<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Cloud NGFW for Azure - Forced Tunneling in Cloud NGFW for Azure Articles</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-articles/cloud-ngfw-for-azure-forced-tunneling/ta-p/1256484</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;H1&gt;&lt;STRONG&gt;Cloud NGFW for Azure&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cloud NGFW automatically provides source NAT (SNAT) for all outbound traffic to public IP addresses you associate with it. Cloud NGFW doesn’t SNAT when the destination IP address is a private IP address range per IANA RFC 1918.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cloud ngfw.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71798i91D7645856622C08/image-size/large?v=v2&amp;amp;px=999" role="button" title="cloud ngfw.png" alt="cloud ngfw.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By default, outbound internet traffic will be handled by Cloud NGFW, as mentioned below&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The host machine in the Spoke VNet initiates traffic.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;To route the traffic through Cloud NGFW, create a route table associated with the host subnet part of Spoke VNET. Add a route with the next-hop set to the Cloud NGFW's Private IP address.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;After the inspection, the cloud NGFW forwards the traffic through the Public Subnet. Cloud NGFW also performs SNAT using its Public IP address before sending out the traffic onto the internet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Response traffic will follow the same reverse path.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Forced Tunneling&amp;nbsp;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can configure Forced Tunneling on Cloud NGFW to route all Internet-bound traffic to a designated next hop instead of sending it directly to the Internet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Forced tunneling enables your Cloud NGFW to inspect and then redirect (a.k.a force-tunnel)&amp;nbsp; all internet-bound traffic from Cloud NGFW to your on-premises firewall or to chain it to a nearby network virtual appliance (NVA) for additional inspection&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt; &lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;This is typically done to enforce additional security policies on your on-premises firewall or to use the on-premises public IP address for Source Network Address Translation (SNAT), thereby avoiding exposure of the Cloud NGFW's public IP address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There are two primary architectures for forced tunneling:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Forced Tunneling through the Public Subnet&lt;/STRONG&gt;&lt;SPAN&gt; (with SNAT performed by Cloud NGFW)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Forced Tunneling through the Private Subnet&lt;/STRONG&gt;&lt;SPAN&gt; (no SNAT performed by Cloud NGFW)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="1"&gt;&lt;STRONG&gt;Forced Tunneling through Azure Virtual WAN&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;1. Forced Tunneling Through the Public Subnet (Cloud NGFW SNAT)&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This architecture is for customers who want to control traffic based on &lt;/SPAN&gt;&lt;STRONG&gt;trust (Private)&lt;/STRONG&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;STRONG&gt;untrust (Public)&lt;/STRONG&gt;&lt;SPAN&gt; zones on the Cloud NGFW. In this deployment, the Cloud NGFW will perform &lt;/SPAN&gt;&lt;STRONG&gt;SNAT&lt;/STRONG&gt;&lt;SPAN&gt; on the traffic before forwarding it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="public subnet.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71799iF52D10819AD39EBC/image-size/large?v=v2&amp;amp;px=999" role="button" title="public subnet.png" alt="public subnet.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":gear:"&gt;⚙️&lt;/span&gt; Configuration Summary&lt;/STRONG&gt;&lt;/H4&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Spoke VNet Route Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Add Route&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Destination: &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/0&lt;/STRONG&gt;&lt;SPAN&gt; (Internet)&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Next Hop: &lt;/SPAN&gt;&lt;STRONG&gt;Cloud NGFW Private IP address&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud NGFW Public Subnet Route Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Create and Associate&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Add Route: Destination: &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/0&lt;/STRONG&gt;&lt;SPAN&gt; (Internet)&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Next Hop: &lt;/SPAN&gt;&lt;STRONG&gt;VNET Gateway&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H4&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":globe_with_meridians:"&gt;🌐&lt;/span&gt; Traffic Flow Sequence&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Traffic is initiated by the host machine part of the Spoke VNet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The traffic is routed to the &lt;/SPAN&gt;&lt;STRONG&gt;Cloud NGFW Private IP address&lt;/STRONG&gt;&lt;SPAN&gt; for inspection (via the Spoke VNet's route table).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Post inspection, Cloud NGFW attempts to forward the internet traffic through the &lt;/SPAN&gt;&lt;STRONG&gt;Public Subnet&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Cloud NGFW performs &lt;/SPAN&gt;&lt;STRONG&gt;SNAT&lt;/STRONG&gt;&lt;SPAN&gt; on the internet traffic using an IP address from its Public Subnet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The Public Subnet's associated route table forces this traffic to the &lt;/SPAN&gt;&lt;STRONG&gt;VNET Gateway&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The VNET Gateway sends the traffic over the Site-to-Site VPN to the &lt;/SPAN&gt;&lt;STRONG&gt;on-premises Firewall&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The on-premises firewall enforces security policies and forwards the traffic to the internet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Response traffic follows the same reverse path.