Modern Cloud Transit Architecture: Azure Virtual WAN
Network connection is extremely important for all businesses today, especially for global enterprises that have locations in many different countries and areas. Nowadays, it’s common to connect different sites worldwide by using private MPLS circuits as the main connection. If the primary connection fails, there is also the option to use broadband internet as a backup. Both MPLS and the internet each have their own good and bad points. MPLS provides a stable and quick connection, but on the downside, it is not as adaptable and takes more time to set up. On the other hand, the internet may not always be dependable.
As enterprises use more cloud-based applications for their digital transformation, they require faster and more efficient connections between different locations around the world. All IT companies want to be flexible, grow quickly, and release products faster while spending less money by using the cloud. But when you move to the cloud, you face a new problem for staying connected – how do you extend connectivity from branch sites to the cloud?
Azure Virtual WAN
Today, we’re discussing Azure Virtual WAN, which Microsoft has developed as a cutting-edge cloud transit architecture to revolutionize network connectivity.
Azure Virtual WAN is a Unified, Microsoft Managed Framework which helps customers build a solid Backbone and Connectivity solution through the Microsoft Global Network. Azure Virtual WAN is designed to route and safeguard traffic within Microsoft Azure, linking various locations like campus sites, data centers, branches, and more. This innovative architecture enables customers to effortlessly expand their network into the Microsoft Azure cloud, providing secure “any-to-any” connectivity between enterprise on-premises sites and Azure Virtual Network (VNet).
Azure Virtual WAN is a versatile networking service that consolidates numerous networking, security, and routing capabilities into a unified operational interface. Here are some of its key features:
- Centralized Management: Azure Virtual WAN offers a centralized management interface, simplifying the configuration and monitoring of network resources across multiple sites and Azure regions.
- Any-to-Any Connectivity: It provides “any-to-any” connectivity, allowing secure communication between various locations, including on-premises sites, Azure VNets, and remote branches.
- Site-to-Site Connectivity: Azure Virtual WAN enables seamless and secure site-to-site connectivity, connecting your on-premises locations to Azure VNets.
- Branch-to-Azure Connectivity: It offers optimized connectivity for branch offices, improving access to Azure resources and applications hosted in the cloud.
- Azure VNet Peering: Virtual WAN facilitates easy and secure peering between Azure VNets, enhancing network segmentation and isolation.
- Security Integration: Azure Virtual WAN integrates with Azure’s robust security services, such as Azure Firewall and Azure VPN Gateway, to enhance network security and protect traffic between sites and Azure resources.
- Global Reach: Leveraging Microsoft’s global network infrastructure, Virtual WAN provides low-latency, reliable, and high-performance connectivity worldwide.
- Automatic Failover: It includes automatic failover capabilities, ensuring network resilience by redirecting traffic in case of network failures or issues.
- Branch-to-Branch Connectivity: It allows secure connectivity between branch offices, facilitating efficient communication between remote locations.
- Hub-and-Spoke Topology: Azure Virtual WAN supports a hub-and-spoke network topology, making it easier to manage network traffic flows and security policies.
- Scalability: Organizations can scale their network resources as needed, adding or removing sites and locations seamlessly.
- Hybrid Cloud Connectivity: Azure Virtual WAN serves as a bridge between on-premises environments and Azure, facilitating hybrid cloud connectivity and migrations.
- Traffic Analytics: Virtual WAN provides insights and analytics tools to monitor and troubleshoot network performance and traffic patterns.
The Virtual WAN architecture is structured around a hub-and-spoke model, designed with scalability and high performance in mind for various components, including branches (VPN/SD-WAN devices), users (Azure VPN/OpenVPN/IKEv2 clients), ExpressRoute circuits, and virtual networks. This architecture enables the creation of a global transit network, where the central cloud-hosted network “hub” facilitates transitive connectivity among endpoints that might be dispersed across different types of “spokes.”
In a Standard Virtual WAN configuration, Azure regions act as hubs that you have the option to connect to. These hubs are interlinked in a full mesh topology, which simplifies connectivity for users, as it allows them to leverage the Microsoft backbone for seamless any-to-any connectivity between all spokes within the Virtual WAN. This robust network design enhances the overall performance and flexibility of your network infrastructure.

Global transit network architecture and Virtual WAN
Modern enterprises have a growing need for seamless connectivity that spans across hyper-distributed applications, data, and users, both in the cloud and on-premises. To address this requirement, many enterprises are turning to the adoption of a global transit network architecture. This architecture serves as a strategic solution for consolidating, connecting, and managing the increasingly cloud-centric and geographically dispersed IT footprint of modern, global enterprises.
The global transit network architecture is founded on a classic hub-and-spoke connectivity model. In this model, the cloud-hosted network “hub” serves as a central point of connectivity. It plays a crucial role by facilitating transitive connectivity among various endpoints that might be dispersed across different types of “spokes.” This architecture empowers organizations to create a cohesive and efficient network environment, allowing for the streamlined flow of data and communication between various components of their IT infrastructure, whether they are located in the cloud or at on-premises locations.

In this model, a spoke can be:
- Virtual network (VNets)
- Physical branch site
- Remote user
- Internet
Azure Virtual WAN allows a global transit network architecture by enabling ubiquitous, any-to-any connectivity between globally distributed sets of cloud workloads in VNets, branch sites, SaaS and PaaS applications, and users.
In the Azure Virtual WAN architecture, virtual WAN hubs are provisioned in Azure regions, to which you can choose to connect your branches, VNets, and remote users. The physical branch sites are connected to the hub by Premium or Standard ExpressRoute or site-to site-VPNs, VNets are connected to the hub by VNet connections, and remote users can directly connect to the hub using User VPN (point-to-site VPNs). Virtual WAN also supports cross-region VNet connection where a VNet in one region can be connected to a virtual WAN hub in a different region.
You can establish a virtual WAN by creating a single virtual WAN hub in the region that has the largest number of spokes (branches, VNets, users), and then connecting the spokes that are in other regions to the hub. This is a good option when an enterprise footprint is mostly in one region with a few remote spokes.
Any-to-any connectivity
Global transit network architecture enables any-to-any connectivity via virtual WAN hubs. This architecture eliminates or reduces the need for full mesh or partial mesh connectivity between spokes that are more complex to build and maintain. In addition, routing control in hub-and-spoke vs. mesh networks is easier to configure and maintain. Any-to-any connectivity (in the context of a global architecture) allows an enterprise with globally distributed users, branches, datacenters, VNets, and applications to connect to each other through the “transit” hub(s). Azure Virtual WAN acts as the global transit system.

In summary, both Global Transit Network Architecture and Virtual WAN offer a range of advantages that cater to the demands of global connectivity, including reduced latency, enhanced security, scalability, geographical reach, and cost efficiency. When effectively implemented, these technologies can significantly boost an organization’s ability to connect, communicate, and collaborate across the globe, contributing to improved operational efficiency and better user experiences.
Ready to deploy Azure Virtual WAN?
Contact us for further discussions and seamless implementation.