You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

用Terraform配置Azure Firewall Premium的TLS Inspection与IDPS是否遗漏步骤?

问题背景

我希望通过Terraform启用Azure Firewall Policy的TLS Inspection和IDPS高级功能,已执行证书生成命令并将证书存入Key Vault,编写了对应的Terraform配置,请问当前配置是否存在遗漏?

证书生成命令:

# Create root CA
openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCA.key -sha256 -days 3650 -out rootCA.crt -subj '/C=US/ST=US/O=Self Signed/CN=Self Signed Root CA' -config openssl.cnf -extensions rootCA_ext

# Create intermediate CA request
openssl req -new -nodes -newkey rsa:4096 -keyout interCA.key -sha256 -out interCA.csr -subj '/C=US/ST=US/O=Self Signed/CN=Self Signed Intermediate CA'

# Sign on the intermediate CA
openssl x509 -req -in interCA.csr -CA rootCA.crt -CAkey rootCA.key -CAcreateserial -out interCA.crt -days 3650 -sha256 -extfile openssl.cnf -extensions interCA_ext

# Export the intermediate CA into PFX
openssl pkcs12 -export -out interCA.pfx -inkey interCA.key -in interCA.crt -password 'pass:'

Write-Host ""
Write-Host "================"
Write-Host "Successfully generated root and intermediate CA certificates"
Write-Host "   - rootCA.crt/rootCA.key - Root CA public certificate and private key"
Write-Host "   - interCA.crt/interCA.key - Intermediate CA public certificate and private key"
Write-Host "   - interCA.pfx - Intermediate CA pkcs12 package which could be uploaded to Key Vault"
Write-Host "================"

Key Vault证书存储配置:

resource "azurerm_key_vault_certificate" "example" {
  name         = "imported-cert"
  key_vault_id = azurerm_key_vault.example.id

  certificate {
    contents = filebase64("interCA.pfx")
    password = ""
  }
}

Azure Firewall Policy配置:

resource "azurerm_firewall_policy" "example" {
  name                = "example"
  resource_group_name = "example"
  location            = "West Europe"
  identity {
      type = "UserAssigned"
      user_assigned_identity_ids = [azurerm_user_assigned_identity.test.id]
  }
  sku="Premium"
  tls_certificate{
      key_vault_secret_id = azurerm_key_vault_secret.example.id
      name = "imported-cert"
  }
  intrusion_detection {
      mode="Alert"
      signature_overrides {
          id = "sigOverrideParam1 id (2024897)" 
          state = "Deny" 
      }
      signature_overrides {
          id = "sigOverrideParam2 id (2024898)"
          state = "Alert"
      }
      traffic_bypass {
          name = "SecretBypass"
          protocol ="TCP"
          source_addresses = ["*"]
          destination_addresses =["1.1.1.1"]
          destination_ports = ["80"]
      }
  }
}
配置遗漏点分析

以下是当前配置中存在的关键遗漏项:

1. Key Vault证书引用错误

在Firewall Policy的tls_certificate块中,你使用了azurerm_key_vault_secret.example.id,但实际导入的证书资源是azurerm_key_vault_certificate.example。Key Vault证书资源会自动生成对应的Secret,正确的引用方式应该是使用证书资源的secret_id属性:

tls_certificate{
    key_vault_secret_id = azurerm_key_vault_certificate.example.secret_id
    name = "imported-cert"
}

2. 用户分配身份的Key Vault权限缺失

Firewall Policy的用户分配身份需要具备访问Key Vault中证书的权限,否则无法读取证书用于TLS Inspection。需要在Key Vault的访问策略中添加该身份的Certificate Get和Secret Get权限:

resource "azurerm_key_vault_access_policy" "firewall_policy" {
  key_vault_id = azurerm_key_vault.example.id
  tenant_id    = data.azurerm_client_config.current.tenant_id

  object_id = azurerm_user_assigned_identity.test.principal_id

  certificate_permissions = [
    "Get",
  ]

  secret_permissions = [
    "Get",
  ]
}

3. TLS Inspection未在规则层面启用

仅配置TLS证书不足以开启TLS Inspection功能,需要在**应用规则集合(Application Rule Collection)**中显式启用TLS检查。例如:

resource "azurerm_firewall_policy_rule_collection_group" "example" {
  name               = "example-rule-group"
  firewall_policy_id = azurerm_firewall_policy.example.id
  priority           = 100

  application_rule_collection {
    name     = "tls-inspect-rules"
    priority = 100
    action   = "Allow"
    tls_inspection_enabled = true # 关键:启用TLS检查

    rule {
      name = "allow-http"
      source_addresses = ["10.0.0.0/24"]
      destination_fqdns = ["*"]
      protocols {
        port = 80
        type = "Http"
      }
      protocols {
        port = 443
        type = "Https"
      }
    }
  }
}

4. Key Vault网络访问配置(若启用Key Vault防火墙)

如果Key Vault启用了网络防火墙,需要确保允许Firewall Policy的用户分配身份访问Key Vault:

  • 要么将Key Vault的网络设置为允许信任的Azure服务访问
  • 要么将Firewall所在的虚拟网络加入Key Vault的允许列表

5. OpenSSL配置文件的CA扩展验证

需要确保openssl.cnf中的rootCA_ext和interCA_ext配置了正确的CA属性,否则证书无法被Azure Firewall识别为有效CA:

[rootCA_ext]
basicConstraints = CA:TRUE
keyUsage = keyCertSign, cRLSign
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer

[interCA_ext]
basicConstraints = CA:TRUE, pathlen:0
keyUsage = keyCertSign, cRLSign
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer

6. IDPS签名ID格式验证

当前配置中的签名ID包含额外描述(如(2024897)),需确保仅使用纯数字签名ID,否则会导致配置无效:

signature_overrides {
    id = "2024897" 
    state = "Deny" 
}
signature_overrides {
    id = "2024898"
    state = "Alert"
}

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 01:20:47