@@ -12,20 +12,20 @@ metadata:
12
12
author : vhorne
13
13
ms.author : victorh
14
14
manager : kumudD
15
- ms.date : 11/17/2023
15
+ ms.date : 07/03/2024
16
16
17
17
highlightedContent :
18
18
# itemType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | tutorial | whats-new
19
19
items :
20
20
- title : Azure network security overview
21
21
itemType : overview # controls the icon image and super-title text
22
22
url : ../../security/fundamentals/network-overview.md
23
- - title : Configure network security
24
- itemType : learn
25
- url : /training/modules/ network-security/
23
+ - title : Azure best practices for network security
24
+ itemType : concept
25
+ url : ../../security/fundamentals/ network-best-practices.md
26
26
- title : What's new in Azure Networking and Security?
27
27
itemType : whats-new
28
- url : https://techcommunity .microsoft.com/t5/azure-network-security-blog/bg-p/AzureNetworkSecurityBlog
28
+ url : https://azure .microsoft.com/en-us/updates/?category=networking&query=security
29
29
- title : Azure Well-Architected Framework review - Azure Firewall
30
30
itemType : architecture
31
31
url : /azure/well-architected/services/networking/azure-firewall
@@ -38,149 +38,123 @@ highlightedContent:
38
38
- title : Choose a secure network topology
39
39
itemType : concept
40
40
url : ../secure-network-topology.md
41
- - title : Choose a secure application delivery service
41
+ - title : Azure networking services overview
42
42
itemType : concept
43
- url : ../secure-application-delivery .md
43
+ url : ../fundamentals/networking-overview .md
44
44
45
+ productDirectory :
46
+ title : Get started
47
+ items :
48
+ - title : Firewall Manager
49
+ imageSrc : https://static.docs.com/ui/media/product/azure/firewall-manager.svg
50
+ summary : " Central network security policy and route management for globally distributed, software-defined perimeters"
51
+ url : ../../firewall-manager/index.yml
52
+ - title : Azure Firewall
53
+ summary : Native firewalling capabilities with built-in high availability, unrestricted cloud scalability, and zero maintenance
54
+ imageSrc : https://static.docs.com/ui/media/product/azure/firewall.svg
55
+ url : ../../firewall/index.yml
56
+ - title : Azure Web Application Firewall
57
+ summary : A cloud-native web application firewall (WAF) service that provides powerful protection for web apps
58
+ imageSrc : https://static.docs.com/ui/media/product/azure/frontdoor-waf-policies.svg
59
+ url : ../../web-application-firewall/index.yml
60
+ - title : Azure DDoS Protection
61
+ summary : Protect your applications from Distributed Denial of Service (DDoS) attacks.
62
+ imageSrc : https://static.docs.com/ui/media/product/azure/ddos-protection.svg
63
+ url : ../../ddos-protection/index.yml
45
64
46
65
# additionalContent section (optional)
47
66
# Card with links style
48
67
additionalContent :
49
68
# Supports up to 4 sections
50
69
sections :
51
- - title : Secure your perimeter # < 60 chars (optional)
70
+ - title : Use cases and scenarios # < 60 chars (optional)
52
71
items :
53
72
# Card
54
- - title : I want to...
