Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9133683
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 17, 20262026-06-17T08:31:48+00:00 2026-06-17T08:31:48+00:00

I would like to create an extra-paranoid hub-and-spoke DMZ setup on Azure using IaaS

  • 0

I would like to create an extra-paranoid hub-and-spoke DMZ setup on Azure using IaaS VMs.

I have an public internet facing front end server (i.e. an IIS web server) that I’d like to severely lockdown. However, the front end requires access to some back end servers (i.e. a database, a domain controller, etc.). I want to ensure:

  1. Only the front end server can talk to the back end servers, and only on agreed upon ports.
  2. The back end servers cannot receive or send traffic from/to the public internet.
  3. The back end servers cannot talk to each other.
  4. These rules are enforced beyond the VM operating system layer to provide defense in depth.

This seems like a reasonable scenario, but I can’t seem to achieve it on Azure. The closest I’ve been able to do is:

  • Create an IaaS VM front end and restrict its endpoints appropriately
  • Create an Azure Virtual Network with a “FrontEnd” and “BackEnd” subnets placing each machine on the appropriate subnets.
  • Prevent RDP access to the back end VMs. If I want to RDP to the backend machines, I must do it through the front end VM.
  • Setup Windows Firewall rules on each of these machines to enforce these hub-and-spoke style of rules.

This works ok but it’s not as locked down as I’d like. I really want to have defense-in-depth so that I don’t have to rely on Windows/Linux firewall settings on each machine. For example, let’s say that a back end server must run an application with administrator credentials (assume there are no alternatives to this). I want an extra layer of protection such that a bug (or a malicious query) on the back end server could not:

  • Reconfigure the back end’s firewall to be less restrictive.
  • Talk to anyone else but the front end machine (this includes the public internet).

As far as I can tell, this isn’t possible on Azure using the Virtual Networking because:

  • Azure Virtual Networks don’t seem to expose ACLs or any other advanced filtering support.
  • Azure IaaS VMs only support a single NIC and thus the front end can’t be multihomed on both a front end and back end subnet.

Am I missing something? It seems like I might be able to hack something together using multiple virtual networks and VPN them together as a bunch of /30 subnets but that seems quite awful. If I can’t figure this out on Azure it seems my only reasonable alternative is to try to setup something like this on AWS using Virtual Private Cloud (VPC). Any help/guidance would be appreciated.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-17T08:31:49+00:00Added an answer on June 17, 2026 at 8:31 am

    I received a private answer from the Azure team that effectively said that this is not currently possible. It’s a requested feature but there is no set timeline for its implementation.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

i would like create a array of structure which have a dynamic array :
I would like to create this shape using just css. I am pretty sure
I would like to create an extension that adds extra pages to and existing
I'm using Visual Studio 2008 and would like to create a sort of container
I would like to create a two-color border-right in li-element navigation, without JavaScript, extra
I would like to create a CustomEventBanner but have some questions. Im not sure
I'm developing a simple web quiz and using javascript, I would like to create
I have a time-series dataset consisting of 10 variables. I would like to create
I would like to create an app using python on google app engine to
I would like to create a c++ type that mimic the build-in type exactly.

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.