{"id":2474,"date":"2022-02-19T14:39:53","date_gmt":"2022-02-19T14:39:53","guid":{"rendered":"https:\/\/exceedthecloud.com\/?p=2474"},"modified":"2022-02-19T14:44:44","modified_gmt":"2022-02-19T14:44:44","slug":"secure-your-virtual-hub-using-azure-firewall-manager","status":"publish","type":"post","link":"https:\/\/exceedthecloud.com\/?p=2474","title":{"rendered":"Secure your virtual hub using Azure Firewall Manager"},"content":{"rendered":"\n<p>In this lab, you will create the spoke virtual network and create a secured virtual hub, then you will connect the hub and spoke virtual networks and route traffic to your hub. Next you will deploy the workload servers, then create a firewall policy and secure your hub, and finally you will test the firewall.<\/p>\n\n\n\n<p><strong>Create a hub and spoke architecture<\/strong><\/p>\n\n\n\n<p>In this part of the lab, you will create the spoke virtual networks and subnets where you will place the workload servers. Then you will create the secured virtual hub and connect the hub and spoke virtual networks.<\/p>\n\n\n\n<p>In this lab, you will:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Task 1: Create two spoke virtual networks and subnets<\/li><li>Task 2: Create the secured virtual hub<\/li><li>Task 3: Connect the hub and spoke virtual networks<\/li><li>Task 4: Deploy the servers<\/li><li>Task 5: Create a firewall policy and secure your hub<\/li><li>Task 6: Associate the firewall policy<\/li><li>Task 7: Route traffic to your hub<\/li><li>Task 8: Test the application rule<\/li><li>Task 9: Test the network rule<\/li><\/ul>\n\n\n\n<p>Prerequisites for this labs :&nbsp;<a href=\"https:\/\/azure.microsoft.com\/en-us\/free\/\" target=\"_blank\" rel=\"noreferrer noopener\">Azure Account<\/a>&nbsp;\/&nbsp;<a href=\"https:\/\/github.com\/marcelin-ndjila\/Practical-Labs-Series\/blob\/master\/Azurelabs07.zip\" target=\"_blank\" rel=\"noreferrer noopener\">Download Labs Files here<\/a><\/p>\n\n\n\n<p><strong>Task 1: Create two spoke virtual networks and subnets<\/strong><\/p>\n\n\n\n<p>In this task, you will create the two spoke virtual networks each containing a subnet that will host your workload servers.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>On the Azure portal home page, in the search box, type <strong>virtual network<\/strong> and select <strong>Virtual Network<\/strong> when it appears.<\/li><li>Click <strong>Create<\/strong>.<\/li><li>In <strong>Resource group<\/strong>, select <strong>Create new<\/strong>, and enter <strong>fw-manager-rg<\/strong> as the name and click <strong>OK<\/strong>.<\/li><li>In <strong>Name<\/strong>, enter <strong>Spoke-01<\/strong>.<\/li><li>In <strong>Region<\/strong>, select your region.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"813\" height=\"482\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture1-8.png\" alt=\"\" class=\"wp-image-2475\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture1-8.png 813w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture1-8-300x178.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture1-8-768x455.png 768w\" sizes=\"auto, (max-width: 813px) 100vw, 813px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Click <strong>Next: IP Addresses<\/strong>.<\/li><li>In <strong>IPv4 address space<\/strong>, enter <strong>10.0.0.0\/16<\/strong>.<\/li><li><strong>Delete<\/strong> any other address spaces listed here, such as <strong>10.1.0.0\/16<\/strong>.<\/li><li>Under <strong>Subnet name<\/strong>, click the word <strong>default<\/strong>.<\/li><li>In the <strong>Edit subnet<\/strong> dialog box, change the name to <strong>Workload-01-SN<\/strong>.<\/li><li>Change the <strong>Subnet address range<\/strong> to <strong>10.0.1.0\/24<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"295\" height=\"528\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture2-8.png\" alt=\"\" class=\"wp-image-2476\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture2-8.png 295w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture2-8-168x300.png 168w\" sizes=\"auto, (max-width: 295px) 100vw, 295px\" \/><\/figure>\n\n\n\n<p>Click <strong>Save<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"857\" height=\"481\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture3-8.png\" alt=\"\" class=\"wp-image-2477\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture3-8.png 857w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture3-8-300x168.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture3-8-768x431.png 768w\" sizes=\"auto, (max-width: 857px) 100vw, 857px\" \/><\/figure>\n\n\n\n<p>Click <strong>Review + create<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"802\" height=\"476\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture4-8.png\" alt=\"\" class=\"wp-image-2478\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture4-8.png 802w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture4-8-300x178.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture4-8-768x456.png 768w\" sizes=\"auto, (max-width: 802px) 100vw, 802px\" \/><\/figure>\n\n\n\n<p>Click <strong>Create<\/strong>.