Azure firewall vs Azure network security group Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern) Come Celebrate our 10 Year Anniversary!Allowing Internet traffic into DMZ using Azure Network Security GroupAzure “firewall” capture VPN trafficWhat is the difference between an Azure network security group and a VNET?How Network Security Groups affect Azure VM IPs?Add Azure SQL Server in to Azure VNETNSG: Block all outbount Internet trafficHow can I log IP addresses of all connections to virtual machines in Azure?How to restrict RDPs to Azure VMs only via VPN?Restrict traffic between peered VNETs in AzureAccess Azure PostgreSQL with S2S VPN

How do I stop a creek from eroding my steep embankment?

What exactly is a "Meth" in Altered Carbon?

How would the world control an invulnerable immortal mass murderer?

Using audio cues to encourage good posture

What is the meaning of the new sigil in Game of Thrones Season 8 intro?

Is it true that "carbohydrates are of no use for the basal metabolic need"?

Why is my conclusion inconsistent with the van't Hoff equation?

Why am I getting the error "non-boolean type specified in a context where a condition is expected" for this request?

Storing hydrofluoric acid before the invention of plastics

51k Euros annually for a family of 4 in Berlin: Is it enough?

Can I cast Passwall to drop an enemy into a 20-foot pit?

3 doors, three guards, one stone

Book where humans were engineered with genes from animal species to survive hostile planets

prime numbers and expressing non-prime numbers

Why is "Consequences inflicted." not a sentence?

What does this icon in iOS Stardew Valley mean?

Bete Noir -- no dairy

How discoverable are IPv6 addresses and AAAA names by potential attackers?

Is there a program I can run on the C64 to speed up booting of a game?

What's the meaning of 間時肆拾貳 at a car parking sign

Can a non-EU citizen traveling with me come with me through the EU passport line?

If a contract sometimes uses the wrong name, is it still valid?

porting install scripts : can rpm replace apt?

Why are there no cargo aircraft with "flying wing" design?



Azure firewall vs Azure network security group



Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 17/18, 2019 at 00:00UTC (8:00pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Allowing Internet traffic into DMZ using Azure Network Security GroupAzure “firewall” capture VPN trafficWhat is the difference between an Azure network security group and a VNET?How Network Security Groups affect Azure VM IPs?Add Azure SQL Server in to Azure VNETNSG: Block all outbount Internet trafficHow can I log IP addresses of all connections to virtual machines in Azure?How to restrict RDPs to Azure VMs only via VPN?Restrict traffic between peered VNETs in AzureAccess Azure PostgreSQL with S2S VPN



.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I've been trying to understand the difference between a Azure firewall (https://azure.microsoft.com/en-us/services/azure-firewall/) and the features offered by NSGs/network security groups (https://docs.microsoft.com/en-us/azure/virtual-network/security-overview).



In our designed landscape, we currently have around 5~10 virtual networks within our subscription. Each of these has it's own network security group at the moment. These networks contain a variety of Azure products(web apps, vms, exposed to only trusted locations, exposed to the internet, ...). From my perspective, we can manage the in- & outbound traffic based via the network security groups. The only benefit of the firewall, I see, is that it can be used as a single point for managing traffic rules. But I don't see the cost of the firewall being worth just reducing the management of this. I think I'm missing something painstakingly obvious in the picture about the difference between what a Azure firewall does, and how a network security group operate. But I don't understand what.



To have a concrete question:



  • When is it necessary to have a Azure firewall within your architecture?

  • What is the difference between an Azure network security group and the Azure firewall to manage traffic rules (HTTPS & RDP)









share|improve this question







New contributor




Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.


























    1















    I've been trying to understand the difference between a Azure firewall (https://azure.microsoft.com/en-us/services/azure-firewall/) and the features offered by NSGs/network security groups (https://docs.microsoft.com/en-us/azure/virtual-network/security-overview).



    In our designed landscape, we currently have around 5~10 virtual networks within our subscription. Each of these has it's own network security group at the moment. These networks contain a variety of Azure products(web apps, vms, exposed to only trusted locations, exposed to the internet, ...). From my perspective, we can manage the in- & outbound traffic based via the network security groups. The only benefit of the firewall, I see, is that it can be used as a single point for managing traffic rules. But I don't see the cost of the firewall being worth just reducing the management of this. I think I'm missing something painstakingly obvious in the picture about the difference between what a Azure firewall does, and how a network security group operate. But I don't understand what.



