No video

Azure Virtual WAN Overview

  Рет қаралды 60,434

John Savill's Technical Training

John Savill's Technical Training

Күн бұрын

In this video I walk through an overview of Azure Virtual WAN, what it is, why we have it and the connectivity is provides! Includes connecting vnets, expressroute, S2S and P2S!

Пікірлер: 122
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Someone asked on Reddit about controlling access between vnets. I talked about a default route table but you can also use custom route tables for the vnets to control which vnets can talk to which other vnets enabling you to control vnet-to-vnet if required.
@z0nerider
@z0nerider 3 жыл бұрын
Azure vWAN seems a bit complicated with route table association and propagation, can you make a deep dive on this ????
@gultekinbutun7910
@gultekinbutun7910 2 жыл бұрын
Even the video is 2 year old, still watching it. Thanks a lot John.
@diegolagosmorales2536
@diegolagosmorales2536 Жыл бұрын
you are a wizard, you were able to explain to me Virtual WAN, when looking at the documentation I was not totally able to understand the capabilities of the product. Well done
@cinthyagarciarodriguez5098
@cinthyagarciarodriguez5098 Жыл бұрын
I am networking support engineer right now. I cannot thank you enough for your great guidance to reach technical knowledge and feel motivated to reach more.
@satishraju5188
@satishraju5188 Жыл бұрын
You are the best teacher ever ❤️❤️ thank you so much. Also People are lucky enough to have your lessons for free..🙏 And unlucky people who have not watched your videos yet, I wish they all should get their luck soon 😊
@NTFAQGuy
@NTFAQGuy Жыл бұрын
Wow, thank you
@kamatapa
@kamatapa 3 жыл бұрын
On a first glance I've dismissed VWAN on the grounds that I could do the same by other means. But this is big-enterprise stuff and there are so many things to explore in this topic that I would love to watch a "Azure Virtual WAN deep dive" in the near future. Who knows? :-)
@mansourshokri6176
@mansourshokri6176 2 жыл бұрын
Another amazing training video, great job John, I am getting ready for AZ-305 exam next week and these videos are so damn helpful, thanks a lot to spend so much to create these videos.
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
Best of luck!
@eliassal1
@eliassal1 2 ай бұрын
Great video, understood really the difference betweenn VWan and VPN Gateways
@santiagoleoni3833
@santiagoleoni3833 3 жыл бұрын
The Azure God doing it again. Thanks John!
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Lol, thanks :)
@shobanad8256
@shobanad8256 Жыл бұрын
Always very informative and simple in the explanations, thank you
@NTFAQGuy
@NTFAQGuy Жыл бұрын
My pleasure!
@Tech-ub8dd
@Tech-ub8dd Жыл бұрын
Thank you John , love all your work! Thank you!
@MonsterPOV
@MonsterPOV 3 жыл бұрын
so in AWS terms, this is similar to Transit Gateway :)
@ibmuser13
@ibmuser13 3 жыл бұрын
exactly! the only difference being, the wvan hubs in different regions can by default talk to each other .. versus in AWS, the transit gateways in different regions have to be peered. slightly different ways of implementing the spoke to spoke communication .. but good Azure has something for this use case... (heavy TGW user here)
@saltspicemagic
@saltspicemagic Жыл бұрын
Thank you , you are explaining things so well which were really hard to grasp🤟
@kdedesko
@kdedesko 5 ай бұрын
Simply the best John !!!!
@Apollo26gaming
@Apollo26gaming 3 жыл бұрын
Excellent Video John. Really cleared my concept on Virtual WAN.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Excellent
@Sergio-Here-In-Community
@Sergio-Here-In-Community 2 жыл бұрын
Hey John.... Amazing training... the best of the best trainer ever!!!
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
Thanks!
@Certified_Chad_42
@Certified_Chad_42 3 жыл бұрын
As usual a great video. Thank JohnTechSavill!!!
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Hehe, thanks
@jimlosinsky5548
@jimlosinsky5548 7 ай бұрын
GREAT 😀😀😀😀
@masoudkooranloo908
@masoudkooranloo908 2 жыл бұрын
Thank you John!
@PrashantSharma-ql4yb
@PrashantSharma-ql4yb Жыл бұрын
brilliant explanation!