<\/p>\n\n\n\n<p>Repeat steps 1 to 14 above to create another similar virtual network and subnet but using the following information:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Resource Group: <strong>fw-manager-rg<\/strong> (select existing)<\/li><li>Name: <strong>Spoke-02<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"852\" height=\"484\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture5-8.png\" alt=\"\" class=\"wp-image-2479\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture5-8.png 852w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture5-8-300x170.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture5-8-768x436.png 768w\" sizes=\"auto, (max-width: 852px) 100vw, 852px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Address space: <strong>10.1.0.0\/16<\/strong> &#8211; (delete any other listed address spaces)<\/li><li>Subnet name: <strong>Workload-02-SN<\/strong><\/li><li>Subnet address range: <strong>10.1.1.0\/24<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"288\" height=\"518\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture6-7.png\" alt=\"\" class=\"wp-image-2480\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture6-7.png 288w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture6-7-167x300.png 167w\" sizes=\"auto, (max-width: 288px) 100vw, 288px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"846\" height=\"474\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture7-7.png\" alt=\"\" class=\"wp-image-2481\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture7-7.png 846w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture7-7-300x168.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture7-7-768x430.png 768w\" sizes=\"auto, (max-width: 846px) 100vw, 846px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"803\" height=\"474\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture8-6.png\" alt=\"\" class=\"wp-image-2482\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture8-6.png 803w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture8-6-300x177.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture8-6-768x453.png 768w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/figure>\n\n\n\n<p><strong>Task 2: Create the secured virtual hub<\/strong><\/p>\n\n\n\n<p>In this task you will create your secured virtual hub using Firewall Manager.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>From the Azure portal home page, click <strong>All services<\/strong>.<\/li><li>In the search box, type <strong>firewall manager<\/strong> and select <strong>Firewall Manager<\/strong> when it appears.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"327\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture9-6-1024x327.png\" alt=\"\" class=\"wp-image-2483\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture9-6-1024x327.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture9-6-300x96.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture9-6-768x245.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture9-6.png 1129w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>On the <strong>Firewall Manager<\/strong> page, from the Overview page, click <strong>View secured virtual hubs<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"423\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture10-4-1024x423.png\" alt=\"\" class=\"wp-image-2484\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture10-4-1024x423.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture10-4-300x124.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture10-4-768x318.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture10-4.png 1139w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>On the <strong>Virtual hubs<\/strong> page, click <strong>Create new secured virtual hub<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"376\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture11-4-1024x376.png\" alt=\"\" class=\"wp-image-2485\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture11-4-1024x376.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture11-4-300x110.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture11-4-768x282.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture11-4.png 1118w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>For <strong>Resource group<\/strong>, select <strong>fw-manager-rg<\/strong>.<\/li><li>For <strong>Region<\/strong>, select your region.<\/li><li>For the <strong>Secured virtual hub name<\/strong>, enter <strong>Hub-01<\/strong>.<\/li><li>For <strong>Hub address space<\/strong>, enter <strong>10.2.0.0\/16<\/strong>.<\/li><li>Choose <strong>New vWAN<\/strong>.<\/li><li>In <strong>Virtual WAN Name<\/strong>, enter <strong>Vwan-01<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"816\" height=\"507\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture12-3.png\" alt=\"\" class=\"wp-image-2486\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture12-3.png 816w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture12-3-300x186.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture12-3-768x477.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture12-3-80x50.png 80w\" sizes=\"auto, (max-width: 816px) 100vw, 816px\" \/><\/figure>\n\n\n\n<p>Click <strong>Next: Azure Firewall<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"401\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture13-1-1024x401.png\" alt=\"\" class=\"wp-image-2487\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture13-1-1024x401.