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&lt;STRONG&gt;2. Forced Tunneling Through the Private Subnet (No Cloud NGFW SNAT)&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This architecture is intended for customers who require &lt;/SPAN&gt;&lt;STRONG&gt;visibility of the actual source IP address&lt;/STRONG&gt;&lt;SPAN&gt; from which the traffic was initiated at the On-Premise Firewall. In this deployment, the Cloud NGFW will &lt;/SPAN&gt;&lt;STRONG&gt;not perform NAT&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="private subnet.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71800i024FDF61FF206F09/image-size/large?v=v2&amp;amp;px=999" role="button" title="private subnet.png" alt="private subnet.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":gear:"&gt;⚙️&lt;/span&gt; Configuration Summary&lt;/STRONG&gt;&lt;/H4&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Spoke VNet Route Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Add Route&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Destination: &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/0&lt;/STRONG&gt;&lt;SPAN&gt; (Internet)&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Next Hop: &lt;/SPAN&gt;&lt;STRONG&gt;Cloud NGFW Private IP address&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud NGFW Private Subnet Route Table&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Create and Associate&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Add Route: Destination: &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/0&lt;/STRONG&gt;&lt;SPAN&gt; (Internet)&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Next Hop: &lt;/SPAN&gt;&lt;STRONG&gt;VNET Gateway&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud NGFW Networking &amp;amp; NAT Settings&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Configure&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Set &lt;/SPAN&gt;&lt;STRONG&gt;Additional Prefixes to Private Traffic Range&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/1,128.0.0.0/1&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt; The "Additional Prefixes" configuration is crucial. It causes the Cloud NGFW to consider internet traffic as &lt;/SPAN&gt;&lt;STRONG&gt;Private Traffic&lt;/STRONG&gt;&lt;SPAN&gt;. This prevents the traffic from being forwarded towards the Public Subnet and ensures it is sent out using the Private Subnet itself without performing any NAT.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":globe_with_meridians:"&gt;🌐&lt;/span&gt; Traffic Flow Sequence&lt;/STRONG&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Traffic is initiated by the host machine part of the Spoke VNet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The traffic is routed to the &lt;/SPAN&gt;&lt;STRONG&gt;Cloud NGFW Private IP address&lt;/STRONG&gt;&lt;SPAN&gt; for inspection (via the Spoke VNet's route table).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The Cloud NGFW attempts to forward the internet traffic through the Public Subnet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Due to the route table associated with the &lt;/SPAN&gt;&lt;STRONG&gt;Private Subnet&lt;/STRONG&gt;&lt;SPAN&gt; and the "Additional Prefixes" configuration, the traffic is sent out using the &lt;/SPAN&gt;&lt;STRONG&gt;Private Subnet&lt;/STRONG&gt;&lt;SPAN&gt; and is forced to the &lt;/SPAN&gt;&lt;STRONG&gt;VNET Gateway&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;This traffic is sent without performing any NAT.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The VNET Gateway sends the traffic over the Site-to-Site VPN to the &lt;/SPAN&gt;&lt;STRONG&gt;on-premises Firewall&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The on-premises firewall enforces security policies and forwards the traffic to the internet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Response traffic will follow the same reverse path.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;BR /&gt;&lt;BR /&gt;
&lt;H3&gt;&lt;STRONG&gt;3. Forced Tunneling through Azure Virtual WAN&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Virtual WAN routing intent allows you to send both private and Internet traffic to Cloud NGFW deployed in the Virtual WAN hub.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;While you can break out internet traffic directly through Cloud NGFW, Force Tunneling feature in Azure Virtual WAN enables a new routing capability that allows customers&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;to inspect internet traffic first via a security solution deployed directly in the hub(Cloud NGFW), then forward it to an on-premises or NVA deployed in a spoke VNET connected to Virtual&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;WAN for another layer of inspection and breakout.&lt;/SPAN&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Architecture below demonstrates Force Tunneling via NVA deployed in a Spoke VNET connected to Virtual WAN&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azure virtual wan.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71802iFF4C28C2B277F7AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="azure virtual wan.png" alt="azure virtual wan.