Azure Virtual Network - Street-Level Ops¶
Hub-and-Spoke¶
A common enterprise topology:
on-premises
|
VPN / ExpressRoute
|
connectivity hub VNet
├── Azure Firewall or NVA
├── DNS Private Resolver
├── Bastion / shared operations
└── gateway resources
|
+-- spoke VNet: application A
+-- spoke VNet: application B
+-- spoke VNet: shared data
Spokes peer to the hub. Because peering is non-transitive, routing between spokes normally uses:
- An NVA/Azure Firewall with UDRs.
- Azure Virtual Network Manager routing/connectivity features.
- Direct spoke-to-spoke peering where justified.
Secure Subnet Build¶
rg=rg-sre-lab
location=eastus
vnet=vnet-platform
subnet=snet-app
az network vnet create \
--resource-group "$rg" \
--location "$location" \
--name "$vnet" \
--address-prefixes 10.50.0.0/16 \
--subnet-name "$subnet" \
--subnet-prefixes 10.50.10.0/24
az network nsg create \
--resource-group "$rg" \
--location "$location" \
--name nsg-app
az network nsg rule create \
--resource-group "$rg" \
--nsg-name nsg-app \
--name allow-https-from-gateway \
--priority 200 \
--direction Inbound \
--access Allow \
--protocol Tcp \
--source-address-prefixes 10.50.1.0/24 \
--destination-port-ranges 443
az network vnet subnet update \
--resource-group "$rg" \
--vnet-name "$vnet" \
--name "$subnet" \
--network-security-group nsg-app \
--default-outbound-access false
The last flag depends on CLI/API support; validate it in the deployed API version. The architectural intent is explicit egress, not reliance on platform default outbound.
NAT Gateway Pattern¶
az network public-ip create \
--resource-group "$rg" \
--name pip-nat-app \
--sku Standard \
--allocation-method Static
az network nat gateway create \
--resource-group "$rg" \
--name nat-app \
--public-ip-addresses pip-nat-app \
--idle-timeout 10
az network vnet subnet update \
--resource-group "$rg" \
--vnet-name "$vnet" \
--name "$subnet" \
--nat-gateway nat-app
NAT Gateway is outbound-only. It does not provide inbound DNAT, packet inspection, URL filtering, or east-west segmentation.
Peering Pattern¶
Both links are required:
az network vnet peering create \
--resource-group rg-hub \
--vnet-name vnet-hub \
--name hub-to-app \
--remote-vnet /subscriptions/.../resourceGroups/rg-app/providers/Microsoft.Network/virtualNetworks/vnet-app \
--allow-vnet-access
az network vnet peering create \
--resource-group rg-app \
--vnet-name vnet-app \
--name app-to-hub \
--remote-vnet /subscriptions/.../resourceGroups/rg-hub/providers/Microsoft.Network/virtualNetworks/vnet-hub \
--allow-vnet-access \
--use-remote-gateways
The hub side must allow gateway transit before a spoke can use remote gateways.
Forced Tunneling and Inspection¶
To send outbound traffic through Azure Firewall/NVA:
- Create route table.
- Add
0.0.0.0/0with next hopVirtualApplianceand firewall private IP. - Associate route table with workload subnets.
- Ensure the appliance has IP forwarding and correct return routing.
- Preserve required platform/service routes or use service tags/private endpoints deliberately.
Do not place an arbitrary default route on GatewaySubnet; it can break VPN/ExpressRoute gateway operation.
Private Link Pattern¶
For a storage account:
- Disable or restrict public network access.
- Create private endpoint for
blob. - Create/link
privatelink.blob.core.windows.netPrivate DNS zone. - Ensure on-premises DNS forwards the private zone into Azure.
- Validate from each network path with
dig,nslookup, connection tests, and service logs.
Treat DNS as part of the resource deployment, not a post-deployment ticket.
Troubleshooting Workflow¶
Use:
az network nic show-effective-route-table.az network nic list-effective-nsg.- Network Watcher connection troubleshoot.
- NSG flow logs/virtual network flow logs according to current support.
- Packet capture.
- Azure Firewall/NVA logs.
- DNS resolution from the actual workload namespace.
- Guest
ip route,ss,nft list ruleset,tcpdump.
The effective state is the composition of system routes, UDRs, BGP routes, peering, NSGs at subnet and NIC, platform security admin rules, guest firewall, and service firewall.