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture13-1-300x117.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture13-1-768x301.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture13-1.png 1293w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click <strong>Next: Security Partner Provider<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"977\" height=\"501\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture14-1.png\" alt=\"\" class=\"wp-image-2488\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture14-1.png 977w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture14-1-300x154.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture14-1-768x394.png 768w\" sizes=\"auto, (max-width: 977px) 100vw, 977px\" \/><\/figure>\n\n\n\n<p>Click <strong>Next: Review + create.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"837\" height=\"507\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture15-1.png\" alt=\"\" class=\"wp-image-2489\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture15-1.png 837w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture15-1-300x182.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture15-1-768x465.png 768w\" sizes=\"auto, (max-width: 837px) 100vw, 837px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Click <strong>Create<\/strong>.<\/li><\/ul>\n\n\n\n<p><strong>[!NOTE]<\/strong><\/p>\n\n\n\n<p>This can take up to 30 minutes to deploy.<\/p>\n\n\n\n<p>\u200b<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\" start=\"2\"><li>When the deployment completes, from the Azure portal home page, click <strong>All services<\/strong>.<\/li><li>In the search box, type <strong>firewall manager<\/strong> and select <strong>Firewall Manager<\/strong> when it appears.<\/li><li>On the <strong>Firewall Manager<\/strong> page, click <strong>Virtual hubs<\/strong>.<\/li><li>Click <strong>Hub-01<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"326\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture16-1-1024x326.png\" alt=\"\" class=\"wp-image-2490\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture16-1-1024x326.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture16-1-300x96.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture16-1-768x245.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture16-1.png 1299w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Click <strong>Public IP configuration<\/strong>.<\/li><li>Note down the public IP address (e.g., <strong>20.106.142.72<\/strong>), which you will use later.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"995\" height=\"412\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture17-1.png\" alt=\"\" class=\"wp-image-2491\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture17-1.png 995w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture17-1-300x124.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture17-1-768x318.png 768w\" sizes=\"auto, (max-width: 995px) 100vw, 995px\" \/><\/figure>\n\n\n\n<p><strong>Task 3: Connect the hub and spoke virtual networks<\/strong><\/p>\n\n\n\n<p>In this task you will connect the hub and spoke virtual networks. This is commonly known as peering.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>From the Azure portal home page, click <strong>Resource groups<\/strong>.<\/li><li>Select the <strong>fw-manager-rg<\/strong> resource group, then select the <strong>Vwan-01<\/strong> virtual WAN.<\/li><li>Under <strong>Connectivity<\/strong>, click <strong>Virtual network connections<\/strong>.<\/li><li>Click <strong>Add connection<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"327\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture18-1-1024x327.png\" alt=\"\" class=\"wp-image-2492\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture18-1-1024x327.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture18-1-300x96.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture18-1-768x245.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture18-1.png 1290w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>For <strong>Connection name<\/strong>, enter <strong>hub-spoke-01<\/strong>.<\/li><li>For <strong>Hubs<\/strong>, select <strong>Hub-01<\/strong>.<\/li><li>For <strong>Resource group<\/strong>, select <strong>fw-manager-rg<\/strong>.<\/li><li>For <strong>Virtual network<\/strong>, select <strong>Spoke-01<\/strong>.<\/li><li>Click <strong>Create<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"829\" height=\"520\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture19-1.png\" alt=\"\" class=\"wp-image-2493\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture19-1.png 829w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture19-1-300x188.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture19-1-768x482.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture19-1-80x50.png 80w\" sizes=\"auto, (max-width: 829px) 100vw, 829px\" \/><\/figure>\n\n\n\n<p>Repeat steps 4 to 9 above to create another similar connection but using the connection name of <strong>hub-spoke-02<\/strong> to connect the <strong>Spoke-02<\/strong> virtual network.