Skip to content

Commit d884e90

Browse files
authored
Update policy-overview.md
1 parent 7411746 commit d884e90

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

articles/firewall-manager/policy-overview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ Azure Firewall supports both Classic rules and policies, but policies is the rec
3030

3131
| Subject | Policy | Classic rules |
3232
| ------- | ------- | ----- |
33-
|Contains |NAT, Network, Application rules, custom DNS and DNS proxy settings, IP Groups, and Threat Intelligence settings (including allow list), IDPS, TLS Inspection, Web Categories, URL Filtering|NAT, Network, and Application rules, custom DNS and DNS proxy settings, IP Groups, and Threat Intelligence settings (including allow list)|
33+
|Contains |NAT, Network, Application rules, custom DNS and DNS proxy settings, IP Groups, and Threat Intelligence settings (including allowlist), IDPS, TLS Inspection, Web Categories, URL Filtering|NAT, Network, and Application rules, custom DNS and DNS proxy settings, IP Groups, and Threat Intelligence settings (including allowlist)|
3434
|Protects |Virtual hubs and Virtual Networks|Virtual Networks only|
3535
|Portal experience |Central management using Firewall Manager|Standalone firewall experience|
3636
|Multiple firewall support |Firewall Policy is a separate resource that can be used across firewalls|Manually export and import rules, or using third-party management solutions |
@@ -57,7 +57,7 @@ Network rule collections inherited from a parent policy are always prioritized a
5757

5858
Threat Intelligence mode is also inherited from the parent policy. You can set your threat Intelligence mode to a different value to override this behavior, but you can't turn it off. It's only possible to override with a stricter value. For example, if your parent policy is set to **Alert only**, you can configure this local policy to **Alert and deny**.
5959

60-
Like Threat Intelligence mode, the Threat Intelligence allow list is inherited from the parent policy. The child policy can add additional IP addresses to the allow list.
60+
Like Threat Intelligence mode, the Threat Intelligence allowlist is inherited from the parent policy. The child policy can add additional IP addresses to the allowlist.
6161

6262
NAT rule collections aren't inherited because they're specific to a given firewall.
6363

0 commit comments

Comments
 (0)