Virtual Network Flow Logs: What is the "PlatformRule"

Yoav 20 Reputation points
2024-11-26T15:52:10.0633333+00:00

Hey,

While exploring our VNET flow logs I noticed a recurring entry that's associated with aclID "00000000-0000-0000-0000-000000000000" and rule "PlatformRule". The traffic seems to be originating from Microsoft-owned IPs.

The rule and aclID are not part of the rules I created in any of my NSGs nor are they part of the default NSG rules.

Unfortunately, I couldn't find any information elaborating on the rule and its purpose.I'm looking for additional info regarding this rule, what traffic does it allow\block, should I expect to see malicious traffic blocked or is it simply traffic from Microsoft's infra?

best regards,

Yoav

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,584 questions
{count} votes

Accepted answer
  1. Sai Prasanna Sinde 2,695 Reputation points Microsoft Vendor
    2024-12-02T01:49:19.6966667+00:00

    Hi @Yoav,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    We have received the following updates from the product team:

    Q: The rule and aclID are not part of the rules I created in any of my NSGs nor are they part of the default NSG rules.

    This is the placeholder value for the Acls which are not customer configured Acls and corresponding rules as platform rules.

    These are some internal rules configured by various networking components and their functionality. Flows under this acl represent internal flows.

    Q: I couldn't find any information elaborating on the rule and its purpose. I'm looking for additional info regarding this rule.

    The product team is actively reviewing the Platform rules behavior in various scenarios and will provide an update in the public document soon.

    Q: What traffic does it allow\block, should I expect to see malicious traffic blocked or is it simply traffic from Microsoft's infra?

    This is Microsoft infrastructure traffic only.

    If above is unclear and/or you are unsure about something add a comment below.

    Please click 'Accept Answer' and 'upvote' if the above was helpful as this can be beneficial to other community members facing the same issues.

    Thanks,

    Sai Prasanna.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.