{"id":22117,"date":"2020-07-20T13:22:12","date_gmt":"2020-07-20T12:22:12","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=22117"},"modified":"2020-07-22T15:07:03","modified_gmt":"2020-07-22T14:07:03","slug":"azure-virtual-wan-arm-the-resources","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=22117","title":{"rendered":"Azure Virtual WAN ARM \u2013 The Resources"},"content":{"rendered":"<p>In this post, I will explain the types of resources used in Azure Virtual WAN and the nature of their relationships.<\/p>\n<p><em>Note, I have not included any content on the recently announced preview of third-party NVAs. I have not seen any materials on this yet to base such a post on and, being honest, I don&#8217;t have any use-cases for third-party NVAs.<\/em><\/p>\n<p>As you can see &#8211; there are quite a few resources involved &#8230; and some that you won&#8217;t see listed at all because of the &#8220;appliance-like&#8221; nature of the deployment. I have not included any detail on spokes or &#8220;branch offices&#8221;, which would require further resources. The below diagram is enough to get a hub operational and connected to on-premises locations and spoke virtual networks.<\/p>\n<p><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-22149\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2-1024x807.png\" alt=\"\" width=\"600\" height=\"473\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2-1024x807.png 1024w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2-300x237.png 300w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2-768x606.png 768w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2-600x473.png 600w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2.png 1447w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<h2>The Virtual WAN &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/virtualwans\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/virtualWans<\/a><\/h2>\n<p>You need at least one Virtual WAN to be deployed. This is what the hub will connect to, and you can connect many hubs to a common Virtual WAN to get automated any-to-any connectivity across the Microsoft physical WAN.<\/p>\n<p>Surprisingly, the resource is deployed to an Azure region and not as a global resource, such as other global resources such as Traffic Manager or Azure DNS.<\/p>\n<h2>The Virtual Hub &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/virtualhubs\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/virtualHubs<\/a><\/h2>\n<p>Also known as the hub, the Virtual Hub is deployed once, and once only, per Azure region where you need a hub. This hub replaces the old hub virtual network (plus gateway(s), plus firewall, plus route tables) deployment you might be used to. The hub is deployed as a hidden resource, managed through the Virtual WAN in the Azure Portal or via scripting\/ARM.<\/p>\n<p>The hub is associated with the Virtual WAN through a virtualWAN property that references the resource ID of the virtualWans resource.<\/p>\n<p>In a <a href=\"https:\/\/aidanfinn.com\/?p=22073\" target=\"_blank\" rel=\"noopener noreferrer\">previous post<\/a>, I referred to a chicken &amp; egg scenario with the virtualHubs resource. The hub has properties that point to the resource IDs of each deployed gateway:<\/p>\n<ul>\n<li>vpnGateway: For site-to-site VPN.<\/li>\n<li>expressRouteGateway: For ExpressRoute circuit connectivity.<\/li>\n<li>p2sVpnGateway: For end-user\/device tunnels.<\/li>\n<\/ul>\n<p>If you choose to deploy a &#8220;Secured Virtual Hub&#8221; there will also be a property called azureFirewall that will point to the resource ID of an Azure Firewall with the AZFW_Hub SKU.<\/p>\n<p>Note, the restriction of 1 hub per Azure region does introduce a bottleneck. Under the covers of the platform, there is actually a virtual network. The only clue to this network will be in the peering properties of your spoke virtual networks. A single virtual network can have, today, a maximum of 500 spokes. So that means you will have a maximum of 500 spokes per Azure region.<\/p>\n<h2>Routing Tables &#8211; <a href=\"Microsoft.Network\/virtualHubs\/hubRouteTables\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/virtualHubs\/hubRouteTables<\/a> &amp; <a href=\"Microsoft.Network\/virtualHubs\/routeTables\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/virtualHubs\/routeTables<\/a><\/h2>\n<p>These are resources that are used in custom routing, a recently announced as GA feature that won&#8217;t be live until August 3rd, according to the Azure Portal. The resource control the flows of traffic in your hub and spoke architecture. They are child-resources of the virtualHubs resource so no references of hub resource IDs are required.