SlideShare a Scribd company logo
2
Most read
6
Most read
7
Most read
Azure Landing Zone (Azure Firewall/WAF)
Azure Firewall:
On-premises network Gateway subnet
UDR
Management
subnet
Hub
VNet
Web tier Business tier Data tier
App Services Managed Database
Jumpbox
VNet
Peering
(Bidirectional)
VNet
Peering
(Bidirectional)
VNet
(Spoke 1)
VNet
(Spoke 2)
1
Azure Landing Zone (NVA)
On-premises network Gateway subnet
UDR
Management
subnet
Hub
VNet
Web tier Business tier Data tier
VNet
(Spoke 2)
App Services Managed Database
VNet
Peering
(Bidirectional)
Jumpbox
Availability
set
Public DMZ in Public DMZ out
Availability
set
Private DMZ in Private DMZ out
VNet
Peering
(Bidirectional)
VNet
(Spoke 1)
https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/secure-vnet-dmz
2
Azure Network Architecture: Deployment to Primary Azure Region
On-premises Network HQ
Internet
VNet
Peering
(Bidirectional)
Prod Subscription
Prod Resource Group(s)*
Prod VNet
(Spoke 3)
10.xx.xx.xx/yy
10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz
Prod Management Group
Gateway Subnet
Hub
VNet
Firewall
Subnet
SIEM
Subnet
WAF
Subnet
Management
Subnet
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/yy
Hub Resource Group(s)*
Hub Subscription
Hub Management Group
VNet
Peering
(Bidirectional)
VNet
Peering
(Bidirectional)
Non-Prod Subscription
Dev Resource Group(s)*
Non-Prod Management Group
Dev VNet
(Spoke 1)
10.xx.xx.xx/yy
10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz
Test VNet
(Spoke 2)
10.xx.xx.xx/yy
10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz
Test Resource Group(s)*
Additional Resource Groups will be used for Azure resources as required for better
resource management and security control
*
P2S VPN Tunnel
S2S VPN Tunnel
HTTP/HTTPS
VPN Client
On-premises Network Site 2
S2S VPN Tunnel
3
Azure Network Architecture: with animation
VNet
Peering
(Bidirectional)
Prod Subscription
Prod Resource Group(s)*
Prod VNet
(Spoke 3)
10.xx.xx.xx/yy
10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz
Prod Management Group
Non-Prod Subscription
Dev Resource Group(s)*
Non-Prod Management Group
Dev VNet
(Spoke 1)
10.xx.xx.xx/yy
10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz
Test VNet
(Spoke 2)
10.xx.xx.xx/yy
10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz
Gateway Subnet
Hub
VNet
Firewall
Subnet
SIEM
Subnet
WAF
Subnet
Management
Subnet
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/zz
10.xx.xx.xx/yy
Hub Resource Group(s)*
Hub Subscription
Hub Management Group
Test Resource Group(s)*
VNet
Peering
(Bidirectional)
VNet
Peering
(Bidirectional)
Additional Resource Groups will be used for Azure resources as required for better
resource management and security control
*
On-premises Network HQ
Internet
P2S VPN Tunnel
S2S VPN Tunnel
HTTP/HTTPS
VPN Client
On-premises Network Site 2
S2S VPN Tunnel
4
Hub and Spoke Network Topology
VPN Client On-premises
Network HQ
On-premises
Network Site 2
Hub VNet
Hub Subnets
P2S VPN
Tunnel
S2S VPN
Tunnel
Gateway
Subnet
Spoke 2 VNet
Spoke 1 Subnets
Spoke 2 VNet
Spoke 2 Subnets
Spoke 3 VNet
Spoke 3 Subnets
Spoke 4 VNet
Spoke 4 Subnets
HTTP/
HTTPS
5
Hub and Spoke Topology
Benefits Drawbacks
Hub & Spoke  Easier to manage shared services
 Lower licensing costs
 Improved segregation
 Easy to scale
 Single point of failure
 Overhead of managing UDRs
Simplified  No single point of failure  Duplication of shared services (Firewall, SIEM)
 Higher licensing costs
 Challenging to scale
VPN Client On-premises
Network HQ
On-premises
Network Site 2
Hub VNet
Hub Subnets
P2S VPN
Tunnel
S2S VPN
Tunnel
Gateway
Subnet
Spoke 2 VNet
Spoke 1 Subnets
Spoke 2 VNet
Spoke 2 Subnets
Spoke 3 VNet
Spoke 3 Subnets
Spoke 4 VNet
Spoke 4 Subnets
HTTP/
HTTPS
6
Example Azure Network Plan: VNets & Subnets
ID vNET Subnet Netmask CIDR
# Of
hosts Subscription Security zone Gateway unit Gateway address
1 HUB 10.151.98.0 26 10.151.98.0/26 62 Hub HUB_SZ_MSS Microsoft Azure 10.151.98.1
2 HUB 10.151.96.0 26 10.151.96.0/26 62 Hub HUB_SZ_PRIVATE_DMZ Firewall 1(Internal) 10.151.96.1
3 HUB 10.151.97.0 24 10.151.97.0/24 254 Hub HUB_SZ_PUBLIC_DMZ Firewall 0 (External) 10.151.97.1
4 HUB 10.151.98.64 26 10.151.98.64/26 62 Hub HUB_SZ_JUMP_BOX Microsoft Azure 10.151.98.65
5 PROD 10.151.0.0 19 10.151.0.0/19 8190 Prod PROD_SZ_WORKLOAD1 Microsoft Azure 10.151.0.1
6 DEV 10.151.32.0 19 10.151.32.0/19 8190 Non-Prod DEV_SZ_NON_PROD Microsoft Azure 10.151.32.1
7 STAGING 10.151.64.0 19 10.151.64.0/19 8190 Non-Prod STAGING_SZ_NON_PROD Microsoft Azure 10.151.64.1
7

More Related Content

PPTX
Azure Networking (1).pptx
PPTX
Overview of Enterprise-scale landing zones using Cloud Adoption Framework Rea...
PDF
Azure landing zones - Terraform module design considerations - Azure Architec...
PDF
AWS Community Day 2022 Joe Daly FinOps
PDF
DataOps for the Modern Data Warehouse on Microsoft Azure @ NDCOslo 2020 - Lac...
PDF
CAF intro Hosters modern
PPTX
Microsoft Azure Networking Basics
PPTX
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Networking (1).pptx
Overview of Enterprise-scale landing zones using Cloud Adoption Framework Rea...
Azure landing zones - Terraform module design considerations - Azure Architec...
AWS Community Day 2022 Joe Daly FinOps
DataOps for the Modern Data Warehouse on Microsoft Azure @ NDCOslo 2020 - Lac...
CAF intro Hosters modern
Microsoft Azure Networking Basics
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar

What's hot (20)

PPTX
Let's Talk About: Azure Networking
PPTX
Azure: PaaS or IaaS
PPTX
Azure Introduction
PPTX
Azure App Service
PPTX
Azure migration
PPTX
Azure Migrate
PDF
Az 104 session 3 azure compute
PPTX
Introduction to Microsoft Azure
PPTX
Microsoft Azure cloud services
PPTX
Azure WAF
PPTX
Windows Azure Virtual Machines
PPTX
Microsoft azure
PDF
Microsoft Azure Active Directory
PDF
Azure DDoS Protection Standard
PPTX
Microsoft Azure Technical Overview
PPTX
Azure App Service Deep Dive
PDF
Azure Resource Manager (ARM) Templates
PPTX
Azure fundamentals
PDF
Azure Monitoring Overview
PDF
AWS Control Tower
Let's Talk About: Azure Networking
Azure: PaaS or IaaS
Azure Introduction
Azure App Service
Azure migration
Azure Migrate
Az 104 session 3 azure compute
Introduction to Microsoft Azure
Microsoft Azure cloud services
Azure WAF
Windows Azure Virtual Machines
Microsoft azure
Microsoft Azure Active Directory
Azure DDoS Protection Standard
Microsoft Azure Technical Overview
Azure App Service Deep Dive
Azure Resource Manager (ARM) Templates
Azure fundamentals
Azure Monitoring Overview
AWS Control Tower
Ad

Similar to Azure Hub spoke v1.0 (20)

PPTX
Microsoft Azure Hub_Spoke_Ampliado.pptx
PPTX
CCI2019 - Architecting and Implementing Azure Networking
PPTX
Securing your cloud perimeter with azure network security brk3185
PPTX
Azure Networking: Innovative Features and Multi-VNet Topologies
PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
PPTX
Virtual Data Center VDC - Azure Cloud Reference Architecture CRA
PPTX
Part 03: Azure Virtual Networks – Understanding and Creating Point-to-Site VP...
PPTX
Cloud-Reference-Architecture-Virtual-Data-Center-VDC-Azure.pptx
PPTX
Cld006 azure v_net___express_route_最新情報
PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
PPTX
It's all about Security! Let’s get you started with Azure Bastion
PDF
Cld006 azure v_net___express_route_最新情報
PPTX
CCI2018 - Azure Network - Security Best Practices
PPTX
VMWARE Professionals - Security, Multitenancy and Flexibility
PDF
VMware NSX for vSphere - Intro and use cases
PDF
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
PPTX
Aymeric weinbach ze cloud intro et nouveautés
PDF
Andy Kennedy - Scottish VMUG April 2016
PPTX
Azure Network and Infrastructure
PPTX
Microsoft cloud stack
Microsoft Azure Hub_Spoke_Ampliado.pptx
CCI2019 - Architecting and Implementing Azure Networking
Securing your cloud perimeter with azure network security brk3185
Azure Networking: Innovative Features and Multi-VNet Topologies
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
Virtual Data Center VDC - Azure Cloud Reference Architecture CRA
Part 03: Azure Virtual Networks – Understanding and Creating Point-to-Site VP...
Cloud-Reference-Architecture-Virtual-Data-Center-VDC-Azure.pptx
Cld006 azure v_net___express_route_最新情報
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
It's all about Security! Let’s get you started with Azure Bastion
Cld006 azure v_net___express_route_最新情報
CCI2018 - Azure Network - Security Best Practices
VMWARE Professionals - Security, Multitenancy and Flexibility
VMware NSX for vSphere - Intro and use cases
OVHcloud Hosted Private Cloud Platform Network use cases with VMware NSX
Aymeric weinbach ze cloud intro et nouveautés
Andy Kennedy - Scottish VMUG April 2016
Azure Network and Infrastructure
Microsoft cloud stack
Ad

Recently uploaded (20)

PDF
VCE English Exam - Section C Student Revision Booklet
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PDF
Microbial disease of the cardiovascular and lymphatic systems
PDF
2.FourierTransform-ShortQuestionswithAnswers.pdf
PDF
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
PDF
102 student loan defaulters named and shamed – Is someone you know on the list?
PPTX
The Healthy Child – Unit II | Child Health Nursing I | B.Sc Nursing 5th Semester
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PPTX
master seminar digital applications in india
PPTX
Microbial diseases, their pathogenesis and prophylaxis
PPTX
Cell Types and Its function , kingdom of life
PDF
01-Introduction-to-Information-Management.pdf
PDF
Anesthesia in Laparoscopic Surgery in India
PDF
Classroom Observation Tools for Teachers
PDF
Basic Mud Logging Guide for educational purpose
PDF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
PDF
O7-L3 Supply Chain Operations - ICLT Program
VCE English Exam - Section C Student Revision Booklet
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
Microbial disease of the cardiovascular and lymphatic systems
2.FourierTransform-ShortQuestionswithAnswers.pdf
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
human mycosis Human fungal infections are called human mycosis..pptx
102 student loan defaulters named and shamed – Is someone you know on the list?
The Healthy Child – Unit II | Child Health Nursing I | B.Sc Nursing 5th Semester
FourierSeries-QuestionsWithAnswers(Part-A).pdf
master seminar digital applications in india
Microbial diseases, their pathogenesis and prophylaxis
Cell Types and Its function , kingdom of life
01-Introduction-to-Information-Management.pdf
Anesthesia in Laparoscopic Surgery in India
Classroom Observation Tools for Teachers
Basic Mud Logging Guide for educational purpose
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
O5-L3 Freight Transport Ops (International) V1.pdf
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
O7-L3 Supply Chain Operations - ICLT Program

