You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/virtual-wan/howto-firewall.md
+30-15Lines changed: 30 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,55 +17,70 @@ A **secured hub** is an Azure Virtual WAN hub with Azure Firewall. This article
17
17
18
18
## Before you begin
19
19
20
-
The steps in this article assume that you have already deployed a virtual WAN with one or more hubs.
20
+
The steps in this article assume that you've already deployed a virtual WAN with one or more hubs.
21
21
22
22
To create a new virtual WAN and a new hub, use the steps in the following articles:
23
23
24
24
*[Create a virtual WAN](virtual-wan-site-to-site-portal.md#openvwan)
25
25
*[Create a hub](virtual-wan-site-to-site-portal.md#hub)
26
26
27
+
> [!IMPORTANT]
28
+
> Virtual WAN is a collection of hubs and services made available inside the hub. The user can have as many Virtual WAN per their need. In a Virtual WAN hub, there are multiple services like VPN, ExpressRoute etc. Each of these services is automatically deployed across **Availability Zones***except* Azure Firewall, if the region supports Availability Zones. To deploy an Azure Firewall with Availability Zones (recommended) in a Secure vWAN Hub, [this article](https://docs.microsoft.com/azure/firewall-manager/secure-cloud-network) must be used.
29
+
27
30
## View virtual hubs
28
31
29
32
The **Overview** page for your virtual WAN shows a list of virtual hubs and secured hubs. The following figure shows a virtual WAN with no secured hubs.
30
33
31
-
:::image type="content" source="./media/howto-firewall/overview.png" alt-text="Screenshot shows the Overview page for a virtual WAN with a list of virtual hubs." lightbox="./media/howto-firewall/overview.png":::
34
+
:::image type="content" source="./media/howto-firewall/vwan-overview-page.jpg" alt-text="Screenshot showing the Overview page for an Azure Virtual WAN." lightbox="./media/howto-firewall/vwan-overview-page.jpg":::
32
35
33
36
## Convert to secured hub
34
37
35
-
1. On the **Overview** page for your virtual WAN, select the hub that you want to convert to a secured hub. On the virtual hub page, you see two options to deploy Azure Firewall into this hub. Select either option.
38
+
1. On the **Overview** page for your virtual WAN, select the hub that you want to convert to a secured hub.
39
+
40
+
2. Once in the hub properties, select on **Azure Firewall and Firewall Manager** under the "Security" section on the left:
3. Select on **Next: Azure Firewall** button at the bottom of screen:
36
45
37
-
:::image type="content" source="./media/howto-firewall/security.png" alt-text="Screenshot shows the Overview page for your virtual WAN where you can select either Convert to secure hub or Azure Firewall." lightbox="./media/howto-firewall/security.png":::
46
+
:::image type="content" source="./media/howto-firewall/vwan-select-hub.png" alt-text="Screenshot showing [Select virtual hubs] step in the conversion flow" lightbox="./media/howto-firewall/vwan-select-hub.png":::
38
47
39
-
1. After you select one of the options, you see the **Convert to secure hub** page. Select a hub to convert, and then select **Next: Azure Firewall**at the bottom of the page.
48
+
4. Select the Azure Firewall properties and status desired, then complete the wizard up to the **Review + confirm**tab:
40
49
41
-
:::image type="content" source="./media/howto-firewall/select-hub.png" alt-text="Screenshot of Convert to secure hub with a hub selected." lightbox="./media/howto-firewall/select-hub.png":::
42
-
1. After completing the workflow, select **Confirm**.
50
+
:::image type="content" source="./media/howto-firewall/vwan-firewall-properties-conversion.png" alt-text="[Azure Firewall] step in the conversion flow" lightbox="./media/howto-firewall/vwan-firewall-properties-conversion.png":::
43
51
44
-
:::image type="content" source="./media/howto-firewall/confirm.png" alt-text="Screenshot shows the Convert to secure hub pane with Confirm selected." lightbox="./media/howto-firewall/confirm.png":::
45
-
1. After the hub has been converted to a secured hub, you can view it on the virtual WAN **Overview** page.
52
+
> [!NOTE]
53
+
> As reported at the beginning of the article, the procedure described in this article will not permit the usage of Availability Zones for Azure Firewall.
