Can we connect multiple hub and spoke networks to a vWAN in the same region?

Renjit Aravind 1 Reputation point
2021-11-23T19:49:26.907+00:00

Hi All,

To address the security/business requirements, we have multiple hubs and spokes connected to on-prem via ER in the same region (Dev Hub, Prod Hub etc) . Now would like to move towards vWAN so wanted to know,

1) Would it be possible to connect multiple hubs from the same region to a vWAN hub?
2) What are the design and routing considerations?

**Noe - We are using Azure FW solution in the hub

I couldn't find any docs addressing multiple hubs from the same region so any helpful docs/links on this would be highly appreciated..

Please redirected to the correct the group by tagging.

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,029 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Renjit Aravind 1 Reputation point
    2021-11-24T18:27:00.647+00:00

    @Justin Bragg @Azure Network
    Thank you for the response.

    I have gone through that link earlier and it doesn't refer to a scenario about multiple hubs from the same region and its design considerations. So looking forward to get some help on this topic.

    0 comments No comments

  2. SaiKishor-MSFT 17,141 Reputation points
    2021-11-24T20:12:21.783+00:00

    @Renjit Aravind Thank you for reaching out to Microsoft Q&A. I understand that you were having questions regarding connecting Multiple Secured Hubs from the same region to vWAN. Answering your questions below,

    1) Would it be possible to connect multiple hubs from the same region to a vWAN hub?

    This is possible. As seen from the below architecture,

    152280-figure5.png

    These Secure Hubs can be in the same region or a different region. Irrespective of that this can be connected to the vWAN.

    2) What are the design and routing considerations?
    Please remember that Inter-hub processing of traffic via firewall is currently not supported. Traffic between hubs will be routed to the proper branch within the secured virtual hub, however traffic will bypass the Azure Firewall in each hub.
    For more design considerations regarding this setup, please refer to this document.
    Please let us know if you have any further questions and we will be glad to assist you further. Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.

    0 comments No comments