The square design with hub-and-spoke

This is a continuation from my previous post Azure Route Server route maps: more than a feature, where I discussed some of the patterns not supported by route maps in Azure Route Server (ARS), such as VNet-to-VNet VPN connections and BGP peers in another hub (although these ones might be addressed by the time route … Continue reading The square design with hub-and-spoke

Azure Route Server route maps: more than a feature

If you have been following the Azure Networking space lately, you will probably have noticed the global preview of a new feature: route maps for Azure Route Server. Others have already blogged about this; for example, make sure to read Simon Painter’s blog post about it here. I finally had some time to try it, … Continue reading Azure Route Server route maps: more than a feature

Many-regions networking with Azure Route Server

The AI era has brought many good things: from endless cat videos to applications vibe-coded during the lunch break, but there is also something else they have brought to the table: capacity issues in public clouds. If you are a user of public cloud, you have probably experienced this problem: the virtual machine size you … Continue reading Many-regions networking with Azure Route Server

Connecting Microsoft Fabric to on-premises databases with Private Link

Azure Networking is already a complex enough topic, and if you add to the mix the moving parts of data analytics services the results are always interesting, to say the least. On top of that, documentation is not always created to explain in detail what is actually happening or why, adding insult to injury. Consequently, … Continue reading Connecting Microsoft Fabric to on-premises databases with Private Link

Private Link reality bites – Private endpoints are an illusion

Welcome to this new series of blog posts in which I will be explaining some not-so-well-known facts about Azure Private Link and some associated technologies! This idea is born from the fact that I have been helping some colleagues and customers lately with some questions around Private Link, and that has made me realize that … Continue reading Private Link reality bites – Private endpoints are an illusion

Interregional traffic in hub-and-spoke

In Azure you have two main ways of managing your virtual network connectivity: self-managed hub-and-spoke and Virtual WAN. Virtual WAN is a solution where Microsoft manages part of your virtual networks for you, and in exchange it gives you some benefits such as any-to-any routing out of the box. However, what if you need that … Continue reading Interregional traffic in hub-and-spoke

Simulating VPN sites in Azure with Ubuntu 24.04 and StrongSwan

Disclaimer: this post is going to be quite geeky. So this is not the kind of post you want to read if you don’t need this stuff. But hey, I needed to tell someone after getting this to work, plus this might be useful for somebody else, since I struggled to find these details out … Continue reading Simulating VPN sites in Azure with Ubuntu 24.04 and StrongSwan

Do not let ExpressRoute, VPN and SDWAN traffic bypass your firewall

I have recently expanded my SDWAN in hub-and-spoke networks design guide to include SDWAN-to-firewall routing. Initially I didn’t have this point, but recent conversations have made me realize that not everybody understand this. The main difficulty in this topic is related to the fact that you cannot inspect the effective routes of your Virtual Network … Continue reading Do not let ExpressRoute, VPN and SDWAN traffic bypass your firewall

Monitoring Azure Networks with Alerts

Monitoring is one of those underrated disciplines: everybody tells you to do it, but nobody tells you exactly how. As a consequence, there are many different approaches and few concrete recommendations. Before continuing, a word of caution: I am not going to cover introductory topics in this post. If you are not familiar with Virtual … Continue reading Monitoring Azure Networks with Alerts

You want to use AS-path as your virtual hub routing preference

Wow, that was a long title. Let me give you another one: if you haven’t tested your High Availability (HA) or Disaster Recovery (DR) plans, you shouldn’t rely on them. This is of course regardless of whether your infrastructure runs on your premises, on public cloud, or anywhere else. In this post I am going … Continue reading You want to use AS-path as your virtual hub routing preference