VNET Peering > Hub > Spoke and Azure Firewall

Zero Trust Solutions 0 Reputation points
2025-02-17T09:26:02.8466667+00:00

Hi,

Inquiry on Hub - Spoke Peering with Azure Firewall in Spoke subscription. Please advise how to configure the routing in Hub and Spoke with Azure Firewall in spoke. In addition, hub has a site to site VPN to on-premise.

Thanks,

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,647 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Ganesh Patapati 3,765 Reputation points Microsoft Vendor
    2025-02-18T13:02:24.0166667+00:00

    @Zero Trust Solutions

    In a traditional hub-and-spoke model, spokes cannot communicate directly with each other unless routed through the hub.

    1. for, Transit connectivity cannot be achieved as per the documentation.
      User's image

    Refer: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq#if-i-peer-vneta-to-vnetb-and-i-peer-vnetb-to-vnetc-does-that-mean-vneta-and-vnetc-are-peered

    Another possible solution,

    1. Implementing Azure Virtual WAN can facilitate transitive connectivity between spokes without needing to route traffic through the hub. This service allows for any-to-any connectivity.

    Refer: https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-about

    Refer: https://learn.microsoft.com/en-us/azure/architecture/networking/architecture/hub-spoke-vwan-architecture

    Refer: https://learn.microsoft.com/en-us/azure/virtual-wan/scenario-route-through-nvas-custom

    Refer: https://learn.microsoft.com/en-us/azure/virtual-wan/scenario-route-through-nva


    I hope this has been helpful!

    If above is unclear and/or you are unsure about something add a comment below.

    Your feedback is important so please take a moment to accept answers. If you still have questions, please let us know what is needed in the comments so the question can be answered. Thank you for helping to improve Microsoft Q&A!

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.