{"id":62010,"date":"2026-08-30T21:04:24","date_gmt":"2026-08-30T21:04:24","guid":{"rendered":"https:\/\/www.eccentrix.ca\/?p=62010"},"modified":"2026-08-31T19:21:04","modified_gmt":"2026-08-31T19:21:04","slug":"azure-hub-and-spoke-architecture","status":"publish","type":"post","link":"https:\/\/www.eccentrix.ca\/en\/eccentrix-corner\/azure-hub-and-spoke-architecture\/","title":{"rendered":"Azure hub-and-spoke networking: the field checklist (DNS, routing, NSG, Firewall)"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"62010\" class=\"elementor elementor-62010 elementor-61776\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1a96984f e-flex e-con-boxed e-con e-parent\" data-id=\"1a96984f\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-58bac4a elementor-widget elementor-widget-heading\" data-id=\"58bac4a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\nWhy the Azure hub-and-spoke model remains the \u201cdefault\u201d in the enterprise<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4e9eab47 elementor-widget elementor-widget-text-editor\" data-id=\"4e9eab47\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Azure hub-and-spoke isn&#8217;t &#8220;just&#8221; a VNet scheme. It&#8217;s an operating model: centralizing shared services (security, connectivity, DNS, inspection) in a hub, and isolating workloads (applications, environments, business units) in spokes.<\/p><p>The goal: to reduce complexity, better control traffic flow, and make governance more predictable (and auditable).<\/p><p>But in practice, most incidents stem from details: a poorly designed DNS, a UDR route that breaks a connection, an overly permissive &#8220;temporary&#8221; NSG, or a firewall inspection that was never aligned with application requirements.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-362c907 elementor-widget elementor-widget-image\" data-id=\"362c907\" data-element_type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/learn.microsoft.com\/fr-ca\/azure\/architecture\/networking\/architecture\/hub-spoke\" target=\"_blank\" rel=\"noopener\">\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/www.eccentrix.ca\/wp-content\/uploads\/elementor\/thumbs\/hub-and-spoke-azure-scaled-rsooh1k8chqepcl80l4f63gw4kct5en0a5l69caj6o.png\" title=\"hub and spoke azure\" alt=\"hub and spoke azure\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Hub-and-spoke Azure Architecture - Microsoft Learn<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3889cf1 elementor-widget elementor-widget-heading\" data-id=\"3889cf1\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The \"network\" checklist before even drawing the diagram<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2278df5 elementor-widget elementor-widget-text-editor\" data-id=\"2278df5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Before creating VNets, clarify these points:<\/p><ul><li>Segmentation: Which spokes (production\/non-production, by application, by business unit)?<\/li><li>Connectivity: Direct outbound internet, via firewall, via NVA, via proxy?<\/li><li>On-premises: VPN, ExpressRoute, both, and which failover model?<\/li><li>DNS: Internal resolution, private zones, split-horizon, AD DS integration?<\/li><li>Inspection: Which flows should be inspected (north-south, east-west)?<\/li><li>Private vs. public: Generalized private endpoint or on a case-by-case basis?<\/li><li>Observability: Network logs, flow logs, alerting, standardized diagnostics.<\/li><\/ul><p>If these decisions are not made, the Azure hub-and-spoke becomes a tightly wired, unmanageable &#8220;spaghetti&#8221; network.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d8ecc5c elementor-widget elementor-widget-heading\" data-id=\"d8ecc5c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Design checklist: peering, routing, and transit<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b84acca elementor-widget elementor-widget-heading\" data-id=\"b84acca\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">1. VNet Peering: simple\u2026 until transit<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e978d44 elementor-widget elementor-widget-text-editor\" data-id=\"e978d44\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.eccentrix.ca\/en\/eccentrix-corner\/understanding-the-difference-between-vpn-and-vnet-peering-in-azure\/\" target=\"_blank\" rel=\"noopener\">Peering<\/a><\/span>\u00a0is quick to set up, but you must decide explicitly:<\/p><ul><li>Allow forwarded traffic (if you have Firewall\/NVA)<\/li><li>Use remote gateways \/ Allow gateway transit (if the hub carries the gateway)<\/li><li>Topology: single hub, regional hubs, or global hub + local hubs<\/li><\/ul><p>Key point: peering is not transitive. You need to design the transit through hub (and associated routing), otherwise the spokes don&#8217;t \u201csee\u201d as expected.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d689083 elementor-widget elementor-widget-heading\" data-id=\"d689083\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">2. Routing: UDR, BGP, and \u201cwho decides the path\u201d<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-705ab83 elementor-widget elementor-widget-text-editor\" data-id=\"705ab83\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Routing is often the number one source of surprises.