Connects VNets privately with low latency across the Microsoft backbone, whether in different regions, subscriptions or tenants or not. Because it is non-transitive, spokes sharing a hub need direct peering, or UDRs through a hub firewall or NVA, to talk.
Also called VNet peering.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104AZ-700SC-500AI-300AZ-900SC-900ALZ
Each book explains Virtual network peering in context, with comparison tables and the common traps.
Terms in this definition
- Virtual hub
Inside a Virtual WAN, a VNet managed by Microsoft that contains the hub router plus the VPN, ExpressRoute and User VPN gateways. Typically there is one per region, but several hubs can share a region.
- NVA
Network virtual appliance, a VM from a third party acting as a firewall, router or other network device.
Related terms
- Add-AzVirtualNetworkPeering
Az.Network cmdlet for creating a VNet peering link in a single direction. For hub-and-spoke gateway sharing, set
-AllowGatewayTransiton the link from hub to spoke and-UseRemoteGatewayson the link from spoke to hub. - Azure Government
Separate cloud for US government workloads, physically isolated from global Azure, so VNet peering between the two isn't possible.
- Microsoft Azure operated by 21Vianet
Azure cloud in China, run by 21Vianet and physically isolated from global Azure; VNet peering between the two isn't possible.
- VNet-to-VNet VPN
Links the VPN gateways of two VNets with an encrypted IPsec/IKE tunnel. Each VNet needs a gateway, and compared with VNet peering it is pricier and adds latency.