Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (AzureFirewallManagementSubnet and a management public IP) for it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Forced tunnelling in context, with comparison tables and the common traps.
Terms in this definition
- Geographic
A Traffic Manager routing method that picks the endpoint according to where the user is located geographically.
- NVA
Network virtual appliance, a VM from a third party acting as a firewall, router or other network device.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- Default route
The 0.0.0.0/0 route matching any destination. Advertised by on-premises routers through BGP on ExpressRoute private peering (Microsoft peering won't do), it sends internet traffic from connected VNets back on-premises.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- BGP
Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
- Default Site
In forced tunnelling, the route-based VPN gateway is pointed at one local network gateway as its default, and every internet-bound packet goes there. That on-premises device must permit 0.0.0.0/0 in its traffic selectors.
Related terms
- Azure KMS
Endpoint used to activate Windows on Azure VMs: azkms.core.windows.net (20.118.99.224 and 40.83.235.53) on TCP port 1688. With forced tunnelling in place, user-defined routes sending those IPs to next hop Internet keep activation working.
- Firewall Management NIC
A second Azure Firewall interface, in AzureFirewallManagementSubnet with a public IP of its own, carrying management traffic. Forced tunnelling requires it; an existing firewall gains one after a stop and restart.
- Get-AzLocalNetworkGateway
Az.Network cmdlet returning a local network gateway object; for forced tunnelling, that object can be passed as
-GatewayDefaultSite.