Azure Firewall Forced Tunnel Setup
Budget: ₹600 – ₹1,500 INR
I have a lab in Azure where I need to enable forced tunneling on an Azure Firewall and fine-tune its network rules so that traffic from VPN users is routed exactly as intended.
Here is the current scenario: a handful of users in India connect over a site-to-site / P2S link to a VPN Gateway that lives in East US 2. Their internet-bound traffic crawls; I want to prove in the lab whether the issue is routing, rule order, or something deeper in the stack.
What I need from you
• Turn on and validate forced tunneling on the Azure Firewall.
• Build or adjust the required network rules—both inbound and outbound—to steer traffic through the firewall without breaking existing resources.
• Replicate the same rule set on a Windows Server firewall and on a Linux host (iptables or nftables is fine) to compare behaviour outside of Azure Firewall.
• Walk me through the test plan so we can measure throughput and latency before and after the changes. Azure Network Watcher, packet capture, or similar tooling is welcome.
Success looks like clear documentation of each step, working rules in all three environments, and empirical proof that traffic takes the right path with acceptable throughput. I’ll provide subscription access, current route tables, and test accounts as soon as we start.
Here is the current scenario: a handful of users in India connect over a site-to-site / P2S link to a VPN Gateway that lives in East US 2. Their internet-bound traffic crawls; I want to prove in the lab whether the issue is routing, rule order, or something deeper in the stack.
What I need from you
• Turn on and validate forced tunneling on the Azure Firewall.
• Build or adjust the required network rules—both inbound and outbound—to steer traffic through the firewall without breaking existing resources.
• Replicate the same rule set on a Windows Server firewall and on a Linux host (iptables or nftables is fine) to compare behaviour outside of Azure Firewall.
• Walk me through the test plan so we can measure throughput and latency before and after the changes. Azure Network Watcher, packet capture, or similar tooling is welcome.
Success looks like clear documentation of each step, working rules in all three environments, and empirical proof that traffic takes the right path with acceptable throughput. I’ll provide subscription access, current route tables, and test accounts as soon as we start.
Related categories:
System Admin
Linux
Azure
Network Administration
Documentation
Network Security
VPN
Firewall