Building a Hub and Spoke Azure Network with Site to Site VPN Part 1 Architecture

Part: 1 Architecture Overview

Scenario: Building a demo or proof of concept to understand the technology, azure resources and configuration settings that involve Azure Virtual Networks, VNet Peerings, Virtual Network Gateway, and Site to Site VPN Connections. The architecture is to emulate a hybrid cloud topology with on-premises network emulated with an Azure VNETs in a hub and spoke network topology.

My Azure CLI script to build most of this network architecture can be found at

The key drivers that would for this demo is for technical planning, design and implementation where you you are building out or extending your Azure Network design to have some on-premises connectivity with a Site to Site VPN Connection. This would be suitable for small to medium sized organizations. Also can be a starting point for large organizations. Moreover it is intended for cloud networking novices to establish foundational knowledge.

Architecture Overview

The high level architecture composes of the following

  1. Hybrid connection between “On-Premises” and Azure Virtual Network using Site to Site VPN
  2. Azure Virtual Network Hub and Spoke Topology
  3. VNET, subnet and network peerings
  4. Network security considerations

These components are to facilitate the following capabilities and design goals

  1. Hybrid cloud support
  2. Flexible networking topology to support multiple environments
  3. Adopt security best practices

Read further for the Site to Site VPN Connection design in part 2.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s