How do I solve common connection lost issue with the Azure Scanner Appliance?
Some Azure Appliances are experiencing a connection issue due to the Application Control in The Azure firewall.
In some environments, Application Control policies in Azure Firewall may block or interfere with the communication from the Scanner Appliance. To ensure the scanner operates correctly, you need to exclude the scanner appliance IP address from application control inspection.
Preparation:
-
Azure Portal access
-
Permissions to modify Azure Firewall policies or rules
-
The IP address of the Scanner Appliance
Step-by-Step guide:
-
Log in to your Azure portal.
-
Sign in with an account that has Firewall or Network Contributor permissions and navigate to Azure Firewall.
- Select the Azure Firewall instance used by your environment.
- Open the Firewall Policy associated with the firewall.
- Go to Rules and open the Rule Collection Group where outbound traffic is managed.
- Create an Allow Network Rule for the Scanner Appliance to bypass application control inspection.
- Ensure that you have included the Scanner Appliance IP, ports, and the whitelisted IPs.
- Ensure the allow rule has a higher priority than any rule that applies application control or filtering. Azure Firewall processes rules based on priority order.
- Click save changes to apply and save.
- Done!