Try our new research platform with insights from 80,000+ expert users
reviewer2315676 - PeerSpot reviewer
Cloud Architect at a computer software company with 1,001-5,000 employees
MSP
Helps us save time and money
Pros and Cons
  • "Azure Firewall is a cloud-native solution that removes the pain of load balancers."
  • "The tool needs to improve the onboarding and transition process for on-prem users."

What is our primary use case?

We use Azure Firewall to protect customer workloads. 

What is most valuable?

Azure Firewall is a cloud-native solution that removes the pain of load balancers. 

What needs improvement?

The tool needs to improve the onboarding and transition process for on-prem users. 

For how long have I used the solution?

I have been using the product for three years. 

Buyer's Guide
Azure Firewall
April 2025
Learn what your peers think about Azure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
845,589 professionals have used our research since 2012.

What do I think about the stability of the solution?

The tool's stability is great. 

What do I think about the scalability of the solution?

The solution's scalability is great. 

How are customer service and support?

Microsoft's support is quick.

How would you rate customer service and support?

Positive

How was the initial setup?

The tool's deployment is straightforward. 

What about the implementation team?

We did the deployment internally. 

What's my experience with pricing, setup cost, and licensing?

Azure Firewall is expensive. 

What other advice do I have?

Azure Firewall has helped us save 30 percent of the time. We don't require time for designing architecture and support. It frees up time and helps me focus on other tasks. 

The product has helped us save a decent amount of money. I rate it an eight out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
reviewer1651275 - PeerSpot reviewer
Senior Security Operations and Cyber Risk Analyst at a financial services firm with 51-200 employees
Real User
Good value for your money, good URL filtering, supports intrusion prevention, and is stable
Pros and Cons
  • "I think that one of the best features is definitely the premium version, along with the IDPs in terms of the intrusion detection and prevention system."
  • "For larger enterprises, they need to adjust the scalability."

What is our primary use case?

We use it to protect the Azure space and to be the bridge between on-premise and the cloud.

When I have had a site-to-site VPN set up and configured, and would use it to allow ordinary traffic from the on-premise device to the cloud and from other third-party suppliers to the Azure platform.

We also use it to provide connectivity to various network security groups that have been created within Azure.

How has it helped my organization?

I would say that this solution is really good compared to other solutions that we have had before. We would have used the FortiGate firewall in the Azure space. 

We find this process was quicker. It would get a faster turnaround time once we would generate and modify the firewall rules. Because of the visibility, we would have seen it. When compared to FortiGate, it would get a bit more visibility in terms of integration with the security center so that we would be able to review based on overall posture, see what needs to be fixed, or what changes need to be made. 

The turnaround time turns off rules and any gaps that exist would increase the turnaround time for that as well. It would also help us to increase our response time and reduce our attack surface by 20% so far.

What is most valuable?

With the recent upgrade to the premium version, it facilitates IP Groups, URL filtering, TLS inspection, IDPs, and the Web Categories.

Before using the premium version, a lot of our customers had concerns with the URL filter, where you would not be able to allow or block a specific URL. The feature set without a premium version would only allow you to do it via IP address, which is tedious.

At times, many of these vendors would be using some kind of CDN solution. It would be the case where multiple IPs appear, changing behind the URL when it would be easier if you're using the URL feature. The URL maps onto the IP address and it would be the easiest way to do that.

I think that one of the best features is definitely the premium version, along with the IDPs in terms of the intrusion detection and prevention system.

Many other vendors, when you do not have the license for the IP at some point, then you would be left not being able to do any prevention. The fact that the premium version includes this is good.

The TLS inspection allows you to decrypt the outbound traffic and encrypt data. Otherwise, we would have been using our third-party vendors, and whatever solution is within Azure.

With the various business units, we will be reaching out to other solutions there are in the web category to reduce the attack surface to see if this is a category that is alone or not.

The fact that Azure also ties into a security center is another good feature. You can also get rid of that visibility because of the tight integration with these Azure products.

What needs improvement?

We had an instance where it wasn't processing the rules and we had to engage Microsoft to resolve that issue. Microsoft Support needs to improve its response time.