73
+ - title : Secure your perimeter
55
74
links :
56
- - text : Protect my network from DDos attacks
57
- url : ../../ddos-protection/ddos-protection-overview.md
58
75
- text : Protect my outbound network connections
59
76
url : ../../firewall/overview.md
60
77
- text : Protect my inbound web application connections
61
78
url : ../../web-application-firewall/overview.md
62
- - text : Manage my network firewall
63
- url : ../../firewall-manager/overview.md
64
- - text : Learn more about Azure Firewall
65
- url : ../../firewall/index.yml
66
- - text : Learn about the Azure Firewall solution for Microsoft Sentinel
67
- url : https://techcommunity.microsoft.com/t5/azure-network-security-blog/new-detections-hunting-queries-and-response-automation-in-azure/ba-p/2688746
68
- - text : Detect malware
69
- url : ../../firewall/detect-malware-with-sentinel.md
70
- - text : Detect new threats
71
- url : ../../web-application-firewall/waf-new-threat-detection.md
72
- - text : Enhance network security using custom WAF geomatch rules
73
- url : ../../web-application-firewall/geomatch-custom-rules-examples.md
74
- - title : Training
75
- links :
76
- - text : Introduction to Azure Firewall
77
- url : /training/modules/introduction-azure-firewall/
78
- - text : Introduction to Azure Firewall Manager
79
- url : /training/modules/intro-to-azure-firewall-manager/
80
- - text : Introduction to Azure Web Application Firewall
81
- url : /training/modules/introduction-azure-web-application-firewall/
82
- - text : Design and implement network security
83
- url : /training/modules/design-implement-network-security-monitoring/
84
- - text : Design solutions for network security
85
- url : /training/modules/design-solutions-network-security/
86
- - text : Design and implement network monitoring
87
- url : /training/modules/design-implement-network-monitoring/
88
- - title : Architecture
89
- links :
90
- - text : Implement the Zero Trust model
91
- url : https://techcommunity.microsoft.com/t5/azure-network-security-blog/zero-trust-with-azure-network-security/ba-p/3668280
92
- - text : Apply Zero Trust principles to an Azure Virtual WAN deployment
93
- url : /security/zero-trust/azure-virtual-wan
94
- - text : Securely managed web applications
95
- url : /azure/architecture/example-scenario/apps/fully-managed-secure-apps
96
- - text : Firewall and Application Gateway for virtual networks
97
- url : /azure/architecture/example-scenario/gateway/firewall-application-gateway
98
- - text : Improved-security access to multitenant web apps from an on-premises network
99
- url : /azure/architecture/web-apps/guides/networking/access-multitenant-web-app-from-on-premises
100
79
- text : Implement a secure hybrid network
101
80
url : /azure/architecture/reference-architectures/dmz/secure-vnet-dmz?tabs=portal
102
- - text : Mission-critical baseline architecture with network control
103
- url : /azure/architecture/reference-architectures/containers/aks-mission-critical/mission-critical-network-architecture
104
- - text : Build the first layer of defense with Azure Security services
105
- url : /azure/architecture/solution-ideas/articles/azure-security-build-first-layer-defense
106
- - text : Secure and govern workloads with network-level segmentation
107
- url : /azure/architecture/reference-architectures/hybrid-networking/network-level-segmentation
108
- - title : Secure your virtual networks
109
- items :
110
81
# Card
111
- - title : I want to...
82
+ - title : Secure your virtual networks
112
83
links :
113
- - text : Secure networks with Zero Trust
114
- url : /security/zero-trust/deploy/networks
115
- - text : Filter network traffic between Azure resources
116
- url : ../../virtual-network/network-security-groups-overview.md
117
- - text : Secure access to Azure services
118
- url : ../../virtual-network/virtual-network-service-endpoints-overview.md
119
84
- text : Inspect traffic to a private endpoint
120
85
url : https://techcommunity.microsoft.com/t5/azure-network-security-blog/deploy-azure-firewall-to-inspect-traffic-to-a-private-endpoint/ba-p/3714575
121
- - text : Learn more about Azure Virtual Network
122
- url : ../../virtual-network/index.yml
123
- - text : Create a site-to-site VPN connection
124
- url : ../../vpn-gateway/tutorial-site-to-site-portal.md
125
- - text : Deploy security admin rules with Virtual Network manager
126
- url : ../../virtual-network-manager/how-to-block-network-traffic-portal.md
127
- - title : Training
128
- links :
129
- - text : Configure network security groups
130
- url : /training/modules/configure-network-security-groups/
131
- - text : Secure and isolate access to Azure resources by using network security groups and service endpoints
132
- url : /training/modules/secure-and-isolate-with-nsg-and-service-endpoints/
133
- - text : Troubleshoot platform-as-a-service issues in Microsoft Azure
134
- url : /training/modules/troubleshoot-platform-service-issues/
135
- - text : Connect my on-premises network to Azure with VPN gateways
136
- url : /training/modules/connect-on-premises-network-with-vpn-gateway/
137
86
- text : Monitor and troubleshoot your end-to-end Azure network infrastructure
138
87
url : /training/modules/troubleshoot-azure-network-infrastructure/
139
- - title : Architecture
140
- links :
141
- - text : Apply Zero Trust principles to a spoke virtual network in Azure
142
- url : /security/zero-trust/azure-infrastructure-iaas
143
- - text : Apply Zero Trust principles to a hub virtual network in Azure
144
- url : /security/zero-trust/azure-infrastructure-networking
145
88
- text : Hub-spoke network topology in Azure
146
89
url : /azure/architecture/reference-architectures/hybrid-networking/hub-spoke
147
- - text : Choose between virtual network peering and VPN gateways
148
- url : /azure/architecture/reference-architectures/hybrid-networking/vnet-peering
149
- - text : Extend an on-premises network using ExpressRoute
150
- url : /azure/architecture/reference-architectures/hybrid-networking/expressroute
151
90
- text : Azure Network Virtual Application Firewall architecture
152
91
url : /azure/architecture/example-scenario/firewalls/
153
- - title : Protect your apps and services
154
- items :
155
92
# Card
156
- - title : I want to...
93
+ - title : Protect your apps and services
157
94
links :
158
95
- text : Protect my service from DDoS attacks
159
96
url : ../../ddos-protection/ddos-protection-overview.md
160
- - text : Protect against PaperCut vulnerability
161
- url : https://techcommunity.microsoft.com/t5/azure-network-security-blog/protect-against-papercut-vulnerability-with-azure-firewall/ba-p/3859945
97
+ - text : Learn more about Azure DDoS Protection
98
+ url : ../../ddos-protection/index.yml
99
+ - text : Introduction to Azure DDoS Protection
100
+ url : /training/modules/introduction-azure-ddos-protection/
101
+ - text : Use Azure Firewall to help protect an Azure Kubernetes Service (AKS) cluster
102
+ url : /azure/architecture/guide/aks/aks-firewall
103
+ - title : Learn more about Azure network security
104
+ items :
105
+ # Card
106
+ - title : Scenarios
107
+ links :
162
108
- text : Securely access my PaaS Services in Azure
163
109
url : ../../private-link/private-link-overview.md
164
110
- text : Create a private interface to connect to a service
165
111
url : ../../private-link/private-endpoint-overview.md
166
112
- text : Connect a service using a private link
167
113
url : ../../private-link/private-link-service-overview.md
168
- - text : Learn more about Azure DDoS Protection
169
- url : ../../ddos-protection/index.yml
114
+ - text : Apply Zero Trust principles to a spoke virtual network with Azure PaaS Services
115
+ url : /security/zero-trust/azure-infrastructure-paas
116
+ - text : Secure networks with Zero Trust
117
+ url : /security/zero-trust/deploy/networks
118
+ - text : Filter network traffic between Azure resources
119
+ url : ../../virtual-network/network-security-groups-overview.md
120
+ - text : Secure access to Azure services
121
+ url : ../../virtual-network/virtual-network-service-endpoints-overview.md
122
+ - text : Deploy security admin rules with Virtual Network manager
123
+ url : ../../virtual-network-manager/how-to-block-network-traffic-portal.md
124
+ - text : Apply Zero Trust principles to a spoke virtual network in Azure
125
+ url : /security/zero-trust/azure-infrastructure-iaas
126
+ - text : Apply Zero Trust principles to a hub virtual network in Azure
127
+ url : /security/zero-trust/azure-infrastructure-networking
128
+ - text : Implement the Zero Trust model
129
+ url : https://techcommunity.microsoft.com/t5/azure-network-security-blog/zero-trust-with-azure-network-security/ba-p/3668280
