Skip to content

Commit da17aac

Browse files
authored
Merge pull request #300620 from mbender-ms/wb-security-v2
Portfolio Consolidation | Security updates
2 parents 93274c3 + f018dfc commit da17aac

File tree

11 files changed

+74
-48
lines changed

11 files changed

+74
-48
lines changed

articles/ddos-protection/TOC.yml

Lines changed: 18 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,8 @@
1010
href: ddos-protection-sku-comparison.md
1111
- name: Price comparison
1212
href: ddos-pricing-guide.md
13+
- name: What is Azure network security?
14+
href: /azure/networking/security/network-security.md?toc=/azure/ddos-protection/toc.json
1315
- name: FAQ
1416
href: ddos-faq.yml
1517
- name: Configure
@@ -53,6 +55,22 @@
5355
href: ../application-gateway/tutorial-protect-application-gateway-ddos.md?toc=/azure/ddos-protection/TOC.json
5456
- name: Deploy Load Balancer with DDoS Protection
5557
href: ../load-balancer/tutorial-protect-load-balancer-ddos.md?toc=/azure/ddos-protection/TOC.json
58+
- name: Secure
59+
items:
60+
- name: DDoS Protection on Front Door
61+
href: ../frontdoor/front-door-ddos.md?toc=/azure/ddos-protection/TOC.json
62+
- name: Defend against API Management DDoS attacks
63+
href: ../api-management/protect-with-ddos-protection.md?toc=/azure/ddos-protection/TOC.json
64+
- name: Inline L7 DDoS protection with Gateway Load Balancer and partner NVAs
65+
href: inline-protection-glb.md
66+
- name: Manage permissions and restrictions
67+
href: manage-permissions.md
68+
- name: Onboard partners
69+
href: ddos-protection-partner-onboarding.md
70+
- name: Security baseline
71+
href: /security/benchmark/azure/baselines/azure-ddos-protection-security-baseline?toc=%2fazure%2fddos-protection%2ftoc.json?toc=/azure/ddos-protection/TOC.json
72+
- name: Azure Security blog
73+
href: https://techcommunity.microsoft.com/category/azure-network-security/blog/azurenetworksecurityblog
5674
- name: Resiliency
5775
items:
5876
- name: Components of a DDoS response strategy
@@ -85,22 +103,6 @@
85103
href: test-through-simulations.md
86104
- name: Engage DDoS Rapid Response (DRR)
87105
href: ddos-rapid-response.md
88-
- name: Security
89-
items:
90-
- name: DDoS Protection on Front Door
91-
href: ../frontdoor/front-door-ddos.md?toc=/azure/ddos-protection/TOC.json
92-
- name: Defend against API Management DDoS attacks
93-
href: ../api-management/protect-with-ddos-protection.md?toc=/azure/ddos-protection/TOC.json
94-
- name: Inline L7 DDoS protection with Gateway Load Balancer and partner NVAs
95-
href: inline-protection-glb.md
96-
- name: Manage permissions and restrictions
97-
href: manage-permissions.md
98-
- name: Onboard partners
99-
href: ddos-protection-partner-onboarding.md
100-
- name: Security baseline
101-
href: /security/benchmark/azure/baselines/azure-ddos-protection-security-baseline?toc=%2fazure%2fddos-protection%2ftoc.json?toc=/azure/ddos-protection/TOC.json
102-
- name: Azure Security blog
103-
href: https://techcommunity.microsoft.com/category/azure-network-security/blog/azurenetworksecurityblog
104106
- name: Reference
105107
items:
106108
- name: Azure Policy built-ins

articles/ddos-protection/ddos-protection-overview.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,9 @@ Azure DDoS Protection, combined with application design best practices, provides
2020

2121
Azure DDoS Protection protects at layer 3 and layer 4 network layers. For web applications protection at layer 7, you need to add protection at the application layer using a WAF offering. For more information, see [Application DDoS protection](../web-application-firewall/shared/application-ddos-protection.md).
2222

23+
> [!NOTE]
24+
> Azure DDoS Protections is one of the services that make up the Network Security category in Azure. Other services in this category include [Azure Firewall](../firewall/overview.md) and [Azure Web Application Firewall](../web-application-firewall/overview.md). Each service has its own unique features and use cases. For more information on this service category, see [Network Security](../networking/security/network-security.md).
25+
2326
## Tiers
2427

2528
### DDoS Network Protection

articles/ddos-protection/index.yml

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -107,9 +107,13 @@ landingContent:
107107
linkLists:
108108
- linkListType: get-started
109109
links:
110-
- text: Documentation
111-
url: https://learn.microsoft.com/en-us/azure/networking/security/
110+
- text: What is Azure Network Security?
111+
url: /azure/networking/security/network-security
112+
- text: Learm more about Azure network security
113+
url: /azure/networking/security/
114+
- linkListType: overview
115+
links:
112116
- text: Azure Firewall
113-
url: /azure/firewall/
114-
- text: Azure WAF
115-
url: /azure/web-application-firewall/
117+
url: /azure/firewall/overview
118+
- text: Azure Web Application Firewall
119+
url: /azure/web-application-firewall/overview

articles/firewall/index.yml

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ metadata:
1010
ms.topic: landing-page
1111
author: duongau
1212
ms.author: duau
13-
ms.date: 03/17/2025
13+
ms.date: 05/30/2025
1414
ms.custom: e2e-hybrid
1515