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"823\" height=\"518\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture20-1.png\" alt=\"\" class=\"wp-image-2494\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture20-1.png 823w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture20-1-300x189.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture20-1-768x483.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture20-1-80x50.png 80w\" sizes=\"auto, (max-width: 823px) 100vw, 823px\" \/><\/figure>\n\n\n\n<p><strong>Task 4: Deploy the servers<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>In the Azure portal, open the <strong>PowerShell<\/strong> session within the <strong>Cloud Shell<\/strong> pane.<\/li><li>In the toolbar of the Cloud Shell pane, select the Upload\/Download files icon, in the drop-down menu, select Upload and upload the following files <strong>FirewallManager.json<\/strong> and <strong>FirewallManager.parameters.json<\/strong> into the Cloud Shell home directory from the source folder <strong>F:\\Allfiles\\Labs\\M06<\/strong>.<\/li><li>Deploy the following ARM templates to create the VM needed for this lab:<\/li><\/ol>\n\n\n\n<p>code<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$RGName = \"fw-manager-rg\"\n   \nNew-AzResourceGroupDeployment -ResourceGroupName $RGName -TemplateFile FirewallManager.json -TemplateParameterFile FirewallManager.parameters.json\n<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"215\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture21-1-1024x215.png\" alt=\"\" class=\"wp-image-2495\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture21-1-1024x215.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture21-1-300x63.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture21-1-768x162.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture21-1.png 1360w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>When the deployment is complete, go to the Azure portal home page, and then select <strong>Virtual Machines<\/strong>.<\/li><li>On the <strong>Overview<\/strong> page of <strong>Srv-workload-01<\/strong>, in the right-hand pane, under the <strong>Networking<\/strong> section, note down the <strong>Private IP address<\/strong> (e.g., <strong>10.0.1.4<\/strong>).<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"436\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture22-1-1024x436.png\" alt=\"\" class=\"wp-image-2496\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture22-1-1024x436.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture22-1-300x128.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture22-1-768x327.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture22-1.png 1192w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>On the <strong>Overview<\/strong> page of <strong>Srv-workload-02<\/strong>, in the right-hand pane, under the <strong>Networking<\/strong> section, note down the <strong>Private IP address<\/strong> (e.g., <strong>10.1.1.4<\/strong>).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"442\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture23-1-1024x442.png\" alt=\"\" class=\"wp-image-2497\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture23-1-1024x442.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture23-1-300x130.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture23-1-768x332.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture23-1.png 1193w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Task 5: Create a firewall policy and secure your hub<\/strong><\/p>\n\n\n\n<p>In this task you will first create your firewall policy, then secure your hub. The firewall policy will define collections of rules to direct traffic on one or more Secured virtual hubs.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>From the Azure portal home page, click <strong>Firewall Manager<\/strong>.<ul><li>If the Firewall Manager icon does not appear on the homepage, then click <strong>All services<\/strong>. Then in the search box, type <strong>firewall manager<\/strong> and select <strong>Firewall Manager<\/strong> when it appears.<\/li><\/ul><\/li><li>From <strong>Firewall Manager<\/strong>, from the Overview page, click <strong>View Azure Firewall Policies<\/strong>.<\/li><li>Click <strong>Create Azure Firewall Policy<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"327\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture24-1-1024x327.png\" alt=\"\" class=\"wp-image-2498\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture24-1-1024x327.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture24-1-300x96.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture24-1-768x245.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture24-1.png 1299w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>In <strong>Resource group<\/strong>, select <strong>fw-manager-rg<\/strong>.<\/li><li>Under <strong>Policy details<\/strong>, for the <strong>Name<\/strong>, enter <strong>Policy-01<\/strong>.<\/li><li>In <strong>Region<\/strong> select your region.<\/li><li>In <strong>Policy tier<\/strong>, select <strong>Standard<\/strong>.<\/li><li>Click <strong>Next : DNS Settings<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"400\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture25-1-1024x400.png\" alt=\"\" class=\"wp-image-2499\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture25-1-1024x400.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture25-1-300x117.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture25-1-768x300.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture25-1.png 1294w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click <strong>Next : TLS Inspection (preview)<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1005\" height=\"502\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture26-1.png\" alt=\"\" class=\"wp-image-2500\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture26-1.png 1005w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture26-1-300x150.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture26-1-768x384.png 768w\" sizes=\"auto, (max-width: 1005px) 100vw, 1005px\" \/><\/figure>\n\n\n\n<p>Click <strong>Next : Rules<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"957\" height=\"504\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture27-1.png\" alt=\"\" class=\"wp-image-2501\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture27-1.png 957w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture27-1-300x158.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture27-1-768x404.png 768w\" sizes=\"auto, (max-width: 957px) 100vw, 957px\" \/><\/figure>\n\n\n\n<p>On the <strong>Rules<\/strong> tab, click <strong>Add a rule collection<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"405\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture28-1-1024x405.png\" alt=\"\" class=\"wp-image-2502\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture28-1-1024x405.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture28-1-300x119.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture28-1-768x304.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture28-1.png 1292w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>On the <strong>Add a rule collection<\/strong> page, in <strong>Name<\/strong>, enter <strong>App-RC-01<\/strong>.<\/li><li>For <strong>Rule collection type<\/strong>, select <strong>Application<\/strong>.<\/li><li>For <strong>Priority<\/strong>, enter <strong>100<\/strong>.<\/li><li>Ensure <strong>Rule collection action<\/strong> is <strong>Allow<\/strong>.<\/li><li>Under <strong>Rules<\/strong>, in <strong>Name<\/strong> type <strong>Allow-msft<\/strong>.<\/li><li>For the <strong>Source type<\/strong>, select <strong>IP Address<\/strong>.<\/li><li>For <strong>Source<\/strong>, enter *.<\/li><li>For <strong>Protocol<\/strong>, enter <strong>http,https<\/strong>.<\/li><li>Ensure <strong>Destination type<\/strong> is <strong>FQDN<\/strong>.<\/li><li>For <strong>Destination<\/strong>, enter <strong>*.microsoft.com<\/strong>.<\/li><li>Click <strong>Add<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"482\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture29-1-1024x482.png\" alt=\"\" class=\"wp-image-2503\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture29-1-1024x482.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture29-1-300x141.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture29-1-768x361.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture29-1.png 1101w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>To add a DNAT rule so you can connect a remote desktop to the Srv-workload-01 VM, click <strong>Add a rule collection<\/strong>.<\/li><li>For <strong>Name<\/strong>, enter <strong>dnat-rdp<\/strong>.<\/li><li>For <strong>Rule collection type<\/strong>, select <strong>DNAT<\/strong>.<\/li><li>For <strong>Priority<\/strong>, enter <strong>100<\/strong>.<\/li><li>Under <strong>Rules<\/strong>, in <strong>Name<\/strong> enter <strong>Allow-rdp<\/strong>.<\/li><li>For the <strong>Source type<\/strong>, select <strong>IP Address<\/strong>.<\/li><li>For <strong>Source<\/strong>, enter *.<\/li><li>For <strong>Protocol<\/strong>, select <strong>TCP<\/strong>.<\/li><li>For <strong>Destination Ports<\/strong>, enter <strong>3389<\/strong>.<\/li><li>For <strong>Destination Type<\/strong>, select <strong>IP Address<\/strong>.<\/li><li>For <strong>Destination<\/strong>, enter the firewall virtual hub public IP address that you noted down earlier (e.g., <strong>51.143.226.18<\/strong>).<\/li><li>For <strong>Translated address<\/strong>, enter the private IP address for <strong>Srv-workload-01<\/strong> that you noted down earlier (e.g., <strong>10.0.1.4<\/strong>).<\/li><li>For <strong>Translated port<\/strong>, enter <strong>3389<\/strong>.<\/li><li>Click <strong>Add<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"480\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture30-1-1024x480.png\" alt=\"\" class=\"wp-image-2504\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture30-1-1024x480.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture30-1-300x141.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture30-1-768x360.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture30-1.png 1110w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>To add a Network rule so you can connect a remote desktop from Srv-workload-01 to Srv-workload-02 VM, click <strong>Add a rule collection<\/strong>.<\/li><li>For <strong>Name<\/strong>, enter <strong>vnet-rdp<\/strong>.<\/li><li>For <strong>Rule collection type<\/strong>, select <strong>Network<\/strong>.<\/li><li>For <strong>Priority<\/strong>, enter <strong>100<\/strong>.<\/li><li>For <strong>Rule collection action<\/strong>, select <strong>Allow<\/strong>.<\/li><li>Under <strong>Rules<\/strong>, in <strong>Name<\/strong> enter <strong>Allow-vnet<\/strong>.<\/li><li>For the <strong>Source type<\/strong>, select <strong>IP Address<\/strong>.<\/li><li>For <strong>Source<\/strong>, enter *.<\/li><li>For <strong>Protocol<\/strong>, select <strong>TCP<\/strong>.<\/li><li>For <strong>Destination Ports<\/strong>, enter <strong>3389<\/strong>.<\/li><li>For <strong>Destination Type<\/strong>, select <strong>IP Address<\/strong>.<\/li><li>For <strong>Destination<\/strong>, enter the private IP address for <strong>Srv-workload-02<\/strong> that you noted down earlier (e.g., <strong>10.1.1.4<\/strong>).<\/li><li>Click <strong>Add<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"477\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture31-1-1024x477.png\" alt=\"\" class=\"wp-image-2505\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture31-1-1024x477.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture31-1-300x140.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture31-1-768x358.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture31-1.png 1112w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>You should now have 3 rule collections listed.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"397\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture32-1-1024x397.png\" alt=\"\" class=\"wp-image-2506\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture32-1-1024x397.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture32-1-300x116.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture32-1-768x298.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture32-1.png 1305w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click <strong>Review + create<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"405\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture33-1-1024x405.png\" alt=\"\" class=\"wp-image-2507\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture33-1-1024x405.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture33-1-300x119.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture33-1-768x304.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture33-1.png 1290w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Click <strong>Create<\/strong>.<\/p>\n\n\n\n<p><strong>Task 6: Associate the firewall policy<\/strong><\/p>\n\n\n\n<p>In this task you will associate the firewall policy with the virtual hub.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>From the Azure portal home page, click <strong>Firewall Manager<\/strong>.<ul><li>If the Firewall Manager icon does not appear on the homepage, then click <strong>All services<\/strong>. Then in the search box, type <strong>firewall manager<\/strong> and select <strong>Firewall Manager<\/strong> when it appears.<\/li><\/ul><\/li><li>In <strong>Firewall Manager<\/strong>, under <strong>Security<\/strong>, click <strong>Azure Firewall Policies<\/strong>.<\/li><li>Select the checkbox for <strong>Policy-01<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"319\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture34-1-1024x319.png\" alt=\"\" class=\"wp-image-2508\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture34-1-1024x319.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture34-1-300x93.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture34-1-768x239.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture34-1.png 1302w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Select <strong>Manage associations&gt;Associate hubs<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"328\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture35-1-1024x328.png\" alt=\"\" class=\"wp-image-2509\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture35-1-1024x328.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture35-1-300x96.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture35-1-768x246.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture35-1.png 1304w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Select the checkbox for <strong>Hub-01<\/strong>.<\/li><li>Click <strong>Add<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"485\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture37-1-1024x485.png\" alt=\"\" class=\"wp-image-2510\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture37-1-1024x485.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture37-1-300x142.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture37-1-768x364.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture37-1.png 1094w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When the policy has been attached, click <strong>Refresh<\/strong>. The association should be displayed.