For larger enterprises, they need to adjust the scalability. This is the only issue that I'm have found that it attributed to the two weeks of downtime we had experienced.

They need to offer either a scaled-up or scaled-out version or versions for larger enterprise companies.

This would greatly improve the solution.

For how long have I used the solution?

I have been using Azure Firewall for approximately two and a half years.

I have recently upgraded to the premium version.

What do I think about the stability of the solution?

Azure Firewall is pretty stable. 

I believe that they listen to various sponsors, which is why they were able to release the premium version. It is a more established firewall that vendors now have. 

I'm seeing where they have met up with the dynamics of the market, and I am expecting that they will be a leader sometime in the near future.

What do I think about the scalability of the solution?

They need to find a way to scale it out or scale it up a bit more. The scalability, it's okay, but it needs a lot more improvement. For a regular customer that's utilizing it, that's good, but for large enterprise companies, it is not as good.

The industry is telecoms. We have millions of customers. For that type of environment, they need better and more scalability.

We haven't totally assessed the premium version to see if the new features offer greater scalability. 

We utilize it across the cloud estate. We plan to expand our subscriptions. Most definitely, we will increase our usage.

Recently, we transitioned to the premium version, which will be extended to the other subscription once it has been rolled out across 32 countries, and with more instances, it will be rolled out across various continents.

How are customer service and technical support?

The turnaround time in resolving the issue where it wasn't processing the rules is an area that needs improvement. It wasn't resolved in a timely manner.

Microsoft support took a bit of time to assist us in resolving that issue. It created a bit of downtime for us and it was longer than we expected. 

I would say those would be the cons so far when utilizing it.

I would rate the Microsoft support a five out of ten because they did not respond in a timely manner and the impact it caused in terms of the downtime it created for us. We were down for a week or two during a high-impact period.

They were assisting us but it took a good amount of time to get it resolved when we needed to be putting out things daily. Two weeks is a long time for a fast-paced environment. 

Which solution did I use previously and why did I switch?

Previously, we were using FortiGate Firewall. We switched because of the migrating of the Security Center and the ease of use. The cost was also considered.

How was the initial setup?

The initial setup was straightforward.

We had another tool which was FortiGate. We migrated from FortiGate to the Azure Firewall.

It was a straightforward migration.

The deployment took approximately three to four weeks.

The implementation strategy would include copying over rules, ensuring that all the services are able to run, and also ensuring that both firewalls were running in parallel. Until we are sure that the Azure Firewall can handle the workload, both firewall products will continue to operate.

After that, we were able to power down the virtual appliance that was on the FortiGate Firewall.

We had it running for quite some time, approximately a month and a half. Because there were no issues, we stopped using the FortiGate Firewall altogether, once that process was complete.

We have a server team, a cloud team, and a network team to administer and maintain this solution. It's approximately eight to ten people, some are network security engineers, a network security manager, and network engineers.

What was our ROI?

There have been some cost benefits as well. When using another vendor in comparison where you bring your own license, the cost would have gone down. It's more cost-effective to use the Azure Firewall along with the premium version than using a third-party as an option from the marketplace. I would say that as well, where it gives you better spend in terms of OPEX. It's better value for your money.

What's my experience with pricing, setup cost, and licensing?

The licensing module is good. Pricing is one of the reasons we switched to this solution.

For smaller businesses, they could probably put one or two features from premium into the regular standard versions. For example, that URL filtering is a pain point for many customers. 

If they could find a way to scale down that URL and the IPs feature to include it in the standard version, then that would allow them to get more traction and more customers from the small to medium-sized business perspective.

Which other solutions did I evaluate?

We were using Check Point mostly. We had decided to move to FortiGate, and then we moved to Azure Firewall. 

We did not go with Check Point because of the premium features such as the URL filtering, and the TLS inspection included with Check Point cost a lot more. This was the reason we chose the Azure Firewall.

What other advice do I have?

It's a solid solution. I would tell anybody to definitely give it a try, and consider it as one of the options when looking for a firewall to use in Azure space.