<\/p>\n<h2>Azure Firewall &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/azurefirewalls\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/azureFirewalls<\/a><\/h2>\n<p>This is an optional resource that is deployed when you want a &#8220;Secured Virtual Hub&#8221;. Today, this is the only way to put a firewall into the hub, although a new preview program should make it possible for third-parties to join the hub. Alternatively, you can use custom routing to force north-south and east-west traffic through an NVA that is running in a spoke, although that will double peering costs.<\/p>\n<p>The Azure Firewall is deployed with the AZFW_Hub SKU. The firewall is not a hidden resource. To manage the firewall, you must use an Azure Firewall Policy (aka Azure Firewall Manager). The firewall has a property called firewallPolicy that points to the resource ID of a firewallPolicies resource.<\/p>\n<h2>Azure Firewall Policy &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/firewallpolicies\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/firewallPolicies<\/a><\/h2>\n<p>This is a resource that allows you to manage an Azure Firewall, in this case, an AZFW_Hub SKU of Azure Firewall. Although not shown here, you can deploy a parent\/child configuration of policies to <a href=\"https:\/\/aidanfinn.com\/?p=22006\" target=\"_blank\" rel=\"noopener noreferrer\">manage firewall configurations and rules in a global\/local way<\/a>.<\/p>\n<h2>VPN Gateway &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/vpngateways\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/vpnGateways<\/a><\/h2>\n<p>This is one of 3 ways (one, two or all three at once) that you can connect on-premises (branch) sites to the hub and your Azure deployment(s). This gateway provides you with site-to-site connectivity using VPN. The VPN Gateway uses a property called virtualHub to point at the resource ID of the associated hub or virtualHubs resource. This is a hidden resource.<\/p>\n<p>Note that the virtualHubs resource <a href=\"https:\/\/aidanfinn.com\/?p=22073\" target=\"_blank\" rel=\"noopener noreferrer\">must also point at the resource ID of the VPN gateway resource ID using a property called vpnGateway<\/a>.<\/p>\n<h2>ExpressRoute Gateway &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/expressroutegateways\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/expressRouteGateways<\/a><\/h2>\n<p>This is one of 3 ways (one, two or all three at once) that you can connect on-premises (branch) sites to the hub and your Azure deployment(s). This gateway provides you with site-to-site connectivity using ExpressRoute. The ExpressRoute Gateway uses a property called virtualHub to point at the resource ID of the associated hub or virtualHubs resource. This is a hidden resource.<\/p>\n<p>Note that the virtualHubs resource <a href=\"https:\/\/aidanfinn.com\/?p=22073\" target=\"_blank\" rel=\"noopener noreferrer\">must also point at the resource ID of the ExpressRoute gateway resource ID using a property called p2sGateway<\/a>.<\/p>\n<h2>Point-to-Site Gateway &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/p2svpngateways\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/p2sVpnGateways<\/a><\/h2>\n<p>This is one of 3 ways (one, two or all three at once) that you can connect on-premises (branch) sites to the hub and your Azure deployment(s). This gateway provides users\/devices with connectivity using VPN tunnels. The Point-to-Site Gateway uses a property called virtualHub to point at the resource ID of the associated hub or virtualHubs resource. This is a hidden resource.<\/p>\n<p>The Point-to-Site Gateway inherits a VPN configuration from a VPN configuration resource based on Microsoft.Network\/vpnServerConfigurations, referring to the configuration resource by its resource ID using a property called vpnServerConfiguration.<\/p>\n<p>Note that the virtualHubs resource <a href=\"https:\/\/aidanfinn.com\/?p=22073\" target=\"_blank\" rel=\"noopener noreferrer\">must also point at the resource ID of the Point-to-Site gateway resource ID using a property called p2sVpnGateway<\/a>.<\/p>\n<h2>VPN Server Configuration &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/vpnserverconfigurations\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/vpnServerConfigurations<\/a><\/h2>\n<p>This configuration for Point-to-Site VPN gateways can be seen in the Azure WAN and is intended as a shared configuration that is reusable with more than one Point-to-Site VPN Gateway. To be honest, I can see myself using it as a per-region configuration because of some values like DNS servers and RADIUS servers that will probably be placed per-region for performance and resilience reasons. This is a hidden resource.