Azure Firewalls that processed under 1 MB and hit no rules in 30 days
What does ZopNight detect here?
ZopNight flags an Azure Firewall when `DataProcessed` stays under 1 MB and both `NetworkRuleHit` and `ApplicationRuleHit` stay under 1, on average and at peak, across at least 30 days, and the firewall has a known cost. Azure Firewall bills per deployment hour whether or not traffic passes, so an idle one is costly.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1365 |
| Category | idle |
| Severity | critical |
| Metric | DataProcessed, NetworkRuleHit, ApplicationRuleHit |
| Threshold | DataProcessed < 1 MB, rule hits < 1 |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | Microsoft.Network/azureFirewalls/read · Microsoft.Insights/Metrics/Read |
Where it applies
An always-on hourly charge for a firewall with no traffic
Azure Firewall pricing has two parts for each of the Basic, Standard and Premium SKUs: a price per deployment hour and a price per GB processed. The deployment hour is charged for as long as the firewall is allocated, even if no packet reaches it. The per-GB part falls to zero with the traffic; the hourly part does not.
Firewalls often outlive the network design that needed them, for example after a hub is moved to a different region or a spoke is decommissioned.
Checking a firewall’s traffic and rule hits
az network firewall list --query "[].{name:name, rg:resourceGroup, sku:sku.tier}" -o table
az monitor metrics list --resource <firewall-resource-id> \ --metric DataProcessed NetworkRuleHit ApplicationRuleHit --offset 30d --interval PT24H --aggregation Total Maximumaz network firewall commands come from the Azure CLI azure-firewall extension.
Three signals that must all be quiet
- All three series are present:
DataProcessed,NetworkRuleHitandApplicationRuleHit. - Their peak data covers at least 30 distinct days.
DataProcessedis below 1 MB on both average and peak.- Network and application rule hits are below 1 on both average and peak.
- The firewall has a known monthly cost above zero.
Each signal is a hard requirement. A firewall that processes a trickle of data but hits a rule now and then is doing its job.
Firewalls that are left running
Any activity on any of the three signals ends the check. So does a missing series or less than 30 days of history, because a firewall is too critical to act on thin evidence. The severity on this finding is critical for the cost reason alone; it does not mean ZopNight considers the firewall safe to remove without review.
What stopping the firewall recovers
saving = current monthly cost of the firewallcost after fix = 0 (deallocated or deleted)Deallocating or deleting an idle firewall
- Check every route table and virtual WAN hub route that sends traffic to the firewall’s private IP, and confirm the policy is not shared with a firewall that is still in use.
- To stop billing but keep the configuration, deallocate it with Azure PowerShell:
$azfw = Get-AzFirewall -Name "fw-name" -ResourceGroupName "rg-name", then$azfw.Deallocate()andSet-AzFirewall -AzureFirewall $azfw. Microsoft notes billing stops and starts with it, but the private IP can change when it is allocated again. - If it will not come back, delete it:
az network firewall delete --resource-group rg-name --name fw-name, then release its public IPs.