Network virtual appliance, a VM from a third party acting as a firewall, router or other network device.
Also called network virtual appliance.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700AZ-900AZ-802ALZ
Each book explains NVA in context, with comparison tables and the common traps.
Related terms
- Allow forwarded traffic
Peering option permitting traffic that did not start in the peer VNet, but was forwarded by a gateway or NVA, to pass over the peering.
- BGP peering with the virtual hub
Virtual WAN capability where a network virtual appliance in a spoke connected directly to the hub runs a BGP session with the hub's router; the spoke's VNet connection must be associated with
defaultRouteTable. - Forced tunnelling
Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (
AzureFirewallManagementSubnetand a management public IP) for it. - Indirect spoke
VNet that hangs off an NVA's VNet through peering instead of attaching to the virtual hub. Reaching it takes a static route on the hub towards the NVA VNet connection, a static route on that connection towards the NVA's IP, and a UDR so replies return through the NVA.
- IP forwarding
A NIC setting allowing a VM, such as an NVA, to accept and pass on traffic destined for other IP addresses. It must be on when UDRs route traffic through the appliance.
- Next hop type
Describes what a route forwards to. Options are Internet, Virtual network, Virtual network gateway, Virtual appliance (the private IP of an NVA or firewall) and None.
- NGFW
Short for next-generation firewall: a third-party network virtual appliance which, when built into a Virtual WAN hub, can be chosen as where routing intent sends traffic. Each hub supports only a single integrated NVA.
- Routing intent
With this Virtual WAN feature, a hub forces private traffic, internet traffic or both through a security solution inside it (Azure Firewall, an NGFW NVA or a SaaS offering). Branch-to-branch and hub-to-hub traffic is then inspected without hand-built route tables.