I would say if they can go for the premium version upfront, rather than starting with the standard version, then trying to transition to a premium version. It addresses a lot of the issues and concerns in this space today. They should start with the premium rather than upgrade. Once they can afford it, go straight to premium.

I would rate Azure Firewall an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Azure Firewall
April 2025
Learn what your peers think about Azure Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
845,589 professionals have used our research since 2012.
Hammad Naeem - PeerSpot reviewer
Infrastructure Team Lead at Speridian Technologies
Real User
Top 10
Helps in server and application deployment
Pros and Cons
  • "We use the solution for application and server deployment."
  • "The solution should incorporate features similar to competitors like split tunneling."

What is our primary use case?

We use the solution for application and server deployment. 

What needs improvement?

The solution should incorporate features similar to competitors like split tunneling. 

For how long have I used the solution?

I have been working with the product for five years. 

What do I think about the stability of the solution?

The product is stable. 

What do I think about the scalability of the solution?

The solution is scalable and doesn't take more than five minutes to scale. 

How are customer service and support?

The product's support is bad. 

How would you rate customer service and support?

Neutral

How was the initial setup?

The product's deployment was straightforward. 

What other advice do I have?

I would rate the product an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer896049 - PeerSpot reviewer
Cloud Architect at a financial services firm with 1,001-5,000 employees
Real User
Easy to deploy and configure, but you need to have a defined IP range to associate it with your network
Pros and Cons
  • "I can easily configure it."
  • "You have to have a defined IP range within your network to associate it with your network. The problem is you have to plan ahead of time if you expect to use the firewall in the future so that you don't have to reconfigure your subnets or that specific IP range. Other than that, I don't any issues. I use it for basic configuration for a single application, so I really don't try to leverage it for multiple applications where I might find some complexity or challenges."

What is our primary use case?

It is associated with our web resources, such as PaaS applications. I don't use it that much. I spend way more time working with function apps or something else on the Azure platform.

I am using its latest version.

What is most valuable?

I can easily configure it.

What needs improvement?

You have to have a defined IP range within your network to associate it with your network. The problem is you have to plan ahead of time if you expect to use the firewall in the future so that you don't have to reconfigure your subnets or that specific IP range. Other than that, I don't any issues. I use it for basic configuration for a single application, so I really don't try to leverage it for multiple applications where I might find some complexity or challenges.

For how long have I used the solution?

I have been using this solution for four years.

What do I think about the stability of the solution?

I don't get into any kind of real scale configuration. There might be bugs that I don't know because I just use the general configuration.

What do I think about the scalability of the solution?

I can't say about scalability, but we have 20,000 employees.

How are customer service and support?

I have not used their technical support.

Which solution did I use previously and why did I switch?

Most of the time, I've used Azure Firewall for cloud services. We also have AWS, and then, of course, we have hardware firewalls on-premise, but I haven't worked with anything.

How was the initial setup?

It is pretty straightforward for what I'm using it for.

What other advice do I have?

I would rate Azure Firewall a seven out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
CEO at Foresight Cyber Ltd
Reseller
Easy to set up, good integration, and the technical support is good
Pros and Cons
  • "The most valuable feature is the integration into the overall cloud platform."
  • "Currently, it only supports IP addresses, so you have to be specific about the IPs that are in your environment."

What is our primary use case?

Azure Firewall makes up part of our security solution. We use it internally but we are a consulting company and also advise our customers on the use of it.

What is most valuable?

The most valuable feature is the integration into the overall cloud platform. The orchestration is very easy using automation with APIs and scripts.

What needs improvement?

Currently, it only supports IP addresses, so you have to be specific about the IPs that are in your environment. They could add specific instance names, such as an instance ID to be specified or a resource group.

Tagging is supported but not on the instances, which is something that could be improved.

The selection of the internal resources into the ruleset could be improved.

Support for layer-seven application filtering should be added because it is not there yet, at all.

It is capable of filtering on the fully qualified domain name (FQDN) but it cannot do the more advanced features that Palo Alto or FortiGate can do, where you can grant or limit access to Facebook but you don't need to specify the domain name because it knows about Facebook as an application. You should be able to simply say "Allow Facebook", but also have it block Facebook Chat, for example. Having control over those specific application protocols within the traffic would be an improvement.

