azure-networking-audit
Azure VNet Networking Security Audit
Cloud resource audit for Azure Virtual Network (VNet) architecture, network security posture, and hybrid connectivity. This skill evaluates provider-specific Azure networking constructs — VNet design, NSG priority- based rules, Azure Firewall rule collection groups, ExpressRoute circuits, VNet Peering topology, UDR forced tunneling, and Application Gateway placement — not generic cloud networking advice.
Scope covers VNet-layer networking: address space planning, subnet
delegation, NSG filtering, Azure Firewall inspection, hybrid connectivity
via ExpressRoute and VPN Gateway, and route management. Out of scope:
Azure Front Door CDN policies, Azure WAF custom rule authoring,
application-layer routing in Application Gateway path rules, and Azure
DNS zone management. Reference references/cli-reference.md for read-only
Azure CLI commands organized by audit step, and references/vnet-architecture.md
for the VNet packet flow model, NSG evaluation order, and ExpressRoute
routing architecture.