Deployment of Firewall ends with Provisioning state 'Failed'

Yen Sheng 0 Reputation points
2024-08-28T09:28:54.6033333+00:00

I am having a hub/spoke network architecture. Whenever I tried provisioning Azure Firewall, it will go into a Failed state. And it seems like the only way to resolve this is to add a route table to it and configure a 0.0.0.0/0 route to the Internet.

My understanding is Azure Firewall by default does not requires any route table, right?

Any help would be appreciated

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
671 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Rohith Vinnakota 680 Reputation points Microsoft Vendor
    2024-08-29T04:43:29.6633333+00:00

    Hi Yen Sheng,

    Thank you for posting your query on Microsoft Q&A.

    • Yes, that's right. Azure Firewall does not require a route table by default. However, in your hub/spoke network setup, the failure to provision the Azure Firewall is likely due to conflicts caused by the ExpressRoute gateway.
    • Your approach of setting up a route table to direct all outbound traffic to the internet is a correct solution.
    • Azure Firewall, it automatically creates a default route (0.0.0.0/0) to the Internet

    If you have any further queries, do let us know.

    Thank you,

    Vinnakota Rohith


    If the answer is helpful, please click "Accept Answer" and "Upvote it."


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.