A network layout in which a central hub virtual network holds shared services and the on-premises gateway, and each workload's spoke network is peered with the hub. Peering by itself does not let spokes reach one another via the hub.
Also called hub-spoke topology.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Hub-and-spoke in context, with comparison tables and the common traps.
Terms in this definition
- Hub virtual network
In a hub-and-spoke design, the central virtual network that holds shared network services and the gateways linking Azure to on-premises sites. Traffic from the peered spokes typically leaves and is inspected through it.
- Workload
Also called an experience: a Fabric toolset aimed at one job role, e.g. Data Factory, Data Engineering, Data Warehouse, Real-Time Intelligence or Power BI. Each keeps its data in OneLake.
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
Related terms
- Add-AzVirtualNetworkPeering
Az.Network cmdlet for creating a VNet peering link in a single direction. For hub-and-spoke gateway sharing, set
-AllowGatewayTransiton the link from hub to spoke and-UseRemoteGatewayson the link from spoke to hub. - Azure Virtual Network Manager
Service for centrally managing connectivity, as hub-and-spoke or mesh, and security admin rules across VNets in many subscriptions. VNets in other tenants must be added as static members, because dynamic membership driven by Azure Policy works only within one tenant.
- Connectivity configuration
Virtual Network Manager setting that creates mesh or hub-and-spoke topologies, using peerings or connected groups, over a network group; route exchange between gateways isn't part of it.
- Direct connectivity
A setting in an Azure Virtual Network Manager hub-and-spoke configuration that lets spokes in the same network group reach each other without going through the hub. Their effective routes list ConnectedGroup as the next hop, and no peerings appear.