Do not expect Azure Firewall private SNAT ranges to preserve application-rule source addresses

The private-range setting controls network-rule SNAT; application rules always use source translation.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

The private-range setting controls network-rule SNAT; application rules always use source translation.

Potentially affected

Azure Firewall designs using custom private SNAT ranges and network or application rules.

DSE recommendation

Identify the actual rule type before changing private ranges to preserve a source address.

Source facts

Azure Firewall’s private SNAT range configuration applies only to network rules. Application rules always use SNAT. A destination’s inclusion in the private-range list therefore does not provide the same source-address behavior across both rule types.

A custom list must retain the default private ranges if those defaults are still required. When a firewall is associated with a Firewall Policy, configure the SNAT range in that policy; the firewall’s PrivateRange property is ignored. Microsoft Learn.

Applicability

Record the matching rule type, policy association, destination and expected source seen by the receiving service. Treat the SNAT private list separately from other controls that also classify addresses as private.

DSE recommendation

DSE recommends resolving the traffic’s actual rule path before proposing a range change. If the receiving service requires original client addresses, have its owner review the supported design rather than assuming a private-range exception solves application-rule traffic. Preserve intended default ranges and change the owning policy instead of an ineffective local property.

Verification

Use an approved test connection and inspect the source address at the receiver together with the matched firewall rule. Compare the observed result with the documented behavior for that rule type. Validate an intended network-rule change separately from application-rule traffic and confirm unrelated private destinations retain their approved behavior. Keep the effective policy and test evidence together.

Official references

Microsoft Learn: Azure Firewall SNAT private IP address ranges. Source retrieved September 9, 2026.

Primary reference

Review the official source

Azure Firewall SNAT private IP address ranges | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE