Thank you for the comment received.
My understanding is that new Microsoft Azure VM's are no longer going to be configurable with direct internet access outbound from 30th September 2025.
As a result, a control point will need to be in use, between the devices in a Private network and the internet.
There will need to be a route out to the internet provided by something, which can control outbound traffic and potential inbound flow.
For outbound access, to sites that Microsoft needs you to access, they provide large IP address blocks, and wildcard DNS addresses for their services to be accessed.
To use the Meraki in this way, we will need to be able to firewall based on IP Address blocks, *.FQDN rules, and ideally the "Azure service tag" groupings that Microsoft provide.
How will the Meraki firewalling platform work for this use case please
As an example, for the Defender service, Microsoft provides the following details of what needs to be accessible:
https://learn.microsoft.com/en-us/defender-cloud-apps/network-requirements?source=recommendations
cdn.cloudappsecurity.com
cdn-discovery.cloudappsecurity.com
adaproddiscovery.azureedge.net
*.s-microsoft.com
*.msecnd.net
dev.virtualearth.net
flow.microsoft.com
static2.sharepointonline.com
*.blob.core.windows.net
discoveryresources-cdn-prod.cloudappsecurity.com
also for the defender datacentre(s) you're using: e.g. US1
13.107.219.0/24, 13.107.227.0/24, 13.107.228.0/24, 13.107.229.0/24, 150.171.97.0/24, 13.64.26.88, 13.64.29.32, 13.80.125.22, 13.91.91.243, 40.74.1.235, 40.74.6.204, 51.143.58.207, 52.137.89.147, 52.183.75.62, 23.101.201.123, 20.228.186.154 *.us.portal.cloudappsecurity.com
For Office 365, Sharepoint / other services, similar blocks of addresses and URLs need to also be configured.
How can Meraki be setup to view, log, and track what is blocked / flowing currently, so you can see what activity is going on? will Geo-Blocking be available?
What sustained throughput would be realistic for design engineering for the platform doing this level of traffic inspection in the Azure environment please - 10 devices, 30, 50 100, 200 with gig e connections ? I note that the VMX-L says it is able to do 1GBPS of throughput, so how should we engineer for maximum throughput.
Is there any traffic throughput penalties for applying any IDS / IDP functionality or rules to be aware of ?
Many thanks
Stuart
Many thanks
Stuart