<\/p><ul><li>UDR (User Defined Routes): useful for forcing traffic through firewalls\/NVAs<\/li><li>BGP: useful with ExpressRoute\/VPNs, but can introduce unexpected routes<\/li><li>Priority: a UDR can overload system routes and break a flow that worked yesterday<\/li><\/ul><p>Routing checklist:<\/p><ul><li>Define on-premises, spoke, and shared service prefixes<\/li><li>Document routing tables per subnet (not just per VNet)<\/li><li>Validate the internet exit path (SNAT, inspection, exceptions)<\/li><li>Test critical flows: DNS, AD, updates, PaaS access, external APIs<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a5dd235 elementor-widget elementor-widget-heading\" data-id=\"a5dd235\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Security checklist: NSG, Azure Firewall, and realistic micro-segmentation<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fefd8bc elementor-widget elementor-widget-heading\" data-id=\"fefd8bc\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">NSG: the bare minimum (but not enough)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-28554e7 elementor-widget elementor-widget-text-editor\" data-id=\"28554e7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>NSGs are ideal for L3\/L4 segmentation close to workloads.<\/p><ul><li>Standardize <strong>patterns<\/strong> (spoke-app, spoke-data, management)<\/li><li>Avoid &#8220;Any\/Any&#8221; rules, even temporary ones<\/li><li>Use <strong>Application Security Groups (ASGs)<\/strong> to reduce rule debt<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-362160b elementor-widget elementor-widget-heading\" data-id=\"362160b\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Azure Firewall: The place where it all ends up<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-04efd9a elementor-widget elementor-widget-text-editor\" data-id=\"04efd9a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If you centralize inspection, you must treat Azure Firewall as an operational product:<\/p><ul><li><strong>Policy-as-code<\/strong> (or at a minimum: versioning + change management)<br \/><strong>Network<\/strong> vs. <strong>application<\/strong> rules (FQDN): clarify intent<\/li><li><strong>DNAT<\/strong>: document entries (and justify them)<\/li><li>Logs: enable and leverage them (don&#8217;t just &#8220;collect&#8221;)<\/li><\/ul><p>Common pitfall: you enable the Firewall, then discover that PaaS flows (Storage, Key Vault, ACR) require a clear policy (Private Endpoint, service endpoints, or controlled exceptions).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f75a007 elementor-widget elementor-widget-heading\" data-id=\"f75a007\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">DNS & Private Endpoints: Where architectures are won (or lost)\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7e403f elementor-widget elementor-widget-text-editor\" data-id=\"d7e403f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>DNS is often underestimated, especially when Private Endpoints are widely adopted.<\/p><p>DNS Checklist:<\/p><ul><li>Choose the model: Azure DNS Private Resolver, DNS servers in the hub, AD DS, or hybrid<\/li><li>Create the necessary Private DNS Zones (per service)<\/li><li>Link the zones to the relevant VNets (hub + spokes)<\/li><li>Manage split-horizon (same name, different internal\/external resolution)<\/li><li>Test resolution from each spoke (not just from the hub)<\/li><\/ul><p>If you use Private Endpoints without consistent DNS, you will experience unusual symptoms: intermittent timeouts, access working from one spoke but not another, or applications falling back to public endpoints.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c2a1f91 elementor-widget elementor-widget-heading\" data-id=\"c2a1f91\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Observability: what you need to activate from day 1<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4150c60 elementor-widget elementor-widget-text-editor\" data-id=\"4150c60\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li><strong>NSG Flow Logs<\/strong> (and an actionable retention strategy)<\/li><li><strong>Azure Firewall logs<\/strong> (Application + Network + Threat Intel if used)<\/li><li><strong>Connection Monitor<\/strong> for critical flows<\/li><li><strong>Standardized diagnostic<\/strong> settings (policy)<\/li><li>A minimal dashboard: top denials, top flows, top destinations, anomalies<\/li><\/ul><p>Without observability, you&#8217;re debugging randomly. With it, you reduce MTTR and secure changes.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7b65079 elementor-widget elementor-widget-heading\" data-id=\"7b65079\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The final test: 10 validations before saying \u201cit\u2019s ready\u201d<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b35b6a0 elementor-widget elementor-widget-text-editor\" data-id=\"b35b6a0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li style=\"font-weight: 400;\" aria-level=\"1\">Internal DNS resolution OK (hub + each spoke)<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Expected PaaS access (public\/private) validated<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Compliant internet outbound traffic (SNAT, inspection, exceptions)<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">On-premises \u2194 spoke traffic validated (VPN\/ER)<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Spoke \u2194 spoke traffic (if allowed) validated via hub<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">NSG: no unjustified &#8220;open&#8221; rules<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Firewall: minimal rules, logging enabled, documented policy<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Monitoring: flow logs + basic alerting in place<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Documentation: diagram + routing + DNS + responsibilities<\/li><li style=\"font-weight: 400;\" aria-level=\"1\">Incident runbook: &#8220;where to look first&#8221; (DNS, routes, NSG, Firewall)<\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-57caf6b elementor-widget elementor-widget-heading\" data-id=\"57caf6b\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Training: AZ-700 (and reinforcement with AZ-104)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-795c4bd elementor-widget elementor-widget-text-editor\" data-id=\"795c4bd\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If you design, secure, or troubleshoot Azure networks, the <a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/microsoft\/azure\/microsoft-certified-azure-network-engineer-associate-az700\/\" target=\"_blank\" rel=\"noopener\">Azure Network Engineer Associate (AZ-700)<\/a> certification course is an excellent framework for structuring your skills in connectivity, security, DNS, hybrid networks, and troubleshooting.