An unexpected friendship: subnet peering and advertised gateway prefixes

You might have read my previous blogs about subnet peering, like this introduction to subnet peering when it was launched and the effect of subnet peering on ExpressRoute routing a bit later. Subnet peering is a technique used in today a number of designs, one of them being the Firewall-as-a-Service (FWaaS) topology in SAP RISE. … Continue reading An unexpected friendship: subnet peering and advertised gateway prefixes

Optimal routing with ExpressRoute – Revisited

There are two articles in Microsoft documentation that contain the most important guidelines to configure routing over ExpressRoute: Optimize routing for Azure ExpressRoute Azure ExpressRoute: Designing for disaster recovery Both are good articles and describe correct design patterns, but they were written a long time ago and most readers struggle to map those concepts to … Continue reading Optimal routing with ExpressRoute – Revisited

Which Azure network design is cheaper?

If you have been reading some of my blog posts, you probably know that I have been working on Azure networking for a while. Part of that work has consisted of helping customers to create network architectures based on their requirements. Last week I got a similar ask from a colleague for a large-scale hub-and-spoke … Continue reading Which Azure network design is cheaper?

Azure Firewall and Service Endpoints

In my recent blog series Private Link reality bites I briefly mentioned the possibility of inspecting Service Endpoints with Azure Firewall, and many have asked for more details on that configuration. Here we go! First things first: what the heck am I talking about? Most Azure services such as Azure Storage, Azure SQL and many … Continue reading Azure Firewall and Service Endpoints

Private Link reality bites – service endpoints vs private link

Welcome to the sixth post in the Private Link Reality Bites series! Before we begin, let me recap the existing episodes of the series: Private Link reality bite #1: endpoints are an illusion (control plane vs data plane) Private Link reality bite #2: your routes might be lying (routing in virtual network gateways) Private Link reality bite #3: what’s … Continue reading Private Link reality bites – service endpoints vs private link

Private Link reality bites: what’s my source IP?

Welcome to the third post in the Private Link Reality Bites series! Before we begin, let me recap the existing episodes of the series: Private Link reality bite #1: endpoints are an illusion (control plane vs data plane) Private Link reality bite #2: your routes might be lying (routing in virtual network gateways) Private Link … Continue reading Private Link reality bites: what’s my source IP?

Private Link reality bites – Your routes might be lying

Welcome to the second post in the Private Link Reality Bites series! Before we begin, let me recap the existing episodes of the series: Private Link reality bite #1: endpoints are an illusion (control plane vs data plane) Private Link reality bite #2: your routes might be lying (routing in virtual network gateways) Private Link … Continue reading Private Link reality bites – Your routes might be lying

Do not let ExpressRoute, VPN and SDWAN traffic bypass your firewall

I have recently expanded my SDWAN in hub-and-spoke networks design guide to include SDWAN-to-firewall routing. Initially I didn’t have this point, but recent conversations have made me realize that not everybody understand this. The main difficulty in this topic is related to the fact that you cannot inspect the effective routes of your Virtual Network … Continue reading Do not let ExpressRoute, VPN and SDWAN traffic bypass your firewall

Designing your SDWAN and Firewall into Azure Hub and Spoke

Designing network connectivity in public cloud can very quickly become a daunting task. Of course, public cloud providers do offer native networking services, and with those it is fairly easy. This should always be your primary route (pun intended). For example, in the case of Azure, using Virtual WAN and its native integration with both … Continue reading Designing your SDWAN and Firewall into Azure Hub and Spoke

Deploy (Azure) Network-as-Code as a champ

Virtually every expert out there recommends following an Infrastructure-as-Code approach to manage Azure Networks, and even more so when dealing with traffic segmentation features such as firewall rulesets and network security groups (those tend to change more frequently than other resources). And yet, there is surprisingly little guidance on how to do so, and about … Continue reading Deploy (Azure) Network-as-Code as a champ