Check IDPS private ranges before interpreting Azure Firewall traffic direction

The IDPS private-range definition determines inbound, outbound and internal classification used by direction-specific signatures.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

The IDPS private-range definition determines inbound, outbound and internal classification used by direction-specific signatures.

Potentially affected

Azure Firewall Premium IDPS deployments with address ranges requiring explicit direction classification.

DSE recommendation

Compare the actual address plan with IDPS private ranges before changing signature modes.

Source facts

Azure Firewall Premium IDPS uses configured private IP ranges to classify traffic as inbound, outbound or internal. Its signatures apply to specific directions. By default, only RFC 1918 ranges are classified as private, and traffic between private ranges is considered internal.

Administrators can edit, add or remove those ranges. The separate IDPS bypass list excludes selected addresses or subnets from filtering; Microsoft cautions that it is not intended as a throughput-improvement mechanism. Microsoft Learn.

Applicability

Identify the relevant source and destination ranges and their intended network roles. Keep IDPS direction classification separate from routing, network-rule permission and a filtering bypass.

DSE recommendation

DSE recommends reviewing the address plan against the private-range definition before interpreting unexpected signature behavior. Have the network and security owners agree on the intended classification, including internally used space outside the default ranges. Correct an approved classification mismatch rather than immediately disabling a signature or bypassing an entire subnet.

Verification

Use authorized representative flows to compare their addresses and expected direction with the current IDPS configuration and signature scope. Preserve the pre-change definition and observed results. After an approved adjustment, retest both the intended path and an adjacent path that should retain its classification. Document unresolved differences without claiming that direction classification alone proves complete threat detection.

Official references

Microsoft Learn: Azure Firewall Premium features implementation guide. Source retrieved September 9, 2026.

Primary reference

Review the official source

Azure Firewall Premium features implementation guide | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE