question

SAPAzure-7452 avatar image
0 Votes"
SAPAzure-7452 asked ChaitanyaNaykodiMSFT-9638 answered

Internet Traffic Flow for Web App Server in multi region and placement of Azure Traffic manager & NVA & App Gateway

Hello All,
I`m trying to implement Traffic Manager, application gateway and Palo Alto Firewall. However, not sure what Is the right flow after Traffic Manager i.e.

I have NVA firewall in region 1 only and no firewall in region 2. App service and DB implemented in both regions

Example: Accessing a Web Server via Internet through Traffic Manager

Internet ---->Traffic Manager (using performance routing between 2 regions)----> Azure App Gateway - WAF ----> Target App Service

is it possible to protect the traffic with NVA firewall also or no need, what is the recommended design and traffic flow? and where to add Azure CDN?


azure-application-gatewayazure-load-balancerazure-traffic-manager
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

ChaitanyaNaykodiMSFT-9638 avatar image
0 Votes"
ChaitanyaNaykodiMSFT-9638 answered

Hello @SAPAzure-7452, Thank you for reaching out.

Yes it is possible to protect traffic with NVA firewall as you can redirect all traffic through it using static routes/ User Defined routes. You can refer to this architecture for implementing highly available NVAs in Azure.
Azure Azure App Gateway - WAF provides these benefits, at application layer and is highly recommended for web workloads. Regarding implementing a Firewall along with a WAF you can refer to this document which describes the benefits of implementing both and in what order. Additionally you can also follow this best practices doc for NVA deployment.

As both Azure Traffic manager and Azure CDN come under Application delivery services of Azure Networking. You can go through this document to understand the benefits of using them together.

Please let me if have any additional questions or concerns, I will be glad to continue with our discussion. Thank you!


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.