# Check IDPS private ranges before interpreting Azure Firewall traffic direction

> The IDPS private-range definition determines inbound, outbound and internal classification used by direction-specific signatures.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-404-check-idps-private-ranges-before-interpreting-azure-firewall-traffic-direction/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:12+00:00
- Modified: 2026-09-10T02:04:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The IDPS private-range definition determines inbound, outbound and internal classification used by direction-specific signatures.

## Potentially affected

Azure Firewall Premium IDPS deployments with address ranges requiring explicit direction classification.

## DSE recommendation

Compare the actual address plan with IDPS private ranges before changing signature modes.

## Article

## Source facts

Azure Firewall Premium IDPS uses configured private IP ranges to classify traffic as inbound, outbound or internal. Its signatures apply to specific directions. By default, only RFC 1918 ranges are classified as private, and traffic between private ranges is considered internal.

Administrators can edit, add or remove those ranges. The separate IDPS bypass list excludes selected addresses or subnets from filtering; Microsoft cautions that it is not intended as a throughput-improvement mechanism. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/firewall/premium-features).

## Applicability

Identify the relevant source and destination ranges and their intended network roles. Keep IDPS direction classification separate from routing, network-rule permission and a filtering bypass.

## DSE recommendation

DSE recommends reviewing the address plan against the private-range definition before interpreting unexpected signature behavior. Have the network and security owners agree on the intended classification, including internally used space outside the default ranges. Correct an approved classification mismatch rather than immediately disabling a signature or bypassing an entire subnet.

## Verification

Use authorized representative flows to compare their addresses and expected direction with the current IDPS configuration and signature scope. Preserve the pre-change definition and observed results. After an approved adjustment, retest both the intended path and an adjacent path that should retain its classification. Document unresolved differences without claiming that direction classification alone proves complete threat detection.

## Official references

[Microsoft Learn: Azure Firewall Premium features implementation guide](https://learn.microsoft.com/en-us/azure/firewall/premium-features). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure Firewall Premium features implementation guide | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/firewall/premium-features
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check IDPS private ranges before interpreting Azure Firewall traffic direction,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-404-check-idps-private-ranges-before-interpreting-azure-firewall-traffic-direction/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
