Skip to content

Commit efbc036

Browse files
Merge pull request #309377 from duongau/duau/azure-firewall-freshness-review
Add threat intelligence filtering information to azure firewall overview
2 parents 60dc3bf + cbd0d8a commit efbc036

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

articles/firewall/overview.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,12 @@ Azure Firewall Premium provides advanced capabilities, including signature-based
5050

5151
For more information, see [Azure Firewall features by SKU](features-by-sku.md#azure-firewall-premium-features).
5252

53+
## Threat intelligence-based filtering
54+
55+
Threat intelligence-based filtering can be enabled for your firewall to alert and deny traffic from/to known malicious IP addresses and domains. The IP addresses and domains are sourced from the Microsoft Threat Intelligence feed. Intelligent Security Graph powers Microsoft threat intelligence and is used by multiple services including Microsoft Defender for Cloud.
56+
57+
When threat intelligence-based filtering is enabled, the associated rules are processed before any of the NAT rules, network rules, or application rules.
58+
5359
## Feature comparison
5460

5561
To compare all Azure Firewall SKU features, see [Choose the right Azure Firewall SKU to meet your needs](choose-firewall-sku.md).

0 commit comments

Comments
 (0)