You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure防火墙策略规则集配置:常用规则遗漏排查咨询

Azure Firewall Policy规则集配置咨询

我需要配置包含最常用网络规则与应用规则的Azure Firewall Policy规则集,已经整理出如下Terraform配置代码,但不确定是否遗漏了某些常见必备规则,特此咨询:

resource "azurerm_firewall_policy_rule_collection_group" "fwpolrcg" {
  name               = "fwpolicy-rcg"
  firewall_policy_id = azurerm_firewall_policy.fwpol.id
  priority           = 100

  network_rule_collection {
    name     = "network_rule_collection1"
    priority = 100
    action   = "Allow"

    rule {
      name                  = "AllowHubToSpokeRDP"
      protocols             = ["TCP","UDP"]
      source_addresses      = var.hub_firewall_ip_range
      destination_addresses = var.spoke_firewall_ip_range
      destination_ports     = ["3389"]
    }

    rule {
      name                  = "AllowSpokeToHubRDP"
      protocols             = ["TCP","UDP"]
      source_addresses      = var.spoke_firewall_ip_range
      destination_addresses = var.hub_firewall_ip_range
      destination_ports     = ["3389"]
    }

    rule {
      name                  = "AllowHubToSpokeHTTPS"
      protocols             = ["TCP"]
      source_addresses      = var.hub_firewall_ip_range
      destination_addresses = var.spoke_firewall_ip_range
      destination_ports     = ["443"]
    } 

    rule {
      name                  = "AllowSpokeToHubHTTPS"
      protocols             = ["TCP"]
      source_addresses      = var.spoke_firewall_ip_range
      destination_addresses = var.hub_firewall_ip_range
      destination_ports     = ["443"]
    }

    rule {
      name                  = "AllowHubToSpokeDNS"
      protocols             = ["TCP","UDP"]
      source_addresses      = var.hub_firewall_ip_range
      destination_addresses = var.spoke_firewall_ip_range
      destination_ports     = ["53"]
    }

    rule {
      name                  = "AllowSpokeToHubDNS"
      protocols             = ["TCP","UDP"]
      source_addresses      = var.spoke_firewall_ip_range
      destination_addresses = var.hub_firewall_ip_range
      destination_ports     = ["53"]
    }
  }

  application_rule_collection {
    name     = "application_rule_collection1"
    priority = 100
    action   = "Allow"

  rule {
    name = "Windows Update"
    source_addresses = ["*"]
    fqdn_tags = [
      "AppServiceEnvironment", 
      "AzureBackup", 
      "AzureKubernetesService", 
      "HDInsight", 
      "MicrosoftActiveProtectionService", 
      "WindowsDiagnostics", 
      "WindowsUpdate",
      "WindowsVirtualDesktop"]
  }    

    rule {
      name             = "AllowMicrosoftFqdns"
      source_addresses = ["*"]

      destination_fqdns = [
        "*.cdn.mscr.io",
        "mcr.microsoft.com",
        "*.data.mcr.microsoft.com",
        "management.azure.com",
        "login.microsoftonline.com",
        "acs-mirror.azureedge.net",
        "dc.services.visualstudio.com",
        "*.opinsights.azure.com",
        "*.oms.opinsights.azure.com",
        "*.microsoftonline.com",
        "*.monitoring.azure.com",
      ]

      protocols {
        port = "80"
        type = "Http"
      }

      protocols {
        port = "443"
        type = "Https"
      }
    }

    rule {
      name             = "AllowFqdnsForOsUpdates"
      source_addresses = ["*"]

      destination_fqdns = [
        "download.opensuse.org",
        "security.ubuntu.com",
        "ntp.ubuntu.com",
        "packages.microsoft.com",
        "snapcraft.io"
      ]

      protocols {
        port = "80"
        type = "Http"
      }

      protocols {
        port = "443"
        type = "Https"
      }
    }
    
    rule {
      name             = "AllowImagesFqdns"
      source_addresses = ["*"]

      destination_fqdns = [
        "auth.docker.io",
        "registry-1.docker.io",
        "production.cloudflare.docker.com"
      ]

      protocols {
        port = "80"
        type = "Http"
      }

      protocols {
        port = "443"
        type = "Https"
      }
    }

    rule {
      name             = "AllowAzure"
      source_addresses = ["*"]

      destination_fqdns = [
        "*.azure.*"
      ]

      protocols {
        port = "80"
        type = "Http"
      }

      protocols {
        port = "443"
        type = "Https"
      }
    }
  }

  rule {
    name             = "AllowBing"
    source_addresses = ["*"]

    destination_fqdns = [
      "*.bing.com"
    ]

    protocols {
      port = "80"
      type = "Http"
    }

    protocols {
      port = "443"
      type = "Https"
    }
  }

  rule {
    name             = "AllowGoogle"
    source_addresses = ["*"]

    destination_fqdns = [
      "*.google.com"
    ]

    protocols {
      port = "80"
      type = "Http"
    }

    protocols {
      port = "443"
      type = "Https"
    }
  }  

  depends_on                = [azurerm_firewall_policy.fwpol]
}

现有代码问题与遗漏规则分析

先修正语法错误

代码末尾的AllowBing和AllowGoogle规则直接放在了资源根节点下,不属于任何application_rule_collection,这是语法错误,需将它们移动到application_rule_collection1内部。

网络规则补充

  • SSH访问规则:如果环境中有Linux虚拟机,需添加允许TCP 22端口的双向规则,和RDP规则对应,支持Hub与Spoke之间的SSH连通
  • NTP时间同步:添加允许UDP 123端口的规则,源为内部网段,目标可指定Azure时间服务(time.windows.com对应IP段或服务标签AzureTimeServices),确保系统时间同步
  • ICMP连通性测试:允许内部网段之间的ICMP流量(Ping),方便排查网络连通性问题
  • 出站公共DNS转发:如果内部DNS服务器需要转发到公共DNS(如8.8.8.8、1.1.1.1),需添加允许UDP/TCP 53端口到这些地址的规则
  • Azure服务标签规则:比如允许到AzureMonitor、AzureStorage的网络流量,提升Azure PaaS服务的访问效率

应用规则补充

  • 完善Linux更新源:当前AllowFqdnsForOsUpdates仅覆盖部分发行版,建议补充:
    • Debian/Ubuntu:deb.debian.org、archive.ubuntu.com
    • RHEL/CentOS:mirror.centos.org、registry.access.redhat.com
    • Docker相关:download.docker.com
  • Azure AD Graph API:将graph.microsoft.com加入AllowMicrosoftFqdns,很多Azure服务和企业应用依赖该API
  • 扩展容器镜像源:若使用其他镜像仓库,添加gcr.io、quay.io、ghcr.io等FQDN到镜像规则中
  • 缩小AllowAzure规则范围:当前*.azure.*过于宽泛,建议根据实际使用的Azure服务缩小范围,比如*.storage.azure.com、*.database.azure.com等,降低安全风险
  • 日志与存储访问:若需访问Azure存储账户的Blob或文件服务,添加对应FQDN(如*.blob.core.windows.net)
  • 安全工具相关FQDN:若使用第三方安全扫描、漏洞管理工具,添加对应FQDN规则,比如qualys.com、tenable.com等

其他建议

  • 规则优先级:将更具体的规则设置为更高优先级(数值更小),避免宽泛规则覆盖具体规则
  • 源地址限制:尽量避免使用*作为源地址,根据实际业务范围限制源地址段,提升安全性
  • 日志配置:确保Azure Firewall的日志配置正确,方便后续排查规则命中情况

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 01:30:29