<\/p><p>If you want to strengthen your broader Azure administration skills (identity, compute, storage, governance), the <a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/microsoft\/azure\/microsoft-certified-azure-administrator-associate-az104\/\" target=\"_blank\" rel=\"noopener\">Azure Administrator AZ-104<\/a> course is a great complement.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a76984c elementor-widget elementor-widget-heading\" data-id=\"a76984c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7a5c4f7 elementor-widget elementor-widget-accordion\" data-id=\"7a5c4f7\" data-element_type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1281\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-1281\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is Azure hub-and-spoke \u201cmandatory\u201d in business?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1281\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-1281\"><p>No, but it is often the most governable model at scale as soon as you need to standardize connectivity, inspection, DNS and segmentation across multiple environments\/teams.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1282\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-1282\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the #1 mistake in a hub-and-spoke design?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1282\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-1282\"><p>Do not decide (and test) the DNS + Private Endpoints model from the start: private zones, VNet links (hub + spokes), hybrid resolution, split-horizon.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1283\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-1283\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Does VNet peering make the spokes transitive through the hub?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1283\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-1283\"><p>No. Peering is not transitive. Spoke\u2194spoke transit \u201cvia hub\u201d must be explicitly designed (routing\/UDR + security + possible inspection).<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1284\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-1284\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Forced tunneling ou split tunneling : lequel choisir ?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1284\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-1284\"><p>Forced tunneling = centralized control\/inspection but complexity (UDR, SNAT, SaaS dependencies).<\/p><p>Split tunneling = simpler, but less centralized control. Choose according to your inspection and compliance requirements.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1285\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-1285\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Why does \u201cit sometimes work\u201d but not the time-out app?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1285\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-1285\"><p>Often this is due to asymmetric routing (outgoing through Firewall\/NVA, different return path) or inconsistent DNS between spokes. This is the classic source of \u201cintermittent\u201d outages.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1286\" class=\"elementor-tab-title\" data-tab=\"6\" role=\"button\" aria-controls=\"elementor-tab-content-1286\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">NSG vs Azure Firewall: Are NSGs sufficient?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1286\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"6\" role=\"region\" aria-labelledby=\"elementor-tab-title-1286\"><p>Often this is due to asymmetric routing (outgoing through Firewall\/NVA, different return path) or inconsistent DNS between spokes. This is the classic source of \u201cintermittent\u201d outages.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Why the Azure hub-and-spoke model remains the \u201cdefault\u201d in the enterprise Azure hub-and-spoke isn&#8217;t &#8220;just&#8221; a VNet scheme. It&#8217;s an operating model: centralizing shared services (security, connectivity, DNS, inspection) in a hub, and isolating workloads (applications, environments, business units) in spokes. The goal: to reduce complexity, better control traffic flow, and make governance more predictable [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":61835,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jet_sm_ready_style":"","_jet_sm_style":"","_jet_sm_controls_values":"","_jet_sm_fonts_collection":"","_jet_sm_fonts_links":"","footnotes":""},"categories":[84],"tags":[],"class_list":["post-62010","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-eccentrix-corner"],"_links":{"self":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/62010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/comments?post=62010"}],"version-history":[{"count":8,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/62010\/revisions"}],"predecessor-version":[{"id":62081,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/62010\/revisions\/62081"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/media\/61835"}],"wp:attachment":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/media?parent=62010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/categories?post=62010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/tags?post=62010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}