🎯 Mục tiêu chương
- Triển khai Azure Firewall Standard/Premium bảo vệ egress traffic.
- Quản lý Firewall Policy tập trung với rule collection group.
- Cấu hình DNAT, Network Rule và Application Rule.
- Triển khai Application Gateway Layer 7 cho web app.
- Bảo vệ ứng dụng web bằng WAF policy và OWASP Core Rule Set.
Azure Firewall Premium bổ sung IDPS (Intrusion Detection & Prevention), TLS inspection và URL filtering. Từ 2026, Firewall Basic bị retire — chỉ dùng Standard hoặc Premium cho production. Firewall Policy thay thế classic rules.
📚 Nội dung chi tiết
6.1 Azure Firewall
- • DNAT rule: chuyển tiếp inbound traffic từ public IP → private IP
- • Network rule: lọc TCP/UDP/ICMP theo IP và port
- • Application rule: lọc HTTP/HTTPS theo FQDN, URL category
- • Standard: FQDN filtering, threat intel, network/app rules
- • Premium: + IDPS, TLS inspection, URL filtering, web categories
- • Forced tunneling: gửi internet traffic qua on-prem
- • Availability Zone: HA across zones
| Rule Type | Layer | Use case điển hình |
|---|---|---|
| DNAT | L4 | Cho phép RDP/SSH từ Internet vào VM private qua firewall public IP |
| Network Rule | L3–L4 | Cho phép VM truy cập DNS server, Active Directory trên IP cụ thể |
| Application Rule | L7 | Cho phép VM truy cập *.microsoft.com, chặn mọi domain khác |
6.2 Azure Firewall Manager & Policy
Tập trung toàn bộ rules vào 1 policy object. Gán policy cho nhiều firewalls. Rule Collection Group với priority.
Alert mode: log khi traffic khớp threat intel feed. Deny mode: chặn tự động. Microsoft cập nhật feed liên tục.
Tích hợp Azure Firewall vào Virtual WAN Hub. Quản lý nhiều firewalls từ Firewall Manager.
6.3 Application Gateway
Application Gateway là Layer 7 load balancer — phân phối traffic HTTP/HTTPS dựa vào URL path, hostname, header.
- • Listener: nhận HTTP/HTTPS trên port/hostname
- • Backend Pool: VM, VMSS, App Service, IP
- • HTTP Setting: protocol, port, cookie-based affinity
- • Routing Rule: listener → backend pool
- • TLS Termination: decrypt tại Gateway
- • Backend không cần Public IP
- • TLS termination tập trung
- • Tích hợp WAF policy
- • Health probe tự động loại backend lỗi
- • Private frontend (Internal SKU)
6.4 Web Application Firewall (WAF)
- • Detection mode: log không chặn — dùng để tune rule
- • Prevention mode: log và chặn request vi phạm
- • Khuyến nghị: Detection trước → kiểm tra log → bật Prevention
- • SQL injection, XSS, LFI, RFI
- • Remote code execution
- • HTTP protocol violations
- • CRS 3.2 (mặc định) hoặc DRS 2.1
Tự định nghĩa điều kiện lọc: IP, geo-location, request header, URI. Priority cao hơn managed rules.
Loại trừ request attribute cụ thể khỏi rule check — dùng khi app có false positive hợp lệ.
6.5 Azure Front Door & DDoS Protection
- • Global entry point, CDN tích hợp
- • WAF policy tại edge (gần user)
- • URL-based routing, SSL offload
- • Health probe, failover tự động
- • Latency-based routing toàn cầu
- • DDoS Network Protection: per-VNet, telemetry, SLA
- • DDoS IP Protection: per-Public IP, chi phí thấp hơn
- • Basic (Infrastructure): miễn phí, tự động
- • Cost guarantee: credit nếu bị tấn công và scale
- • Rapid Response Team hỗ trợ khi sự cố
| Dịch vụ | Scope | WAF | Layer |
|---|---|---|---|
| App Gateway | Regional | Có | L7 |
| Front Door | Global | Có (edge) | L7 |
| Azure Firewall | Regional | Không | L3–L7 |
| NSG | Subnet/NIC | Không | L3–L4 |
🧪 Lab trong chương
Tạo VNet với AzureFirewallSubnet, deploy Firewall, UDR ép traffic qua FW, application rule cho phép domain chỉ định.
Xem labVM private không có Public IP, tạo DNAT rule trên Firewall cho phép IP quản trị truy cập qua FW Public IP.
Xem labTạo Firewall Policy, gắn vào Firewall, tạo rule collection group, bật Threat Intelligence Alert/Deny, xem log.
Xem labTạo backend pool (VM/App Service), cấu hình listener, HTTP setting, routing rule, kiểm tra truy cập web qua App GW.
Xem labTạo WAF policy với OWASP managed rules, gắn vào App Gateway, gửi request có pattern bất thường (SQL injection test), xem WAF log phát hiện/chặn.
Xem lab