Modifying the default routing behavior
In some scenarios that you may have, the default flow of traffic as defined by system routes may not meet your organizational requirements. For example, you may want to implement the following scenarios:
- Forward outbound network traffic to NVAs, such as third-party firewall solutions, for inspection before being sent to the final destination.
- Direct all internet-bound traffic through your on-premises network maybe for compliance reasons. This is also referred to as forced tunneling.
- Completely isolate a VNet from the internet for compliance reasons.
For these scenarios, we have two main options for implementing custom routing. Since we cannot modify or update system routes, we can override system routes with user-defined routes or use the Border Gateway Protocol (BGP) to exchange routes.
What is a network virtual appliance?
An NVA is a virtual appliance that can be deployed from Azure Marketplace into Azure subnets...