly available with built-in auto-scaling.

 

Flow Trace logs are now generally available.

 

Azure Firewall logging provides logs for various traffic—such as network, application, and threat intelligence traffic. Today, these logs show traffic through the firewall in the first attempt at a Transmission Control Protocol (TCP) connection, also known as the SYN packet. However, this fails to show the full journey of the packet in the TCP handshake. The ability to monitor and track every packet through the firewall is paramount for identifying packet drops or asymmetric routes.

 

As a result, one can verify if a packet has successfully flowed through the firewall or if there is asymmetric routing by viewing the additional TCP handshake logs in Flow Trace. To do so, you can monitor network logs to view the first SYN packet and enable Flow Trace logs to view the rest of the packets for verification:

 

  • SYN-ACK
  • FIN
  • FIN-ACK
  • RST
  • INVALID

 

With these additional flags in Flow Trace logs, IT administrators can now see the return packet, if there was a failed connection, or an unrecognized packet. To enable these logs, please visit the Flow Trace documentation.

 

surenj_0-1707763648053.png

 

Figure 1. Flow Trace logs in Log Analytics workspace.

 

 

Autoscaling based on the number of connections is now generally available.

 

We are excited to announce a new enhancement for Azure Firewall, a cloud-native, highly available service with built-in autoscaling. Azure Firewall can now auto-scale based on the number of connections, in addition to throughput and CPU utilization.

This means that Azure Firewall can better adapt to your traffic patterns and auto-scale more accurately and efficiently. To learn more about Azure Firewall and its autoscaling capabilities, please visit the Azure Firewall FAQ documentation

 

Parallel IP Group update support is now in public preview.

 

IP Groups is a top-level Azure resource that allows you to group and manage IP addresses in Azure Firewall rules. You can give your IP group a name and create one by entering IP addresses or uploading a file. IP Groups ease your management experience and reduce time spent on managing IP addresses, by allowing you to use group objects across multiple firewalls.

 

With this product update, you can now update more than one IP Group for Azure Firewall at the same time, instead of sequentially. You can update up to 20 IP Groups that a Firewall Policy refers to in one go. This helps administrators who want to speed up and scale configuration changes, especially when using a dev ops approach (templates, ARM, CLI, and Azure PowerShell).

 

To learn more about Azure Firewall and its IP Groups feature, please visit the Parallel IP Group updates (Preview) documentation.

 

surenj_0-1707765797389.png

Figure 2. Creating a new IP Group. 

 

Published on:

Learn more
Azure Network Security Blog articles
Azure Network Security Blog articles

Azure Network Security Blog articles

Share post:

Related posts

IPv6 Adoption: Enhancing Azure WAF on Front Door

The transition to IPv6 is a significant step for enterprise corporations, reflecting the evolution of internet technology and the need for a l...

1 year ago

Azure WAF’s Bot Manager 1.1 and JavaScript Challenge (Preview): Navigating the Bot Threat Terrain

Introduction   Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...

1 year ago

Private IP DNAT Support (Preview) and Scenarios with Azure Firewall

Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...

1 year ago

Getting Started with Azure DDoS Protection REST API: A Step-by-Step Guide

REST API is a cornerstone in the management of resources on Azure, providing a streamlined and efficient approach for executing create, read, ...

1 year ago

Monitoring Azure DDoS Protection Mitigation Triggers

Monitoring Azure DDoS Protection Mitigation Triggers In today’s digital landscape, Distributed Denial of Service (DDoS) attacks pose a signifi...

1 year ago

Azure WAF’s Bot Manager 1.1 and JavaScript Challenge: Navigating the Bot Threat Terrain

Introduction   Bots are a common presence on the internet, serving a range of functions from automating customer service to indexing page...

1 year ago

Utilizing Azure DDoS Protection Workbook for DDoS attack traffic Analysis

In today's digital age, the security of applications, servers, and networks is paramount. One of the most significant threats to this security...

1 year ago

Independent Configuration of Size Enforcement and Inspection Limits in Application Gateway WAF

Introduction   In the constantly changing world of cybersecurity, both flexibility and effective security are essential for safeguarding ...

1 year ago

Private IP DNAT Support and Scenarios with Azure Firewall

Introduction Azure Firewall is a cloud native security service to protect your workloads running in Azure. It is a stateful firewall as a serv...

1 year ago

Monitoring traffic flows in Azure Firewall using Virtual Network Flow Logs

Azure Firewall is a managed service designed to protect your Azure Virtual Network resources, providing advanced threat protection and advance...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.