Forum Discussion
Vibin_Balagopal1988
Jul 26, 2022Copper Contributor
Azure vWAN (hybrid connectivity enabled with OnPrem DC) data packet flow - inbound and outbound
Could anyone explain me the end to end to Inbound and Outbound data packet flow in Azure vWAN Hub connectivity through EC between OnPrem and Azure Cloud? Consider we've Azure FW enabled. Multipl...
Kidd_Ip
Oct 25, 2025MVP
Below the End-to-End Packet Flow in Azure vWAN (Hybrid Setup)
Ingress Traffic (On-Prem → Azure VMs)
- On-Premises Gateway: Traffic originates from your on-prem DC or branch.
- ExpressRoute Gateway (EC GW): Connects to Azure via ExpressRoute circuit.
- vWAN Hub Router: EC terminates at the vWAN Hub, which routes traffic.
- Azure Firewall (Secured Hub): Traffic is inspected and filtered.
- NSG (Network Security Group): Applies subnet-level access control.
- Destination VMs: Traffic reaches the target VM in connected VNET.
Egress Traffic (Azure VMs → On-Prem)
- Source VMs: Initiate outbound traffic.
- NSG: Applies outbound rules.
- Azure Firewall: Traffic is inspected and routed.
- vWAN Hub Router: Routes traffic to EC GW.
- ExpressRoute Gateway (EC GW): Sends traffic to on-premises.
- On-Prem Gateway: Receives traffic.