Secure Network Traffic with NSGs and Azure Firewall
Pluralsight Hands-On Lab — Security
At a Glance
| Platform | Pluralsight |
| Category | Azure Networking & Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Windows VM via Azure Bastion, Log Analytics, KQL |
| Completed | 2026 |
Overview
Network Security Groups and Azure Firewall serve complementary roles in securing Azure network traffic — NSGs control access at the network interface and subnet level, while Azure Firewall provides centralized, application-layer filtering with FQDN-based rules. In this lab, I built a layered network security architecture: an NSG to restrict inbound access to RDP only, an Azure Firewall with application rule collections to explicitly allow GitHub and deny Facebook, a route table to force all VM egress through the firewall, and a Log Analytics workspace to capture and query firewall activity logs using KQL.
What I Did
- Created an NSG (Server-NSG) with a single inbound rule allowing TCP port 3389 from any source at priority 100, and attached it to the Windows Server VM's network interface
- Created two dedicated subnets on the virtual network — one for Azure Firewall and one for Firewall Management (forced tunneling)
- Deployed Azure Firewall (Standard SKU, classic rules mode) with a new public IP and management public IP, and recorded the firewall's private IP
- Created an Allow application rule collection (priority 100) permitting HTTP and HTTPS traffic to github.com and related GitHub domains
- Created a Deny application rule collection (priority 200) blocking HTTP and HTTPS traffic to facebook.com and related Facebook domains
- Created a route table (rt-firewall-egress) with a default route (0.0.0.0/0) pointing to the firewall's private IP as a virtual appliance, and associated it with the VM subnet to force all egress through the firewall
- Created a Log Analytics workspace (Lab-Logs) and attached it to the firewall via a diagnostic setting sending all logs to the workspace using resource-specific destination tables
- Connected to the Windows VM via Azure Bastion, browsed to github.com (allowed) and facebook.com (blocked), then queried firewall logs in Log Analytics using KQL to confirm both allow and deny events were recorded:
AZFWApplicationRule
| where Fqdn has_any ("github", "facebook")
| project TimeGenerated, SourceIp, Fqdn, Action, RuleCollection, Rule
| sort by TimeGenerated desc
← Back to Pluralsight Labs