The documentation from Microsoft could be slightly improved, although it could be related to the fact that the product is quickly changing. It may be a case that the documentation updates are of a lower priority than the product itself.

For how long have I used the solution?

I have been using the Azure Firewall for about one year.

What do I think about the stability of the solution?

The stability is excellent.

What do I think about the scalability of the solution?

The scalability is very good and you don't have to think about sizing, as in the case of a traditional firewall where you have to think about the throughput. With Azure Firewall, it scales automatically.

We have customers ranging in size from small to enterprise-level organizations. One of them is a large company with 40,000 users on Azure Firewall.

How are customer service and technical support?

We use the customer support that our customer has access to. If they have enterprise support then we use it, whereas if they do not then we use standard support.

Personally, my experience with Microsoft support has been very good. Their professionals are very quick to respond and they have good feedback. They also have very good support forums and the documentation is fairly good. 

Which solution did I use previously and why did I switch?

I have experience with similar solutions by Palo Alto and Fortinet. With the inclusion of more advanced features, Azure Firewall will be on par with these products.

How was the initial setup?

The initial setup is straightforward and very easy.

What other advice do I have?

My advice to anybody who is considering this solution is to be clear about your requirements. It is critical to know what the capabilities of the firewall are, as well as what is nice to have when it comes to filtering and protecting the environment.

There are different threat profiles when it comes to protecting user traffic. For example, in a VDI environment, where the users are in the cloud, generating traffic and browsing the internet on virtual machines, Azure might not be the best fit. On the other hand, to protect the workloads on servers like application servers or database servers, it's a perfect fit. So, it is important to be clear about the use cases in order to determine whether it is suitable.

This is a relatively new product but Microsoft is really fast in their development and you never know what they are planning. In perhaps six months, I might rate it a ten out of ten. Nonetheless, at this time there is still some room for improvement.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
reviewer1404387 - PeerSpot reviewer
Cloud Architect at a pharma/biotech company with 10,001+ employees
Real User
Stable and can autoscale but requires more use cases
Pros and Cons
  • "The solution can autoscale."
  • "Azure should be able to work better as a balancer also, instead of just being a firewall. It should have a wider mandate."

What is our primary use case?

We mostly utilize the solution for effectively controlling the networks.

What is most valuable?

The ability to provide better control of the traffic is the solution's most valuable aspect.

The solution is stable.

The solution can autoscale.

The initial setup is pretty easy.

Technical support has been good to us so far.

What needs improvement?

The solution isn't missing features per se.

Azure should be able to work better as a balancer also, instead of just being a firewall. It should have a wider mandate.

There should be more use cases, specifically use cases for domains for, for example, healthcare and specific use cases for web applications.

For how long have I used the solution?

I've been using the solution for one year.

What do I think about the stability of the solution?

The stability of the solution is good. We haven't had any issues. It's a managed service.

What do I think about the scalability of the solution?

The solution is autoscalable. It scales based on your deployment and/or based on your loads, due to the fact that it's a managed service. A company that expects to expand shouldn't have a problem scaling with this solution.

We have about 50-100 users on the solution currently. We may increase usage in the future.

How are customer service and technical support?

We've had some experience with technical support from Azure. We've found them to be quite good and are satisfied with the level of service that's been provided. I would say they ar knowledgeable and responsive to our queries.

Which solution did I use previously and why did I switch?

Before Azure Firewall, I used to work on a VPN-based firewall. 

How was the initial setup?

The solution doesn't have a complex installation process. It's pretty straightforward to implement. When we went forward with the solution we didn't face any setup issues.

Our initial deployment took about three months, and, now that it's a managed service, we've handed the deployment over to them.

I'm not sure how many staff members we used for deployment and how many handle any maintenance aspects.

What about the implementation team?

While we handled the initial implementation, we get Azure to handle the deployments for us. We didn't use a reseller or a consultant to assist with the deployment.

What other advice do I have?

We're just a customer at this time. We don't have any kind of special business relationship with Azure.

