With this Virtual WAN feature, a hub forces private traffic, internet traffic or both through a security solution inside it (Azure Firewall, an NGFW NVA or a SaaS offering). Branch-to-branch and hub-to-hub traffic is then inspected without hand-built route tables.
Also called routing policies.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Routing intent in context, with comparison tables and the common traps.
Terms in this definition
- Virtual WAN
A networking service built around hubs that Microsoft manages. The Basic type handles only site-to-site VPN; Standard brings in ExpressRoute, point-to-site and full transit.
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- NGFW
Short for next-generation firewall: a third-party network virtual appliance which, when built into a Virtual WAN hub, can be chosen as where routing intent sends traffic. Each hub supports only a single integrated NVA.
- NVA
Network virtual appliance, a VM from a third party acting as a firewall, router or other network device.
- SaaS
A cloud model in which you consume a finished application that the provider operates, Microsoft 365 for instance. Nearly everything is the provider's job; you look after your data, users and devices.
- Branch-to-branch
Optional Azure Route Server feature, disabled by default, that passes routes among NVAs and the VPN and ExpressRoute gateways in its VNet, enabling transit between ExpressRoute and site-to-site VPN.
Related terms
- Custom route table
Route table you create in a Virtual WAN hub to isolate traffic, for instance for a set of VNets; it can't be used once routing intent is turned on.
- Internet traffic routing policy
On a Virtual WAN hub, this routing intent setting makes Azure Firewall, a third-party next-generation firewall or a SaaS security product the single exit for traffic heading to the internet, by advertising a default route to everything attached. A hub may carry one such policy plus one private traffic policy.