Explanation
Why the waste happens and who it affects.
Firewalls in development, test, lab and training environments are typically needed only during business hours, but they are deployed like production hubs and run 24x7, so nights and weekends are paid at the full deployment rate.
Azure Firewall can be deallocated and later allocated again with its configuration preserved, and Microsoft's Well-Architected guide recommends stopping deployments that don't need to run continuously. There is no portal stop button or built-in schedule: the documented method is an Azure PowerShell deallocate and allocate sequence, so it only happens where someone has automated it. The same environments also accumulate firewalls that no longer carry any traffic at all, which Microsoft recommends identifying from metrics and route tables and deleting.
Billing model
The pricing dimensions that drive this cost.
Azure Firewall billing has a fixed and a variable component, both per firewall deployment.
- Deployment hour
- A fixed hourly fee per firewall by SKU (Basic, Standard, Premium) charged regardless of scale; a partial hour is billed as a full hour
- Data processed
- A per-GB fee for traffic processed by the firewall
- Deallocated firewall
- Microsoft states that billing stops when the firewall is stopped (deallocated) and starts again when it is allocated
- Public IP addresses
- Standard static public IPs attached to the firewall are billed separately and continue to bill while the firewall is deallocated
How to detect
4 checks to find it in your estate.
- List Microsoft.Network/azureFirewalls in non-production subscriptions or tagged as dev, test or lab, and check whether any automation deallocates them
- Chart the Data processed (DataProcessed) and Throughput metrics by hour over several weeks; firewalls with near-zero traffic outside working hours are candidates for a schedule
- For firewalls with almost no traffic at any time, check Application rules hit count (ApplicationRuleHit) and Network rules hit count (NetworkRuleHit) and look for route tables whose next hop is the firewall's private IP; no hits and no routes suggest the firewall is unused
- In Cost Management, group Azure Firewall cost by resource and meter to see how much of each non-production firewall's cost is the fixed deployment fee versus data processed
How to fix
4 ways to remove the waste.
- Schedule deallocation outside working hours with an Azure Automation runbook that calls Deallocate() and Set-AzFirewall, and allocate again before working hours with Allocate() passing the virtual network and public IPs (and the management public IP for forced tunneling, or the virtual hub ID for a secured hub)
- Keep the virtual network in the same resource group as the firewall, as Allocate requires, and plan for the firewall's private IP possibly changing after allocation if route tables point to it
- Delete firewalls that have no rule hits and no routes pointing to them, after confirming with network owners; also remove their public IPs, which otherwise continue to bill
- Where a non-production firewall runs Premium without needing Premium features, also review the SKU choice covered in the separate Premium SKU inefficiency
Documentation
Vendor references for pricing and configuration.