Do not treat a successful Azure Firewall packet capture as coverage of every instance

The documented success threshold is captures from at least half of the firewall's underlying compute instances.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

The documented success threshold is captures from at least half of the firewall's underlying compute instances.

Potentially affected

Azure Firewall packet-capture investigations with the required Management NIC enabled.

DSE recommendation

Record capture coverage limits, filters and stop conditions before drawing a negative traffic conclusion.

Source facts

Azure reports packet-capture success when at least half of the firewall’s underlying compute instances provide captures. The portal does not identify which instances contributed. Success therefore does not establish complete instance coverage.

A capture requires at least one filter and records matching traffic in both directions. Both a packet maximum and a time limit are required; whichever is reached first stops collection. The documented feature also requires an enabled Management NIC. Microsoft Learn.

Applicability

Review the actual capture prerequisites, approved storage destination, filters and diagnostic objective before collection. Keep capture-data access and retention under the organization’s security controls; this article is not a blanket approval for the storage settings in a tutorial.

DSE recommendation

DSE recommends preserving the success status together with its documented coverage limit. Describe a missing packet as absent from the collected evidence, not proof that no firewall instance processed it. Review whether filters and stop conditions were capable of observing the traffic in question before planning further collection. Broaden collection only with appropriate approval for the additional data.

Verification

Use a controlled test flow to check the intended capture filter and inspect the resulting files and timing. Compare the observed traffic with the selected protocol and stop limits. Record any unknown instance coverage explicitly and corroborate the investigation through other approved evidence where needed. Do not silently upgrade a successful collection status into a complete traffic history.

Official references

Microsoft Learn: Use Packet Capture to Troubleshoot Azure Firewall. Source retrieved September 9, 2026.

Primary reference

Review the official source

Use Packet Capture to Troubleshoot Azure Firewall | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE