AZ-500 CHƯƠNG 06 5 Labs Network Security 20–25% đề thi

Azure Firewall, Application Gateway & WAF

Triển khai Azure Firewall bảo vệ egress traffic, quản lý Firewall Policy tập trung, cấu hình DNAT, Application Gateway Layer 7 và WAF chống tấn công OWASP Top 10.

🎯 Mục tiêu chương

  • Triển khai Azure Firewall Standard/Premium bảo vệ egress traffic.
  • Quản lý Firewall Policy tập trung với rule collection group.
  • Cấu hình DNAT, Network Rule và Application Rule.
  • Triển khai Application Gateway Layer 7 cho web app.
  • Bảo vệ ứng dụng web bằng WAF policy và OWASP Core Rule Set.
Cập nhật 2026 — Azure Firewall Premium & Standard SKU

Azure Firewall Premium bổ sung IDPS (Intrusion Detection & Prevention), TLS inspection và URL filtering. Từ 2026, Firewall Basic bị retire — chỉ dùng Standard hoặc Premium cho production. Firewall Policy thay thế classic rules.

📚 Nội dung chi tiết

6.1 Azure Firewall

Các loại Rule
  • DNAT rule: chuyển tiếp inbound traffic từ public IP → private IP
  • Network rule: lọc TCP/UDP/ICMP theo IP và port
  • Application rule: lọc HTTP/HTTPS theo FQDN, URL category
Standard vs Premium
  • • Standard: FQDN filtering, threat intel, network/app rules
  • • Premium: + IDPS, TLS inspection, URL filtering, web categories
  • • Forced tunneling: gửi internet traffic qua on-prem
  • • Availability Zone: HA across zones
Rule Type Layer Use case điển hình
DNATL4Cho phép RDP/SSH từ Internet vào VM private qua firewall public IP
Network RuleL3–L4Cho phép VM truy cập DNS server, Active Directory trên IP cụ thể
Application RuleL7Cho phép VM truy cập *.microsoft.com, chặn mọi domain khác

6.2 Azure Firewall Manager & Policy

Firewall Policy

Tập trung toàn bộ rules vào 1 policy object. Gán policy cho nhiều firewalls. Rule Collection Group với priority.

Threat Intelligence

Alert mode: log khi traffic khớp threat intel feed. Deny mode: chặn tự động. Microsoft cập nhật feed liên tục.

Secured Virtual Hub

Tích hợp Azure Firewall vào Virtual WAN Hub. Quản lý nhiều firewalls từ Firewall Manager.

6.3 Application Gateway

Application Gateway là Layer 7 load balancer — phân phối traffic HTTP/HTTPS dựa vào URL path, hostname, header.

Thành phần
  • Listener: nhận HTTP/HTTPS trên port/hostname
  • Backend Pool: VM, VMSS, App Service, IP
  • HTTP Setting: protocol, port, cookie-based affinity
  • Routing Rule: listener → backend pool
  • TLS Termination: decrypt tại Gateway
Lợi ích bảo mật
  • • Backend không cần Public IP
  • • TLS termination tập trung
  • • Tích hợp WAF policy
  • • Health probe tự động loại backend lỗi
  • • Private frontend (Internal SKU)

6.4 Web Application Firewall (WAF)

WAF Modes
  • Detection mode: log không chặn — dùng để tune rule
  • Prevention mode: log và chặn request vi phạm
  • • Khuyến nghị: Detection trước → kiểm tra log → bật Prevention
OWASP Core Rule Set
  • • SQL injection, XSS, LFI, RFI
  • • Remote code execution
  • • HTTP protocol violations
  • • CRS 3.2 (mặc định) hoặc DRS 2.1
Custom Rules

Tự định nghĩa điều kiện lọc: IP, geo-location, request header, URI. Priority cao hơn managed rules.

Exclusion

Loại trừ request attribute cụ thể khỏi rule check — dùng khi app có false positive hợp lệ.

6.5 Azure Front Door & DDoS Protection

Azure Front Door
  • • Global entry point, CDN tích hợp
  • • WAF policy tại edge (gần user)
  • • URL-based routing, SSL offload
  • • Health probe, failover tự động
  • • Latency-based routing toàn cầu
DDoS Protection 2026
  • DDoS Network Protection: per-VNet, telemetry, SLA
  • DDoS IP Protection: per-Public IP, chi phí thấp hơn
  • • Basic (Infrastructure): miễn phí, tự động
  • • Cost guarantee: credit nếu bị tấn công và scale
  • • Rapid Response Team hỗ trợ khi sự cố
Dịch vụ Scope WAF Layer
App GatewayRegionalL7
Front DoorGlobalCó (edge)L7
Azure FirewallRegionalKhôngL3–L7
NSGSubnet/NICKhôngL3–L4

🧪 Lab trong chương

✅ Checklist cuối chương

Zalo