Skip to content

Commit 5b7ad24

Browse files
authored
Merge pull request #201300 from igorpag/igorpag-wan-patch5
Updated graphics and added AZ concept
2 parents aeae918 + 4d9ee6e commit 5b7ad24

8 files changed

+30
-15
lines changed

articles/virtual-wan/howto-firewall.md

Lines changed: 30 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -17,55 +17,70 @@ A **secured hub** is an Azure Virtual WAN hub with Azure Firewall. This article
1717

1818
## Before you begin
1919

20-
The steps in this article assume that you have already deployed a virtual WAN with one or more hubs.
20+
The steps in this article assume that you've already deployed a virtual WAN with one or more hubs.
2121

2222
To create a new virtual WAN and a new hub, use the steps in the following articles:
2323

2424
* [Create a virtual WAN](virtual-wan-site-to-site-portal.md#openvwan)
2525
* [Create a hub](virtual-wan-site-to-site-portal.md#hub)
2626

27+
> [!IMPORTANT]
28+
> Virtual WAN is a collection of hubs and services made available inside the hub. The user can have as many Virtual WAN per their need. In a Virtual WAN hub, there are multiple services like VPN, ExpressRoute etc. Each of these services is automatically deployed across **Availability Zones** *except* Azure Firewall, if the region supports Availability Zones. To deploy an Azure Firewall with Availability Zones (recommended) in a Secure vWAN Hub, [this article](https://docs.microsoft.com/azure/firewall-manager/secure-cloud-network) must be used.
29+
2730
## View virtual hubs
2831

2932
The **Overview** page for your virtual WAN shows a list of virtual hubs and secured hubs. The following figure shows a virtual WAN with no secured hubs.
3033

31-
:::image type="content" source="./media/howto-firewall/overview.png" alt-text="Screenshot shows the Overview page for a virtual WAN with a list of virtual hubs." lightbox="./media/howto-firewall/overview.png":::
34+
:::image type="content" source="./media/howto-firewall/vwan-overview-page.jpg" alt-text="Screenshot showing the Overview page for an Azure Virtual WAN." lightbox="./media/howto-firewall/vwan-overview-page.jpg":::
3235

3336
## Convert to secured hub
3437

35-
1. On the **Overview** page for your virtual WAN, select the hub that you want to convert to a secured hub. On the virtual hub page, you see two options to deploy Azure Firewall into this hub. Select either option.
38+
1. On the **Overview** page for your virtual WAN, select the hub that you want to convert to a secured hub.
39+
40+
2. Once in the hub properties, select on **Azure Firewall and Firewall Manager** under the "Security" section on the left:
41+
42+
:::image type="content" source="./media/howto-firewall/vwan-convert-firewall-start.png" alt-text="Screenshot showing Azure Virtual WAN Hub properties." lightbox="./media/howto-firewall/vwan-convert-firewall-start.png":::
43+
44+
3. Select on **Next: Azure Firewall** button at the bottom of screen:
3645

37-
:::image type="content" source="./media/howto-firewall/security.png" alt-text="Screenshot shows the Overview page for your virtual WAN where you can select either Convert to secure hub or Azure Firewall." lightbox="./media/howto-firewall/security.png":::
46+
:::image type="content" source="./media/howto-firewall/vwan-select-hub.png" alt-text="Screenshot showing [Select virtual hubs] step in the conversion flow" lightbox="./media/howto-firewall/vwan-select-hub.png":::
3847

39-
1. After you select one of the options, you see the **Convert to secure hub** page. Select a hub to convert, and then select **Next: Azure Firewall** at the bottom of the page.
48+
4. Select the Azure Firewall properties and status desired, then complete the wizard up to the **Review + confirm** tab:
4049

41-
:::image type="content" source="./media/howto-firewall/select-hub.png" alt-text="Screenshot of Convert to secure hub with a hub selected." lightbox="./media/howto-firewall/select-hub.png":::
42-
1. After completing the workflow, select **Confirm**.
50+
:::image type="content" source="./media/howto-firewall/vwan-firewall-properties-conversion.png" alt-text="[Azure Firewall] step in the conversion flow" lightbox="./media/howto-firewall/vwan-firewall-properties-conversion.png":::
4351

