Public Connectivity with Azure Virtual WAN

Azure Virtual WAN enables you to achieve robust and scalable public connectivity for your virtual networks and on-premises sites. This article details the different methods and considerations for enabling public access through your Virtual WAN hub.

Understanding Public Connectivity

Public connectivity in the context of Virtual WAN typically refers to the ability for resources within your Azure environment, or connected on-premises sites, to access the public internet. This is often achieved through a Virtual WAN hub, which acts as a central point for traffic routing and policy enforcement.

Key scenarios include:

Methods for Public Connectivity

1. Virtual WAN Hub as an Internet Gateway

The Virtual WAN hub can be configured to act as a universal internet gateway. When you deploy a Virtual WAN hub, you can enable an option to route internet-bound traffic from connected VNets and remote sites through the hub to the public internet.

Configuration Steps:

  1. Ensure your Virtual WAN hub is deployed.
  2. Associate your Azure VNets with the Virtual WAN hub.
  3. Configure a Virtual WAN connection for your on-premises VPN sites or ExpressRoute circuits.
  4. In the Virtual WAN hub configuration, enable the "Internet routing" or similar option. This typically involves associating a Public IP address with the hub's gateway.
  5. Route tables within the hub will direct internet-bound traffic appropriately.

Diagram:

Virtual WAN Hub as Internet Gateway

2. Using Network Virtual Appliances (NVAs)

For advanced inspection and filtering of internet-bound traffic, you can deploy Network Virtual Appliances (NVAs) such as firewalls or Unified Threat Management (UTM) devices within your Virtual WAN hub. Traffic destined for the internet is then routed through these NVAs.

Deployment Considerations:

This approach offers granular control over security policies, content filtering, and intrusion detection for internet traffic.

Key Features and Benefits

Pricing and Licensing

Public connectivity through Virtual WAN involves costs associated with the Virtual WAN hub itself, data transfer, and potentially NVAs if used. Refer to the Azure pricing page for detailed information.

Next Steps

To implement public connectivity, consider the following resources:

Important: Ensure you understand the routing implications within your Virtual WAN hub. Proper configuration of effective routes and route propagation is crucial for correct internet traffic flow.