    To have a concrete question:



    • When is it necessary to have a Azure firewall within your architecture?

    • What is the difference between an Azure network security group and the Azure firewall to manage traffic rules (HTTPS & RDP)









    share|improve this question







    New contributor




    Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
    Check out our Code of Conduct.






















      1












      1








      1








      I've been trying to understand the difference between a Azure firewall (https://azure.microsoft.com/en-us/services/azure-firewall/) and the features offered by NSGs/network security groups (https://docs.microsoft.com/en-us/azure/virtual-network/security-overview).



      In our designed landscape, we currently have around 5~10 virtual networks within our subscription. Each of these has it's own network security group at the moment. These networks contain a variety of Azure products(web apps, vms, exposed to only trusted locations, exposed to the internet, ...). From my perspective, we can manage the in- & outbound traffic based via the network security groups. The only benefit of the firewall, I see, is that it can be used as a single point for managing traffic rules. But I don't see the cost of the firewall being worth just reducing the management of this. I think I'm missing something painstakingly obvious in the picture about the difference between what a Azure firewall does, and how a network security group operate. But I don't understand what.



      To have a concrete question:



      • When is it necessary to have a Azure firewall within your architecture?

      • What is the difference between an Azure network security group and the Azure firewall to manage traffic rules (HTTPS & RDP)









      share|improve this question







      New contributor




      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.












      I've been trying to understand the difference between a Azure firewall (https://azure.microsoft.com/en-us/services/azure-firewall/) and the features offered by NSGs/network security groups (https://docs.microsoft.com/en-us/azure/virtual-network/security-overview).



      In our designed landscape, we currently have around 5~10 virtual networks within our subscription. Each of these has it's own network security group at the moment. These networks contain a variety of Azure products(web apps, vms, exposed to only trusted locations, exposed to the internet, ...). From my perspective, we can manage the in- & outbound traffic based via the network security groups. The only benefit of the firewall, I see, is that it can be used as a single point for managing traffic rules. But I don't see the cost of the firewall being worth just reducing the management of this. I think I'm missing something painstakingly obvious in the picture about the difference between what a Azure firewall does, and how a network security group operate. But I don't understand what.



      To have a concrete question:



      • When is it necessary to have a Azure firewall within your architecture?

      • What is the difference between an Azure network security group and the Azure firewall to manage traffic rules (HTTPS & RDP)






      azure azure-networking network-security-group






      share|improve this question







      New contributor




      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.











      share|improve this question







      New contributor




      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      share|improve this question




      share|improve this question






      New contributor




      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.









      asked Apr 11 at 10:07









      ReinardReinard

      1063




      1063




      New contributor




      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.





      New contributor





      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.






      Reinard is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
      Check out our Code of Conduct.




















          2 Answers
          2






          active

          oldest

          votes


















          1














          Azure Firewall features
          https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-capabilities-are-supported-in-azure-firewall



          Azure Firewall vs NSG
          https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-is-the-difference-between-network-security-groups-nsgs-and-azure-firewall



          I use NSG to limit access within a vNET and Azure Firewall to limit access to a vNET from the outside. There are some good detailed explanation in the docs articles






          share|improve this answer























          • but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

            – Reinard
            Apr 13 at 8:41












          • That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

            – Jarnstrom
            Apr 13 at 8:48


















          0














          Azure security groups is a feature of VNet that describe firewall rules on the subnets in Azure.



          Azure firewall is a product for your transit VNet to secure traffic to Azure, across subscriptions and VNets.



          Look at the diagrams in the documentation and decide what meets your design.






          share|improve this answer























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );






            Reinard is a new contributor. Be nice, and check out our Code of Conduct.