130
+ - text : Apply Zero Trust principles to an Azure Virtual WAN deployment
131
+ url : /security/zero-trust/azure-virtual-wan
132
+
133
+
170
134
- title : Training
171
135
links :
172
- - text : Introduction to Azure DDoS Protection
173
- url : /training/modules/introduction-azure-ddos-protection/
174
136
- text : Introduction to Azure Private Link
175
137
url : /training/modules/introduction-azure-private-link/
176
138
- text : Design and implement private access to Azure Services
177
139
url : /training/modules/design-implement-private-access-to-azure-services/
178
140
- text : Encrypt network traffic end to end with Application gateways
179
141
url : /training/modules/end-to-end-encryption-with-app-gateway/
142
+ - text : Configure network security groups
143
+ url : /training/modules/configure-network-security-groups/
144
+ - text : Secure and isolate access to Azure resources by using network security groups and service endpoints
145
+ url : /training/modules/secure-and-isolate-with-nsg-and-service-endpoints/
146
+ - text : Connect my on-premises network to Azure with VPN gateways
147
+ url : /training/modules/connect-on-premises-network-with-vpn-gateway/
148
+ - text : Design and implement network security
149
+ url : /training/modules/design-implement-network-security-monitoring/
150
+ - text : Design solutions for network security
151
+ url : /training/modules/design-solutions-network-security/
152
+ - text : Design and implement network monitoring
153
+ url : /training/modules/design-implement-network-monitoring/
154
+
155
+
180
156
- title : Architecture
181
157
links :
182
- - text : Apply Zero Trust principles to a spoke virtual network with Azure PaaS Services
183
- url : /security/zero-trust/azure-infrastructure-paas
184
158
- text : Zero-trust network for web applications with Azure Firewall and Application Gateway
185
159
url : /azure/architecture/example-scenario/gateway/application-gateway-before-azure-firewall
186
160
- text : Azure Private Link in a hub-and-spoke network
@@ -189,29 +163,13 @@ additionalContent:
189
163
url : /azure/architecture/guide/networking/private-link-virtual-wan-dns-guide
190
164
- text : Secure network access to Kubernetes
191
165
url : /azure/architecture/aws-professional/eks-to-aks/private-clusters
192
- - text : Use Azure Firewall to help protect an Azure Kubernetes Service (AKS) cluster
193
- url : /azure/architecture/guide/aks/aks-firewall
194
- - title : Secure your virtual machines
195
- items :
196
- # Card
197
- - title : I want to...
198
- links :
199
- - text : Connect to my VMs without a public IP address exposure
200
- url : ../../bastion/bastion-overview.md
201
- - text : Learn more about Azure Bastion
202
- url : ../../bastion/index.yml
203
- - text : Enable just-in-time access on VMs
204
- url : ../../defender-for-cloud/just-in-time-access-usage.yml
205
- - title : Training
206
- links :
207
- - text : Configure the network for your virtual machines
208
- url : /training/modules/configure-network-for-azure-virtual-machines/
209
- - text : Introduction to Azure Bastion
210
- url : /training/modules/intro-to-azure-bastion/
211
- - text : Connect to a VM using Azure Bastion
212
- url : /training/modules/connect-vm-with-azure-bastion/
213
- - title : Architecture
214
- links :
215
- - text : Multilayered protection for Azure virtual machine access
216
- url : /azure/architecture/solution-ideas/articles/multilayered-protection-azure-vm
217
-
166
+ - text : Extend an on-premises network using ExpressRoute
167
+ url : /azure/architecture/reference-architectures/hybrid-networking/expressroute
168
+ - text : Securely managed web applications
169
+ url : /azure/architecture/example-scenario/apps/fully-managed-secure-apps
170
+ - text : Mission-critical baseline architecture with network control
171
+ url : /azure/architecture/reference-architectures/containers/aks-mission-critical/mission-critical-network-architecture
172
+ - text : Build the first layer of defense with Azure Security services
173
+ url : /azure/architecture/solution-ideas/articles/azure-security-build-first-layer-defense
174
+ - text : Secure and govern workloads with network-level segmentation
175
+ url : /azure/architecture/reference-architectures/hybrid-networking/network-level-segmentation
0 commit comments