You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/firewall/ip-groups.md
+28-29Lines changed: 28 additions & 29 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,12 +1,11 @@
1
1
---
2
-
title: IP Groups in Azure Firewall
2
+
title: IP Groups in Azure Firewall
3
3
description: IP groups allow you to group and manage IP addresses for Azure Firewall rules.
4
-
services: firewall
5
4
author: duau
5
+
ms.author: duau
6
6
ms.service: azure-firewall
7
7
ms.topic: concept-article
8
-
ms.date: 02/10/2025
9
-
ms.author: duau
8
+
ms.date: 03/28/2026
10
9
ms.custom:
11
10
- devx-track-azurepowershell
12
11
- sfi-image-nochange
@@ -15,16 +14,16 @@ ms.custom:
15
14
16
15
# IP Groups in Azure Firewall
17
16
18
-
IP Groups allow you to group and manage IP addresses for Azure Firewall rules in the following ways:
17
+
IP Groups make it easy to group and manage IP addresses for Azure Firewall rules. Use IP Groups in the following ways:
19
18
20
19
- As a source address in DNAT rules
21
20
- As a source or destination address in network rules
22
21
- As a source address in application rules
23
22
24
23
25
-
An IP Group can have a single IP address, multiple IP addresses, one or more IP address ranges or addresses and ranges in combination.
24
+
An IP Group can include a single IP address, multiple IP addresses, one or more IP address ranges, or a combination of addresses and ranges.
26
25
27
-
IP Groups can be reused in Azure Firewall DNAT, network, and application rules for multiple firewalls across regions and subscriptions in Azure. Group names must be unique. You can configure an IP Group in the Azure portal, Azure CLI, or REST API. A sample template is provided to help you get started.
26
+
You can use IP Groups in Azure Firewall DNAT, network, and application rules for multiple firewalls across regions and subscriptions in Azure. Group names must be unique. You can configure an IP Group in the Azure portal, Azure CLI, or REST API. A sample template is provided to help you get started.
28
27
29
28
## Sample format
30
29
@@ -36,63 +35,63 @@ The following IPv4 address format examples are valid to use in IP Groups:
36
35
37
36
## Create an IP Group
38
37
39
-
An IP Group can be created using the Azure portal, Azure CLI, or REST API. For more information, see [Create an IP Group](create-ip-group.md).
38
+
Create an IP Group by using the Azure portal, Azure CLI, or REST API. For more information, see [Create an IP Group](create-ip-group.md).
40
39
41
40
## Browse IP Groups
42
-
1. In the Azure portal search bar, type **IP Groups** and select it. You can see the list of the IP Groups, or you can select **Add** to create a new IP Group.
41
+
1. In the Azure portal search bar, type `IP Groups` and select it. You can see the list of IP Groups, or you can select **Add** to create a new IP Group.
43
42
1. Select an IP Group to open the overview page. You can edit, add, or delete IP addresses or IP Groups.
44
43
45
44
46
45
## Manage an IP Group
47
46
48
-
You can see all the IP addresses in the IP Group and the rules or resources that are associated with it. To delete an IP Group, you must first dissociate the IP Group from the resource that is using it.
47
+
You can see all the IP addresses in the IP Group and the rules or resources that are associated with it. To delete an IP Group, you must first dissociate the IP Group from the resource that uses it.
49
48
50
-
1. To view or edit the IP addresses, select **IP Addresses** under **Settings**on the left pane.
51
-
1. To add a single or multiple IP address(es), select **Add IP Addresses**. This opens the **Drag or Browse** page for an upload, or you can enter the address manually.
52
-
1. Selecting the ellipses (**…**) to the right to edit or delete IP addresses. To edit or delete multiple IP addresses, select the boxes and select **Edit** or **Delete** at the top.
53
-
1. Finally, can export the file in the CSV file format.
49
+
1. To view or edit the IP addresses, select **IP Addresses** under **Settings**in the left pane.
50
+
1. To add single or multiple IP addresses, select **Add IP Addresses**. This action opens the **Drag or Browse** page for an upload, or you can enter the address manually.
51
+
1.Select the ellipses (**…**) to the right to edit or delete IP addresses. To edit or delete multiple IP addresses, select the check boxes and select **Edit** or **Delete** at the top.
52
+
1. Finally, you can export the file in the CSV file format.
54
53
55
54
> [!NOTE]
56
-
> If you delete all the IP addresses in an IP Group while it is still in use in a rule, that rule is skipped.
