Forum Discussion

Ganesh1903's avatar
Ganesh1903
Copper Contributor
Sep 19, 2022

Best practices for Azure App gateway before Azure firewall

Hello Community members I am looking for best landing zone practices with azure App gateway before Azure firewall

 

 

 

 

 

4 Replies

  • PradeepDeiva's avatar
    PradeepDeiva
    Copper Contributor

    this is a very open ended question and the reply could be  quite vast , but to give u some crisp answer - mine is specific to check points on APP Gateway - check on these parameters , the number one would be WAF , creation of proper Vnets and Subnets, monitor the traffic , creation of workspace to store the logs , threat detection and automation of alerts notification , associating NSG and using dedicated subnets for critical applications . also stick to the basics like user access of the application and network admin (lesser the access given better the job done). if you want more info let me know , can give u some articles from MS docs for reference . this would be a good start - https://learn.microsoft.com/en-us/security/benchmark/azure/baselines/application-gateway-security-baseline

    • Ganesh1903's avatar
      Ganesh1903
      Copper Contributor
      We are designing new Landing zone in Hub and spoke model
      where we are planning to place Azure app GW before Azure firewall in Hub and workloads in
      other spoke ,I am looking for best practices for this scenario and any example will be great .
      • PradeepDeiva's avatar
        PradeepDeiva
        Copper Contributor

        Ganesh1903 

        The Landing zone prep and implementation process is more about the type of the Org u want to migrate and the level of governance u need to have . the hub spoke scenario is not new and it doesn't play a major part in getting the landing zone ready coz the firewall architecture and all its Networking components will be grouped under a Networking / Connectivity Subscription .

         

        Landing Environment design areas should consider Identity /Access , Network , Billing and Resource. For compliance do consider Security, Management and Governance . For all the subscribing division u have make sure to assign proper Role to Manage , Policy to Govern , security and Traffic Monitoring. 

         

        After you decide and align the above ,decide on the implementation option - we have several, like Migration, BluePrint , Terraform Modules  and Partner - choose the best for you and work it out 

        For more info - check , https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/implementation-options

         

        Do consider using the Landing zone accelerator  - Iam sure ur aware of this , this has lot of options on pre prepared ARM templates which are easy to be modified and used accordingly . 

         

        Hope this helps u out on the basic layout of the landing zone prep and factors to consider .

Resources