Azure Firewall query

%3CLINGO-SUB%20id%3D%22lingo-sub-2415536%22%20slang%3D%22en-US%22%3EAzure%20Firewall%20query%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2415536%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Community%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20customer%20has%20a%20security%20layer%20subscription%20which%20they%20want%20to%20route%20and%20control%20all%20other%20subscription%20traffic%20via.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBasically%2C%20they%20want%20to%20remove%20direct%20VPeers%20between%20subscriptions%20and%20to%20configure%20Azure%20Firewalls%20to%20allow%20them%20to%20control%20and%20route%20all%20other%20subscriptions%20traffic.%26nbsp%3B%20All%20internet%20traffic%20would%20then%20be%20routed%20down%20our%20S2S%20VPN%20to%20our%20Palo%20Alto%E2%80%99s%20in%20Greenwich%20for%20internet%20access%20(both%20ways).%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20there%20may%20be%20some%20machines%20they%20would%20assign%20Azure%20Public%20IP%E2%80%99s%20to%20for%20inbound%20web%20server%20connectivity%2C%20but%20all%20other%20access%20from%20external%20clients%20would%20be%20routed%20via%20the%20Palos%20inbound.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EQuestions%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3COL%3E%3CLI%3EWhich%20one%20(Azure%20Firewall%20or%20Azure%20WAN)%20would%20be%20best%20option%3F%3C%2FLI%3E%3CLI%3EWhat%20are%20the%20pros%20and%20cons%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20reference%20would%20be%20of%20great%20help.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2415536%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Firewall%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Network%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20WAN%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Hi Community,

 

Our customer has a security layer subscription which they want to route and control all other subscription traffic via.  

 

Basically, they want to remove direct VPeers between subscriptions and to configure Azure Firewalls to allow them to control and route all other subscriptions traffic.  All internet traffic would then be routed down our S2S VPN to our Palo Alto’s in Greenwich for internet access (both ways). 

 

However, there may be some machines they would assign Azure Public IP’s to for inbound web server connectivity, but all other access from external clients would be routed via the Palos inbound. 

 

Questions:

 

  1. Which one (Azure Firewall or Azure WAN) would be best option?
  2. What are the pros and cons?

 

Any reference would be of great help.

0 Replies