Why Azure Firewall, ASGs, and NSGs should be part of your security posture

September 22 2021

There are a lot of terms when it comes to network security. Business leaders and newcomers often get confused with the many acronyms and security jargon being thrown around. What exactly is the difference between a firewall and a Network Security Group (NSG)? What about an Application Security Group (ASG)?

The safety of your data and the reputation of your organization depends on knowing the differences and focusing on best practices with these technologies.

The main difference between these tools is the placement in your network and where the management is happening. NSGs are typically placed at the network interface and subnet level, whereas firewalls—including the cloud-based Azure Firewall--control traffic coming in and out of the virtual networks (VNets). You can't put Azure Firewall on a network interface.

Think of cloud security like the layers of an onion. Each layer focusing on different issues. Traffic coming in from the internet hits the Azure firewall, then the virtual network NSG, then the subnet NSG, and finally the network interface NSG, each with their own set of rules.

The role Application Security Groups (ASG) play is providing the ability to allow you to group virtual machines and define network security policies based on those groups. You can group virtual machines with a common function and apply a NSG rule to the group rather than have to apply NSG’s individually to each resource.

About Jeff Christman

Jeff Christman is a Navy Veteran with over 20 years of experience in the IT field. Specializing in cloud migrations, he has worked for companies such as Raytheon, AT&T, and NASA. Currently, he is a Sr. Cloud Security Consultant at a large consulting firm. In addition to his daytime job, he also has published content and courses for Pluralsight.com, Techsnips.io, and Adamtheautomator.com. 

In his off time, he loves fantasy football, everything tech, and embarrassing his teenage daughters.

More about Jeff Christman