Azure forced tunneling sends Internet-bound traffic through a designated VPN or hub path instead of letting it leave Azure directly. The setup is not one universal switch: the route controls and egress requirements differ for site-to-site (S2S) VPN Gateway, point-to-site (P2S) clients, Virtual WAN, and Azure Firewall. First choose where traffic should be inspected and where it should exit to the Internet; then select the routing method that matches that topology.
What forced tunneling changes
By default, Internet-bound traffic from workloads in an Azure virtual network goes directly to the Internet. Forced tunneling changes that path so traffic is sent through a chosen tunnel or hub route—for example, to an on-premises security stack for inspection and auditing. Microsoft describes S2S forced tunneling as redirecting Internet-bound traffic back to the on-premises location through the S2S VPN tunnel for inspection and auditing (Microsoft Learn: About forced tunneling for site-to-site configurations).
The routing goal and the return path both matter. A route that sends traffic into a tunnel does not, by itself, provide Internet access at the far end. The destination network or hub must have a valid onward egress route, and the design must account for which subnets or clients are in scope.
Choose the route method for your topology
| Topology | How traffic is directed | Key design requirement |
|---|---|---|
| S2S VPN Gateway | Advertise 0.0.0.0/0 over BGP, or configure a Default Site on a route-based gateway. |
Provide on-premises egress and account for route precedence and any subnet-specific UDRs. The Default Site approach requires the on-premises VPN device to use 0.0.0.0/0 traffic selectors. (Microsoft Learn) |
| Traditional P2S VPN Gateway | Advertise the custom routes 0.0.0.0/1 and 128.0.0.0/1 to clients. |
These routes are more specific than a client adapter’s default route, but the gateway does not itself supply Internet egress. Provide an onward route or Internet traffic sent into the VPN is dropped. (Microsoft Learn) |
| Virtual WAN P2S | Advertise a default route to P2S clients and use the Virtual WAN hub’s forwarding design. | Configure a supported onward path through a Network Virtual Appliance, Azure Firewall, a branch, or another supported design. Enable the P2S gateway’s EnableInternetSecurity setting. (Microsoft Learn) |
| Azure Firewall | Configure the firewall’s forced-tunneling path and routes for the intended traffic. | Keep firewall management traffic’s direct Internet connectivity. Consider the DNAT limitation and preserve a direct Internet route for the firewall where needed. (Microsoft Learn; Azure Firewall FAQ) |
Direct Internet traffic through an S2S VPN Gateway
For an S2S design, Microsoft documents two ways to direct Azure Internet-bound traffic through the VPN Gateway tunnel. They are alternatives for establishing the default route; select the one that fits the on-premises VPN device and routing design.
#1 Best Overall
- Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
- Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
- Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
- MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
Option 1: Advertise a default route with BGP
Have the on-premises BGP peer advertise 0.0.0.0/0 to Azure. This tells Azure that the on-premises network is a route for all destinations not covered by a more-specific route. Ensure the on-premises network can forward inspected traffic onward to the Internet and handle return traffic for the Azure sources.
Option 2: Set a Default Site
For a route-based VPN Gateway, configure a Default Site to direct Internet-bound traffic through the selected S2S connection. Microsoft specifies that the on-premises VPN device must use 0.0.0.0/0 as its traffic selectors for this approach. Check device interoperability and the gateway configuration before relying on this path.
Rank #2
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Account for UDRs and route precedence
A forced default route does not mean every subnet must use the same egress path. User-defined routes (UDRs) can direct selected subnets toward a different next hop. Evaluate the effective route for each relevant subnet and destination: a more-specific route can take precedence over a default route, while the chosen default route applies to destinations without a more-specific match. Document which workloads use the inspection path and which, if any, intentionally use another path.
Force Internet traffic from traditional P2S clients into the VPN
For the documented custom-route approach, advertise two routes to P2S clients: 0.0.0.0/1 and 128.0.0.0/1. Together they cover IPv4 destinations; each is more specific than the client’s ordinary 0.0.0.0/0 default route, so the VPN routes are preferred for those destinations.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #3
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Do not treat route advertisement as complete Internet connectivity. Azure VPN Gateway does not provide Internet access on behalf of P2S clients. If a client sends Internet-bound packets into the tunnel and the Azure or connected network has no onward egress route, that traffic is dropped. Build and verify the exit path—such as routing through the intended inspection network—before distributing the client configuration.
Configure forced tunneling for Virtual WAN P2S
Virtual WAN P2S uses hub routing and forwarding rather than the traditional P2S Gateway custom-route method alone. Microsoft’s documented design advertises a default route to P2S clients, configures an onward forwarding path through a supported hub-connected destination, and enables the P2S gateway’s EnableInternetSecurity setting.
Rank #4
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
The destination may be a Network Virtual Appliance, Azure Firewall, a branch, or another supported design. The chosen hub route must actually carry the traffic to that destination and provide onward Internet egress; advertising the default route without a functioning forwarding path can strand client traffic.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Plan for Azure Firewall’s management and inbound traffic
Azure Firewall forced tunneling has a specific exception to the general goal of routing traffic through an inspection path: firewall management traffic must retain direct Internet connectivity. If the AzureFirewallSubnet learns a default route to on premises through BGP, Microsoft documents a 0.0.0.0/0 UDR with next hop Internet as a way to preserve the firewall’s direct Internet access.
Best Value
- Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
- A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
- Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
- Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
- Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Forced-tunneling mode also has an inbound-service trade-off. Microsoft warns that DNAT is not supported in this mode because inbound traffic cannot reach the firewall’s public IP directly; the documentation notes that a Management NIC configuration supports DNAT. Check the current Azure Firewall configuration requirements against the intended inbound design before adopting forced tunneling. The Azure Firewall FAQ states that the Basic tier supports forced tunneling.
Validate the end-to-end path before rollout
- Define scope: Identify whether all VNet workloads, selected subnets, P2S clients, or only particular destinations should use the forced path.
- Confirm route propagation: Check that the intended BGP default route, Default Site, P2S custom routes, or Virtual WAN route reaches the right workloads or clients.
- Verify onward egress: Confirm the tunnel endpoint, hub, branch, or appliance can forward traffic to the inspection point and then to the Internet.
- Check return routing: Ensure responses can return through a valid route to the originating Azure workload or VPN client; asymmetric paths can disrupt stateful inspection and connectivity.
- Review exceptions: Validate UDRs and the Azure Firewall management route so a default route does not unintentionally capture traffic that needs a different next hop.
- Test representative traffic: Test from each affected subnet or client type, including an Internet destination and any inbound service that the design is expected to support.
Microsoft’s security guidance recommends S2S forced tunneling when Azure workload Internet traffic needs on-premises security inspection and auditing (Microsoft Cloud Adoption Framework: Plan for network security). The appropriate implementation still depends on the selected Azure networking service and the route and egress design around it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

