A security team wants Azure Firewall to resolve FQDNs in network rules.What must be configured in the firewall policy to enable this?