Azure防火墙策略规则集配置:常用规则遗漏排查咨询
Azure Firewall Policy规则集配置咨询
我需要配置包含最常用网络规则与应用规则的Azure Firewall Policy规则集,已经整理出如下Terraform配置代码,但不确定是否遗漏了某些常见必备规则,特此咨询:
resource "azurerm_firewall_policy_rule_collection_group" "fwpolrcg" { name = "fwpolicy-rcg" firewall_policy_id = azurerm_firewall_policy.fwpol.id priority = 100 network_rule_collection { name = "network_rule_collection1" priority = 100 action = "Allow" rule { name = "AllowHubToSpokeRDP" protocols = ["TCP","UDP"] source_addresses = var.hub_firewall_ip_range destination_addresses = var.spoke_firewall_ip_range destination_ports = ["3389"] } rule { name = "AllowSpokeToHubRDP" protocols = ["TCP","UDP"] source_addresses = var.spoke_firewall_ip_range destination_addresses = var.hub_firewall_ip_range destination_ports = ["3389"] } rule { name = "AllowHubToSpokeHTTPS" protocols = ["TCP"] source_addresses = var.hub_firewall_ip_range destination_addresses = var.spoke_firewall_ip_range destination_ports = ["443"] } rule { name = "AllowSpokeToHubHTTPS" protocols = ["TCP"] source_addresses = var.spoke_firewall_ip_range destination_addresses = var.hub_firewall_ip_range destination_ports = ["443"] } rule { name = "AllowHubToSpokeDNS" protocols = ["TCP","UDP"] source_addresses = var.hub_firewall_ip_range destination_addresses = var.spoke_firewall_ip_range destination_ports = ["53"] } rule { name = "AllowSpokeToHubDNS" protocols = ["TCP","UDP"] source_addresses = var.spoke_firewall_ip_range destination_addresses = var.hub_firewall_ip_range destination_ports = ["53"] } } application_rule_collection { name = "application_rule_collection1" priority = 100 action = "Allow" rule { name = "Windows Update" source_addresses = ["*"] fqdn_tags = [ "AppServiceEnvironment", "AzureBackup", "AzureKubernetesService", "HDInsight", "MicrosoftActiveProtectionService", "WindowsDiagnostics", "WindowsUpdate", "WindowsVirtualDesktop"] } rule { name = "AllowMicrosoftFqdns" source_addresses = ["*"] destination_fqdns = [ "*.cdn.mscr.io", "mcr.microsoft.com", "*.data.mcr.microsoft.com", "management.azure.com", "login.microsoftonline.com", "acs-mirror.azureedge.net", "dc.services.visualstudio.com", "*.opinsights.azure.com", "*.oms.opinsights.azure.com", "*.microsoftonline.com", "*.monitoring.azure.com", ] protocols { port = "80" type = "Http" } protocols { port = "443" type = "Https" } } rule { name = "AllowFqdnsForOsUpdates" source_addresses = ["*"] destination_fqdns = [ "download.opensuse.org", "security.ubuntu.com", "ntp.ubuntu.com", "packages.microsoft.com", "snapcraft.io" ] protocols { port = "80" type = "Http" } protocols { port = "443" type = "Https" } } rule { name = "AllowImagesFqdns" source_addresses = ["*"] destination_fqdns = [ "auth.docker.io", "registry-1.docker.io", "production.cloudflare.docker.com" ] protocols { port = "80" type = "Http" } protocols { port = "443" type = "Https" } } rule { name = "AllowAzure" source_addresses = ["*"] destination_fqdns = [ "*.azure.*" ] protocols { port = "80" type = "Http" } protocols { port = "443" type = "Https" } } } rule { name = "AllowBing" source_addresses = ["*"] destination_fqdns = [ "*.bing.com" ] protocols { port = "80" type = "Http" } protocols { port = "443" type = "Https" } } rule { name = "AllowGoogle" source_addresses = ["*"] destination_fqdns = [ "*.google.com" ] protocols { port = "80" type = "Http" } protocols { port = "443" type = "Https" } } depends_on = [azurerm_firewall_policy.fwpol] }
现有代码问题与遗漏规则分析
先修正语法错误
代码末尾的AllowBing和AllowGoogle规则直接放在了资源根节点下,不属于任何application_rule_collection,这是语法错误,需将它们移动到application_rule_collection1内部。
网络规则补充
- SSH访问规则:如果环境中有Linux虚拟机,需添加允许TCP 22端口的双向规则,和RDP规则对应,支持Hub与Spoke之间的SSH连通
- NTP时间同步:添加允许UDP 123端口的规则,源为内部网段,目标可指定Azure时间服务(
time.windows.com对应IP段或服务标签AzureTimeServices),确保系统时间同步 - ICMP连通性测试:允许内部网段之间的ICMP流量(Ping),方便排查网络连通性问题
- 出站公共DNS转发:如果内部DNS服务器需要转发到公共DNS(如8.8.8.8、1.1.1.1),需添加允许UDP/TCP 53端口到这些地址的规则
- Azure服务标签规则:比如允许到
AzureMonitor、AzureStorage的网络流量,提升Azure PaaS服务的访问效率
应用规则补充
- 完善Linux更新源:当前
AllowFqdnsForOsUpdates仅覆盖部分发行版,建议补充:- Debian/Ubuntu:
deb.debian.org、archive.ubuntu.com - RHEL/CentOS:
mirror.centos.org、registry.access.redhat.com - Docker相关:
download.docker.com
- Debian/Ubuntu:
- Azure AD Graph API:将
graph.microsoft.com加入AllowMicrosoftFqdns,很多Azure服务和企业应用依赖该API - 扩展容器镜像源:若使用其他镜像仓库,添加
gcr.io、quay.io、ghcr.io等FQDN到镜像规则中 - 缩小
AllowAzure规则范围:当前*.azure.*过于宽泛,建议根据实际使用的Azure服务缩小范围,比如*.storage.azure.com、*.database.azure.com等,降低安全风险 - 日志与存储访问:若需访问Azure存储账户的Blob或文件服务,添加对应FQDN(如
*.blob.core.windows.net) - 安全工具相关FQDN:若使用第三方安全扫描、漏洞管理工具,添加对应FQDN规则,比如
qualys.com、tenable.com等
其他建议
- 规则优先级:将更具体的规则设置为更高优先级(数值更小),避免宽泛规则覆盖具体规则
- 源地址限制:尽量避免使用
*作为源地址,根据实际业务范围限制源地址段,提升安全性 - 日志配置:确保Azure Firewall的日志配置正确,方便后续排查规则命中情况
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

