In forced tunnelling, the route-based VPN gateway is pointed at one local network gateway as its default, and every internet-bound packet goes there. That on-premises device must permit 0.0.0.0/0 in its traffic selectors.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Default Site in context, with comparison tables and the common traps.
Terms in this definition
- Forced tunnelling
Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (
AzureFirewallManagementSubnetand a management public IP) for it. - Route-based VPN
Type of VPN gateway that relies on routing tables and any-to-any traffic selectors. Point-to-site, BGP and gateway transit all need it, and it is the only type you can create in the portal.
- Local network gateway
Represents the on-premises site in Azure, recording the VPN device's public IP and the address prefixes behind it, for use by site-to-site VPN connections. Point-to-site doesn't use it.
- Default route
The 0.0.0.0/0 route matching any destination. Advertised by on-premises routers through BGP on ExpressRoute private peering (Microsoft peering won't do), it sends internet traffic from connected VNets back on-premises.
Related terms
- Get-AzVirtualNetworkGateway
Az.Network cmdlet used to fetch a virtual network gateway object. Setting the default site is outside what it does, as it only reads.