Skip to main content
Cloud / Azure / Products / Azure Virtual WAN - Global Network Hub

Azure Virtual WAN - Global Network Hub

Azure Virtual WAN simplifies global network architectures with automated routing, VPN, and ExpressRoute in one hub.

networking
Pricing Model Billed by hub usage (Basic/Standard), gateway scale units for VPN/ExpressRoute, and data transfer
Availability Available in numerous Azure regions worldwide
Data Sovereignty EU regions available
Reliability SLA as published by the provider (see official SLA page) SLA

What is Azure Virtual WAN?

Azure Virtual WAN is a networking service that brings together many networking, security, and routing functions into a single operational interface. The service provides a global transit hub that connects branch offices, data centers, and Azure VNets over the Microsoft backbone. Virtual WAN simplifies complex hub-and-spoke architectures through automated routing and integrated security.

Instead of manually managing VPN gateways, route tables, and peering connections, Virtual WAN handles the orchestration and enables global any-to-any connectivity. All hubs within a Standard Virtual WAN are automatically connected in a full-mesh topology over the Microsoft backbone.

Core Features

  • Automated routing: BGP-based routing between all connected networks without manual route tables
  • Site-to-site and point-to-site VPN: Built-in VPN connectivity for sites and individual remote users
  • ExpressRoute integration: Native ExpressRoute gateway integration for private connections, optionally with IPsec encryption over ExpressRoute
  • Azure Firewall integration: Secured Virtual Hub with integrated firewall for centralized security
  • SD-WAN partner integration: Automated connectivity with partner solutions for connectivity automation
  • Transit connectivity between VNets: Each virtual hub router supports, according to Microsoft, an aggregate throughput of up to 50 Gbps (Standard Virtual WAN)

Typical Use Cases

Global enterprise networks: Connecting many branch offices worldwide with Azure workloads over the Microsoft backbone.

Multi-region Azure deployment: Transit routing between Azure VNets in different regions without complex manual peering setup.

Centralized security: Secured Virtual Hubs with Azure Firewall for unified security policies across all locations.

Benefits

  • Simplified architecture: Replaces complex hub-and-spoke setups with manual route tables
  • Global reach: Microsoft backbone with low latency between connected hubs
  • Scalable: Per-hub capacity can be adjusted via gateway scale units or hub infrastructure units
  • Integrated security: Firewall-as-a-service without additional NVA management

Frequently Asked Questions about Azure Virtual WAN

What is the difference between Basic and Standard Virtual WAN?

Basic Virtual WAN supports only site-to-site VPN and does not allow adjusting gateway scale units for higher throughput. Standard Virtual WAN additionally offers ExpressRoute, point-to-site VPN, transit connectivity between hubs and VNets, Azure Firewall integration, and NVA support in the hub. You can upgrade from Basic to Standard, but not downgrade back to Basic.

How does routing work in Virtual WAN?

Virtual WAN uses BGP for dynamic routing. All connected networks (VNets, branches, ExpressRoute) automatically exchange routes via the hub router. Custom route tables with association and propagation enable segmentation and traffic isolation.

Can I use existing VPN hardware?

Yes, Virtual WAN is compatible with standard IPsec/IKEv2 VPN devices. Microsoft provides configuration guidance for devices from various vendors. Certified SD-WAN and VPN partner solutions can also automatically establish connectivity to the hub.

What does Virtual WAN cost?

Costs consist of hub usage (Basic or Standard), gateway scale units for VPN/ExpressRoute, and data transfer costs, including potential Global VNet peering charges for cross-hub connections in different regions. Current exact pricing is available on the official Azure pricing page.

How do I integrate Azure Firewall?

Create a Secured Virtual Hub via Azure Firewall Manager. The firewall is deployed within the hub so that inter-hub and internet traffic can be centrally filtered.

Integration with innFactory

As a Microsoft Solutions Partner, innFactory supports you with Azure Virtual WAN: from evaluating whether Virtual WAN is suitable for your topology, to designing global network architectures, to migrating existing hub-and-spoke setups.

Contact us for a non-binding consultation on Azure Virtual WAN and Microsoft Azure.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Certificate Manager - Central TLS Certificate Management

Certificate Manager acquires, manages, and deploys TLS certificates for Cloud Load Balancing, Secure Web Proxy, and …

Pricing Pricing as published on the official …
SLA SLA as published by the provider
Compare →
Google Cloud

Cloud Domains - Domain Registration in Google Cloud

Cloud Domains lets you register and manage domains directly in Google Cloud, with billing through Cloud Billing and …

Pricing Per top-level domain pricing as …
SLA SLA as published by the provider
Compare →
Google Cloud

Data Transfer Essentials - Data Transfer Between Cloud Providers

Data Transfer Essentials provides cost-optimized data transfer between the services of an application that resides …

Pricing Currently offered at no charge when used …
SLA SLA as published by the provider
Compare →
Google Cloud

Secure Access Connect - Attach SSE Services to NCC Gateway

Secure Access Connect lets you connect security service edge products to NCC Gateway for security processing and secure …

Pricing Billed according to NCC Gateway pricing …
SLA SLA as published by the provider
Compare →
Google Cloud

Service Extensions - Custom Code in the Network Data Path

Service Extensions inserts custom code into the data path of Cloud Load Balancing, Media CDN, and Secure Web Proxy, as …

Pricing Billed per invocation: plugins on Cloud …
SLA As published by the provider / see official documentation
Compare →
Google Cloud

Telecom Network Automation - Cloud-Native Automation for Telecom Networks

Telecom Network Automation is Google's managed cloud implementation of the open source Nephio project for intent-driven …

Pricing Pay-as-you-go per automated vCPU per …
SLA SLA per provider / see official documentation
Compare →

53 comparable products found across other clouds.

Ready to start with Azure Virtual WAN - Global Network Hub?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation