What is Azure Virtual WAN?
Azure Virtual WAN is a networking service that brings together many networking, security, and routing functions into a single operational interface. The service provides a global transit hub that connects branch offices, data centers, and Azure VNets over the Microsoft backbone. Virtual WAN simplifies complex hub-and-spoke architectures through automated routing and integrated security.
Instead of manually managing VPN gateways, route tables, and peering connections, Virtual WAN handles the orchestration and enables global any-to-any connectivity. All hubs within a Standard Virtual WAN are automatically connected in a full-mesh topology over the Microsoft backbone.
Core Features
- Automated routing: BGP-based routing between all connected networks without manual route tables
- Site-to-site and point-to-site VPN: Built-in VPN connectivity for sites and individual remote users
- ExpressRoute integration: Native ExpressRoute gateway integration for private connections, optionally with IPsec encryption over ExpressRoute
- Azure Firewall integration: Secured Virtual Hub with integrated firewall for centralized security
- SD-WAN partner integration: Automated connectivity with partner solutions for connectivity automation
- Transit connectivity between VNets: Each virtual hub router supports, according to Microsoft, an aggregate throughput of up to 50 Gbps (Standard Virtual WAN)
Typical Use Cases
Global enterprise networks: Connecting many branch offices worldwide with Azure workloads over the Microsoft backbone.
Multi-region Azure deployment: Transit routing between Azure VNets in different regions without complex manual peering setup.
Centralized security: Secured Virtual Hubs with Azure Firewall for unified security policies across all locations.
Benefits
- Simplified architecture: Replaces complex hub-and-spoke setups with manual route tables
- Global reach: Microsoft backbone with low latency between connected hubs
- Scalable: Per-hub capacity can be adjusted via gateway scale units or hub infrastructure units
- Integrated security: Firewall-as-a-service without additional NVA management
Frequently Asked Questions about Azure Virtual WAN
What is the difference between Basic and Standard Virtual WAN?
Basic Virtual WAN supports only site-to-site VPN and does not allow adjusting gateway scale units for higher throughput. Standard Virtual WAN additionally offers ExpressRoute, point-to-site VPN, transit connectivity between hubs and VNets, Azure Firewall integration, and NVA support in the hub. You can upgrade from Basic to Standard, but not downgrade back to Basic.
How does routing work in Virtual WAN?
Virtual WAN uses BGP for dynamic routing. All connected networks (VNets, branches, ExpressRoute) automatically exchange routes via the hub router. Custom route tables with association and propagation enable segmentation and traffic isolation.
Can I use existing VPN hardware?
Yes, Virtual WAN is compatible with standard IPsec/IKEv2 VPN devices. Microsoft provides configuration guidance for devices from various vendors. Certified SD-WAN and VPN partner solutions can also automatically establish connectivity to the hub.
What does Virtual WAN cost?
Costs consist of hub usage (Basic or Standard), gateway scale units for VPN/ExpressRoute, and data transfer costs, including potential Global VNet peering charges for cross-hub connections in different regions. Current exact pricing is available on the official Azure pricing page.
How do I integrate Azure Firewall?
Create a Secured Virtual Hub via Azure Firewall Manager. The firewall is deployed within the hub so that inter-hub and internet traffic can be centrally filtered.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Azure Virtual WAN: from evaluating whether Virtual WAN is suitable for your topology, to designing global network architectures, to migrating existing hub-and-spoke setups.
Contact us for a non-binding consultation on Azure Virtual WAN and Microsoft Azure.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
