Hello,
We are about to start the journey of migrating many virtual servers from our VMware estate to Azure. We only have about 5 servers in there now, but will move around 100 over this year I think. At the moment I'm just using the NSGs for firewall on each virtual server, but I'm looking at the bigger picture and wondered what your thoughts were on getting a NGFW in a Azure and do we need one (or 2 for HA) as NSGs are ok (question I got).
I'm use to have ASAs on the perimeter network with a DMZ or 2 and IPS, NATs/PATs etc. In Azure we have an address space of 192.168.144.0/22 that is subnetted into 5 VLANs (Prod, Dev, UAT, DMZ, Gateway). Other than the NSGs on each VM these are just layer 3 networks and the DMZ isn't a real DMZ. I'm trying to come up with the pros and cons I guess. vs NSGs
I don't won't to migrate 100 virtual servers then to be asked to add a virtual FW and would prefer to add now.
When installing the ASAv is it aware of the virtual networks you already have in Azure and ask which ones to traverse the ASAv?
I see on the Marketplace there is a free trial of the ASAv on low throughput, I don't want to install that and it causes a huge bottleneck unless I can just add the DMZ network which only has 1 test server.
It's difficult to get a gauge on the throughput at this point.
Any info on the above would be really appreciated.