The 0.0.0.0/0 route matching any destination. Advertised by on-premises routers through BGP on ExpressRoute private peering (Microsoft peering won't do), it sends internet traffic from connected VNets back on-premises.
Also called 0.0.0.0/0.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Default route in context, with comparison tables and the common traps.
Terms in this definition
- BGP
Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- Private peering
The ExpressRoute routing domain for reaching Azure VNets from on-premises networks over private addressing. Unless IPsec or MACsec is layered on, the traffic travels unencrypted.
- Microsoft peering
Routing domain on ExpressRoute that reaches public endpoints of Azure PaaS and Microsoft 365 using public IP prefixes you own. Circuits created since August 2017 advertise nothing until you attach a route filter.
Related terms
- AzureFirewallManagementSubnet
Subnet (minimum /26) set aside for the management NIC of Azure Firewall; that NIC must have a public IP address of its own and a default route to the internet.
- Default Site
In forced tunnelling, the route-based VPN gateway is pointed at one local network gateway as its default, and every internet-bound packet goes there. That on-premises device must permit 0.0.0.0/0 in its traffic selectors.
- Forced tunnelling
Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (
AzureFirewallManagementSubnetand a management public IP) for it. - Internet traffic routing policy
On a Virtual WAN hub, this routing intent setting makes Azure Firewall, a third-party next-generation firewall or a SaaS security product the single exit for traffic heading to the internet, by advertising a default route to everything attached. A hub may carry one such policy plus one private traffic policy.
- Longest prefix match
How Azure chooses between routes: if more than one matches a destination, the most specific prefix is used. That is why a 0.0.0.0/0 UDR leaves traffic inside the VNet untouched.
- System route
A default route Azure creates automatically for each subnet, such as traffic within the VNet or 0.0.0.0/0 to the Internet. UDRs override them.