46
54
47
-
:::image type="content" source="./media/howto-firewall/secured-hub.png" alt-text="Screenshot of view secured hub." lightbox="./media/howto-firewall/secured-hub.png":::
55
+
5. After the hub has been converted to a secured hub, Azure Firewall status will be reported as in the image below:
56
+
57
+
:::image type="content" source="./media/howto-firewall/vwan-firewall-secured-final.png" alt-text="Screenshot showing end result of the conversion flow." lightbox="./media/howto-firewall/vwan-firewall-secured-final.png":::
48
58
49
59
## View hub resources
50
60
51
61
From the virtual WAN **Overview** page, select the secured hub. On the hub page, you can view all the virtual hub resources, including Azure Firewall.
52
62
53
-
To view Azure Firewall settings from the secured hub, under **Security**, select **Secured virtual hub settings**.
63
+
To view Azure Firewall settings from the secured hub, select on **Azure Firewall and Firewall Manager** under the "Security" section on the left:
64
+
65
+
:::image type="content" source="./media/howto-firewall/vwan-secured-hub-status.png" alt-text="Screenshot showing Azure Virtual WAN status view in Firewall Manager." lightbox="./media/howto-firewall/vwan-secured-hub-status.png":::
66
+
67
+
Usage of Availability Zones for Azure Firewall in the Azure Virtual WAN Hub, can be checked accessing the security properties of the hub, as shown in the screenshot below:
68
+
69
+
:::image type="content" source="./media/howto-firewall/vwan-firewall-hub-az-correct-zone.png" alt-text="Screenshot showing Availability Zones property in Virtual WAN secured hub." lightbox="./media/howto-firewall/vwan-firewall-hub-az-correct-zone.png":::
54
70
55
-
:::image type="content" source="./media/howto-firewall/hub-settings.png" alt-text="Screenshot of Secured virtual hub settings." lightbox="./media/howto-firewall/hub-settings.png":::
56
71
57
72
## Configure additional settings
58
73
59
74
To configure additional Azure Firewall settings for the virtual hub, select the link to **Azure Firewall Manager**. For information about firewall policies, see [Azure Firewall Manager](../firewall-manager/secure-cloud-network.md#create-a-firewall-policy-and-secure-your-hub).
60
75
61
-
:::image type="content" source="./media/howto-firewall/additional-settings.png" alt-text="Screenshot of Overview with Manage security provider route settings for this Secured virtual hub in Azure Firewall Manager selected." lightbox="./media/howto-firewall/additional-settings.png":::
To return to the hub **Overview** page, you can navigate back by clicking the path, as shown by the arrow in the following figure.
64
79
65
-
:::image type="content" source="./media/howto-firewall/arrow.png" alt-text="Screenshot showing how to return to the overview page." lightbox="./media/howto-firewall/arrow.png":::
80
+
:::image type="content" source="./media/howto-firewall/arrow.png" alt-text="Screenshot showing how to return to the Overview page." lightbox="./media/howto-firewall/arrow.png":::
66
81
67
82
## Upgrade to Azure Firewall Premium
68
-
At any time, it is possible to upgrade from Azure Firewall Standard to Premium following these [instructions](../firewall/premium-migrate.md#migrate-a-secure-hub-firewall). This operation will require a maintenance windows since some minimal downtime will be generated.
83
+
At any time, it's possible to upgrade from Azure Firewall Standard to Premium following these [instructions](../firewall/premium-migrate.md#migrate-a-secure-hub-firewall). This operation will require a maintenance window since some minimal downtime will be generated.
0 commit comments