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"313\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture38-1-1024x313.png\" alt=\"\" class=\"wp-image-2511\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture38-1-1024x313.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture38-1-300x92.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture38-1-768x235.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture38-1.png 1302w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Task 7: Route traffic to your hub<\/strong><\/p>\n\n\n\n<p>In this task you will ensure that network traffic gets routed through your firewall.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>In <strong>Firewall Manager<\/strong>, click <strong>Virtual hubs<\/strong>.<\/li><li>Click <strong>Hub-01<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"315\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture39-1-1024x315.png\" alt=\"\" class=\"wp-image-2512\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture39-1-1024x315.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture39-1-300x92.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture39-1-768x236.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture39-1.png 1299w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Under <strong>Settings<\/strong>, click <strong>Security configuration<\/strong>.<\/li><li>In <strong>Internet traffic<\/strong>, select <strong>Azure Firewall<\/strong>.<\/li><li>In <strong>Private traffic<\/strong>, select <strong>Send via Azure Firewall<\/strong>.<\/li><li>Click <strong>Save<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"386\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture40-1-1024x386.png\" alt=\"\" class=\"wp-image-2513\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture40-1-1024x386.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture40-1-300x113.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture40-1-768x289.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture40-1.png 1296w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>This will take a few minutes to complete.<\/li><li>Once configuration has completed, ensure that under <strong>INTERNET TRAFFIC<\/strong> and <strong>PRIVATE TRAFFIC<\/strong>, it says <strong>Secured by Azure Firewall<\/strong> for both hub-spoke connections.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"392\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture41-1-1024x392.png\" alt=\"\" class=\"wp-image-2514\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture41-1-1024x392.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture41-1-300x115.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture41-1-768x294.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture41-1.png 1297w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><strong>Task 8: Test the application rule<\/strong><\/p>\n\n\n\n<p>In this part of the lab, you will connect a remote desktop to the firewall public IP address, which is NATed to Srv-Workload-01. You will then use a web browser to test the application rule and connect a remote desktop to Srv-Workload-02 to test the network rule.<\/p>\n\n\n\n<p>In this task you will test the application rule to confirm that it works as expected.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Open <strong>Remote Desktop Connection<\/strong> on your PC.<\/li><li>In the <strong>Computer<\/strong> box, enter the <strong>firewall\u2019s public IP address<\/strong> (e.g., <strong>20.106.142.72<\/strong>).<\/li><li>Click <strong>Show Options<\/strong>.<\/li><li>In the <strong>Username<\/strong> box, enter <strong>TestUser<\/strong>.<\/li><li>Click <strong>Connect<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"402\" height=\"471\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture42-1.png\" alt=\"\" class=\"wp-image-2515\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture42-1.png 402w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture42-1-256x300.png 256w\" sizes=\"auto, (max-width: 402px) 100vw, 402px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>In the <strong>Enter your credentials<\/strong> dialog box, log into the <strong>Srv-workload-01<\/strong> server virtual machine, by using the password, <strong>TestPa$$w0rd!<\/strong>.<\/li><li>Click <strong>OK<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"452\" height=\"334\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture43-1.png\" alt=\"\" class=\"wp-image-2516\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture43-1.png 452w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture43-1-300x222.png 300w\" sizes=\"auto, (max-width: 452px) 100vw, 452px\" \/><\/figure>\n\n\n\n<p>Click <strong>Yes<\/strong> on the certificate message.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"388\" height=\"399\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture44.png\" alt=\"\" class=\"wp-image-2517\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture44.png 388w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture44-292x300.png 292w\" sizes=\"auto, (max-width: 388px) 100vw, 388px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>Open Internet Explorer and click <strong>OK<\/strong> in the <strong>Set up Internet Explorer 11<\/strong> dialog box.