44-
:::image type="content" source="./media/howto-firewall/confirm.png" alt-text="Screenshot shows the Convert to secure hub pane with Confirm selected." lightbox="./media/howto-firewall/confirm.png":::
45-
1. After the hub has been converted to a secured hub, you can view it on the virtual WAN **Overview** page.
52+
> [!NOTE]
53+
> As reported at the beginning of the article, the procedure described in this article will not permit the usage of Availability Zones for Azure Firewall.
4654
47-
:::image type="content" source="./media/howto-firewall/secured-hub.png" alt-text="Screenshot of view secured hub." lightbox="./media/howto-firewall/secured-hub.png":::
55+
5. After the hub has been converted to a secured hub, Azure Firewall status will be reported as in the image below:
56+
57+
:::image type="content" source="./media/howto-firewall/vwan-firewall-secured-final.png" alt-text="Screenshot showing end result of the conversion flow." lightbox="./media/howto-firewall/vwan-firewall-secured-final.png":::
4858

4959
## View hub resources
5060

5161
From the virtual WAN **Overview** page, select the secured hub. On the hub page, you can view all the virtual hub resources, including Azure Firewall.
5262

53-
To view Azure Firewall settings from the secured hub, under **Security**, select **Secured virtual hub settings**.
63+
To view Azure Firewall settings from the secured hub, select on **Azure Firewall and Firewall Manager** under the "Security" section on the left:
64+
65+
:::image type="content" source="./media/howto-firewall/vwan-secured-hub-status.png" alt-text="Screenshot showing Azure Virtual WAN status view in Firewall Manager." lightbox="./media/howto-firewall/vwan-secured-hub-status.png":::
66+
67+
Usage of Availability Zones for Azure Firewall in the Azure Virtual WAN Hub, can be checked accessing the security properties of the hub, as shown in the screenshot below:
68+
69+
:::image type="content" source="./media/howto-firewall/vwan-firewall-hub-az-correct-zone.png" alt-text="Screenshot showing Availability Zones property in Virtual WAN secured hub." lightbox="./media/howto-firewall/vwan-firewall-hub-az-correct-zone.png":::
5470

55-
:::image type="content" source="./media/howto-firewall/hub-settings.png" alt-text="Screenshot of Secured virtual hub settings." lightbox="./media/howto-firewall/hub-settings.png":::
5671

5772
## Configure additional settings
5873

5974
To configure additional Azure Firewall settings for the virtual hub, select the link to **Azure Firewall Manager**. For information about firewall policies, see [Azure Firewall Manager](../firewall-manager/secure-cloud-network.md#create-a-firewall-policy-and-secure-your-hub).
6075

61-
:::image type="content" source="./media/howto-firewall/additional-settings.png" alt-text="Screenshot of Overview with Manage security provider route settings for this Secured virtual hub in Azure Firewall Manager selected." lightbox="./media/howto-firewall/additional-settings.png":::
76+
:::image type="content" source="./media/howto-firewall/additional-settings.png" alt-text="Screenshot showing Secured Hub overview with Manage Security Provider." lightbox="./media/howto-firewall/additional-settings.png":::
6277

6378
To return to the hub **Overview** page, you can navigate back by clicking the path, as shown by the arrow in the following figure.
6479

65-
:::image type="content" source="./media/howto-firewall/arrow.png" alt-text="Screenshot showing how to return to the overview page." lightbox="./media/howto-firewall/arrow.png":::
80+
:::image type="content" source="./media/howto-firewall/arrow.png" alt-text="Screenshot showing how to return to the Overview page." lightbox="./media/howto-firewall/arrow.png":::
6681

6782
## Upgrade to Azure Firewall Premium
68-
At any time, it is possible to upgrade from Azure Firewall Standard to Premium following these [instructions](../firewall/premium-migrate.md#migrate-a-secure-hub-firewall). This operation will require a maintenance windows since some minimal downtime will be generated.
83+
At any time, it's possible to upgrade from Azure Firewall Standard to Premium following these [instructions](../firewall/premium-migrate.md#migrate-a-secure-hub-firewall). This operation will require a maintenance window since some minimal downtime will be generated.
6984

7085
## Next steps
7186

50.1 KB
Loading
42.2 KB
Loading
66.2 KB
Loading
55.9 KB
Loading
107 KB
Loading
31.2 KB
Loading
67.4 KB
Loading

0 commit comments

Comments
 (0)