Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Build a hub-and-spoke Azure network by deciding which flows must be inspected, routing those flows deliberately, assigning clear DNS authority, and using NSGs to segment workloads. Peering alone does not create transitive connectivity or force traffic through a firewall. Use this checklist to define the intended paths, configure the controls, and verify the deployed design.

Set the topology and connectivity boundaries first

Plan non-overlapping address spaces

  • Allocate non-overlapping CIDR ranges to the hub, each spoke, and connected on-premises networks. Leave address space for future spokes.
  • Check the ranges together before creating peerings; overlapping VNet address spaces prevent peering.

Microsoft’s hub-and-spoke topology guidance describes the addressing and peering requirements.

Put shared services in the hub and workloads in spokes

Use the hub for shared network services such as Azure Firewall, VPN or ExpressRoute gateways, Bastion, and DNS services. Place application workloads in spokes so they can be organized and governed separately from shared infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose how spokes communicate

VNet peering is non-transitive: peering two spokes to the hub does not, by itself, let those spokes reach one another. Decide explicitly which model applies to each spoke pair:

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
  • Isolated spokes: Do not provide a path for lateral traffic unless a workload requirement calls for one.
  • Inspected spoke-to-spoke traffic: Route selected inter-spoke prefixes through the hub firewall or another network virtual appliance (NVA).
  • Direct connectivity: Use direct peering or Azure Virtual Network Manager connectivity for selected trusted flows. Those flows can bypass central inspection.

Azure Virtual Network Manager can apply connectivity and routing configurations across network groups; manually managed peerings and route tables may suit a smaller scope. See Microsoft’s hub-and-spoke deployment guidance for Azure Virtual Network Manager.

Decide which spokes need hybrid routes

Determine whether spokes need to reach on-premises networks through the hub VPN or ExpressRoute gateway. Gateway transit shares gateway routes with connected spokes, so grant it only where the resulting reachability is intended and governed.

Define the path for each traffic class

Write down the expected path before configuring route tables or firewall rules. The path should be explicit for internet-bound traffic, on-premises traffic, and traffic between spokes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Firewall Appliance 10GbE Mini PC with SFP+, Intel Alder Lake N100 (4C/4T) 4xIntel I226-V 2.5GbE 2*Intel 82599ES 10GbE Firewall LTE Router Support AES-NI (N150, NO RAM NO ROM) (N150, NO RAM NO ROM)
  • 【Professional Firewall & NAS SERVER】OAKNODE 10gbe Firewall Appliance Mini PC-MGNASN, a powerful professional firewall router pc equipped with a 12th Gen Alder Lake N100 4C/4T up to 3.4GHz TDP only 6W with Intel UHD Graphics which maximizes the performance of the 2.5GbE port & SFP+ port, bring you a smooth secured and encrypted network environment.
  • 【Rich I/O to meet your needs】Firewall Appliance MGNASN With HDMI 2.0+DP 1.4+TYPE-C(dp 1.2) Support for 3x4K@60Hz together, Dual DDR4 RAM slot support for up to 1x32GB SO-Dimm laptop DDR5 Ram Maximum 5600Mhz and 1xM.2 NVMe/PCIe 3.0x1 2280 SSD slot +1*SATA 3.0 SSD/HDD slots (install externally), also it support boot from TF card slot and it also support PXE/AWOL/Watchdog/GPIO etc. which is perfect for your firewall appliance、VM、Router、home Server needs.
  • 【2xSFP+ 10GbE + 4x2.5GbE】This Firewall Router equipped with 2xIntel 82599ES 10gbe network card and 4*Intel i226-V network card speed maximum up to 2.5GbE(need other device like router, cables etc. also support 2.5Gbe/10gbe)which can bring you more faster and professional network usage(some system not release drivers yet) suggest to install version of below systems: pf-sense plus 23.0X or CE 2.7.X, OPNsense 22.1, OpenWrt, ROS7, ESXI 8 , Proxmox, CentOS etc).
  • 【4G LTE Function supported】This model also support 4G LTE function(mini PCIE slot for 4G modem) and SIM card slot which you can use it as a IOT devices for your server.
  • 【Quality With Warranty】If you have any questions or requirements(like OS installation/ drives/bios updates etc.) on OAKNODE Firewall mini pc MGNASN, PLEASE feel free to contact us. We offered 12 Months warranty for it and WE'LL REPLY YOUR Questions within 12 hours(during Workdays).
Traffic class Design decision Control to configure
Spoke to internet Decide whether traffic must pass through centralized inspection or can use another approved path. For centralized inspection, use a spoke-subnet route table with a default route to the firewall’s private IP.
Spoke to on-premises Decide which spokes need gateway routes and which destinations they may reach. Configure gateway transit where required; check route propagation against the intended route policy.
Spoke to spoke Choose isolation, inspection through the hub, or selected direct connectivity. For inspection, add routes for the relevant inter-spoke prefixes. For direct connectivity, account for the fact that traffic can bypass the hub firewall.

A peering or firewall deployment does not automatically put every flow on the inspected path. Microsoft’s Azure Firewall design guidance explains the role of routing in traffic inspection.

Configure routing and firewall inspection

Send the intended traffic to the firewall

  1. Associate a route table with each spoke subnet whose traffic must use centralized inspection.
  2. For internet-bound traffic, add a route for 0.0.0.0/0 with next hop type VirtualAppliance and the Azure Firewall private IP as the next-hop address.
  3. For inspected inter-spoke traffic, add routes for the destination spoke prefixes that should traverse the firewall.
  4. Review learned gateway routes and route propagation. If BGP-learned on-premises routes would override the intended user-defined route (UDR) policy, Microsoft’s topology guidance describes disabling BGP route propagation where appropriate.
  5. Check both the forward and return paths. A one-way route through the firewall is not enough to establish a working, symmetric design.

Use Microsoft’s deployment guidance alongside its firewall design guidance when implementing a centralized route pattern.

Limit firewall rules to required traffic

Create firewall rules for the flows the workloads need, and make sure the rule type and destination model match the traffic. If using Azure Firewall FQDN application rules, align DNS providers for the firewall and traffic originators so they resolve names consistently; Microsoft warns that different DNS providers can return different resolutions.

Rank #3
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
  • COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
  • FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.

Select firewall capabilities and subnet layout for the design

Choose the firewall tier and layout according to requirements such as forced tunneling, TLS inspection, IDPS, and URL filtering. Forced tunneling on Standard or Premium has specific management-subnet and DNAT implications in Microsoft’s guidance. Confirm current service requirements before implementation because capabilities and subnet requirements can change. See Azure Firewall and traffic inspection and the Cloud Adoption Framework hub-spoke guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Design DNS for Azure, private endpoints, and hybrid names

Assign DNS authority

  • Identify which DNS service is authoritative for Azure workload names, private DNS zones, and on-premises names.
  • Configure spokes to use the intended shared resolver or DNS service, rather than leaving each workload to depend on an accidental or inconsistent resolver choice.

Verify private endpoint name resolution

For each private endpoint, confirm that the required private DNS zone exists, the relevant virtual networks are linked to it, and the forwarding path supports the intended clients. Private endpoint connectivity and name resolution are related but separate checks: a working network path does not prove that a client resolves the service name to the intended private address. Microsoft’s Private Link in a hub-and-spoke network guide describes how Azure-provided DNS and private zones fit into this architecture.

Test resolution across hybrid boundaries

Check that Azure-hosted and on-premises clients can resolve the zones they need in both directions. A forwarding design, including Azure DNS Private Resolver where appropriate, can connect those resolution paths. The Azure Architecture Center hub-and-spoke reference covers hybrid networking considerations.

Rank #4
VNOPN Fanless Firewall Appliance Intel J3710 4C/4T, Firewall Mini PC, 4 x Intel i226 LAN Ports, Network Gateway, Soft Router, Support PF-Sense/OPN-Sense, AES-NI (8GB RAM 128GB SSD)
  • 【Processor & OS】Firewall Mini PC with Intel J3710 CPU up to 2.64GHz, 4Cores 4threads 2MB L2 Cache, TDP 6.5w, supports AES-NI. It tested with pf-sens/opn-sense linux ubuntu and other popular open source os. ("DEL" key to enter BIOS)
  • 【Interfaces】The firewall pc has 4 * Intel I226 lan ports, 2 * USB3.0 ports, 1 * RS232COM port, 2 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
  • 【Fanless Design】only 6.5W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, which can withstand temperatures up to 60°C. support 24/7 hours working, no noise.
  • 【RAM & Storage】The firewall router equipped with 8G DDR3 RAM, max support 8GB; 128GB mSATA SSD, up to 512GB. Not support HDD. Size:5.27 * 4.98 * 1.43 inches, Weigh:500g, small but powerful.
  • 【12 Months Service】You will get a firewall pc and accessories,If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use NSGs to segment spoke workloads

Keep Network Security Groups (NSGs) on appropriate spoke subnet boundaries even when a hub firewall inspects traffic. NSGs provide segmentation and defense in depth; they do not replace a deliberate route and firewall design.

  • Allow required flows explicitly and deny unexpected lateral traffic with explicit deny rules.
  • Review both source and destination subnet rules, rule priority, and any service tags or application security groups used to express workload intent.
  • Assess the effective rules against the actual deployed route and traffic path, not just against the intended architecture diagram.
  • For private endpoints that need restricted access from the hub or on-premises, evaluate an NSG on the private endpoint subnet using the Private Link hub-and-spoke guidance.

Microsoft’s secure hub-spoke design for regional web applications provides additional context for segmentation and defense in depth.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Validate operations and changes

Enable useful diagnostics

Enable diagnostic settings for the Azure Firewall, Bastion, and gateways that need operational visibility. Choose the logs and metrics based on troubleshooting and audit needs while accounting for log volume and monitoring cost.

Best Value
Firewall Mini PC, Intel J1900 4-Port i210 Router, 4GB RAM 64GB SSD
  • 【CPU Optimized for Firewall Mini PCs】This firewall appliance is powered by Intel Quad-Core Celeron J1900, 64-bit, up to 2.0 GHz, supporting software-based encryption. Energy-efficient and reliable, it runs 24/7 for home or small office networks, handling VPNs, multi-WAN routing, and basic firewall tasks efficiently.
  • 【4×Intel i210 Ports】Equipped with four Intel i210 network controllers, each delivering up to 1 GbE for reliable multi-WAN routing, VPN connections, VLAN management, and stable performance in small office or home firewall deployments
  • 【Memory & Storage】This Firewall Mini PC comes with 4 GB DDR3L RAM and a 64 GB mSATA SSD, providing reliable performance for basic networking tasks. AMI BIOS with ACPI support ensures stable system operation and energy-efficient 24/7 use
  • 【Flexible System Compatibility】Compatible with Windows 10, Linux, and professional firewall systems such as pfSense, OPNsense, and VyOS, ensuring stable network management for home or small office use
  • 【After-Sales Support:】This compact, fanless, and silent firewall keeps your network secure. Includes lifetime technical support and a 30-day money-back guarantee!

Use Azure Network Watcher and Connection Monitor to troubleshoot connectivity. In hybrid ExpressRoute scenarios, consider the documented traffic-analysis tooling in Microsoft’s Cloud Adoption Framework hub-spoke guidance.

Run a path-by-path verification

  • Inspect effective routes on representative workload network interfaces and confirm they match the intended destination paths.
  • Check that firewall policy allows the required flows and that logs show the expected traffic.
  • Test name resolution from relevant Azure and on-premises clients, including names for private endpoints.
  • Review effective NSG rules at both ends of a connection.
  • Verify gateway transit and return paths for hybrid flows.

Repeat these checks after material routing, DNS, firewall, or network changes. The Microsoft topology guide recommends phased migration and verifying reachability before retiring an old network.

Migrate in phases

When moving workloads into a new hub-and-spoke layout, start with a non-critical workload. Update DNS if addresses change, verify its new routes and connectivity, and retire the old VNet only after the required paths have been confirmed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.