Chapter 7: Implementing Network Security
In the previous chapter, we covered the options that we have to secure the perimeters of our virtual networks in Azure. However, not all threats come from outside the network! We also need to ensure that we have a reduced network attack surface and can contain breaches to a reduced blast radius even if an attacker gains a foothold on our network. This is in line with the principles of zero trust and micro-segmentation.
In this chapter, we will look at what network security looks like in Azure from both the IaaS and PaaS perspectives. We will also cover how to implement Azure platform features to deliver a highly secure network architecture. Here are the topics that we will cover in this chapter, with accompanying hands-on exercises:
- Implementing virtual network segmentation
- Implementing platform service network security
- Securing Azure network hybrid connectivity