Skip to content

Commit 43f1ba3

Browse files
Merge pull request #237902 from vhorne/fw-suren-511
update prem category and 3rd party config
2 parents 4f5bcde + a6e2c94 commit 43f1ba3

File tree

2 files changed

+10
-0
lines changed

2 files changed

+10
-0
lines changed

articles/firewall-manager/deploy-trusted-security-partner.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,14 @@ Next, you can check if VNet virtual machines or the branch site can access the I
114114

115115
After finishing the route setting steps, the VNet virtual machines as well as the branch sites are sent a 0/0 to the third-party service route. You can't RDP or SSH into these virtual machines. To sign in, you can deploy the [Azure Bastion](../bastion/bastion-overview.md) service in a peered VNet.
116116

117+
## Rule configuration
118+
119+
Use the partner portal to configure firewall rules. Azure Firewall passes the traffic through.
120+
121+
For example, you may observe allowed traffic through the Azure Firewall, even though there is no explicit rule to allow the traffic. This is because Azure Firewall passes the traffic to the next hop security partner provider (ZScalar, CheckPoint, or iBoss). Azure Firewall still has rules to allow outbound traffic, but the rule name is not logged.
122+
123+
For more information, see the partner documentation.
124+
117125
## Next steps
118126

119127
- [Tutorial: Secure your cloud network with Azure Firewall Manager using the Azure portal](secure-cloud-network.md)

articles/firewall/premium-features.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,6 +125,8 @@ URL Filtering can be applied both on HTTP and HTTPS traffic. When HTTPS traffic
125125

126126
Web categories lets administrators allow or deny user access to web site categories such as gambling websites, social media websites, and others. Web categories are also included in Azure Firewall Standard, but it's more fine-tuned in Azure Firewall Premium. As opposed to the Web categories capability in the Standard SKU that matches the category based on an FQDN, the Premium SKU matches the category according to the entire URL for both HTTP and HTTPS traffic.
127127

128+
Azure Firewall Premium web categories are only available in firewall policies. Ensure that your policy SKU matches the SKU of your firewall instance. For example, if you have a Firewall Premium instance, you must use a Firewall Premium policy.
129+
128130
> [!IMPORTANT]
129131
> Microsoft is transitioning to an updated and new Web Content Filtering category feed in the next couple weeks. This will contain more granularity and additional subcategorizations.
130132
>

0 commit comments

Comments
 (0)