Skip to main content
Cloud / Azure / Products / Azure Virtual WAN - Global Network Hub

Azure Virtual WAN - Global Network Hub

Azure Virtual WAN simplifies global network architectures with automated routing, VPN, and ExpressRoute in one hub.

networking
Pricing Model Billed by hub usage (Basic/Standard), gateway scale units for VPN/ExpressRoute, and data transfer
Availability Available in numerous Azure regions worldwide
Data Sovereignty EU regions available
Reliability SLA as published by the provider (see official SLA page) SLA

What is Azure Virtual WAN?

Azure Virtual WAN is a networking service that brings together many networking, security, and routing functions into a single operational interface. The service provides a global transit hub that connects branch offices, data centers, and Azure VNets over the Microsoft backbone. Virtual WAN simplifies complex hub-and-spoke architectures through automated routing and integrated security.

Instead of manually managing VPN gateways, route tables, and peering connections, Virtual WAN handles the orchestration and enables global any-to-any connectivity. All hubs within a Standard Virtual WAN are automatically connected in a full-mesh topology over the Microsoft backbone.

Core Features

  • Automated routing: BGP-based routing between all connected networks without manual route tables
  • Site-to-site and point-to-site VPN: Built-in VPN connectivity for sites and individual remote users
  • ExpressRoute integration: Native ExpressRoute gateway integration for private connections, optionally with IPsec encryption over ExpressRoute
  • Azure Firewall integration: Secured Virtual Hub with integrated firewall for centralized security
  • SD-WAN partner integration: Automated connectivity with partner solutions for connectivity automation
  • Transit connectivity between VNets: Each virtual hub router supports, according to Microsoft, an aggregate throughput of up to 50 Gbps (Standard Virtual WAN)

Typical Use Cases

Global enterprise networks: Connecting many branch offices worldwide with Azure workloads over the Microsoft backbone.

Multi-region Azure deployment: Transit routing between Azure VNets in different regions without complex manual peering setup.

Centralized security: Secured Virtual Hubs with Azure Firewall for unified security policies across all locations.

Benefits

  • Simplified architecture: Replaces complex hub-and-spoke setups with manual route tables
  • Global reach: Microsoft backbone with low latency between connected hubs
  • Scalable: Per-hub capacity can be adjusted via gateway scale units or hub infrastructure units
  • Integrated security: Firewall-as-a-service without additional NVA management

Frequently Asked Questions about Azure Virtual WAN

What is the difference between Basic and Standard Virtual WAN?

Basic Virtual WAN supports only site-to-site VPN and does not allow adjusting gateway scale units for higher throughput. Standard Virtual WAN additionally offers ExpressRoute, point-to-site VPN, transit connectivity between hubs and VNets, Azure Firewall integration, and NVA support in the hub. You can upgrade from Basic to Standard, but not downgrade back to Basic.

How does routing work in Virtual WAN?

Virtual WAN uses BGP for dynamic routing. All connected networks (VNets, branches, ExpressRoute) automatically exchange routes via the hub router. Custom route tables with association and propagation enable segmentation and traffic isolation.

Can I use existing VPN hardware?

Yes, Virtual WAN is compatible with standard IPsec/IKEv2 VPN devices. Microsoft provides configuration guidance for devices from various vendors. Certified SD-WAN and VPN partner solutions can also automatically establish connectivity to the hub.

What does Virtual WAN cost?

Costs consist of hub usage (Basic or Standard), gateway scale units for VPN/ExpressRoute, and data transfer costs, including potential Global VNet peering charges for cross-hub connections in different regions. Current exact pricing is available on the official Azure pricing page.

How do I integrate Azure Firewall?

Create a Secured Virtual Hub via Azure Firewall Manager. The firewall is deployed within the hub so that inter-hub and internet traffic can be centrally filtered.

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you with Azure Virtual WAN: from evaluating whether Virtual WAN is suitable for your topology, to designing global network architectures, to migrating existing hub-and-spoke setups.

Contact us for a non-binding consultation on Azure Virtual WAN and Microsoft Azure.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

AWS

Amazon API Gateway - Managed API Platform

Amazon API Gateway is a fully managed service for creating, publishing, and managing REST, HTTP, and WebSocket APIs.

Pricing Pay per request (tiered by volume), plus …
SLA SLA as published by the provider
Compare →
AWS

Amazon CloudFront: Content Delivery Network

Amazon CloudFront is AWS's global CDN with 750+ Points of Presence for fast content delivery worldwide.

Pricing Pay-as-you-go (data transfer and …
SLA 99.9% Monthly Uptime Percentage per official SLA
Compare →
AWS

Amazon Route 53 - DNS and Domain Registration

Amazon Route 53 is AWS' scalable DNS service for domain registration, routing, and health checks.

Pricing Pay per hosted zone and per DNS query, …
SLA SLA as published by the provider: tiered service credits when monthly availability falls below 99.99% (see official SLA page)
Compare →
AWS

Amazon Route 53 Global Resolver - Hybrid DNS

Amazon Route 53 Global Resolver: internet-reachable anycast DNS resolver for secure DNS resolution across branch, remote …

Pricing Hourly per-region fee + pay-per-query
SLA N/A
Compare →
AWS

Amazon VPC - AWS Networking & Content Delivery Service

Amazon VPC is an AWS service for Network isolation and Multi-tier web applications. GDPR-compliant in EU regions.

Pricing No charge for the VPC itself, pay only …
SLA N/A (free base service; components like NAT Gateway have their own SLAs)
Compare →
AWS

Amazon VPC Lattice - Application Networking

Amazon VPC Lattice simplifies service-to-service communication. Consistent application networking across VPCs and …

Pricing Pay-per-use: hourly per service plus per …
SLA SLA as published by the provider
Compare →

42 comparable products found across other clouds.

Ready to start with Azure Virtual WAN - Global Network Hub?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation