A network administrator needs to improve the security posture of an Azure Virtual Network (VNet) by ensuring that all outbound internet traffic from a specific subnet is inspected and filtered by a centralized firewall. The VNet contains multiple subnets, and only one of them requires this specific outbound filtering.
- AConfigure a Network Security Group (NSG) on the subnet to block all outbound traffic.
- BImplement Azure DDoS Protection Standard on the VNet.
- CDeploy an Azure Firewall and configure User Defined Routes (UDRs) to route traffic through it.
- DEnable Service Endpoints for the subnet to restrict outbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy an Azure Firewall and configure User Defined Routes (UDRs) to route traffic through it.
To force specific outbound internet traffic through a centralized firewall for inspection and filtering, an Azure Firewall should be deployed. User Defined Routes (UDRs) are then used to override Azure's default routing and direct the traffic from the specific subnet to the Azure Firewall, ensuring all outbound internet traffic passes through it.
Why the other options are wrong
- A. An NSG can block outbound traffic but cannot route it through a centralized firewall for inspection and filtering.
- B. Azure DDoS Protection Standard protects against DDoS attacks; it does not inspect or filter outbound internet traffic.
- D. Service Endpoints secure access to Azure services; they do not route outbound internet traffic through a firewall.
Forced Tunneling with UDRs and Azure Firewall
Forced tunneling redirects or 'forces' all internet-bound traffic from Azure virtual machines or subnets to an on-premises or Azure-based firewall for inspection and auditing, typically using User Defined Routes (UDRs).
- Achieved by configuring UDRs on subnets.
- Azure Firewall is a common target for forced tunneling in Azure.
- Ensures all outbound traffic passes through a central security appliance.
Memory trick: To filter all outbound traffic, force it through the firewall's funnel.