Chapter 4

Traffic Inspection in Azure Networks

Security teams often require a deeper level of visibility than the standard traffic logs generated by Azure Firewall, NSGs, and other resources. This deeper level of visibility can take many forms, and native Azure resources can accomplish many of the requirements. Traffic inspection, or Deep Packet Inspection, refers to the ability to inspect the entire packet, rather than just the headers, of a request.

Traffic inspection generally has a few main components:

  • Decryption Encrypted traffic, such as TLS, must be decrypted before any inspection can be done.

  • Inspection Traffic can be inspected using several methodologies, including Intrusion Detection and Prevention Systems (IDPS), Data Loss Prevention ...

Get Microsoft Azure Network Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.