Migrate your Azure firewall policies to Cloud NGFW for Azure using Strata Cloud
Manager for enhanced security and operational efficiency.
| Where Can I Use This? | What Do I Need? |
|
|
- Strata Cloud Manager Essential in a supported region
(Canada, India, United Kingdom, Singapore, or United
States)
- Security Administrator or Superuser role
|
Cloud Service Provider (CSP) Native Firewall Policy Migration enables the automated
transfer of existing security policies from Azure Firewall to Palo Alto Networks®
Software Firewalls (Cloud NGFW and VM-Series) through Strata™ Cloud Manager. This
process transitions your security configurations from native cloud firewall services
to a next-generation firewall platform, providing enhanced security and centralized
policy management.
The migration follows a structured architectural flow. It begins with identifying
policies in your Azure environment. Strata Cloud Manager then translates native
Azure firewall logic into compatible Palo Alto Networks Software Firewall
configurations. You can apply these configurations to existing or new Software
Firewall resources to ensure a consistent security posture across your environment.
Policy migration to Strata Cloud Manager is currently supported in the following
regions: Canada, India, United Kingdom, Singapore, and United States.
The Policy Migration Engine processes your uploaded configuration files to translate
native Azure firewall logic into Strata Cloud Manager snippets through these key
steps:
- Export Native Configuration: Use the Python script
export_azr_fwpolicy.py to extract existing security
policies from your Azure environment into a ZIP file.
- Analyze and Convert: Upload the exported ZIP file to the Strata Cloud
Manager Migration Catalog. The engine translates cloud-native logic into Strata
Cloud Manager-compatible security rules and objects while identifying skipped
items that require manual review.
- Generate Configuration Snippets: Upon successful conversion, the tool
creates a reusable Strata Cloud Manager snippet containing all migrated
rules.
- Associate with Folders: Link the generated snippet to a designated
Strata Cloud Manager folder associated with your Software Firewall resources
(Cloud NGFW or VM-Series).
- Deploy and Verify: Initiate a Config Push to deploy the translated
policy to your active firewall units and monitor the job log to confirm a
successful transition.
Supported Features and Compatibility
The following table outlines the policy components supported for automated migration
from Azure Firewall to Strata Cloud Manager.
| Feature Category | Supported Components | Unsupported or Skipped |
| Rules | Network Rules and Application Rules | None |
| Services | DNS Proxy, Threat Intelligence, IDPS, SNAT Rules, and TLS
Inspection | FQDN Tags |
| Objects | IP Groups, FQDNs, Web Categories, and Service Tags | None |
For Azure D-NAT rules, apply the
configuration based on the platform you intend to use. For Cloud NGFW, Terraform
templates are provided to apply these rules within your Azure account. For
VM-Series, D-NAT policies are included in the generated Strata Cloud Manager
snippet.