1616
# linkListType: architecture | concept | deploy | download | get-started | how-to-guide | learn | overview | quickstart | reference | tutorial | whats-new
@@ -157,16 +157,18 @@ landingContent:
157157
# Card
158158
- title: Learn about Azure network security
159159
linkLists:
160-
- linkListType: overview
160+
- linkListType: get-started
161161
links:
162-
- text: Azure network security
163-
url: ../networking/security/index.yml
164-
- linkListType: concept
162+
- text: What is Azure network security?
163+
url: /azure/networking/security/network-security
164+
- text: Learm more about Azure network security
165+
url: /azure/networking/security/
166+
- linkListType: overview
165167
links:
166168
- text: Azure DDoS Protection
167-
url: ../ddos-protection/index.yml
169+
url: /azure/ddos-protection/ddos-protection-overview
168170
- text: Azure Web Application Firewall
169-
url: ../web-application-firewall/index.yml
171+
url: /azure/web-application-firewall/overview
170172

171173
# Card
172174
- title: Reference

articles/firewall/overview.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,9 @@ Azure Firewall is a cloud-native, intelligent network firewall security service
1717

1818
Azure Firewall is available in three SKUs: Basic, Standard, and Premium.
1919

20+
> [!NOTE]
21+
> Azure Firewall is one of the services that make up the Network Security category in Azure. Other services in this category include [Azure DDoS Protection](../ddos-protection/ddos-protection-overview.md) and [Azure Web Application Firewall](../web-application-firewall/overview.md). Each service has its own unique features and use cases. For more information on this service category, see [Network Security](../networking/security/network-security.md).
22+
2023
## Azure Firewall Basic
2124

2225
Azure Firewall Basic is designed for small and medium-sized businesses (SMBs) to secure their Azure cloud environments. It provides essential protection at an affordable price.

articles/firewall/toc.yml

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,8 @@ items:
77
href: overview.md
88
- name: Well-Architected review of Azure Firewall
99
href: /azure/architecture/framework/services/networking/azure-firewall?toc=/azure/firewall/toc.json&bc=/azure/firewall/breadcrumb/toc.json
10+
- name: What is Azure network security?
11+
href: /azure/networking/security/network-security.md?toc=/azure/firewall/toc.json&bc=/azure/firewall/breadcrumb/toc.json
1012
- name: SKU comparison
1113
href: choose-firewall-sku.md
1214
- name: Preview features
@@ -166,15 +168,7 @@ items:
166168
href: sql-fqdn-filtering.md
167169
- name: SNAT private ranges
168170
href: snat-private-range.md
169-
- name: Migration and upgrades
170-
items:
171-
- name: Migrate to Azure Firewall Premium
172-
href: premium-migrate.md
173-
- name: Migrate to Premium using Terraform
174-
href: /azure/developer/terraform/firewall-upgrade-premium?toc=/azure/firewall/toc.json&bc=/azure/firewall/breadcrumb/toc.json
175-
- name: Easy upgrade/downgrade
176-
href: easy-upgrade.md
177-
- name: Security
171+
- name: Secure
178172
items:
179173
- name: Security baseline
180174
href: /security/benchmark/azure/baselines/firewall-security-baseline?toc=/azure/firewall/toc.json
@@ -196,6 +190,14 @@ items:
196190
href: detect-malware-with-sentinel.md
197191
- name: Network security blog
198192
href: https://techcommunity.microsoft.com/category/azure-network-security/blog/azurenetworksecurityblog
193+
- name: Migration and upgrades
194+
items:
195+
- name: Migrate to Azure Firewall Premium
196+
href: premium-migrate.md
197+
- name: Migrate to Premium using Terraform
198+
href: /azure/developer/terraform/firewall-upgrade-premium?toc=/azure/firewall/toc.json&bc=/azure/firewall/breadcrumb/toc.json
199+
- name: Easy upgrade/downgrade
200+
href: easy-upgrade.md
199201
- name: Operational excellence
200202
items:
201203
- name: Monitoring

articles/networking/load-balancer-content-delivery/index.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ metadata:
1111
author: mbender-ms
1212
ms.author: mbender
1313
manager: kumudD
14-
ms.date: 05/13/2025
14+
ms.date: 05/27/2025
1515
ms.custom: portfolio-consolidation-2025
1616

1717
highlightedContent:
@@ -29,6 +29,9 @@ highlightedContent:
2929
- title: What's new in Azure Load Balancer
3030
itemType: whats-new
3131
url: /azure/load-balancer/whats-new
32+
- title: Choose a load balancing solution in Azure
33+
itemType: concept
34+
url: /azure/architecture/guide/technology-choices/load-balancing-overview
3235

