We are going with hub and spoke model, PA being the hub. When we peer a spoke VNET with the hub does the subnets in peered spoke also go through intrazone rules.
Spoke-vnet - (subnet1, subnet2).
Would subnet1 <> subnet2 communication pass through intrazone rules or does the whole spoke-net is seen as one large routed subnet.
By default azure subnets in spoke vnets are able to communicate directly with no need to reach hub. But you can add outbound deny policy at NSGs to block 'virtual network' traffic. Basically you will need to add 2 statement at outbound nsg for the subnet, first one deny any-any, then allow virtual network to next hub.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!