            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962585%2fazure-firewall-vs-azure-network-security-group%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            2 Answers
            2






            active

            oldest

            votes








            2 Answers
            2






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            1














            Azure Firewall features
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-capabilities-are-supported-in-azure-firewall



            Azure Firewall vs NSG
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-is-the-difference-between-network-security-groups-nsgs-and-azure-firewall



            I use NSG to limit access within a vNET and Azure Firewall to limit access to a vNET from the outside. There are some good detailed explanation in the docs articles






            share|improve this answer























            • but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

              – Reinard
              Apr 13 at 8:41












            • That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

              – Jarnstrom
              Apr 13 at 8:48















            1














            Azure Firewall features
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-capabilities-are-supported-in-azure-firewall



            Azure Firewall vs NSG
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-is-the-difference-between-network-security-groups-nsgs-and-azure-firewall



            I use NSG to limit access within a vNET and Azure Firewall to limit access to a vNET from the outside. There are some good detailed explanation in the docs articles






            share|improve this answer























            • but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

              – Reinard
              Apr 13 at 8:41












            • That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

              – Jarnstrom
              Apr 13 at 8:48













            1












            1








            1







            Azure Firewall features
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-capabilities-are-supported-in-azure-firewall



            Azure Firewall vs NSG
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-is-the-difference-between-network-security-groups-nsgs-and-azure-firewall



            I use NSG to limit access within a vNET and Azure Firewall to limit access to a vNET from the outside. There are some good detailed explanation in the docs articles






            share|improve this answer













            Azure Firewall features
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-capabilities-are-supported-in-azure-firewall



            Azure Firewall vs NSG
            https://docs.microsoft.com/en-us/azure/firewall/firewall-faq#what-is-the-difference-between-network-security-groups-nsgs-and-azure-firewall



            I use NSG to limit access within a vNET and Azure Firewall to limit access to a vNET from the outside. There are some good detailed explanation in the docs articles







            share|improve this answer












            share|improve this answer



            share|improve this answer










            answered Apr 12 at 6:46









            JarnstromJarnstrom

            2843




            2843












            • but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

              – Reinard
              Apr 13 at 8:41












            • That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

              – Jarnstrom
              Apr 13 at 8:48

















            • but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

              – Reinard
              Apr 13 at 8:41












            • That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

              – Jarnstrom
              Apr 13 at 8:48
















            but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

            – Reinard
            Apr 13 at 8:41






            but there is nothing preventing you from using a vnet to manage access from outside the vnet though? Why go for the firewall and not manage it from nsg? In my case I have 3 types of traffic: RDP from a predefined list of IPs, HTTPS from a predefined list of IPs, and internet HTTPS traffic to a limited amount of vnets/servers/endpoints.

            – Reinard
            Apr 13 at 8:41














            That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

            – Jarnstrom
            Apr 13 at 8:48





            That works fine and I have done that on certain environments also. FW has some extra features for l blocking URLs and so on and MS will add more features in the future. But if you only need to block/allow ports and IPs then skip the FW and use NSG.

            – Jarnstrom
            Apr 13 at 8:48













            0














            Azure security groups is a feature of VNet that describe firewall rules on the subnets in Azure.



            Azure firewall is a product for your transit VNet to secure traffic to Azure, across subscriptions and VNets.



            Look at the diagrams in the documentation and decide what meets your design.






            share|improve this answer



























              0














              Azure security groups is a feature of VNet that describe firewall rules on the subnets in Azure.



              Azure firewall is a product for your transit VNet to secure traffic to Azure, across subscriptions and VNets.



              Look at the diagrams in the documentation and decide what meets your design.






              share|improve this answer

























                0












                0








                0







                Azure security groups is a feature of VNet that describe firewall rules on the subnets in Azure.



                Azure firewall is a product for your transit VNet to secure traffic to Azure, across subscriptions and VNets.



                Look at the diagrams in the documentation and decide what meets your design.






                share|improve this answer













                Azure security groups is a feature of VNet that describe firewall rules on the subnets in Azure.



                Azure firewall is a product for your transit VNet to secure traffic to Azure, across subscriptions and VNets.



                Look at the diagrams in the documentation and decide what meets your design.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Apr 11 at 13:12









                John MahowaldJohn Mahowald

                8,9011713




                8,9011713




















                    Reinard is a new contributor. Be nice, and check out our Code of Conduct.









                    draft saved

                    draft discarded


















                    Reinard is a new contributor. Be nice, and check out our Code of Conduct.












                    Reinard is a new contributor. Be nice, and check out our Code of Conduct.











                    Reinard is a new contributor. Be nice, and check out our Code of Conduct.














                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f962585%2fazure-firewall-vs-azure-network-security-group%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

                    Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

                    Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020