Skip to content

Commit dff1b77

Browse files
Merge pull request #230418 from vhorne/fw-rule-limits
add detail to rule limits
2 parents 2c77354 + 95beb90 commit dff1b77

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

includes/firewall-limits.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,15 +5,15 @@
55
author: vhorne
66
ms.service: firewall
77
ms.topic: include
8-
ms.date: 11/03/2022
8+
ms.date: 03/13/2023
99
ms.author: victorh
1010
ms.custom: include file
1111
---
1212

1313
| Resource | Limit |
1414
| --- | --- |
1515
| Max Data throughput | 100 Gbps for Premium, 30 Gbps for Standard, 250 Mbps for Basic (preview) SKU<br><br> For more information, see [Azure Firewall performance](../articles/firewall/firewall-performance.md#performance-data). |
16-
|Rule limits|20,000 unique source/destinations in network rules <br><br> **Unique source/destinations in network** = sum of (unique source addresses * unique destination addresses for each rule)|
16+
|Rule limits|20,000 unique source/destinations in network rules <br><br> **Unique source/destinations in network** = sum of (unique source addresses * unique destination addresses for each rule)<br><br>You can exceed this limit, but you should monitor your latency metric to ensure it doesn't exceed 20 ms during peak hours.|
1717
|Total size of rules within a single Rule Collection Group| 1 MB for Firewall policies created before July 2022<br>2 MB for Firewall policies created after July 2022|
1818
|Number of Rule Collection Groups in a firewall policy|50 for Firewall policies created before July 2022<br>60 for Firewall policies created after July 2022|
1919
|Maximum DNAT rules (Maximum external destinations)|250 maximum [number of firewall public IP addresses + unique destinations (destination address, port, and protocol)]<br><br> The DNAT limitation is due to the underlying platform.<br><br>For example, you can configure 500 UDP rules to the same destination IP address and port (one unique destination), while 500 rules to the same IP address but to 500 different ports exceeds the limit (500 unique destinations).|

0 commit comments

Comments
 (0)