<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure VNET peering in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-vnet-peering/m-p/402555#M1181</link>
    <description>&lt;P&gt;We are going with hub and spoke model, PA being the hub. When we peer a spoke VNET with the hub does the subnets in peered spoke also go through intrazone rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spoke-vnet - (subnet1, subnet2).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would subnet1 &amp;lt;&amp;gt; subnet2 communication pass through intrazone rules or does the whole spoke-net is seen as one large routed subnet.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Apr 2021 23:38:16 GMT</pubDate>
    <dc:creator>raji_toor</dc:creator>
    <dc:date>2021-04-27T23:38:16Z</dc:date>
    <item>
      <title>Azure VNET peering</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-vnet-peering/m-p/402555#M1181</link>
      <description>&lt;P&gt;We are going with hub and spoke model, PA being the hub. When we peer a spoke VNET with the hub does the subnets in peered spoke also go through intrazone rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spoke-vnet - (subnet1, subnet2).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would subnet1 &amp;lt;&amp;gt; subnet2 communication pass through intrazone rules or does the whole spoke-net is seen as one large routed subnet.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 23:38:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-vnet-peering/m-p/402555#M1181</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-04-27T23:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Azure VNET peering</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-vnet-peering/m-p/404542#M1183</link>
      <description>&lt;P&gt;By default azure subnets in spoke vnets are able to communicate directly with no need to reach hub. But you can add outbound deny policy at NSGs to block 'virtual network' traffic. Basically you will need to add 2 statement at outbound nsg for the subnet, first one deny any-any, then allow virtual network to next hub.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 16:13:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/azure-vnet-peering/m-p/404542#M1183</guid>
      <dc:creator>Hasan1</dc:creator>
      <dc:date>2021-05-03T16:13:27Z</dc:date>
    </item>
  </channel>
</rss>