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":gear:"&gt;⚙️&lt;/span&gt; Configuration Summary&lt;/STRONG&gt;&lt;/H4&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Routing Intent and Routing Policies&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Private Traffic &amp;gt; SaaS Solution&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Next Hop: &lt;/SPAN&gt;&lt;STRONG&gt;Cloud NGFW&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Prefixes : &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/0&lt;/STRONG&gt;&lt;SPAN&gt; (Internet) - This is to Force Tunnel Internet traffic&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Internet Traffic &amp;gt; None&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Virtual Network Connections&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Configure&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Add &lt;/SPAN&gt;&lt;STRONG&gt;Static route&lt;/STRONG&gt;&lt;SPAN&gt; to internet(0.0.0.0/0) with next hop as Spoke NVA Firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Disable &lt;/SPAN&gt;&lt;STRONG&gt;Propagate Default Route&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud NGFW Networking &amp;amp; NAT Settings&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Configure&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Set &lt;/SPAN&gt;&lt;STRONG&gt;Additional Prefixes to Private Traffic Range&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/1,128.0.0.0/1&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;BR /&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":globe_with_meridians:"&gt;🌐&lt;/span&gt; Traffic Flow Sequence&lt;/STRONG&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Traffic is initiated by the host machine part of the App VNet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The traffic is routed to Virtual WAN and Routing Intent within VWAN Hub will forward the traffic to Cloud NGFW for inspection.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The Cloud NGFW after inspection will route the traffic towards Spoke Virtual Network Connection.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Because of the Static Default route within Virtual Network Connection, this traffic will be routed towards NVA Firewall with in the Spoke VNET&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The Spoke NVA Firewall after additional inspection will send the traffic onto the internet using its Public IP address and NAT.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Response traffic will follow the reverse path.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Architecture below demonstrates Force Tunneling through On-Prem Firewall connected to Virtual WAN over Site to Site VPN&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="site to site vpn.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71803iBAE799FCAABE5826/image-size/large?v=v2&amp;amp;px=999" role="button" title="site to site vpn.png" alt="site to site vpn.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":gear:"&gt;⚙️&lt;/span&gt; Configuration Summary&lt;/STRONG&gt;&lt;/H4&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Component&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Details&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Routing Intent and Routing Policies&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Private Traffic &amp;gt; SaaS Solution&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Next Hop: &lt;/SPAN&gt;&lt;STRONG&gt;Cloud NGFW&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Additional Prefixes : &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/0&lt;/STRONG&gt;&lt;SPAN&gt; (Internet) - This is to Force Tunnel Internet traffic&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Internet Traffic &amp;gt; None&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Site-to-Site VPN&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Configure&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Add Site-to-Site VPN with VWAN Hub VPN Gateway from On-Prem Firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On-Prem Advertises Default route Over VPN&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud NGFW Networking &amp;amp; NAT Settings&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Configure&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;SPAN&gt;Set &lt;/SPAN&gt;&lt;STRONG&gt;Additional Prefixes to Private Traffic Range&lt;/STRONG&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;STRONG&gt;0.0.0.0/1,128.0.0.0/1&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;BR /&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":globe_with_meridians:"&gt;🌐&lt;/span&gt; Traffic Flow Sequence&lt;/STRONG&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Traffic is initiated by the host machine part of the App VNet.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The traffic is routed to Virtual WAN and Routing Intent within VWAN Hub will forward the traffic to Cloud NGFW for inspection.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;The Cloud NGFW after inspection will route the traffic towards VPN Gateway as there is a default route learnt over the VPN Tunnel from On-Prem Firewall.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Internet traffic from the VPN Gateway will sent over the VPN tunnel towards on-prem Firewall&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;On-Prem Firewall after additional inspection will send the traffic onto the internet using its Public IP address and NAT.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;SPAN&gt;Response traffic will follow the reverse path.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 16 Jun 2026 12:45:22 GMT</pubDate>
    <dc:creator>rpegada</dc:creator>
    <dc:date>2026-06-16T12:45:22Z</dc:date>
    <item>
      <title>Cloud NGFW for Azure - Forced Tunneling</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-articles/cloud-ngfw-for-azure-forced-tunneling/ta-p/1256484</link>
      <description>&lt;P&gt;This technical guide explores how to successfully implement forced tunneling architectures across your Azure environment. Whether you need to maintain complete visibility of the original source IP through a private subnet or route inspected traffic seamlessly across Azure Virtual WAN, you will find the precise route table configurations, configuration summaries, and traffic flow sequences needed to establish secure, multi-layered inspection paths.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 12:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-azure-articles/cloud-ngfw-for-azure-forced-tunneling/ta-p/1256484</guid>
      <dc:creator>rpegada</dc:creator>
      <dc:date>2026-06-16T12:45:22Z</dc:date>
    </item>
  </channel>
</rss>

