Skip to main content
AD Academy
Cloud Computing: Architecture and Security
Beginner13 minLast updated: Topic 5 of 8

Networking in the Cloud: VNet, Subnet, NSG, and On-Premises Connection

What a virtual network in the cloud looks like and who controls traffic.

Not read

What you will learn here

  • Basic Components
  • Connecting Networks
  • What a virtual network in the cloud looks like and who controls traffic.

Worth reading first:Identity in the Cloud: Entra ID vs. Active Directory

A Virtual Network (VNet) is your LAN in the cloud: your own private address range, divided into Subnets. Everything you learned in CCNA about subnetting, routing, and ACL applies here — only the hardware is hidden.

Basic Components

  • VNet — A CIDR range (e.g., 10.0.0.0/16) that exists in one Region.
  • Subnet — Internal division (10.0.1.0/24) by role: Web, App, DB, Management.
  • NSG (Network Security Group) — A Stateful ACL at the Subnet or Network Interface level, with Allow/Deny rules based on Priority.
  • Route Table (UDR) — Custom routing, for example, to direct all traffic through a Firewall.
  • Public IP / / — Controlled exposure to the internet.

The outer frame is VNet 10.0.0.0/16 in a single region. Inside are three subnets: Web 10.0.1.0/24, App 10.0.2.0/24 and DB 10.0.3.0/24, each with its own NSG — 443 from the Internet to Web, 8080 from Web to App, 1433 from App only to DB. Below, a UDR route table forces egress through Azure Firewall or an NVA. At the bottom, three ways to reach on-prem: VNet peering between networks, site-to-site IPsec VPN over the Internet, and ExpressRoute as a private circuit with an SLA. An NSG is a stateful ACL and denies inbound Internet traffic by default.

Short and clear

  • A VNet is your cloud LAN, split into subnets by role: Web, App, DB.
  • An NSG is a stateful ACL — allow only what is needed, everything else is denied.
  • A UDR forces egress traffic through a firewall for inspection and logging.
  • On-prem connectivity: peering between networks, VPN over the Internet, ExpressRoute as a private circuit.

Real-life exampleThe app cannot reach the database: the DB NSG allows 1433 only from the App subnet, and the new server was deployed into the Web subnet by mistake.

Connecting Networks

  • VNet Peering — A private connection between two VNets, fast and without passing through the internet (not transitive).
  • Site-to-Site VPN — An IPsec tunnel between the office router and the cloud; cheap, internet-dependent.
  • ExpressRoute — A dedicated private line to the provider: stable Latency and SLA, more expensive.
  • Private Endpoint — Attaching a PaaS service (Storage, SQL) to a private address within the VNet instead of exposing it to the internet.

Check yourself

What is the role of an NSG?

Which solution provides a dedicated private line with an SLA to the cloud?

Was this page helpful?