In order to confirm that you successfully configured the connector, you must have a Fabric connector address.
- The address or address group is used for source/destination of firewall policies. The address is based on IP addresses. The address contains address(es) within the Azure instance that are running.
- When changes occur to addresses in the Azure environment, the Fabric connector populates and updates the changes automatically based on the specified filtering condition so administrators do not need to reconfigure the address’s content manually.
- As instances that match the filter appear in the environment, changes are propagated to the firewall policies that use the address object.
Configuring one of these addresses is similar to configuring any other address object, but with a few different options.
- Go to Policy & Objects > Addresses.
- Give the address a name.
- From the Type dropdown list, select Fabric Connector Address.
- From the Fabric Connector Type dropdown list, select Microsoft Azure.
- Input a filter into the Filter field.
- Set the interface to a specific port or leave it at the default any.
- Add any Comments or Tags that are applicable.
The CLI commands to configure the same address are as follows:
config firewall address
set type dynamic
set comment ''
set visibility enable
set associated-interface ''
set color 0
set sdn azure
set filter "tag.Owner=test"
Tags are not the only option to filter the address. The Azure Fabric connector supports the following filters:
vmss=<VM scale set>
Just like the tag value, you can find these properties in the Azure interface