Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
When you connect your on-premises network to an Azure virtual network to create a hybrid network, you need to control access to your Azure network resources as part of your overall security plan.
Azure Firewall and Firewall Policy control network access in a hybrid network by using rules that define allowed and denied network traffic.
For this tutorial, you create three virtual networks:
- VNet-Hub - The firewall is in this virtual network.
- VNet-Spoke - The spoke virtual network represents the workload located on Azure.
- VNet-Onprem - The on-premises virtual network represents an on-premises network. In an actual deployment, you can connect it by using either a VPN or ExpressRoute connection. For simplicity, this tutorial uses a VPN gateway connection, and an Azure-located virtual network represents an on-premises network.
In this tutorial, you learn how to:
- Create the firewall hub virtual network
- Create the spoke virtual network
- Create the on-premises virtual network
- Configure and deploy the firewall and policy
- Create and connect the VPN gateways
- Peer the hub and spoke virtual networks
- Create the routes
- Create the virtual machine
- Test the firewall
To use Azure PowerShell instead, see Deploy and configure Azure Firewall in a hybrid network using Azure PowerShell.
Prerequisites
A hybrid network uses the hub-and-spoke architecture model to route traffic between Azure virtual networks and on-premises networks. The hub-and-spoke architecture has the following requirements:
- To route the spoke subnet traffic through the hub firewall, use a user-defined route (UDR) that points to the firewall with the Virtual network gateway route propagation option disabled. The Virtual network gateway route propagation disabled option prevents route distribution to the spoke subnets. This option prevents learned routes from conflicting with your UDR. If you want to keep Virtual network gateway route propagation enabled, make sure to define specific routes to the firewall to override those routes that are published from on-premises over BGP.
- Configure a UDR on the hub gateway subnet that points to the firewall IP address as the next hop to the spoke networks. No UDR is required on the Azure Firewall subnet, as it learns routes from BGP.
To learn how these routes are created, see Create the routes in this tutorial.
Note
Azure Firewall must have direct internet connectivity. If your AzureFirewallSubnet learns a default route to your on-premises network through BGP, you must override this route by using a 0.0.0.0/0 UDR with the NextHopType value set as Internet to maintain direct internet connectivity.
You can configure Azure Firewall to support forced tunneling. For more information, see Azure Firewall forced tunneling.
Note
Traffic between directly peered virtual networks routes directly even if a UDR points to Azure Firewall as the default gateway. To send subnet-to-subnet traffic to the firewall in this scenario, a UDR must contain the target subnet network prefix explicitly on both subnets.
If you don't have an Azure subscription, create a free account before you begin.
Create the firewall hub virtual network
First, create the resource group to contain the resources for this tutorial:
- Sign in to the Azure portal.
- On the Azure portal home page, select Resource groups > Create.
- For Subscription, select your subscription.
- For Resource group name, enter FW-Hybrid-Test.
- For Region, select (US) East US. All resources that you create later must be in the same location.
- Select Review + Create, and then select Create.
Next, create the virtual network:
Note
The size of the AzureFirewallSubnet subnet is /26. For more information about the subnet size, see Azure Firewall FAQ.
- From the Azure portal home page, select Create a resource.
- Under Networking, select Virtual network, and then select Create.
- For Resource group, select FW-Hybrid-Test.
- For Name, enter VNet-hub.
- On the Security tab, select Next.
- For IPv4 Address space, enter 10.5.0.0/16.
- Under Subnets, select default.
- For Subnet purpose, select Azure Firewall.
- For Starting address, enter 10.5.0.0/26.
- Select Save, select Review + create, and then select Create.
Create a second subnet for the gateway.
- On the VNet-hub page, select Subnets.
- Select +Subnet.
- For Subnet purpose, select Virtual Network Gateway.
- For Starting address, enter 10.5.2.0/26.
- Select Add.
Create the spoke virtual network
- From the Azure portal home page, select Create a resource.
- In Networking, select Virtual network, and then select Create.
- For Resource group, select FW-Hybrid-Test.
- For Name, enter VNet-Spoke.
- For Region, select (US) East US.
- Select Next. On the Security tab, select Next.
- For IPv4 address space, enter 10.6.0.0/16.
- Under Subnets, select default.
- For Name, enter SN-Workload.
- For Starting address, enter 10.6.0.0/24.
- Select Save, select Review + create, and then select Create.
Create the on-premises virtual network
- From the Azure portal home page, select Create a resource.
- In Networking, select Virtual network, and then select Create.
- For Resource group, select FW-Hybrid-Test.
- For Name, enter VNet-OnPrem.
- For Region, select (US) East US.
- Select Next. On the Security tab, select Next.
- For IPv4 address space, enter 192.168.0.0/16.
- Under Subnets, select default.
