简体   繁体   中英

Can I counfigure outbound rule in Azure VM using domain name?

Can I counfigure outbound rule in Azure VM using domain name? given that this domain name could be resolved to an IP in a certain range of IPs. Moreover, this range changes from time to time.

The short answer is yes, you can configure security rules using Azure Firewall but not with Azure Network Security Group (which is the standard, basic firewall for VMs).

DNS is a protocol that operates in the application layer of the OSI model, whereas Azure Network Security group operates in the network and transport layer. Therefore it can't inspect the DNS used for the inbound/outbound communication.

Azure Firewall operates in the application layer too, so you can use it to create DNS based security rules.

See more information here https://social.technet.microsoft.com/wiki/contents/articles/53658.azure-security-firewall-vs-nsg.aspx

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM