Azure Portal
Azure Portal
Objective
To create and configure an NSG to control traffic flow for a subnet or individual
virtual machine in Azure.
Prerequisites
1. An active Azure subscription.
2. A Virtual Network (VNet) with at least one subnet.
3. Optional: Virtual Machines (VMs) deployed in the subnet for testing.
2. Test Traffic:
o Use tools like telnet, curl, or ping from other VMs or external
sources to test allowed/blocked traffic.
o Ensure blocked traffic fails and allowed traffic succeeds.
3. Monitor Traffic:
o Use NSG Flow Logs in Azure Monitor to analyze traffic patterns.
Example Rules
Inbound Rules
IP
AllowRDP 200 * 3389 TCP Allow
Addresses
DenyAllInbou
65000 Any * * Any Deny
nd
Outbound Rules
DenyAllOutbou
65000 Any * * Any Deny
nd
Enhancements
1. Service Tags:
o Use Azure service tags like AzureLoadBalancer or Internet to
simplify rule creation.
2. Application Security Groups (ASGs):
o Group VMs into ASGs for easier NSG rule management.
3. Diagnostics:
o Enable NSG Flow Logs for detailed traffic analysis.