用Terraform配置Azure Firewall Premium的TLS Inspection与IDPS是否遗漏步骤?
我希望通过Terraform启用Azure Firewall Policy的TLS Inspection和IDPS高级功能,已执行证书生成命令并将证书存入Key Vault,编写了对应的Terraform配置,请问当前配置是否存在遗漏?
证书生成命令:
# Create root CA openssl req -x509 -new -nodes -newkey rsa:4096 -keyout rootCA.key -sha256 -days 3650 -out rootCA.crt -subj '/C=US/ST=US/O=Self Signed/CN=Self Signed Root CA' -config openssl.cnf -extensions rootCA_ext # Create intermediate CA request openssl req -new -nodes -newkey rsa:4096 -keyout interCA.key -sha256 -out interCA.csr -subj '/C=US/ST=US/O=Self Signed/CN=Self Signed Intermediate CA' # Sign on the intermediate CA openssl x509 -req -in interCA.csr -CA rootCA.crt -CAkey rootCA.key -CAcreateserial -out interCA.crt -days 3650 -sha256 -extfile openssl.cnf -extensions interCA_ext # Export the intermediate CA into PFX openssl pkcs12 -export -out interCA.pfx -inkey interCA.key -in interCA.crt -password 'pass:' Write-Host "" Write-Host "================" Write-Host "Successfully generated root and intermediate CA certificates" Write-Host " - rootCA.crt/rootCA.key - Root CA public certificate and private key" Write-Host " - interCA.crt/interCA.key - Intermediate CA public certificate and private key" Write-Host " - interCA.pfx - Intermediate CA pkcs12 package which could be uploaded to Key Vault" Write-Host "================"
Key Vault证书存储配置:
resource "azurerm_key_vault_certificate" "example" { name = "imported-cert" key_vault_id = azurerm_key_vault.example.id certificate { contents = filebase64("interCA.pfx") password = "" } }
Azure Firewall Policy配置:
resource "azurerm_firewall_policy" "example" { name = "example" resource_group_name = "example" location = "West Europe" identity { type = "UserAssigned" user_assigned_identity_ids = [azurerm_user_assigned_identity.test.id] } sku="Premium" tls_certificate{ key_vault_secret_id = azurerm_key_vault_secret.example.id name = "imported-cert" } intrusion_detection { mode="Alert" signature_overrides { id = "sigOverrideParam1 id (2024897)" state = "Deny" } signature_overrides { id = "sigOverrideParam2 id (2024898)" state = "Alert" } traffic_bypass { name = "SecretBypass" protocol ="TCP" source_addresses = ["*"] destination_addresses =["1.1.1.1"] destination_ports = ["80"] } } }
以下是当前配置中存在的关键遗漏项:
1. Key Vault证书引用错误
在Firewall Policy的tls_certificate块中,你使用了azurerm_key_vault_secret.example.id,但实际导入的证书资源是azurerm_key_vault_certificate.example。Key Vault证书资源会自动生成对应的Secret,正确的引用方式应该是使用证书资源的secret_id属性:
tls_certificate{ key_vault_secret_id = azurerm_key_vault_certificate.example.secret_id name = "imported-cert" }
2. 用户分配身份的Key Vault权限缺失
Firewall Policy的用户分配身份需要具备访问Key Vault中证书的权限,否则无法读取证书用于TLS Inspection。需要在Key Vault的访问策略中添加该身份的Certificate Get和Secret Get权限:
resource "azurerm_key_vault_access_policy" "firewall_policy" { key_vault_id = azurerm_key_vault.example.id tenant_id = data.azurerm_client_config.current.tenant_id object_id = azurerm_user_assigned_identity.test.principal_id certificate_permissions = [ "Get", ] secret_permissions = [ "Get", ] }
3. TLS Inspection未在规则层面启用
仅配置TLS证书不足以开启TLS Inspection功能,需要在**应用规则集合(Application Rule Collection)**中显式启用TLS检查。例如:
resource "azurerm_firewall_policy_rule_collection_group" "example" { name = "example-rule-group" firewall_policy_id = azurerm_firewall_policy.example.id priority = 100 application_rule_collection { name = "tls-inspect-rules" priority = 100 action = "Allow" tls_inspection_enabled = true # 关键:启用TLS检查 rule { name = "allow-http" source_addresses = ["10.0.0.0/24"] destination_fqdns = ["*"] protocols { port = 80 type = "Http" } protocols { port = 443 type = "Https" } } } }
4. Key Vault网络访问配置(若启用Key Vault防火墙)
如果Key Vault启用了网络防火墙,需要确保允许Firewall Policy的用户分配身份访问Key Vault:
- 要么将Key Vault的网络设置为允许信任的Azure服务访问
- 要么将Firewall所在的虚拟网络加入Key Vault的允许列表
5. OpenSSL配置文件的CA扩展验证
需要确保openssl.cnf中的rootCA_ext和interCA_ext配置了正确的CA属性,否则证书无法被Azure Firewall识别为有效CA:
[rootCA_ext] basicConstraints = CA:TRUE keyUsage = keyCertSign, cRLSign subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer [interCA_ext] basicConstraints = CA:TRUE, pathlen:0 keyUsage = keyCertSign, cRLSign subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer
6. IDPS签名ID格式验证
当前配置中的签名ID包含额外描述(如(2024897)),需确保仅使用纯数字签名ID,否则会导致配置无效:
signature_overrides { id = "2024897" state = "Deny" } signature_overrides { id = "2024898" state = "Alert" }
内容的提问来源于stack exchange,提问作者One Developer

