Azure VWAN HUBs

JMN-2253 576 Reputation points
2023-03-24T20:21:21.3166667+00:00

Hi There,

We have 10 VNETs in 2 Locations: West US 2 and North Europe.

Each location has a number of VMs and App Services.

We are spanning over 100 remote locations (including ER, VPN S2S and P2S).

We are considering Azure Virtual WAN Standard SKUs.

Overall, we are planning to have 2 Hubs (1xWest US 2 and 1xNorth Europe).

We have 2 questions:

Is having 2 Hubs the best Best? or single Hub? (if a single hub, then where it should be located)?

If we decided to go with Azure Firewall, then should we deploy 2 Azure Firewalls (one in each region) or what?

Thanks

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
189 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,158 questions
0 comments No comments
{count} votes

Accepted answer
  1. Erkan Sahin 830 Reputation points
    2023-03-25T11:23:51.2366667+00:00

    Having two hubs, one in West US 2 and one in North Europe, is a good approach for your scenario. This will ensure that your remote locations are connecting to the hub that is closest to them, which can help to reduce latency and improve performance.

    Regarding Azure Firewall, you can deploy two Azure Firewalls, one in each region, and then configure them to work together in an active-standby or active-active configuration. This will provide redundancy and ensure that traffic can be routed through the available firewall in case one of them fails. Alternatively, you can also consider deploying Azure Firewall in a centralized manner, which means deploying it in one of the hubs and then routing all traffic through it using User-Defined Routes (UDRs). This approach can help to simplify management and reduce costs, but it may not be suitable if you have specific compliance or regulatory requirements that mandate traffic to be routed locally.

    Please mark if my answer is helpful :-)


0 additional answers

Sort by: Most helpful