
Am I missing something or Microsoft Docs completely skipped the Online and Corp Landing Zones designs
Hey all, I am I missing something? or does MS docs completely define how the Online and Corp zones should be built.
These areas are highly overlooked all I could find were these droplets of info:
and
There are no decision charts that explains how do deal with Traffic inspection centralization and placement of the zones. Then it completely misses the design about
- Coupled Internet and private security policies
- Rapid firewall rule sprawl and management overhead
- A single blast radius across all traffic types
- Throughput and SNAT scalability constraints
- Increased difficulty meeting regulatory separation requirements
- These issues become more pronounced as environments scale across regions and workloads.
Luckily found that the guarded knowledge was covered here in Blogs ! https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/designing-cloud-landing-zones-by-traffic-flow-a-defence%E2%80%91in%E2%80%91depth-dmz%E2%80%91first-archi/4524280
But my team is stuck with poor design now. Its too late (costly) for design change !