As a TRE Administrator
I need every firewall deployment to have a management public IP
So that I can use upcoming Azure Firewall features
Acceptance criteria
- Deployments create a AzureFirewallManagementSubnet in the core virtual network, CIDR /26
- Create a second public IP for the firewall
- Specify the second public IP as the management IP.
- Provide a migration path which requires the firewall to be deallocated, additional IP assigned, and reallocated.