A partner appliance, whether SD-WAN, NGFW or both, placed straight into a Virtual WAN hub where it runs BGP with the hub router. Each hub can hold only one.
Also called integrated NVA.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains NVA in the hub in context, with comparison tables and the common traps.
Terms in this definition
- SD-WAN
Software-defined WAN. A vendor's overlay connects branches over more than one transport and chooses paths centrally; in Virtual WAN, the tunnels end on an SD-WAN NVA inside the hub instead of Microsoft's own VPN or ExpressRoute gateways.
- NGFW
Short for next-generation firewall: a third-party network virtual appliance which, when built into a Virtual WAN hub, can be chosen as where routing intent sends traffic. Each hub supports only a single integrated NVA.
- Virtual WAN
A networking service built around hubs that Microsoft manages. The Basic type handles only site-to-site VPN; Standard brings in ExpressRoute, point-to-site and full transit.
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
- WHERE
Limits a SELECT, UPDATE or DELETE to just the rows meeting a condition. Omit it, and the statement hits every row.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- BGP
Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
- Hub router
The routing component in every virtual hub that swaps routes with connections, gateways and BGP peers, and that carries traffic between VNets.
Related terms
- Service chaining
Using UDRs across peerings to send spoke traffic via a gateway or NVA in the hub. It handles traffic between spokes and suits policy-based gateways that cannot provide gateway transit.