What is Azure Firewall Basic and How to Deploy it
ฝัง
- เผยแพร่เมื่อ 9 ก.ค. 2024
- Azure now has three SKUs for the firewall project: Premium, Standard, and recently GA, Basic. Azure Firewall Basic offers many of the same features as the Premium and Standard firewall but at a reduced cost. Azure Firewall Basic is a good option for small and medium businesses or application-specific deployments where internet or East and West traffic needs to be controlled. In this video, we start with an overview of Azure Firewall Basic and how it differs from Premium and Standard. Then we examine the requirements to deploy it and move into the Azure portal to deploy it.
00:00 - Start
05:00 - Create a Firewall
07:27 - Create a Default Route
09:57 - Configure an Application Rule
13:00 - Configure a Network Rule
14:05 - Configure a DNAT Rule
16:24 - Test the Basic Firewall
Free Azure guide! Subscribe to the newsletter
subscribepage.io/rbsIjt
Zero to Hero with Azure Virtual Desktop
www.udemy.com/course/zero-to-...
Hybrid Identity with Windows AD and Azure AD
www.udemy.com/course/hybrid-i...
Windows 365 Enterprise and Intune Management
www.udemy.com/course/windows-...
Cost Management in Azure
www.udemy.com/course/cost-man... - วิทยาศาสตร์และเทคโนโลยี
Thank you so much, folowed exact and it works
Thanks!
Awesome video as usual Travis!!! :)
Glad you enjoyed!
Great Video and would do you have anything regarding adding the Azure Security hub with the Azure firewall
your shirt is awesome
Layer 3 and layer 7? What about layer 4???
Azure Firewall Basic is an overpriced offering with better third party alternatives. Why use this vs PFSense, for example?
It's not a bad option at under $300 US per month. It's a PaaS service with zonal HA and provides central management with policies. The price of any NVA would be x2 for HA and requires the overhead of OS management. Factor in licensing costs for premium NVAs and in most cases the basic firewall will be cheaper. I just wish filtering with web categories were available, that's a big limitation for enterprise customers.
@@Ciraltos Good points but we use DNS based web filtering, which unfortunately malware can bypass by making DNS queries via DoH. So, we need SSL inspection and specifically the ability to block by MIME type any DoH packets hiding in HTTPS streams.
@@Ciraltos I should also add that the Basic SKU should be bandwidth limited only, all other features should have parity with the other SKUs. In terms of feature set, the Basic SKU is simply too limited and doesn't provide good enough value