Network Security Group
An Azure Network Security Group (NSG) is a stateful firewall that filters inbound and outbound traffic to resources within a virtual network, using prioritized allow/deny rules evaluated in order by priority number. NSGs can be attached to a subnet, a network interface, or both, and Azure evaluates the combined rule set to decide whether traffic is permitted.
Network Security Group
An NSG filters traffic at the subnet or NIC level using ordered priority rules — lower numbers evaluate first, and the first match wins.
Why It Matters in Production
Swiggy's NSG on the database subnet denies all inbound traffic except from the application subnet's IP range on port 5432, so even a compromised public-facing VM can't directly reach the database over unexpected ports.
az network nsg rule create --resource-group swiggy-prod-rg
--nsg-name db-subnet-nsg --name allow-app-postgres
--priority 100 --source-address-prefixes 10.20.1.0/24
--destination-port-ranges 5432 --access Allow --protocol Tcp
SecurityNever leave RDP (3389) or SSH (22) open to
0.0.0.0/0— use Azure Bastion or a VPN instead of exposing management ports to the internet.
Frequently Asked Questions
How does an NSG attached to both a subnet and a NIC actually get evaluated?
For inbound traffic, Azure evaluates the subnet-level NSG first, then the NIC-level NSG — both must allow the traffic for it to reach the VM. For outbound traffic, it's the reverse: NIC-level NSG is evaluated first, then subnet-level. Within a single NSG, rules are evaluated in priority order (lower number = higher priority, 100-4096) and the first matching rule wins, with default rules at the bottom denying everything not explicitly allowed.
What's a common mistake when troubleshooting blocked traffic with NSGs?
Assuming a single NSG's rule list is the full picture is a common mistake — if both a subnet and a NIC have NSGs attached, a rule that looks correct in one can still be silently overridden by a deny in the other. Azure's Network Watcher 'IP flow verify' or 'effective security rules' tool exists specifically to show the combined, actually-enforced rule set, and should be the first stop when NSG behavior doesn't match what the rules seem to say.