What is Azure Firewall?
Azure Firewall is a cloud-native, fully managed firewall-as-a-service with built-in high availability and automatic scaling. The service inspects both east-west and north-south traffic and is available in three SKUs: Basic, Standard, and Premium.
Unlike Network Security Groups, Azure Firewall operates at Layer 3 through Layer 7 and can apply complex filtering rules based on FQDNs, URLs, and protocols.
Core Features
- Stateful firewall with L3-L7 filtering (Standard and Premium)
- FQDN-based rules for outbound traffic
- Threat intelligence feed directly from Microsoft Cyber Security (Standard and Premium; Basic supports alert mode only)
- Signature-based IDPS (Intrusion Detection and Prevention) with thousands of signatures, plus TLS inspection and URL filtering (Premium)
- NAT rules for inbound connections
- Centralized management of multiple firewalls via Azure Firewall Manager, including Virtual WAN environments
Typical Use Cases
Hub-spoke network topology: Central firewall in the hub VNet that controls all traffic between spoke VNets and the internet.
Outbound traffic control: Restricting outbound traffic to allowed FQDNs to prevent data exfiltration and command-and-control connections.
Hybrid networking: Securing traffic between Azure and on-premises via ExpressRoute or VPN, with unified rules for both environments.
SMB protection: Azure Firewall Basic offers essential protection for smaller environments with limited throughput needs at a lower price point.
Benefits
- No capacity planning required through automatic scaling
- Integrated threat detection without additional tools (Standard/Premium)
- Centralized policy management for multiple firewalls across subscriptions and regions
- Native integration with Azure Monitor and Microsoft Sentinel
Frequently Asked Questions
What does Azure Firewall cost?
Azure Firewall is billed hourly depending on the SKU (Basic, Standard, Premium), plus a charge per volume of data processed. Current prices are available on the official Azure Firewall pricing page.
What is the difference between Basic, Standard, and Premium?
Basic targets small and medium environments with limited throughput and supports threat intelligence in alert mode only. Standard provides full L3-L7 filtering and active threat intelligence blocking. Premium adds signature-based IDPS, TLS inspection, URL filtering, and web categories for workloads with higher compliance requirements.
Can Azure Firewall defend against DDoS attacks?
Azure Firewall provides basic protection. For comprehensive DDoS protection, Azure DDoS Protection should be enabled in addition, working together with Azure Firewall.
How do I configure rules for multiple firewalls?
Azure Firewall Manager enables centralized management of policies across multiple firewalls, subscriptions, and regions, for both virtual network and Secure Virtual Hub (Virtual WAN) deployments.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Azure Firewall: network architecture, rule design, threat intelligence, and cost optimization.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
