Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Azure Firewall Setup

    Scheduled Pinned Locked Moved Virtualization
    14 Posts 3 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      I don't think you can do that.

      I would put one on the same subnet as the LAN interface and try changing the 0.0.0.0/0 route on that and see if you at least can get a normal, natted LAN connection going.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • T
        twistedstorm
        last edited by

        So attempt Lan and Wan on same subnet add the 0.0.0.0/0 and see if a NAT connection can be had. I'm no expert at networking could it be possible that 1:1 natting could be used to allow the use of the azure front facing public ips? How do we have two port 80's on one IP? We have a few front end applications we'd like to protect but they share several of the same ports currently we are doing this with NSG's.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          That can be done if:

          1. Azure will route public addresses to the public address of pfSense. In this case you might be able to just use the publics as they are.

          2. Azure will allow multiple public addresses on the WAN interface.

          https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-multiple-ip-addresses-powershell

          You might be able to get away with one outside address for multiple inside servers by using something like HAproxy to steer the traffic to the correct server based on requested hostname or SNI.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • T
            twistedstorm
            last edited by

            Any idea when I route 0.0.0.0/0 to the appliance i lose all communication to the vm's on the lan subnet?

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Did you try it like I suggested with an interface on the LAN subnet + NAT instead of those publics?

              Azure has zero way of knowing it needs to route those inside publics to the pfSense WAN. If it is going to be possible, that needs to happen.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • T
                twistedstorm
                last edited by

                I'm a little confused. Interface on the Lan subnet? what exactly would you like me to do with the interfaces and routes. Currently I have two interfaces in the system.
                Wan = 10.0.3.5 and Lan 10.0.2.4

                In azure I have to virtual subnets 10.0.3.0/24 and 10.0.2.0/24
                Nat set to manual
                allow all on the lan and wan for testing

                been going at this 10/hrs a day since saturday I'll try anything at this point to get it working. Never was this hard to install pfsense locally :)

                Help greatly appreciated

                ![Effective Routes.png](/public/imported_attachments/1/Effective Routes.png)
                ![Effective Routes.png_thumb](/public/imported_attachments/1/Effective Routes.png_thumb)
                nat.png
                nat.png_thumb
                pfsenseinterfaces.png
                pfsenseinterfaces.png_thumb
                subnets.png
                subnets.png_thumb
                routes.png
                routes.png_thumb

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  In azure I have to virtual subnets 10.0.3.0/24 and 10.0.2.0/24

                  Looks like that LAN interface is 10.0.2.4/32 to me.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • T
                    twistedstorm
                    last edited by

                    updated the LAN interface to /24 and removed the old NAT entries this is what I have now not even seeing the attempts to connect on the firewall log.

                    laninterfaceupdated.png
                    laninterfaceupdated.png_thumb
                    natupdated.png
                    natupdated.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • T
                      twistedstorm
                      last edited by

                      Another interesting thing is I can ping from the LAN IP but never can I get connected to or ping the systems in the LAN subnet.

                      pingfromlan.png
                      pingfromlan.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • C
                        ChrisT
                        last edited by

                        Was this ever worked? I am in a similar situation...

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.