@aryan1736
@aryan1736 3 жыл бұрын
Awesomely Explained
@marcelohg
@marcelohg 3 жыл бұрын
Thank you. Great explanation!
@Stateoftheheart
@Stateoftheheart 3 жыл бұрын
Would you advise a VWAN for each Azure Tenant or would it better to use one VWAN to connect all business unit tenants as well as use one central firewall?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
azure ad tenant? most companies will only have one. if you mean subscription then likely would use one as the connectivity hub but would depend on more specific requirements.
@Stateoftheheart
@Stateoftheheart 3 жыл бұрын
@@NTFAQGuy Hi John thanks for the feedback. We have different business units each with its own Azure AD Tenant and subscription. I was wondering if it would be possible to manage all from one Virtual WAN or if I would need different Virtual WAN's for each. The former would prove more cost-effective if possible and possibly less admin.
@JM-bl3ih
@JM-bl3ih 10 күн бұрын
@@Stateoftheheart you can do that but you will need some sort of device that is able keep each tenant's traffic separate. the vwan hub will mesh everything together
@MohammadSameerA
@MohammadSameerA 2 жыл бұрын
Very useful and helpful. Thanks.
@rjbir
@rjbir 3 жыл бұрын
Great explanation, thanks for sharing !!
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Glad it was helpful!
@chandramohanb5585
@chandramohanb5585 Жыл бұрын
Excellent 👌👌👌
@malshawaf
@malshawaf 3 жыл бұрын
Thanks John for the great explanation .In terms of S2S connectivity latency , I think there shouldn't be any difference between using it with vWAN ( hot potato routing that you mentioned ) and the traditional VNG S2S VPN , because MS is using anycast for their IPs globally , so your on-prem site will be connected to the nearest MS "POP" regardless if you are using vWAN or traditional VNG S2S connectivity. This should apply also to the SD-WAN tunnels as they will be using the same mechanism. So you can deploy the SD-WAN NVA on a VNET or on a Vhub and in terms of latency it should be the same. Please correct me if I am getting this wrong. Thanks
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
VPN GW is an ip in a region. But yes is same mechanism with or without vwan. It’s not anycast
@malshawaf
@malshawaf 3 жыл бұрын
@@NTFAQGuy thanks , I got the anycast information from a network expert in Microsoft and he confirmed that all the regions public IPs are populated in all regions using anycast. Maybe I misunderstood.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
@@malshawaf routing is not same as anycast. Regular public ips are regional
@Chris920809
@Chris920809 2 жыл бұрын
Awesome video
@kenrq63
@kenrq63 4 жыл бұрын
Nice update John, thank you.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
You are very welcome
@prrrabu
@prrrabu 2 жыл бұрын
Great Video John !!
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
Thanks 👍
@robertgoldstein5819
@robertgoldstein5819 3 жыл бұрын
what type of device would you have at the branch locations? A standard VPN device or is there a specialized SD-WAN device?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Can be standard WAN or there are specialized partner solutions.
@raymondkissoon8274
@raymondkissoon8274 3 жыл бұрын
Another great video!
@gregtaylor5568
@gregtaylor5568 4 жыл бұрын
Great video, I do have a clarifying question, If you are using a product such as Silver Peak SD-WAN, why would we want to use vWAN to enable any-to-any communication? Wouldn't we just want vWAN to connect to our Azure resources?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
i honestly don't know enough about silver peak to know its capabilities and where virtual wan make may sense to potentially connect locations over the azure back bone which would be better than Internet and then add-in the scope of azure connectivity etc.
@gregtaylor5568
@gregtaylor5568 4 жыл бұрын
@@NTFAQGuy well lets just say SD-WAN vs. Silver Peak. Is the end goal that we are just using the SD-WAN appliance to connect to Azure vWAN, then let it do all the connectivity for us?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
The partner module for Azure Virtual Wan provides easy connectivity from that location to the Azure hub which then provides all the connectivity, yes sir.
@gregtaylor5568
@gregtaylor5568 4 жыл бұрын
@@NTFAQGuy hmmm I think I would loose all of my traffic shaping capabilities, as well as, visibility no?