3336
productDirectory:
3437
title: Get started

articles/networking/security/network-security.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Choosing the right network security solution for your Azure workloads depends on
3131

3232
## Azure Firewall
3333

34-
[Azure Firewall](../../firewall/index.yml) is a cloud-native, intelligent network firewall service that offers full stateful protection with built-in high availability and unlimited cloud scalability. It provides both network and application-level security for your Azure workloads. As a managed service, Azure Firewall can be deployed in a virtual network and integrates seamlessly with other Azure services like Azure Monitor, Azure Security Center, and Microsoft Sentinel for enhanced security and monitoring.
34+
[Azure Firewall](../../firewall/overview.md) is a cloud-native, intelligent network firewall service that offers full stateful protection with built-in high availability and unlimited cloud scalability. It provides both network and application-level security for your Azure workloads. As a managed service, Azure Firewall can be deployed in a virtual network and integrates seamlessly with other Azure services like Azure Monitor, Azure Security Center, and Microsoft Sentinel for enhanced security and monitoring.
3535

3636
:::image type="content" source="./media/network-security/firewall.png" alt-text="Diagram showing how Azure Firewall inspects traffic to and from the internet before routing it to its destination.":::
3737

@@ -53,7 +53,7 @@ For more information, see [Azure Firewall overview](../../firewall/overview.md).
5353

5454
## Azure DDoS Protection
5555

56-
[Azure DDoS Protection](../../ddos-protection/index.yml) is a service that provides enhanced DDoS mitigation features to defend against DDoS attacks. It's automatically tuned to help protect your specific Azure resources in a virtual network. Protection is simple to enable on any new or existing virtual network or public IP address resources, and it requires no application or resource changes.
56+
[Azure DDoS Protection](../../ddos-protection/ddos-protection-overview.md) is a service that provides enhanced DDoS mitigation features to defend against DDoS attacks. It's automatically tuned to help protect your specific Azure resources in a virtual network. Protection is simple to enable on any new or existing virtual network or public IP address resources, and it requires no application or resource changes.
5757

5858
- **IP protection**: Azure DDoS IP Protection provides protection for your Azure resources that are assigned a public IP address. It protects against volumetric, protocol, and application layer attacks.
5959

@@ -73,7 +73,7 @@ For more information, see [Azure DDoS Protection overview](../../ddos-protection
7373

7474
## Azure Web Application Firewall
7575

76-
[Azure Web Application Firewall](../../web-application-firewall/index.yml) (WAF) is a web application firewall that provides centralized protection to your web applications from common exploits and vulnerabilities. WAF uses rules to monitor HTTP requests and responses, and it can block or allow traffic based on the rules you define.
76+
[Azure Web Application Firewall](../../web-application-firewall/overview.md) (WAF) is a web application firewall that provides centralized protection to your web applications from common exploits and vulnerabilities. WAF uses rules to monitor HTTP requests and responses, and it can block or allow traffic based on the rules you define.
7777

7878
:::image type="content" source="./media/network-security/web-application-firewall.png" alt-text="Diagram illustrating Azure Web Application Firewall applied to both Azure Application Gateway and Azure Front Door, allowing valid requests and blocking web attacks.":::
7979

articles/web-application-firewall/index.yml

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -115,16 +115,18 @@ landingContent:
115115
# Card
116116
- title: Learn about Azure network security
117117
linkLists:
118-
- linkListType: overview
118+
- linkListType: get-started
119119
links:
120-
- text: Azure network security
121-
url: ../networking/security/index.yml
122-
- linkListType: concept
120+
- text: What is Azure network security?
121+
url: /azure/networking/security/network-security
122+
- text: Learm more about Azure network security
123+
url: /azure/networking/security/
124+
- linkListType: overview
123125
links:
124126
- text: Azure DDoS Protection
125-
url: ../ddos-protection/index.yml
127+
url: /azure/ddos-protection/ddos-protection-overview
126128
- text: Azure Firewall
127-
url: ../firewall/index.yml
129+
url: /azure/firewall/overview
128130

129131
# Card
130132
- title: Reference

articles/web-application-firewall/overview.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,9 @@ Preventing such attacks in application code is challenging. It can require rigor
2121

2222
A WAF solution can react to a security threat faster by centrally patching a known vulnerability, instead of securing each individual web application.
2323

24+
> [!NOTE]
25+
> Azure Web Application Firewall is one of the services that make up the Network Security category in Azure. Other services in this category include [Azure DDoS Protection](../ddos-protection/ddos-protection-overview.md) and [Azure Firewall](../firewall/overview.md). Each service has its own unique features and use cases. For more information on this service category, see [Network Security](../networking/security/network-security.md).
26+
2427
## Supported service
2528

2629
WAF can be deployed with Azure Application Gateway, Azure Front Door, and Azure Content Delivery Network (CDN) service from Microsoft. WAF on Azure CDN is currently under public preview. WAF has features that are customized for each specific service. For more information about WAF features for each service, see the overview for each service.

0 commit comments

Comments
 (0)