Vnet peering vs vnet cloud networking?

David Kim 66 Reputation points
2020-07-29T21:52:45.937+00:00

1) Within the same region, Vnet peering which is a method of connecting vnets within the same subscription?
Why not just connect VNets to another vnet using a virtual firewall within the same cloud subscription? ( I thought Vnet peering is designed specifically to connect two different subscriptions within the same region? What is the need for vnet peering within the same subscription if high speed connections exist between data centers within the same region/

2) Can Vnet peering be used between two Vnets in separate subscriptions?

3) Would we need a transit gateway or a default gateway in connecting separate subscriptions only? Are the transit gateways needed when using the same subscription?

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,182 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. TravisCragg-MSFT 5,681 Reputation points Microsoft Employee
    2020-07-30T00:59:32.67+00:00

    Azure VNET Peering is a way to securely connect 2 Virtual Networks within Azure. When connected in the same region, latency times between the 2 networks will be the same as within the same network. When peering VNETs in different regions, traffic flows across the Azure backbone network to the new region.

    VNET Peering is an alternative to S2S VPNs, however it comes with some unique limits & constraints. VNET Peering tends to be faster than a VPN because traffic does not need to be encrypted and passed across VPN Gateways.

    1 & 2) The VNETS can be in the same or different subscriptions or tenants.

    3) Gateway Transit with VNET Peering is so that peered connections can access a remote gateway. Peered connections can only access other VNET's gateways in 1 direction of a connection. For example, if I have 2 VNETS in Azure, both with a VPN Gateway that connects to separate on-premise sites, only one of the VNETs will be able to communicate across the other VNETs Gateway. Gateway Transit allows you to configure the direction. The region or subscription does not matter for gateway transit.

    Please let me know if you need any additional information.

    0 comments No comments