A Virtual Network (VNet) is your LAN in the cloud: your own private address range, divided into Subnets. Everything you learned in CCNA about subnetting, routing, and ACL applies here — only the hardware is hidden.
Basic Components
- VNet — A CIDR range (e.g., 10.0.0.0/16) that exists in one Region.
- Subnet — Internal division (10.0.1.0/24) by role: Web, App, DB, Management.
- NSG (Network Security Group) — A Stateful ACL at the Subnet or Network Interface level, with Allow/Deny rules based on Priority.
- Route Table (UDR) — Custom routing, for example, to direct all traffic through a Firewall.
- Public IP / / — Controlled exposure to the internet.
The outer frame is VNet 10.0.0.0/16 in a single region. Inside are three subnets: Web 10.0.1.0/24, App 10.0.2.0/24 and DB 10.0.3.0/24, each with its own NSG — 443 from the Internet to Web, 8080 from Web to App, 1433 from App only to DB. Below, a UDR route table forces egress through Azure Firewall or an NVA. At the bottom, three ways to reach on-prem: VNet peering between networks, site-to-site IPsec VPN over the Internet, and ExpressRoute as a private circuit with an SLA. An NSG is a stateful ACL and denies inbound Internet traffic by default.
Connecting Networks
- VNet Peering — A private connection between two VNets, fast and without passing through the internet (not transitive).
- Site-to-Site VPN — An IPsec tunnel between the office router and the cloud; cheap, internet-dependent.
- ExpressRoute — A dedicated private line to the provider: stable Latency and SLA, more expensive.
- Private Endpoint — Attaching a PaaS service (Storage, SQL) to a private address within the VNet instead of exposing it to the internet.