Virtual WAN Internet traffic Routing via third party NVA but the spoke vnets should be directly connected to virtual hub

SudhirKumar Sampathkumar 25 Reputation points
2024-02-20T22:25:32.4233333+00:00

Scenario:

  • spoke vnets svnet1 ,svnet2, svnet3 is connected to virtual hub
  • NVA Vnet nvavnet is connected to virtual hub
  • Expressroute connected to virtual hub
  • svnet1 and svnet2 are isolated but should be reached by Express route

Expectation:

  • VM's in svnet1 should be reachable through on-prem(ER)
  • VM's in svnet1 and svnet2 should not be reachable (Isolated vnets)
  • VM's in svnet3 should reach VM's in snvet1 and 2
  • Only Internet traffic should go through nvavnet (palo alto)

User's image

since the spokes vnets needs to be connected directly to vhub and only internet connection needs to go to nva vnet, I did not find any documentation with this scenario.

Moreover, I see that this scenario might not be supported per below article https://learn.microsoft.com/en-us/azure/virtual-wan/scenario-route-through-nva

User's image

Can you please let me know if this scenario is possible and another thing I observed is that, the vnet isolation works only if I turn off the "Propagate to default route" switch in connections. Not sure if that is the expected behavior

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
188 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,149 questions
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 23,026 Reputation points Microsoft Employee
    2024-02-21T04:06:33.4666667+00:00

    @SudhirKumar Sampathkumar

    Thank you for reaching out.

    Based on your question above.

    since the spokes vnets needs to be connected directly to vhub and only internet connection needs to go to nva vnet, I did not find any documentation with this scenario.

    I think this architecture is described in this article here

    User's image

    In the Architecture described above

    • All internet bound traffic from VNets 1, 2, and 3 is expected to go via VNet 5 NVA 10.5.0.5.
    • For internet-bound traffic to go via VNet 5, you need VNets 1, 2, and 3 to directly connect via virtual network peering to VNet 5. You also need a user-defined route set up in the virtual networks for 0.0.0.0/0 and next hop 10.5.0.5.

    Which I think satisfies your requirement above.

    Regarding your question related to "Propagate to default route". I do not think you need enable this property as you only change this setting to Enable if you know you want to propagate the default route. As in the scenario above the default route will be applied for the VNET peering connection.

    Hope this helps! Please let me know if you have any additional questions.


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Q&A Assist
    2024-02-20T22:25:32.4266667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    It is possible to route Virtual WAN internet traffic through a third-party NVA while having spoke VNets directly connected to the virtual hub. However, the scenario you described, where some VNets are isolated and some are not, may not be supported. According to the documentation, VNet isolation works only if the "Propagate to default route" switch in connections is turned off. As for the specific scenario you described, I couldn't find any documentation that supports it.

    References:

    0 comments No comments