Skip to content

Azure Virtual Network - Street-Level Ops

Hub-and-Spoke

A common enterprise topology:

on-premises
    |
VPN / ExpressRoute
    |
connectivity hub VNet
  ├── Azure Firewall or NVA
  ├── DNS Private Resolver
  ├── Bastion / shared operations
  └── gateway resources
       |
       +-- spoke VNet: application A
       +-- spoke VNet: application B
       +-- spoke VNet: shared data

Spokes peer to the hub. Because peering is non-transitive, routing between spokes normally uses:

  • An NVA/Azure Firewall with UDRs.
  • Azure Virtual Network Manager routing/connectivity features.
  • Direct spoke-to-spoke peering where justified.

Secure Subnet Build

rg=rg-sre-lab
location=eastus
vnet=vnet-platform
subnet=snet-app

az network vnet create \
  --resource-group "$rg" \
  --location "$location" \
  --name "$vnet" \
  --address-prefixes 10.50.0.0/16 \
  --subnet-name "$subnet" \
  --subnet-prefixes 10.50.10.0/24

az network nsg create \
  --resource-group "$rg" \
  --location "$location" \
  --name nsg-app

az network nsg rule create \
  --resource-group "$rg" \
  --nsg-name nsg-app \
  --name allow-https-from-gateway \
  --priority 200 \
  --direction Inbound \
  --access Allow \
  --protocol Tcp \
  --source-address-prefixes 10.50.1.0/24 \
  --destination-port-ranges 443

az network vnet subnet update \
  --resource-group "$rg" \
  --vnet-name "$vnet" \
  --name "$subnet" \
  --network-security-group nsg-app \
  --default-outbound-access false

The last flag depends on CLI/API support; validate it in the deployed API version. The architectural intent is explicit egress, not reliance on platform default outbound.

NAT Gateway Pattern

az network public-ip create \
  --resource-group "$rg" \
  --name pip-nat-app \
  --sku Standard \
  --allocation-method Static

az network nat gateway create \
  --resource-group "$rg" \
  --name nat-app \
  --public-ip-addresses pip-nat-app \
  --idle-timeout 10

az network vnet subnet update \
  --resource-group "$rg" \
  --vnet-name "$vnet" \
  --name "$subnet" \
  --nat-gateway nat-app

NAT Gateway is outbound-only. It does not provide inbound DNAT, packet inspection, URL filtering, or east-west segmentation.

Peering Pattern

Both links are required:

az network vnet peering create \
  --resource-group rg-hub \
  --vnet-name vnet-hub \
  --name hub-to-app \
  --remote-vnet /subscriptions/.../resourceGroups/rg-app/providers/Microsoft.Network/virtualNetworks/vnet-app \
  --allow-vnet-access

az network vnet peering create \
  --resource-group rg-app \
  --vnet-name vnet-app \
  --name app-to-hub \
  --remote-vnet /subscriptions/.../resourceGroups/rg-hub/providers/Microsoft.Network/virtualNetworks/vnet-hub \
  --allow-vnet-access \
  --use-remote-gateways

The hub side must allow gateway transit before a spoke can use remote gateways.

Forced Tunneling and Inspection

To send outbound traffic through Azure Firewall/NVA:

  1. Create route table.
  2. Add 0.0.0.0/0 with next hop VirtualAppliance and firewall private IP.
  3. Associate route table with workload subnets.
  4. Ensure the appliance has IP forwarding and correct return routing.
  5. Preserve required platform/service routes or use service tags/private endpoints deliberately.

Do not place an arbitrary default route on GatewaySubnet; it can break VPN/ExpressRoute gateway operation.

For a storage account:

  1. Disable or restrict public network access.
  2. Create private endpoint for blob.
  3. Create/link privatelink.blob.core.windows.net Private DNS zone.
  4. Ensure on-premises DNS forwards the private zone into Azure.
  5. Validate from each network path with dig, nslookup, connection tests, and service logs.

Treat DNS as part of the resource deployment, not a post-deployment ticket.

Troubleshooting Workflow

Use:

  • az network nic show-effective-route-table.
  • az network nic list-effective-nsg.
  • Network Watcher connection troubleshoot.
  • NSG flow logs/virtual network flow logs according to current support.
  • Packet capture.
  • Azure Firewall/NVA logs.
  • DNS resolution from the actual workload namespace.
  • Guest ip route, ss, nft list ruleset, tcpdump.

The effective state is the composition of system routes, UDRs, BGP routes, peering, NSGs at subnet and NIC, platform security admin rules, guest firewall, and service firewall.