NSG - Network security group - How to block traffic

Amol Admin account 11 Reputation points
2024-03-01T14:36:43.05+00:00

Hi,

I have a virtual network and subnet 10.185.23.0/24 in it.

There is VM with IP 10.185.23.4.

We have domain controllers in seperate Vnet and subnet 10.185.4.0/26.

I want to block any outgoing traffic towards one of the domain controller 10.185.4.7 from this VM (23.4). For testing using rule for 1 domain controller for now.

Created NSG as below.

inbound

outbound

However i can still do connect on port 53 from test VM to 10.185.4.7. Also Network Watcher shows connectivity Successful. Somehow i am not able to overwrite allvnetoutbound rule which maybe causing all traffic to allow. i read multiple articles but not any is clear on stateless or stateful and how to achive this.

Our goal is to isolate this subnet from reaching to domain controllers.

Office
Office
A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.
1,321 questions
Microsoft Teams
Microsoft Teams
A Microsoft customizable chat-based workspace.
9,135 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
574 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,168 questions
Azure Network Watcher
Azure Network Watcher
An Azure service that is used to monitor, diagnose, and gain insights into network performance and health.
159 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Amol Admin account 11 Reputation points
    2024-03-02T07:49:24.6366667+00:00

    Thanks TP for your help. Really appreciate. See our architecture is hub and spoke. hub is transit vnet where we have azure firewall. so next hop for all vnets in configured as AZ FW using routing table.

    Also, i built new test VM in same subnet for testing today. same result. see screens of network watcher and our architecture. nw2

    nw3

    simplear

    nw1