Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
Also called hub.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Virtual hub in context, with comparison tables and the common traps.
Terms in this definition
- Virtual WAN
A networking service built around hubs that Microsoft manages. The Basic type handles only site-to-site VPN; Standard brings in ExpressRoute, point-to-site and full transit.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- CONTAINS
Searches columns with a full-text index for words, phrases, prefixes, inflected forms or synonyms; you use it as a predicate in
WHERE. - Hub router
The routing component in every virtual hub that swaps routes with connections, gateways and BGP peers, and that carries traffic between VNets.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- User VPN
Point-to-site connectivity in Virtual WAN, giving individual clients a gateway and configuration. It needs the Standard Virtual WAN tier and is not how branch offices connect.
- region
A provider-defined grouping in VCF Automation of Supervisors that all share one NSX Local Manager; tenants consume its compute, storage and memory via quotas set per region.
Related terms
- Add-AzVirtualNetworkPeering
Az.Network cmdlet for creating a VNet peering link in a single direction. For hub-and-spoke gateway sharing, set
-AllowGatewayTransiton the link from hub to spoke and-UseRemoteGatewayson the link from spoke to hub. - Allow gateway transit
Peering option set on the hub, which owns the gateway, so that peered VNets can share its ExpressRoute or VPN gateway. The spoke sets Use remote gateways to match; on a VNet lacking a gateway the option has no effect.
- AS Path (hub routing preference)
Routing preference for a Virtual WAN hub under which the shortest BGP AS path wins regardless of where the route came from. When local routes tie, ExpressRoute is chosen over site-to-site VPN.
- Association
Routing setting for a Virtual WAN hub. Each connection is associated with exactly one route table, and that table determines the routes the connection learns.
- Azure AI Developer
Built-in role scoped to an Azure Machine Learning workspace or hub: holders can do anything inside it except administer the workspace itself. For Foundry projects, the equivalent roles are Foundry Owner and Foundry User.
- Azure Event Hubs Data Sender
Lets a principal send events to an event hub. For change event streaming, the database's managed identity should get this built-in role scoped to the event hub itself, not to its namespace.
- Azure Landing Zone Review
A self-assessment on Microsoft Learn that checks a platform design, looking at areas such as hub networking, management groups and security baselines. It does for the platform what the Well-Architected Review does for workloads.
- BGP peering with the virtual hub
Virtual WAN capability where a network virtual appliance in a spoke connected directly to the hub runs a BGP session with the hub's router; the spoke's VNet connection must be associated with
defaultRouteTable.