Generally Available: FQDN Filtering in DNAT rules in Azure Firewall
Share
Services
Azure Firewall supports the use of Fully Qualified Domain Names (FQDNs) in DNAT (Destination Network Address Translation) rules, allowing inbound traffic to be routed to backend resources using domain names instead of static IP addresses.
This feature is especially useful for scenarios where backend IP addresses are dynamic or centrally managed via DNS.
Key Highlights:
* DNS-based backend targeting: Route inbound traffic to backend servers using FQDNs.
* Dynamic IP support: Ideal for applications where backend IPs change frequently.
* Monitoring: Monitor DNAT activity using AZFWNatRule logs.
**Learn more:**
* About [FQDN Filtering](https://review.learn.microsoft.com/en-us/azure/firewall/fqdn-filtering-network-rules?branch=pr-en-us-299151).
* About [DNAT Rules](https://review.learn.microsoft.com/en-us/azure/firewall/dnat-rule?branch=pr-en-us-299151).
What else is happening at Microsoft Azure?
Read update
Services
Share
Read update
Services
Share
Generally Available: Application Gateway adds MaxSurge support for zero-capacity-impact upgrades
August 21st, 2025
Services
Share