<\/p>\n<p><em>The following resources were added on 22nd July 2020:<\/em><\/p>\n<h2>VPN Sites &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/vpnsites\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/vpnSites<\/a><\/h2>\n<p>This resource has a similar purpose to a Local Network Gateway for site-to-site VPN connections; it describes the on-premises location, AKA &#8220;branch office&#8221;.\u00a0 A VPN site can be associated with one or many hubs, so it is actually connected to the Virtual WAN resource ID using a property called virtualWan. This is a hidden resource.<\/p>\n<p>An array property called vpnSiteLinks describes possible connections to on-premises firewall devices.<\/p>\n<h2>VPN Connections &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/vpngateways\/vpnconnections\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/vpnGateways\/vpnConnections<\/a><\/h2>\n<p>A VPN Connections resource associates a VPN Gateway with the on-premises location that is described by an associated VPN Site. The vpnConnections resource is a child resource of vpnGateways, so there is no actual resource; the vpnConnections resource takes its name from the parent VPN Gateway, and the resource ID is an extension of the parent VPN Gateway resource ID.<\/p>\n<p>By necessity, there is some complexity with this resource type. The remoteVpnSite property links the vpnConnections resource with the resource ID of a VPN Site resource. An array property, called vpnSiteLinkConnections, is used to connect the gateway to the on-premises location using 1 or 2 connections, each linking from vpnSiteLinkConnections to the resource\/property ID of 1 or 2 vpnSiteLinks properties in the VPN Site. With one site link connection, you have a single VPN tunnel to the on-premises location. With 2 link connections, the VPN Gateway will take advantage of its active\/active configuration to set up resilient tunnels to the on-premises location.<\/p>\n<h2>Virtual Network Connections &#8211; <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/virtualhubs\/hubvirtualnetworkconnections\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft.Network\/virtualHubs\/hubVirtualNetworkConnections<\/a><\/h2>\n<p>The purpose of a hub is to share resources with spoke virtual networks. In the case of the Virtual Hub, those resources are gateways, and maybe a firewall in the case of Secured Virtual Hub. As with a normal VNet-based hub &amp; spoke, VNet peering is used. However, the way that VNet peering is used changes with the Virtual Hub; the deployment is done using the hub\/VirtualNetworkConnections child resource, whose parent is the Virtual Hub. Therefore, the name and resource ID are based on the name and resource ID of the Virtual Hub resource.<\/p>\n<p>The deployment is rather simple; you create a Virtual Network Connection in the hub specifying the resource ID of the spoke virtual network, using a property called remoteVirtualNetwork. The underlying resource provider will initiate both sides of the peering connection on your behalf &#8211; there is no deployment required in the spoke virtual network resource. The Virtual Network Connection will reference the Hub Route Tables in the hub to configure route association and propagation.<\/p>\n<h2>More Resources<\/h2>\n<p>There are more resources that I&#8217;ve yet to document, including:<\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/virtualhubs\/bgpconnections\" target=\"_blank\" rel=\"noopener noreferrer\">BGP Connections<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/virtualhubs\/ipconfigurations\" target=\"_blank\" rel=\"noopener noreferrer\">IP Configurations<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/expressroutecrossconnections\" target=\"_blank\" rel=\"noopener noreferrer\">ExpressRoute Connections<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/templates\/microsoft.network\/expressroutecircuits\" target=\"_blank\" rel=\"noopener noreferrer\">ExpressRoute Circuits<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>In this post, I will explain the types of resources used in Azure Virtual WAN and the nature of their relationships. Note, I have not included any content on the recently announced preview of third-party NVAs. I have not seen any materials on this yet to base such a post on and, being honest, I &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=22117\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Azure Virtual WAN ARM \u2013 The