- For Name, enter SN-Corp.
- For Starting address, enter 192.168.1.0/24.
- Select Save, select Review + create, and then select Create.
Create a second subnet for the gateway.
- On the VNet-OnPrem page, select Subnets.
- Select +Subnet.
- For Subnet purpose, select Virtual Network Gateway.
- For Starting address, enter 192.168.2.0/24.
- Select Add.
Configure and deploy the firewall
Deploy the firewall into the firewall hub virtual network.
From the Azure portal home page, select Create a resource.
Search for Firewall, select it from the results, and then select Create.
On Create a Firewall, use the following table to configure the firewall:
Setting Value Subscription Resource group FW-Hybrid-Test Name AzFW01 Region East US Firewall tier Standard Firewall management Use a Firewall Policy to manage this firewall Firewall policy Add new:
hybrid-test-pol
East USChoose a virtual network Use existing:
VNet-hubPublic IP address Add new:
fw-pipClear Enable Firewall Management NIC for this tutorial's direct-internet configuration, and then select Next: Advanced.
Leave Enable NAT gateway cleared for this tutorial. To configure a StandardV2 NAT gateway during firewall creation, see Integrate NAT gateway with Azure Firewall.
Select Next: Tags, and then Next: Review + create. Review the settings, and then select Create.
Deployment takes a few minutes.
After deployment finishes, go to the FW-Hybrid-Test resource group, and select the AzFW01 firewall.
Note the private IP address. You use it later when you create the default route.
Configure network rules
First, add a network rule to allow web traffic.
- From the FW-Hybrid-Test resource group, select the hybrid-test-pol Firewall Policy.
- Under Settings, select Network rules.
- Select Add a rule collection.
- For Name, enter
RCNet01. - For Priority, enter
100. - For Rule collection action, select Allow.
- Under Rules, for Name, enter
AllowWeb. - For Source type, select IP address.
- For Source, enter
192.168.1.0/24. - For Protocol, select TCP.
- For Destination Ports, enter
80. - For Destination type, select IP address.
- For Destination, enter
10.6.0.0/16. - Select Add.
Create and connect the VPN gateways
The hub and on-premises virtual networks connect through VPN gateways.
Create the VPN gateways
Create a VPN gateway for both the hub and on-premises virtual networks. Network-to-network configurations require a RouteBased VpnType. Creating a VPN gateway can often take 45 minutes or more, depending on the selected VPN gateway SKU.
Repeat the following steps for each gateway by using the values in the table.
| Setting | Hub gateway | On-premises gateway |
|---|---|---|
| Name | GW-hub | GW-Onprem |
| Virtual network | VNet-hub | VNet-Onprem |
| Public IP address | VNet-hub-GW-pip | VNet-Onprem-GW-pip |
| Second Public IP address | VNet-hub-GW-pip2 | VNet-Onprem-GW-pip2 |
- From the Azure portal home page, select Create a resource.
- In the search box, type virtual network gateway and press Enter.
- Select Virtual network gateway, and select Create.
- Enter the Name from the table.
- For Region, select the same region that you used previously.
- For Gateway type, select VPN.
- For SKU, select VpnGw1AZ. New deployments require an availability-zone-supported SKU. For more information, see VPN Gateway SKU consolidation.
- Select the Virtual network from the table.
- Set Enable active-active mode to Enabled so each gateway has the two public IP addresses listed in the table.
- For Public IP address, select Create new, and enter the name from the table.
- For Second Public IP address, select Create new, and enter the name from the table.
- Accept the remaining defaults, select Review + create, and then select Create.
Create the VPN connections
Create the VPN connections between the hub and on-premises gateways. You need a connection from each direction, and the shared key must match for both.
Repeat the following steps for each connection by using the values in the table.
| Setting | Hub to on-premises | On-premises to hub |
|---|---|---|
| Gateway to open | GW-hub | GW-Onprem |
| Connection name | Hub-to-Onprem | Onprem-to-Hub |
| First virtual network gateway | GW-hub | GW-Onprem |
| Second virtual network gateway | GW-Onprem | GW-hub |
- Open the FW-Hybrid-Test resource group and select the gateway from the table.
- Under Settings, select Connections in the left column.
- Select Add.
- Enter the Connection name from the table.
- Select VNet-to-VNet for Connection type.
- Select Next : Settings.
- Select the First virtual network gateway and Second virtual network gateway from the table.
- For Shared key (PSK), enter a strong shared key that you generate for this lab. Use the same value for both connections, and store it securely. Don't reuse a published example value.
- Select Review + create, and then select Create.
Verify the connection
After about five minutes, the status of both connections should be Connected.
Peer the hub and spoke virtual networks
Peer the hub and spoke virtual networks.
Open the FW-Hybrid-Test resource group and select the VNet-hub virtual network.
