A peering option that lets spoke VNets use a hub's route-based VPN or ExpressRoute gateway, enabled with Allow gateway transit on the hub and Use remote gateways on the spoke.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Gateway transit in context, with comparison tables and the common traps.
Terms in this definition
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
- Route-based VPN
Type of VPN gateway that relies on routing tables and any-to-any traffic selectors. Point-to-site, BGP and gateway transit all need it, and it is the only type you can create in the portal.
- ExpressRoute gateway
Connects a virtual network to an ExpressRoute circuit from inside GatewaySubnet. Only one is allowed per VNet, and VPN traffic needs a separate gateway.
- Allow gateway transit
Peering option set on the hub, which owns the gateway, so that peered VNets can share its ExpressRoute or VPN gateway. The spoke sets Use remote gateways to match; on a VNet lacking a gateway the option has no effect.
- Use remote gateways
A peering option set on the spoke so its traffic uses the hub's gateway. It concerns gateway transit only and has no effect on VM-to-VM traffic over the peering.
Related terms
- Service chaining
Using UDRs across peerings to send spoke traffic via a gateway or NVA in the hub. It handles traffic between spokes and suits policy-based gateways that cannot provide gateway transit.