Azure Hub spoke v1.0

  • 1. Azure Landing Zone (Azure Firewall/WAF) Azure Firewall: On-premises network Gateway subnet UDR Management subnet Hub VNet Web tier Business tier Data tier App Services Managed Database Jumpbox VNet Peering (Bidirectional) VNet Peering (Bidirectional) VNet (Spoke 1) VNet (Spoke 2) 1
  • 2. Azure Landing Zone (NVA) On-premises network Gateway subnet UDR Management subnet Hub VNet Web tier Business tier Data tier VNet (Spoke 2) App Services Managed Database VNet Peering (Bidirectional) Jumpbox Availability set Public DMZ in Public DMZ out Availability set Private DMZ in Private DMZ out VNet Peering (Bidirectional) VNet (Spoke 1) https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/secure-vnet-dmz 2
  • 3. Azure Network Architecture: Deployment to Primary Azure Region On-premises Network HQ Internet VNet Peering (Bidirectional) Prod Subscription Prod Resource Group(s)* Prod VNet (Spoke 3) 10.xx.xx.xx/yy 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz Prod Management Group Gateway Subnet Hub VNet Firewall Subnet SIEM Subnet WAF Subnet Management Subnet 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/yy Hub Resource Group(s)* Hub Subscription Hub Management Group VNet Peering (Bidirectional) VNet Peering (Bidirectional) Non-Prod Subscription Dev Resource Group(s)* Non-Prod Management Group Dev VNet (Spoke 1) 10.xx.xx.xx/yy 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz Test VNet (Spoke 2) 10.xx.xx.xx/yy 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz Test Resource Group(s)* Additional Resource Groups will be used for Azure resources as required for better resource management and security control * P2S VPN Tunnel S2S VPN Tunnel HTTP/HTTPS VPN Client On-premises Network Site 2 S2S VPN Tunnel 3
  • 4. Azure Network Architecture: with animation VNet Peering (Bidirectional) Prod Subscription Prod Resource Group(s)* Prod VNet (Spoke 3) 10.xx.xx.xx/yy 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz Prod Management Group Non-Prod Subscription Dev Resource Group(s)* Non-Prod Management Group Dev VNet (Spoke 1) 10.xx.xx.xx/yy 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz Test VNet (Spoke 2) 10.xx.xx.xx/yy 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz Gateway Subnet Hub VNet Firewall Subnet SIEM Subnet WAF Subnet Management Subnet 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/zz 10.xx.xx.xx/yy Hub Resource Group(s)* Hub Subscription Hub Management Group Test Resource Group(s)* VNet Peering (Bidirectional) VNet Peering (Bidirectional) Additional Resource Groups will be used for Azure resources as required for better resource management and security control * On-premises Network HQ Internet P2S VPN Tunnel S2S VPN Tunnel HTTP/HTTPS VPN Client On-premises Network Site 2 S2S VPN Tunnel 4
  • 5. Hub and Spoke Network Topology VPN Client On-premises Network HQ On-premises Network Site 2 Hub VNet Hub Subnets P2S VPN Tunnel S2S VPN Tunnel Gateway Subnet Spoke 2 VNet Spoke 1 Subnets Spoke 2 VNet Spoke 2 Subnets Spoke 3 VNet Spoke 3 Subnets Spoke 4 VNet Spoke 4 Subnets HTTP/ HTTPS 5
  • 6. Hub and Spoke Topology Benefits Drawbacks Hub & Spoke  Easier to manage shared services  Lower licensing costs  Improved segregation  Easy to scale  Single point of failure  Overhead of managing UDRs Simplified  No single point of failure  Duplication of shared services (Firewall, SIEM)  Higher licensing costs  Challenging to scale VPN Client On-premises Network HQ On-premises Network Site 2 Hub VNet Hub Subnets P2S VPN Tunnel S2S VPN Tunnel Gateway Subnet Spoke 2 VNet Spoke 1 Subnets Spoke 2 VNet Spoke 2 Subnets Spoke 3 VNet Spoke 3 Subnets Spoke 4 VNet Spoke 4 Subnets HTTP/ HTTPS 6
  • 7. Example Azure Network Plan: VNets & Subnets ID vNET Subnet Netmask CIDR # Of hosts Subscription Security zone Gateway unit Gateway address 1 HUB 10.151.98.0 26 10.151.98.0/26 62 Hub HUB_SZ_MSS Microsoft Azure 10.151.98.1 2 HUB 10.151.96.0 26 10.151.96.0/26 62 Hub HUB_SZ_PRIVATE_DMZ Firewall 1(Internal) 10.151.96.1 3 HUB 10.151.97.0 24 10.151.97.0/24 254 Hub HUB_SZ_PUBLIC_DMZ Firewall 0 (External) 10.151.97.1 4 HUB 10.151.98.64 26 10.151.98.64/26 62 Hub HUB_SZ_JUMP_BOX Microsoft Azure 10.151.98.65 5 PROD 10.151.0.0 19 10.151.0.0/19 8190 Prod PROD_SZ_WORKLOAD1 Microsoft Azure 10.151.0.1 6 DEV 10.151.32.0 19 10.151.32.0/19 8190 Non-Prod DEV_SZ_NON_PROD Microsoft Azure 10.151.32.1 7 STAGING 10.151.64.0 19 10.151.64.0/19 8190 Non-Prod STAGING_SZ_NON_PROD Microsoft Azure 10.151.64.1 7