In the left column, select Peerings.
Select Add.
Under Remote virtual network summary:
Setting name Value Peering link name SpoketoHub Subscription Virtual network VNet-Spoke Allow 'VNet-Spoke' to access 'VNet-hub' selected Allow 'VNet-Spoke' to receive forwarded traffic from 'VNet-Hub' selected Allow gateway or route server in 'VNet-Spoke' to forward traffic to 'VNet-Hub' not selected Enable 'VNet-Spoke' to use 'VNet-hub's' remote gateway or route server selected Under Local virtual network summary:
Setting name Value Peering link name HubtoSpoke Allow 'VNet-hub' to access 'VNet-Spoke' selected Allow 'VNet-hub' to receive forwarded traffic from 'VNet-Spoke' selected Allow gateway or route server in 'VNet-Hub' to forward traffic to 'VNet-Spoke' selected Enable 'VNet-hub' to use 'VNet-Spoke's' remote gateway or route server not selected Select Add.
Create the routes
Next, create two route tables:
- A route from the hub gateway subnet to the spoke subnet through the firewall IP address
- A default route from the spoke subnet through the firewall IP address
Repeat the following steps for each route table by using the values in the table.
| Setting | Hub-to-spoke route | Default spoke route |
|---|---|---|
| Route table name | UDR-Hub-Spoke | UDR-DG |
| Propagate gateway route | Yes (default) | No |
| Route name | ToSpoke | ToHub |
| Destination IP addresses/CIDR ranges | 10.6.0.0/16 | 0.0.0.0/0 |
| Associate virtual network | VNet-hub | VNet-spoke |
| Associate subnet | GatewaySubnet | SN-Workload |
- From the Azure portal home page, select Create a resource.
- In the search box, type route table and press Enter.
- Select Route table, and then select Create.
- Select FW-Hybrid-Test for the resource group.
- For Region, select the same location that you used previously.
- Enter the route table Name from the table. If applicable, set Propagate gateway route to No.
- Select Review + Create, and then select Create.
- After the route table is created, select it to open the route table page.
- Under Settings, select Routes in the left column.
- Select Add.
- Enter the Route name from the table.
- For Destination type, select IP Addresses.
- Enter the Destination IP addresses/CIDR ranges from the table.
- For Next hop type, select Virtual appliance.
- For Next hop address, type the firewall's private IP address that you noted earlier.
- Select Add.
Associate each route table to its subnet.
- On the route table page, select Subnets.
- Select Associate.
- Select the Virtual network and Subnet from the table.
- Select OK.
Create virtual machines
Create the spoke workload and on-premises virtual machines, and place them in the appropriate subnets.
Create the workload virtual machine
Create a virtual machine in the spoke virtual network, running NGINX, with no public IP address.
- From the Azure portal home page, select Create a resource.
- Under Popular Marketplace products, select Ubuntu Server 24.04 LTS.
- Enter these values for the virtual machine:
- Resource group - Select FW-Hybrid-Test
- Virtual machine name: VM-Spoke-01
- Region - Same region that you used previously
- Image - Ubuntu Server 24.04 LTS - x64 Gen2
- Size - Standard_B2s
- Authentication type - SSH public key
- Username: azureuser
- SSH public key source - Generate new key pair
- Key pair name - VM-Spoke-01_key
- For Public inbound ports, select None.
- Select Next: Disks, accept the defaults, and then select Next: Networking.
- Select VNet-Spoke for the virtual network and the subnet is SN-Workload.
- For Public IP, select None.
- Select Next: Management, and then select Next: Monitoring.
- For Boot diagnostics, select Disable.
- Select Review + Create, review the settings on the summary page, and then select Create.
- On the Generate new key pair dialog, select Download private key and create resource. Save the key file as VM-Spoke-01_key.pem.
Install Nginx
After you create the virtual machine, install the Nginx web server.
The spoke's default route sends internet traffic through Azure Firewall. The AllowWeb rule permits on-premises-to-spoke HTTP traffic, not package downloads from the spoke. Add a temporary application rule for installation, and remove it before testing the firewall.
Open hybrid-test-pol. Under Settings > Rules, select Application rules > Add a rule collection.
Enter the following values:
Setting Value Name Install-Nginx Rule collection type Application Priority 100 Rule collection action Allow Rule collection group DefaultApplicationRuleCollectionGroup Rule name Allow-Package-Repositories Source type IP address Source 10.6.0.0/24 Protocol:port http:80, https:443 Destination type FQDN Target FQDNs azure.archive.ubuntu.com, archive.ubuntu.com, security.ubuntu.com, packages.microsoft.com Select Add and wait for the policy update to complete. Keep the VM's default Azure-provided DNS settings for this tutorial.
