Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

6.2.2. Rule Configuration

Rule Types:
TypeLayerUse Case
NAT rulesL3-4DNAT for inbound access
Network rulesL3-4Allow/deny by IP/port
Application rulesL7FQDN, web categories
Processing Order:
  1. NAT rules (DNAT)
  2. Network rules
  3. Application rules

Within each type: Rules processed by priority (collection group → collection → rule).

FQDN Filtering:
Rule: Allow *.microsoft.com on HTTPS
  - Firewall resolves FQDN
  - Inspects SNI header for HTTPS
  - Allows/denies based on match

FQDN Tags: Pre-defined groups of FQDNs:

TagIncludes
WindowsUpdateMicrosoft Update URLs
AppServiceEnvironmentASE dependencies
AzureBackupBackup service URLs
Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications