A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104AZ-700AZ-900SC-900AZ-802
Each book explains Subnet in context, with comparison tables and the common traps.
Terms in this definition
- segment
A layer 2 network in NSX for VM connections. Overlay-backed ones carry traffic in tunnels between TEPs; VLAN-backed ones correspond to a physical VLAN.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Address space
The CIDR block or blocks that define a VNet. Every subnet has to fall inside it; blocks can be added, or altered when nothing is using them.
- FIRST
A DAX function available only inside visual calculations. It fetches the value at the start of one axis of the visual's matrix, which makes it handy for comparing each point with the first; its opposite is LAST.
- LAST
Restricted to visual calculations, this DAX function reads a value from the final position along one of the visual's axes. Writing INDEX(-1) gives the same result.
- IPv4
The 32-bit version of IP addressing. It remains the address format you will see most often in log data and threat indicators.
Related terms
- Access restrictions
Allow and deny rules for inbound App Service traffic, matched on IP range, service tag or subnet. They can, for instance, restrict an app to a corporate NAT's public addresses.
- ANC
Tells Windows 365 which Azure subscription, virtual network and subnet to place Cloud PCs in (plus, where they're hybrid joined, which AD OU and domain). Provisioning policies use it, Intune checks its health at intervals of one to six hours, and you can have 50 per tenant.
- Application Gateway autoscaling
Capability of Application Gateway v2 that varies the instance count between configured minimum and maximum values, at most 125. Plan subnet size for that maximum, adding one address per private frontend IP.
- Application Gateway v2
Present-day Application Gateway SKU, Standard_v2 or WAF_v2, offering zone redundancy, autoscaling, a static VIP, Key Vault integration and header rewrite. It requires its own subnet, ideally a /24.
- Application monitoring high availability
An optional collector group setting in VCF Operations, off by default, that pairs cloud proxies as primary and secondary behind a shared virtual IP on one subnet. If a proxy is lost, application and operating-system monitoring through Telegraf carries on.
- az container create
Azure CLI command that deploys a container group to Azure Container Instances. Its options cover the image, exposed ports, a VNet subnet, the restart policy, and registry access through credentials or
--acr-identity. - Azure DNS Private Resolver
Managed resolver inside a VNet that removes the need for DNS server VMs in hybrid setups. Its inbound and outbound endpoints each need their own subnet of at least /28 delegated to
Microsoft.Network/dnsResolvers, and it can link only to a VNet in the same region. - Azure Extended Network
Windows Admin Center feature letting migrated VMs keep their IP addresses by stretching an on-premises subnet into Azure; two appliance VMs carry a VXLAN tunnel between them, and up to 250 addresses can be extended.