@miketx3494
@miketx3494 4 жыл бұрын
@@gregtaylor5568 SilverPeak is a "bookend" type sdwan solution so it wont function on its on and requires both ends to exist and perform the sdwan functions so the per packet policies will still apply leaving and coming in. An advantage of Azure vWan here would be lower latency than DIA capabilities (think APAC to EMEA or domestic) where standard DIA may be not be performing as well so it will present as a wan link to the device (edgeconnect).
@burgergaming58
@burgergaming58 4 жыл бұрын
Great video love your videos
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Glad you like them!
@narendermann
@narendermann 3 жыл бұрын
these are really awesome.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Thanks
@Stateoftheheart
@Stateoftheheart 4 жыл бұрын
Thanks for another great video John! appreciate everything you do for the community! Do you know when the User/P2S VPN for Azure virtual WAN will support forced tunneling?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Thanks, I believe that feature is in preview.
@Stateoftheheart
@Stateoftheheart 4 жыл бұрын
@@NTFAQGuy Thank you John, that's great news!
@Stateoftheheart
@Stateoftheheart 3 жыл бұрын
@@NTFAQGuy Hi John, I don't see this feature in preview in the UK yet. Do you have any updates?
@jackfang2221
@jackfang2221 2 жыл бұрын
Another great video again, thanks John. Quick question, are "premium" and "GlobalReach" mandates for the Express Route circuit connects to virtual WAN?
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
Glad you like the video. Check the documentation for latest requirements as things have been changing around exact requirements.
@grantpalmer9338
@grantpalmer9338 4 жыл бұрын
Thanks great video really usefull
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Great to hear, thank you!
@Stateoftheheart
@Stateoftheheart 3 жыл бұрын
Thanks John, best VWAN breakdown I've seen! If I was going to implement Azure firewall would you advise going the secure VWAN hub route as opposed to just using a hub VNET with Azure firewall?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
the decision to go vwan has many factors and would not be based on use of Azure Firewall typically. much bigger design/responsibility/cost factors etc.
@Stateoftheheart
@Stateoftheheart 3 жыл бұрын
@@NTFAQGuy Thanks John, we are planning on going SDWAN down the line so I think it would make sense.
@balasubramanianwv3877
@balasubramanianwv3877 4 жыл бұрын
I want to convert my normal hub and spoke to virtual wan. Vnet to Vnet communication happening via NVA Firewall right now. Suppose if I add existing hub vnet to virtual wan hub vnet and the old hub become shared spoke services as per documentation. I hope i can still use UDR at spoke to direct the traffic via old NVA ( shared service spoke) and egress/ingress internet.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Should be possible yes.
@cartierin
@cartierin 4 жыл бұрын
Great Video!! Quick question on S2S . Can I route traffic coming from Site 1 to vent-a and site 2 to vnet-b.
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
So it would be any to any but if you wanted to restrict use nsgs so vneta only talks to site 1 etc. could also control via azure firewall if using.
@eddurguti
@eddurguti 2 жыл бұрын
Hi John, I really enjoy your videos, thank you! Question: I have vWAN in almost every region, it's great, it scales etc. Now I have a third-party vendor that needs access only to one VNET (which is a part of vWAN) via a routed VPN tunnel. I know there's a way to do custom routes, but it appears that I cannot have the vendor VPN in a custom routing table, is there a way to isolate this vnet-to-vendor-vpn connection without using NVA or secured hub?
@NTFAQGuy
@NTFAQGuy 2 жыл бұрын
Vwan supports some 3rt parties. Would check docs for options, eg faq
@ravenbao3334
@ravenbao3334 3 жыл бұрын
Hi John, under what circumstances would we need more than one Virtual Wan under a single subscription - I can't think of a reason given that one Virtual WAN is able to connect multiple regions with a hub in each region? And can different Virtual WANs talk to each other?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Typical 1 then hub in regions
@shubhamgupta3485
@shubhamgupta3485 3 жыл бұрын
I am confused on why the virtual wan is required ? because we can have express route plus site 2 site vpn tunnels on a single azure vnet also with virtual network gateway and the expressroute gateway , also if we need to connect the single vnet to different vnets we can make use of vnet peering between the vnets
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Simplifies management, routing and adds some greater scale and some features I covered
@shubhamgupta3485
@shubhamgupta3485 3 жыл бұрын
@@NTFAQGuy If we compare the price for vnet and virtual wan is there a great difference , I can see vnet is free of charge if not doing anything but virtual wan costs around 150 euro /month , for smaller deployments vnet should be recommended but if a company have a bigger and complex network then virtual wan would be recommended . Please correct me if I am wrong .
