Azure Environment Security Configuration Project
Budget: $25 – $50 USD
Azure Firewall & Forced Tunneling Setup Project Brief
Project Goal
The primary goal of this project is to implement and validate the network architecture, Azure resources, and security configurations shown in the provided Azure Firewall & Forced Tunneling Setup Diagram. The final result must be a fully functional, secured, and documented environment.
Project Description & Scope
The successful candidate will set up an Azure environment that demonstrates secure outbound internet access using Azure Firewall and Forced Tunneling for specific subnets, while also allowing controlled inbound access via DNAT.
The scope includes:
Azure Resource Deployment: Creation of all necessary resources (VNETs, Subnets, VMs, Azure Firewall, Route Tables, Public IPs).
Network Configuration: Setting up VNet Peering between VNet-Firewall and VNet-VMs.
Forced Tunneling Implementation: Configuring the Route Table (RT-Firewall-Forcing) and associating it with the appropriate subnets to ensure all outbound internet-bound traffic from specified subnets is routed through the Azure Firewall's private IP.
Azure Firewall Rule Configuration: Implementing the specific Application Rule and Network Rule collections as outlined in the diagram.
Validation: Testing and proving that all defined traffic flows (Forced/Blocked, Web, RDP/DNAT) are working exactly as intended.
Documentation: Providing a clear, step-by-step documentation of the setup.
Deliverables
A fully provisioned and functioning Azure environment matching the diagram.
A Configuration Script (e.g., PowerShell, Azure CLI, or Terraform) used to deploy the environment.
A Validation Report (or documentation) with screenshots confirming:
The successful RDP connection via DNAT.
The successful general web traffic (HTTP/S).
The explicit blocking of YouTube traffic from a specified VM.
The applied Route Table configuration for Forced Tunneling.
Cleanup Instructions to easily delete all created resources upon project completion.
Ideal Candidate Profile
Proven expertise in Microsoft Azure networking and security.
Strong experience with Azure Firewall configuration (DNAT, Network, and Application Rules).
Deep understanding of Azure Route Tables and Forced Tunneling.
Familiarity with setting up and troubleshooting VNet Peering.
Project Goal
The primary goal of this project is to implement and validate the network architecture, Azure resources, and security configurations shown in the provided Azure Firewall & Forced Tunneling Setup Diagram. The final result must be a fully functional, secured, and documented environment.
Project Description & Scope
The successful candidate will set up an Azure environment that demonstrates secure outbound internet access using Azure Firewall and Forced Tunneling for specific subnets, while also allowing controlled inbound access via DNAT.
The scope includes:
Azure Resource Deployment: Creation of all necessary resources (VNETs, Subnets, VMs, Azure Firewall, Route Tables, Public IPs).
Network Configuration: Setting up VNet Peering between VNet-Firewall and VNet-VMs.
Forced Tunneling Implementation: Configuring the Route Table (RT-Firewall-Forcing) and associating it with the appropriate subnets to ensure all outbound internet-bound traffic from specified subnets is routed through the Azure Firewall's private IP.
Azure Firewall Rule Configuration: Implementing the specific Application Rule and Network Rule collections as outlined in the diagram.
Validation: Testing and proving that all defined traffic flows (Forced/Blocked, Web, RDP/DNAT) are working exactly as intended.
Documentation: Providing a clear, step-by-step documentation of the setup.
Deliverables
A fully provisioned and functioning Azure environment matching the diagram.
A Configuration Script (e.g., PowerShell, Azure CLI, or Terraform) used to deploy the environment.
A Validation Report (or documentation) with screenshots confirming:
The successful RDP connection via DNAT.
The successful general web traffic (HTTP/S).
The explicit blocking of YouTube traffic from a specified VM.
The applied Route Table configuration for Forced Tunneling.
Cleanup Instructions to easily delete all created resources upon project completion.
Ideal Candidate Profile
Proven expertise in Microsoft Azure networking and security.
Strong experience with Azure Firewall configuration (DNAT, Network, and Application Rules).
Deep understanding of Azure Route Tables and Forced Tunneling.
Familiarity with setting up and troubleshooting VNet Peering.