55
+
> If you delete all the IP addresses in an IP Group but the IP Group is still in use in a rule, that rule is skipped.
57
56
58
57
59
58
## Use an IP Group
60
59
61
-
You can now select **IP Group** as a **Source type** or **Destination type** for the IP address(es) when you create Azure Firewall DNAT, application, or network rules.
60
+
Select **IP Group** as a **Source type** or **Destination type** for the IP addresses when you create Azure Firewall DNAT, application, or network rules.
62
61
63
62
## Parallel IP Group updates
64
63
65
-
You can now update multiple IP Groups in parallel at the same time. This is particularly useful for environments requiring faster changes at scale, especially when making those changes using a dev ops approach (templates, ARM, CLI, and Azure PowerShell).
64
+
You can update multiple IP Groups in parallel at the same time. This feature is particularly useful for environments that require faster changes at scale, especially when you make those changes by using a dev ops approach (templates, ARM, CLI, and Azure PowerShell).
66
65
67
-
With this support, you can perform the following:
66
+
By using this feature, you can:
68
67
69
-
-**Update 20 IP Groups at a time:** Perform simultaneous updates up to 20 IP Groups in one operation, referenced by firewall policy or classic firewall.
70
-
-**Update Azure Firewall and IP Groups together:**You can update IP Groups simultaneously with the firewall or with firewall policies.
71
-
-**Improved efficiency:** Parallel IP Group updates now run twice as fast.
68
+
-**Update 20 IP Groups at a time:** Perform simultaneous updates for up to 20 IP Groups in one operation, referenced by firewall policy or classic firewall.
69
+
-**Update Azure Firewall and IP Groups together:**Update IP Groups simultaneously with the firewall or with firewall policies.
70
+
-**Improved efficiency:** Parallel IP Group updates now run twice as fast.
72
71
-**Receive new and improved error messages:**
73
72
74
73
|Error message |Description |Recommended action|
75
74
|---------|---------|---------|
76
-
|**In failed state (skipping update)**|Azure Firewall or Firewall Policy is in a failed state. Updates cannot proceed until the resource is healthy. |Review previous operations and correct any misconfigurations to ensure the resource is healthy.|
75
+
|**In failed state (skipping update)**|Azure Firewall or Firewall Policy is in a failed state. Updates can't proceed until the resource is healthy. |Review previous operations and correct any misconfigurations to ensure the resource is healthy.|
77
76
|**Backend server could not update Firewall at this time**| The backend server was unable to successfully process the request.| Create a support request.|
78
77
|**Error occurred during FW update**| The error is related to the underlying backend servers.| Retry the operation or create a support request if the issue persists.|
79
-
|**Internal server error**| An unexpected backend error has occurred. | Retry the operation or create a support request.|
80
-
81
-
Additionally, note the following status updates:
82
-
-**One or more IP Group failure:** If one IP Group update (out of 20 parallel updates) fails, the provisioning state changes to "Failed" while the remaining IP Groups will continue to update and succeed.
83
-
-**Status update:** If an IP Group update fails, and if the firewall remains healthy, its state will still show as "Succeeded." To verify, check the status on the IP Group resource itself.
78
+
|**Internal server error**| An unexpected backend error occurred. | Retry the operation or create a support request.|
79
+
80
+
Also, note the following status updates:
81
+
-**One or more IP Group failure:** If one IP Group update (out of 20 parallel updates) fails, the provisioning state changes to "Failed" while the remaining IP Groups continue to update and succeed.
82
+
-**Status update:** If an IP Group update fails, and if the firewall remains healthy, its state still shows as "Succeeded." To verify, check the status on the IP Group resource itself.
84
83
85
84
## Region availability
86
85
87
86
IP Groups are available in all public cloud regions.
88
87
89
88
## IP address limits
90
89
91
-
For IP Group limits, see [Azure subscription and service limits, quotas, and constraints](../azure-resource-manager/management/azure-subscription-service-limits.md#azure-firewall-limits)
90
+
For IP Group limits, see [Azure subscription and service limits, quotas, and constraints](../azure-resource-manager/management/azure-subscription-service-limits.md#azure-firewall-limits).
92
91
93
92
## Related Azure PowerShell cmdlets
94
93
95
-
The following Azure PowerShell cmdlets can be used to create and manage IP Groups:
94
+
Use the following Azure PowerShell cmdlets to create and manage IP Groups:
0 commit comments