A networking service built around hubs that Microsoft manages. The Basic type handles only site-to-site VPN; Standard brings in ExpressRoute, point-to-site and full transit.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Virtual WAN in context, with comparison tables and the common traps.
Terms in this definition
- Basic
Low-cost Log Analytics table plan where ingestion is cheap but each query is charged per GB and runs at workspace scope. Full KQL and simple log search alerts are supported; standard log search alerts are not.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
Related terms
- AS Path (hub routing preference)
Routing preference for a Virtual WAN hub under which the shortest BGP AS path wins regardless of where the route came from. When local routes tie, ExpressRoute is chosen over site-to-site VPN.
- Association
Routing setting for a Virtual WAN hub. Each connection is associated with exactly one route table, and that table determines the routes the connection learns.
- Azure Firewall
Stateful network firewall run by Azure as a managed service; it can be placed in Virtual WAN hubs and administered through Firewall Manager.
- BGP peering with the virtual hub
Virtual WAN capability where a network virtual appliance in a spoke connected directly to the hub runs a BGP session with the hub's router; the spoke's VNet connection must be associated with
defaultRouteTable. - Connectivity management group
Part of the platform hierarchy containing the subscription, normally just one, used for shared networking. Typical contents are hubs (VNet or Virtual WAN), Azure Firewall, gateways and DNS.
- CPE
The equipment at a branch, typically an SD-WAN appliance or router, through which that site connects into a Virtual WAN hub; stands for customer premises equipment.
- Custom route table
Route table you create in a Virtual WAN hub to isolate traffic, for instance for a set of VNets; it can't be used once routing intent is turned on.
- defaultRouteTable
Every Virtual WAN hub ships with this route table, labelled Default. Unless configured otherwise, each connection associates with it and propagates routes to it, and branches are required to remain associated.