From the Azure portal, open the Cloud Shell and make sure that it's set to Bash.
Use az vm run-command invoke to install nginx on the virtual machine:
az vm run-command invoke \ --resource-group FW-Hybrid-Test \ --name VM-Spoke-01 \ --command-id RunShellScript \ --scripts 'set -eu; sudo apt-get update; sudo apt-get install -y nginx; hostname | sudo tee /var/www/html/index.html; curl --fail http://localhost'- Confirm that the command completes successfully and returns the spoke VM's hostname from the local web server. If package downloads fail, check the repository hostname in the error against the temporary rule. Allow only the configured package repositories; don't add a wildcard internet rule. See Troubleshoot common issues with APT on Ubuntu.
- Return to hybrid-test-pol and delete the Install-Nginx rule collection. Wait for the policy update to complete before continuing.
Create the on-premises virtual machine
Use this virtual machine to connect by using Azure Bastion. From there, you connect to the spoke server through the firewall.
- From the Azure portal home page, select Create a resource.
- Under Popular Marketplace products, select Ubuntu Server 24.04 LTS.
- Enter these values for the virtual machine:
- Resource group - Select existing, and then select FW-Hybrid-Test.
- Virtual machine name - VM-Onprem.
- Region - Same region that you used previously.
- Image - Ubuntu Server 24.04 LTS - x64 Gen2
- Size - Standard_B2s
- Authentication type - SSH public key
- Username: azureuser
- SSH public key source - Generate new key pair
- Key pair name - VM-Onprem_key
- For Public inbound ports, select None.
- Select Next: Disks, accept the defaults, and then select Next: Networking.
- Select VNet-Onprem for virtual network and the subnet is SN-Corp.
- For Public IP, select None. You connect through Bastion in this virtual network.
- Select Next: Management, and then select Next: Monitoring.
- For Boot diagnostics, select Disable.
- Select Review + Create, review the settings on the summary page, and then select Create.
- On the Generate new key pair dialog, select Download private key and create resource. Save the key file as VM-Onprem_key.pem.
Note
Azure provides a default outbound access IP for VMs that either aren't assigned a public IP address or are in the backend pool of an internal basic Azure load balancer. The default outbound access IP mechanism provides an outbound IP address that isn't configurable.
The default outbound access IP is disabled when one of the following events happens:
- A public IP address is assigned to the VM.
- The VM is placed in the backend pool of a standard load balancer, with or without outbound rules.
- An Azure NAT Gateway resource is assigned to the subnet of the VM.
VMs that you create by using virtual machine scale sets in flexible orchestration mode don't have default outbound access.
For more information about outbound connections in Azure, see Default outbound access in Azure and Use Source Network Address Translation (SNAT) for outbound connections.
Deploy Azure Bastion
Deploy Azure Bastion Basic in VNet-Onprem to connect directly to VM-Onprem. The browser-to-VM connection doesn't need to cross the VPN gateways. The web request you send from VM-Onprem still crosses the VPN connection and Azure Firewall to reach the spoke.
Open VNet-Onprem, select Subnets, and select + Subnet.
Select Azure Bastion for Subnet purpose. Confirm the name is AzureBastionSubnet, enter 192.168.3.0 for Starting address, and select /26 for Size. Select Add.
On the Azure portal menu, select Create a resource.
In the search box, type Bastion and select it from the results.
Select Create.
On Create a Bastion, configure the following settings:
Setting Value Subscription Select your subscription Resource group FW-Hybrid-Test Name Onprem-Bastion Region Same as your other resources Tier Basic Virtual network VNet-Onprem Subnet AzureBastionSubnet Public IP address Create a new Standard, static public IP address named public-ip-bastion. Bastion Basic requires a dedicated subnet and public IP address and incurs charges while deployed. For configuration requirements, see Azure Bastion configuration settings.
Select Review + create. After validation passes, select Create.
Test the firewall
First, note the private IP address for VM-spoke-01 virtual machine.
From the Azure portal, go to the VM-Onprem virtual machine.
Select Connect > Connect via Bastion.
Select Use SSH Private Key from Local File.
For Username, enter azureuser.
Browse to and select the VM-Onprem_key.pem file you downloaded earlier.
Select Connect.
From the SSH session on VM-Onprem, test the web server on the spoke virtual network:
curl http://The web server returns a response.
Next, change the firewall network rule collection action to Deny to verify that the firewall rules work as expected.
- Select the hybrid-test-pol Firewall Policy.
- Select Rule Collections.
- Select the RCNet01 rule collection.
- For Rule collection action, select Deny.
- Select Save.
Run the test again. This time, the test fails.
Clean up resources
Keep your firewall resources for the next tutorial, or if you no longer need them, delete the FW-Hybrid-Test resource group to delete all firewall-related resources.