SkillByAIOpen interactive version →

Lesson 16 / 25

Virtual Networks, Subnets and NSGs

Design a VNet address plan and filter traffic with network security groups.

Your private network in Azure

A virtual network (VNet) is an isolated private network in one region with an address space you choose, such as 10.10.0.0/16, divided into subnets (10.10.1.0/24 for web, 10.10.2.0/24 for data). Azure reserves five addresses in every subnet. Network security groups (NSGs) filter traffic with ordered allow/deny rules on source, destination, port and protocol; rules with lower priority numbers are evaluated first (100 to 4096), and default rules allow traffic inside the VNet and block inbound from the internet. NSGs attach to subnets or network interfaces. VNet peering connects VNets privately over Microsoft's backbone, but it is not transitive: if A peers with B and B with C, A cannot reach C without its own peering or a hub with routing. Common designs use a hub-and-spoke layout, with shared firewalls and gateways in the hub. Prefer Azure Bastion over public SSH or RDP ports.

Hub and spokes

Shared services live in a hub VNet; each workload gets a spoke peered to the hub.

Figure 6.1 — A hub-and-spoke network with subnets in each spoke.

VNet, subnets and a tight NSG rule

Allow HTTPS to the web subnet only from the application gateway subnet.

az network vnet create -g rg-shop-dev-cin -n vnet-shop --address-prefixes 10.10.0.0/16 \
  --subnet-name snet-web --subnet-prefixes 10.10.1.0/24
az network vnet subnet create -g rg-shop-dev-cin --vnet-name vnet-shop -n snet-data --address-prefixes 10.10.2.0/24

az network nsg create -g rg-shop-dev-cin -n nsg-web
az network nsg rule create -g rg-shop-dev-cin --nsg-name nsg-web -n allow-https-from-agw \
  --priority 100 --direction Inbound --access Allow --protocol Tcp \
  --source-address-prefixes 10.10.0.0/24 --destination-port-ranges 443
az network vnet subnet update -g rg-shop-dev-cin --vnet-name vnet-shop -n snet-web --network-security-group nsg-web

Plan address space before you peer

Peered VNets cannot have overlapping address ranges, and neither can VNets connected to your office network. Agree on a company-wide IP plan early; re-addressing a live VNet is painful.

Quick check: VNet A is peered with B, and B is peered with C. Can A reach C directly?

  • Yes, peering is transitive
  • Only if all three are in the same subscription
  • No, peering is not transitive without extra routing or a direct peering
  • Only over the public internet
Answer

No, peering is not transitive without extra routing or a direct peering — VNet peering is non-transitive; you need a direct peering or a hub with a router or firewall.