Deploy Azure Firewall across multiple availability zones
Impact:HighCategory:High Availability
APRL GUID:c72b7fee-1fa0-5b4b-98e5-54bcae95bb74
Description:
Azure Firewall offers different SLAs depending on its deployment; in a single availability zone or across multiple, potentially improving reliability and performance.
Monitor Azure Firewall for overall health, processed throughput, and outbound SNAT port usage. Get alerted before limits impact services. Consider NAT gateway integration with zonal deployments; note limitations with zone redundant firewalls and secure virtual hub networks.
Configure a minimum of two to four public IP addresses per Azure Firewall to avoid SNAT exhaustion. Azure Firewall offers SNAT for all outbound traffic to public IPs, providing 2,496 SNAT ports for each additional PIP.
Click the Azure Resource Graph tab to view the query
//underdevelopment
Monitor "AZFW Latency Probe" metric
Impact:HighCategory:Monitoring and Alerting
APRL GUID:8faace2d-a36e-425c-aa58-2ad99e3e0b7a
Description:
Using the Azure Firewall latency probe metric to monitor sustained latency over 30ms (accounting for normal spikes) can help identify when firewall instance CPU utilization is under stress, potentially indicating performance issues