<\/li><li>Browse to <strong>https:\/\/www.microsoft.com<\/strong>.<\/li><li>In the <strong>Security Alert<\/strong> dialog box, click <strong>OK<\/strong>.<\/li><li>Click <strong>Close<\/strong> on the Internet Explorer security alerts that may pop-up.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"660\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture45-1024x660.png\" alt=\"\" class=\"wp-image-2518\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture45-1024x660.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture45-300x193.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture45-768x495.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture45.png 1074w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>You should see the Microsoft home page.<\/li><li>Browse to <strong>https:\/\/<\/strong> <strong>www.google.com<\/strong>.<\/li><li>You should be blocked by the firewall.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"648\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture46-1024x648.png\" alt=\"\" class=\"wp-image-2519\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture46-1024x648.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture46-300x190.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture46-768x486.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture46-80x50.png 80w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture46.png 1114w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>So, you have verified that you can connect to the one allowed FQDN but are blocked from all others.<\/li><\/ol>\n\n\n\n<p><strong>Task 9: Test the network rule<\/strong><\/p>\n\n\n\n<p>In this task you will test the network rule to confirm that it works as expected.<\/p>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>While still logged in to the <strong>Srv-workload-01<\/strong> RDP session, from this remote computer, open <strong>Remote Desktop Connection<\/strong>.<\/li><li>In the <strong>Computer<\/strong> box, enter the <strong>private IP address<\/strong> of <strong>Srv-workload-02<\/strong> (e.g., <strong>10.1.1.4<\/strong>).<\/li><li>In the <strong>Enter your credentials<\/strong> dialog box, log in to the <strong>Srv-workload-02<\/strong> server by using the username <strong>TestUser<\/strong>, and a password of <strong>TestPa$$w0rd!<\/strong>.<\/li><li>Click <strong>OK<\/strong>.<\/li><li>Click <strong>Yes<\/strong> on the certificate message.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"590\" src=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture47-1024x590.png\" alt=\"\" class=\"wp-image-2520\" srcset=\"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture47-1024x590.png 1024w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture47-300x173.png 300w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture47-768x443.png 768w, https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/picture47.png 1227w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\" type=\"1\"><li>So, now you have verified that the firewall network rule is working, as you have connected a remote desktop from one server to another server located in another virtual network.<\/li><li>Close both RDP sessions to disconnect them.<\/li><\/ul>\n\n\n\n<p>Congratulations! You have configured, tested and secure your virtual hub via Azure Firewall Manager.<\/p>\n\n\n\n<p><mark class=\"kt-highlight\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-virtue-primary-color\">Reminder: Don&#8217;t forget to delete or shutdown all unused Azure resources after your labs for cost saving<\/mark><\/mark><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this lab, you will create the spoke virtual network and create a secured virtual hub, then you will connect the hub and spoke virtual networks and route traffic to your hub. Next you will deploy the workload servers, then &hellip; <a href=\"https:\/\/exceedthecloud.com\/?p=2474\">Continued<\/a><\/p>\n","protected":false},"author":1,"featured_media":2525,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"kt_blocks_editor_width":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[17,4,18,19],"tags":[28,95,97,42,31],"class_list":["post-2474","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-networking","category-practical-labs-series","category-security","category-virtual-machines","tag-azure-network","tag-firewall","tag-policy","tag-virtual-hub","tag-virtual-network"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/exceedthecloud.com\/wp-content\/uploads\/2022\/02\/istockphoto-115949110-612x612-1.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts\/2474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2474"}],"version-history":[{"count":3,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts\/2474\/revisions"}],"predecessor-version":[{"id":2524,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/posts\/2474\/revisions\/2524"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=\/wp\/v2\/media\/2525"}],"wp:attachment":[{"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exceedthecloud.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}