Resources&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_wpcom_ai_launchpad_first_post":false,"footnotes":""},"categories":[5],"tags":[161,170,306,442,454,283,456,242,343,432,80,459,460,457,458,461,453,266,452,444,455],"class_list":["post-22117","post","type-post","status-publish","format-standard","hentry","category-azure","tag-arm","tag-azure","tag-azure-firewall","tag-azure-firewall-policy","tag-custom-routing","tag-expressroute","tag-expressroute-gateway","tag-firewall","tag-gateway","tag-hub-spoke","tag-networking","tag-p2s","tag-p2s-server-configuration","tag-point-to-site-gateway","tag-point-to-site-vpn","tag-resources","tag-route-tables","tag-template","tag-virtual-hub","tag-virtual-wan","tag-vpn-gateway"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"AFinn\"\/>\n\t<meta name=\"google-site-verification\" content=\"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/aidanfinn.com\/?p=22117\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\" \/>\n\t\t<meta property=\"og:type\" content=\"activity\" \/>\n\t\t<meta property=\"og:title\" content=\"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro\" \/>\n\t\t<meta property=\"og:description\" content=\"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/aidanfinn.com\/?p=22117\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@joe_elway\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro\" \/>\n\t\t<meta name=\"twitter:description\" content=\"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@joe_elway\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#article\",\"name\":\"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro\",\"headline\":\"Azure Virtual WAN ARM \\u2013 The Resources\",\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/AzureVirtualWanResources2.png\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117\\\/#articleImage\",\"width\":1447,\"height\":1141},\"datePublished\":\"2020-07-20T13:22:12+01:00\",\"dateModified\":\"2020-07-22T15:07:03+01:00\",\"inLanguage\":\"en-GB\",\"commentCount\":2,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#webpage\"},\"articleSection\":\"Azure, ARM, Azure, Azure Firewall, Azure Firewall Policy, Custom Routing, ExpressRoute, ExpressRoute Gateway, Firewall, Gateway, Hub &amp; Spoke, Networking, P2S, P2S Server Configuration, Point-to-Site Gateway, Point-to-Site VPN, Resources, Route Tables, Template, Virtual Hub, Virtual WAN, VPN Gateway\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"position\":2,\"name\":\"Azure\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#listItem\",\"name\":\"Azure Virtual WAN ARM \\u2013 The Resources\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#listItem\",\"position\":3,\"name\":\"Azure Virtual WAN ARM \\u2013 The Resources\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#webpage\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117\",\"name\":\"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro\",\"description\":\"This post explains the resources used in Azure Virtual WAN and maps\\\/diagrams\\\/illustrates the relationships between those resources.\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22117#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"datePublished\":\"2020-07-20T13:22:12+01:00\",\"dateModified\":\"2020-07-22T15:07:03+01:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"name\":\"Aidan Finn, IT Pro\",\"description\":\"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro","description":"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.","canonical_url":"https:\/\/aidanfinn.com\/?p=22117","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aidanfinn.com\/?p=22117#article","name":"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro","headline":"Azure Virtual WAN ARM \u2013 The Resources","author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"publisher":{"@id":"https:\/\/aidanfinn.com\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/07\/AzureVirtualWanResources2.png","@id":"https:\/\/aidanfinn.com\/?p=22117\/#articleImage","width":1447,"height":1141},"datePublished":"2020-07-20T13:22:12+01:00","dateModified":"2020-07-22T15:07:03+01:00","inLanguage":"en-GB","commentCount":2,"mainEntityOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=22117#webpage"},"isPartOf":{"@id":"https:\/\/aidanfinn.com\/?p=22117#webpage"},"articleSection":"Azure, ARM, Azure, Azure Firewall, Azure Firewall Policy, Custom Routing, ExpressRoute, ExpressRoute Gateway, Firewall, Gateway, Hub &amp; Spoke, Networking, P2S, P2S Server Configuration, Point-to-Site Gateway, Point-to-Site VPN, Resources, Route Tables, Template, Virtual Hub, Virtual WAN, VPN Gateway"},{"@type":"BreadcrumbList","@id":"https:\/\/aidanfinn.com\/?p=22117#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/#listItem","position":1,"name":"Home","item":"https:\/\/aidanfinn.com\/","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","position":2,"name":"Azure","item":"https:\/\/aidanfinn.com\/?cat=5","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=22117#listItem","name":"Azure Virtual WAN ARM \u2013 The Resources"},"previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=22117#listItem","position":3,"name":"Azure Virtual WAN ARM \u2013 The Resources","previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}}]},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/#person","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=22117#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/?author=1#author","url":"https:\/\/aidanfinn.com\/?author=1","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=22117#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"WebPage","@id":"https:\/\/aidanfinn.com\/?p=22117#webpage","url":"https:\/\/aidanfinn.com\/?p=22117","name":"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro","description":"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.","inLanguage":"en-GB","isPartOf":{"@id":"https:\/\/aidanfinn.com\/#website"},"breadcrumb":{"@id":"https:\/\/aidanfinn.com\/?p=22117#breadcrumblist"},"author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"creator":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"datePublished":"2020-07-20T13:22:12+01:00","dateModified":"2020-07-22T15:07:03+01:00"},{"@type":"WebSite","@id":"https:\/\/aidanfinn.com\/#website","url":"https:\/\/aidanfinn.com\/","name":"Aidan Finn, IT Pro","description":"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","inLanguage":"en-GB","publisher":{"@id":"https:\/\/aidanfinn.com\/#person"}}]},"og:locale":"en_GB","og:site_name":"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","og:type":"activity","og:title":"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro","og:description":"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.","og:url":"https:\/\/aidanfinn.com\/?p=22117","twitter:card":"summary","twitter:site":"@joe_elway","twitter:title":"Azure Virtual WAN - The Resources | Aidan Finn, IT Pro","twitter:description":"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.","twitter:creator":"@joe_elway"},"aioseo_meta_data":{"post_id":"22117","title":"Azure Virtual WAN - The Resources | #site_title","description":"This post explains the resources used in Azure Virtual WAN and maps\/diagrams\/illustrates the relationships between those resources.","keywords":[{"label":"Azure","value":"Azure"},{"label":"Networking","value":"Networking"},{"label":"Hub &amp; Spoke","value":"Hub &amp; Spoke"},{"label":"Virtual WAN","value":"Virtual WAN"},{"label":"Virtual Hub","value":"Virtual Hub"},{"label":"Route Tables","value":"Route Tables"},{"label":"Custom Routing","value":"Custom Routing"},{"label":"Azure Firewall","value":"Azure Firewall"},{"label":"Firewall","value":"Firewall"},{"label":"Azure Firewall Policy","value":"Azure Firewall Policy"},{"label":"VPN Gateway","value":"VPN Gateway"},{"label":"Gateway","value":"Gateway"},{"label":"ExpressRoute Gateway","value":"ExpressRoute Gateway"},{"label":"ExpressRoute","value":"ExpressRoute"},{"label":"Point-to-Site Gateway","value":"Point-to-Site Gateway"},{"label":"Point-to-Site VPN","value":"Point-to-Site VPN"},{"label":"P2S","value":"P2S"},{"label":"P2S Server Configuration","value":"P2S Server Configuration"},{"label":"ARM","value":"ARM"},{"label":"Template","value":"Template"},{"label":"JSON","value":"JSON"},{"label":"Resources","value":"Resources"},{"label":"Diagram","value":"Diagram"},{"label":"Map","value":"Map"}],"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":"","og_description":"","og_object_type":"activity","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"","og_article_tags":"","twitter_use_og":false,"twitter_card":"summary","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[],"defaultGraph":"","defaultPostTypeGraph":""},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 03:53:23","updated":"2025-06-04 17:33:02","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/?cat=5\" title=\"Azure\">Azure<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAzure Virtual WAN ARM \u2013 The Resources\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/aidanfinn.com\/"},{"label":"Azure","link":"https:\/\/aidanfinn.com\/?cat=5"},{"label":"Azure Virtual WAN ARM \u2013 The Resources","link":"https:\/\/aidanfinn.com\/?p=22117"}],"amp_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=22117"}],"version-history":[{"count":31,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22117\/revisions"}],"predecessor-version":[{"id":22158,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22117\/revisions\/22158"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=22117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=22117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=22117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}