There are many options for network connectivity when it comes to Azure VMware Solution. This post reviews utilizing a central hub network in Azure.
In the Hub VNet, create a User-Defined Route (UDR) to workloads in the Spoke VNet(s) with a next-hop of the NVA in the gateway subnet. Next, the destination traffic needs to get securely back to the source. The native behavior with Azure VNet peering will bypass the firewall. Disabling BGP route propagation will prevent routes from being learned dynamically via BGP from the gateway, ensuring that traffic doesn't go directly to the gateway of the peered network. From there, creating a default UDR with a next-hop of the NVA will send the return traffic back through the firewall.
Azure VWAN can be used instead of a Traditional Hub VNET or alongside it to provide transit from AVS to Azure and back to on-premises. Azure VWAN is a solid option for using Azure Firewall or large-scale, multisite/multi-regional deployments with several or more ExpressRoute and VPN connections. In a separate Hub Virtual Network, other operations can take place, such as using a 3rd party network appliance to route or filter traffic securely. The Hub VNet can also facilitate Layer-7 operations through Traffic Manager, Application Gateway, or enabling DDOS protection with WAF.
*Note: If you are in a location where Global Reach is unavailable, VWAN with route intent may be used as an alternative for secure transit over the ExpressRoutes between two secured hubs using Azure Firewall. For more information, please see How to configure Virtual WAN Hub routing policies - Azure Virtual WAN
In this video, Sabine Blair - Sr Cloud Solution Architect at Microsoft, will cover these scenarios and more.
Stay tuned for more Azure VMware Solution network scenarios.
Special thanks to Sabine Blair for taking the time to explain the scenario.
As always, please leave feedback so we can continue to improve and help you!
Amy Colyer
Resources:
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.