@wolkwijs324
@wolkwijs324 3 жыл бұрын
Very good video about virtual wan! But I have a question; If you use encrypted expressroute via virtual wan, does global reach break that?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
you mean S2S VPN over ExpressRoute? They should not impact global reach since the VPN is do a particular vnet not the entire expressroute circuit.
@wolkwijs324
@wolkwijs324 3 жыл бұрын
@@NTFAQGuy You're right, I overlooked the " see IPsec over ExpressRoute for Virtual WAN" section in github.com/MicrosoftDocs/azure-docs/blob/master/articles/virtual-wan/virtual-wan-about.md
@felipeccardoso
@felipeccardoso 4 жыл бұрын
And regarding the IP addresses connected in the Virtual WAN Hub (VNET, P2S, S2S, Express Route), there can be no overlap of IPs, correct?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
Correct. If you have overlapping in azure Vnets then private link may help as that does nat
@JohnQ85
@JohnQ85 3 жыл бұрын
If I have an existing Azure VPN Gateway, can I still add and use a Virtual WAN?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
It would not be part of vwan
@MammadovAdil
@MammadovAdil 3 жыл бұрын
thank you! just one question, if I put Firewall to the Hub, and one of locations want to reach out other location using ExpressRoute Global Reach, it will need to go over that inefficient route, right? I mean it can't use barely backbone network then, it has to reach out to Hub?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
I don't understand your question, sorry.
@MammadovAdil
@MammadovAdil 3 жыл бұрын
@@NTFAQGuy I don't want to take too much of your time, if question is irrelevant, please ignore. from 15:00 till 15:15 you explained how with Global reach locations can talk to each other without going to Hub. I just wanted to know if it still true if we add Firewall to the Hub - shouldn't it pass through firewall?
@addinuff
@addinuff 3 жыл бұрын
Hi John - You can have Express Route Standard, it doesnt have to be Premium according to the documentation?
@addinuff
@addinuff 3 жыл бұрын
Ah - if you are crossing geo-political boundaries you need ER Premium, but if you are putting VWAN in a single region (for encryption lets say) then Standard will suffice
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Maybe it’s changed. When I spoke with the pg it had to be premium. I’ll check if changed.
@rstra3
@rstra3 3 жыл бұрын
Is there any way to NAT with Virtual WAN? If I connect a client site-to-site VPN I would want to NAT. If you cannot NAT, how can you get around possible network overlaps?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
there is no native NAT in this solution. Ideally you ensure different networks don't overlap. Solutions like private link NAT.
@rstra3
@rstra3 3 жыл бұрын
@@NTFAQGuy Thank you for the quick response. If I have clients (that I do not manage) that connect into my network and two of them happen to give me overlapping addresses, would something like an NVA work?
@srinidatla1079
@srinidatla1079 3 жыл бұрын
Why would we want to use IPSec over express route? Isn’t express route a dedicated connection?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
Its still a piece of wire going over physical spaces :-) Because of that some companies want extra encryption. For most though its not a concern.
@altanetluke
@altanetluke 3 жыл бұрын
Sounds like that is more a compliance/regulatory requirement vs. actual security.
@joejohnthomas6426
@joejohnthomas6426 3 жыл бұрын
Can we have VWAN Gateway in Tier0 ?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
If you are talking about nsx I’m not aware of 3rd party to directly interface but you could have other gateways on physical network talking to the vlan etc that is connected to nsx
@Apa-is2jz
@Apa-is2jz 3 жыл бұрын
thank youj
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
My pleasure
@steveeyler
@steveeyler 3 жыл бұрын
Think VoIP quality is ok on VWAN?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
VoIP tends to be very picky re QoS, latency etc and would depend on solution and other factors. Honestly not done much with VoIP but maybe others can comment. There is nothing really vWAN specific about it, its more the latency of ExpressRoute/S2S VPN etc.
@steveeyler
@steveeyler 3 жыл бұрын
@@NTFAQGuy I expect it would be at least as good as internet based voip. Curious if VWAN observes DSCP flags for VoIP. Thanks.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
@@steveeyler this is not VWan but rather the various types of links you may have as mentioned earlier. Would depend on links utilized. Within vnet i've seen DSCP maintained.
@daveshanahan3413
@daveshanahan3413 3 жыл бұрын
What happens if a refund fails, or a vwan hub fails?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
not sure what you mean by refund but all the components are redundant, i.e. multiple instances for gateways etc.
@daveshanahan3413
@daveshanahan3413 3 жыл бұрын
@@NTFAQGuy sorry, spell check 😄 I don't quite understand the failover scenarios of virtual wan. If you have a number of sites terminating vpns in UK South as the primary region, then if that hub fails, how would they failover to uk west as a secondary region? I guess BGP stops advertising routes to uk south. The hubs have different address spaces from what I have read, or does the uk west hub advertise the same address space as South, then BGP routing sorts out the routing as the uk west region is now the only route to virtual wan?
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
@@daveshanahan3413 docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-faq has resiliency info
@daveshanahan3413
@daveshanahan3413 3 жыл бұрын
@@NTFAQGuy all it says is "Users can connect to multiple hubs if they want resiliency across regions." It doesn't tell you anywhere how this is achieved and how failure of a vwan hub tells the devices connected that its failed, or the failover times etc. It's very wooly.
@NTFAQGuy
@NTFAQGuy 3 жыл бұрын
@@daveshanahan3413 I think a hub is basically regional. if you want regional resiliency you have multiple hubs then would need to arrange redundant connections to each hub.
@DrDoktor60
@DrDoktor60 4 жыл бұрын
Azure WAN in one sentence?
@NTFAQGuy
@NTFAQGuy 4 жыл бұрын
There would be a lot of commas and semi-colons :-)
@DrDoktor60
@DrDoktor60 4 жыл бұрын
John Savill 😀something for a pseudo-technical person to understand
@philathomas
@philathomas 4 жыл бұрын
@@DrDoktor60 It's a cloud IP routing platform that can links cloud & on prem (S2S,ER) network resources via a single location.
@allwynmasc1
@allwynmasc1 11 ай бұрын
This looks like a SASE solution by Microsoft
@NTFAQGuy
@NTFAQGuy 11 ай бұрын
The Entra SSE provides those capabilities. I have a video on the Entra SSE.
Azure Load Balancer Deep Dive
49:28
John Savill's Technical Training
Рет қаралды 65 М.
Azure Virtual WAN - Advanced Routing Intent Designs
20:50
Adam Stuart
Рет қаралды 3,2 М.
Yum 😋 cotton candy 🍭
00:18
Nadir Show
Рет қаралды 7 МЛН
managed to catch #tiktok
00:16
Анастасия Тарасова
Рет қаралды 46 МЛН
Dad Makes Daughter Clean Up Spilled Chips #shorts
00:16
Fabiosa Stories
Рет қаралды 1,8 МЛН
Understanding DNS in Azure
26:59
John Savill's Technical Training
Рет қаралды 116 М.
Azure Route Server Overview
31:34
John Savill's Technical Training
Рет қаралды 36 М.
Zero to Hero with Azure Virtual WAN from Derek Smith
1:07:58
Captain Hyperscaler
Рет қаралды 10 М.
Containers vs VMs: What's the difference?
8:08
IBM Technology
Рет қаралды 755 М.
Azure Virtual WAN: Hybrid Networking Game-Changer
8:58
Azure Academy
Рет қаралды 10 М.
Azure Virtual Network Manager Deep Dive
1:02:56
John Savill's Technical Training
Рет қаралды 25 М.
Azure DNS Private Resolver Deep Dive
24:49
John Savill's Technical Training
Рет қаралды 49 М.
Designing Microsoft Azure Virtual Networks
18:50
Jafer Sabir
Рет қаралды 20 М.
Highly Available NVAs in Microsoft Azure
45:21
John Savill's Technical Training
Рет қаралды 22 М.
Yum 😋 cotton candy 🍭
00:18
Nadir Show
Рет қаралды 7 МЛН