I'm not sure which version of the solution I'm currently using is.

I'd rate the solution seven out of ten overall. It works well for us in terms of controlling traffic and if is stable and can scale, however, there should be more use cases available.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1577409 - PeerSpot reviewer
Technical Architect at a tech services company with 10,001+ employees
Real User
Provides a good link to Azure and SQL servers but should have groupings for servers
Pros and Cons
  • "The solution should be capable of self-scaling, which is one of the features we like about it."
  • "It would be nice to be able to create groupings for servers and offer groups of IP addresses."

What is our primary use case?

We use the solution as an internal firewall device.

What is most valuable?

The solution provides a good link to Azure and SQL servers.

What needs improvement?

It would be nice to be able to create groupings for servers and offer groups of IP addresses.

I would, also, like to see the manager built into the solution more, such as concerns Azure Firewall Manager. 

I would also like to see some of the items that come with the preview version for the next version with IDS be addressed, as well as the ability to categorize websites, which is done with external traffic.

For how long have I used the solution?

We have been using Azure Firewall for around a year. 

What do I think about the stability of the solution?

The solution has the same stability as Azure.

What do I think about the scalability of the solution?

The solution should be capable of self-scaling, which is one of the features we like about it. We have not encountered any issues with this. 

How are customer service and technical support?

We have never been in contact with technical support concerning the firewall bits, although we have spoken to them about the solution in a more general context.

I would rate the technical support as a seven-point-five out of ten. 

How was the initial setup?

The initial setup was simple.

The deployment of the firewall took about five minutes and full deployment through the Azure mechanism lasted around an hour.

The solution does not require any maintenance. 

What about the implementation team?

We handled the initial setup internally. 

What's my experience with pricing, setup cost, and licensing?

Azure Firewall is quite an expensive product. It can be challenging to work out the price as the fee varies depending on the amount of data that is run with the solution.

Only the built-in usage level incurs licensing fees. There are no additional ones. 

Which other solutions did I evaluate?

Cisco ASA is a better product. The ASA offers VPN functionality that is not found in Azure Firewall, although an ESA can be used as a simple alternative. It's much easier to deploy the Azure Firewall in high availability mode and to make it more scalable.

What other advice do I have?

I would estimate the number of people in our organization who are utilizing the solution to be 100 +.

My advice to others is to set up a free account and try it. It's relatively easy to do. Only this way can a person see if the solution suits his needs. 

I rate Azure Firewall as a seven out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Senior Architect, Infrastructure and Cloud Solutions at a government with 501-1,000 employees
Real User
Stable and scalable with outstanding technical support
Pros and Cons
  • "The solution is very stable. When comparing it to other environments, it's actually quite impressive."
  • "We find it's different implementing it region-to-region. It might help if it was universal across all regions."

What is our primary use case?

On-premise to cloud <-> Cloud to on-premise

How has it helped my organization?

Managed service.

What is most valuable?

Scalability, multi-zone and FQDN TAgs.

What needs improvement?

In a future release, it could be empowered by combining with Azure Private DNS and Front Door.

For how long have I used the solution?

We've been using the solution for 1 year

What do I think about the stability of the solution?

The solution is very stable. When comparing it to other environments, it's actually quite impressive.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and technical support?

We deal with technical support on a regular basis. I'd rate the service we've received ten out of most of the support tickets. 

Which solution did I use previously and why did I switch?

We use several solutions.

What's my experience with pricing, setup cost, and licensing?

Unfortunately, I don't handle the finances or payments for the solution, so I can't compare to others.

Which other solutions did I evaluate?

FortiGate - also nice solution...

What other advice do I have?

We've used both the on-premises as well as the cloud deployment models. We also occasionally use a hybrid model. During migrations, we use hybrids. Once the migration is done, we move onto the full cloud and pass if over to private cloud or have public access as necessary.

The Azure firewall is prioritized as it is managed solution and does not require any infrastructure base (backbone) hardware support.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Azure Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2025
Buyer's Guide
Download our free Azure Firewall Report and get advice and tips from experienced pros sharing their opinions.