Understanding the security considerations of a virtual hub
So far, we have talked about how the virtual WAN makes connecting networks and routing easier. But what if we need to control and inspect the traffic between connected networks? Can we do this? The answer is yes, there are different ways we can do this, depending on what we need it for. In the next sections, we will quickly look at three common ways of doing this.
Approach 1 – deploy Azure Firewall in the virtual hub
The virtual hub (Standard tier only) supports the deployment of Azure Firewall within the hub. This creates a secured hub that can filter and inspect network traffic between virtual networks, branch offices or remote users, and the internet (Figure 7.50).
Figure 7.50 – Secured hub using Azure Firewall
Traffic inspection is supported for the following scenarios:
- Between connected virtual networks
- Between virtual networks and branch offices (ExpressRoute...