Skip to content

Commit 6febe37

Browse files
Updated H&S how-to page
1 parent c8a858a commit 6febe37

File tree

1 file changed

+35
-31
lines changed

1 file changed

+35
-31
lines changed
Lines changed: 35 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -1,49 +1,50 @@
11
---
2-
title: 'Create a hub and spoke topology in Azure - Portal'
3-
description: Learn how to create a hub and spoke network topology for multiple virtual networks with Azure Virtual Network Manager using the Azure portal.
2+
title: 'Create a hub-and-spoke topology in Azure - Portal'
3+
description: Learn how to create a hub-and-spoke network topology for multiple virtual networks with Azure Virtual Network Manager using the Azure portal.
44
author: mbender-ms
55
ms.author: mbender
66
ms.service: azure-virtual-network-manager
77
ms.topic: how-to
8-
ms.date: 10/23/2024
8+
ms.date: 07/11/2025
99
ms.custom: template-concept, engagement-fy23
1010
---
1111

12-
# Create a hub and spoke topology in Azure - Portal
12+
# Create a hub-and-spoke topology in Azure - Portal
1313

14-
In this article, you learn how to create a hub and spoke network topology with Azure Virtual Network Manager. With this configuration, you select a virtual network to act as a hub and all spoke virtual networks have bi-directional peering with only the hub by default. You also can enable direct connectivity between spoke virtual networks and enable the spoke virtual networks to use the virtual network gateway in the hub.
14+
In this article, you learn how to create a hub-and-spoke topology with Azure Virtual Network Manager. With this configuration, you select a virtual network to act as a hub and all spoke virtual networks have bi-directional peering with only the hub by default. You also can enable direct connectivity between spoke virtual networks in the same spoke network group and enable the spoke virtual networks to use the gateway in the hub virtual network.
1515

1616
## Prerequisites
1717

18-
* Read about [Hub-and-spoke](concept-connectivity-configuration.md#hub-and-spoke-topology) network topology.
19-
* Created a [Azure Virtual Network Manager instance](create-virtual-network-manager-portal.md#create-a-virtual-network-manager-instance).
20-
* Identify virtual networks you want to use in the hub-and-spokes configuration or create new [virtual networks](../virtual-network/quick-create-portal.md).
18+
* Read about the [Hub-and-spoke](concept-connectivity-configuration.md#hub-and-spoke-topology) network topology.
19+
* Create a [Azure Virtual Network Manager instance](create-virtual-network-manager-portal.md#create-a-virtual-network-manager-instance).
20+
* Identify the virtual networks you want to use in the hub-and-spoke configuration or create new [virtual networks](../virtual-network/quick-create-portal.md).
2121

2222
## <a name="group"></a> Create a network group
2323

24-
This section helps you create a network group containing the virtual networks you're using for the hub-and-spoke network topology.
24+
This section helps you create a network group containing the virtual networks you're using as the spokes for the hub-and-spoke topology.
2525

2626
> [!NOTE]
27-
> This how-to guide assumes you created a network manager instance using the [quickstart](create-virtual-network-manager-portal.md) guide.
27+
> This how-to guide assumes you created an Azure Virtual Network Manager instance using the [quickstart](create-virtual-network-manager-portal.md) guide.
2828
2929
[!INCLUDE [virtual-network-manager-create-network-group](../../includes/virtual-network-manager-create-network-group.md)]
3030

3131
## Define network group members
3232

33-
Azure Virtual Network manager allows you two methods for adding membership to a network group. You can manually add virtual networks or use Azure Policy to dynamically add virtual networks based on conditions. This how-to covers [manually adding membership](concept-network-groups.md#static-membership). For information on defining group membership with Azure Policy, see [Define network group membership with Azure Policy](concept-network-groups.md#dynamic-membership).
33+
Azure Virtual Network Manager provides you with two methods for adding membership to a network group. You can manually add virtual networks or use Azure Policy to conditionally add virtual networks to the network group. This how-to [manually adds membership](concept-network-groups.md#static-membership). For information on defining group membership with Azure Policy, see [Define network group membership with Azure Policy](concept-network-groups.md#dynamic-membership).
3434

3535
### Manually adding virtual networks
36-
To manually add the desired virtual networks for your Mesh configuration to your Network Group, follow the steps below:
36+
37+
To manually add the desired virtual networks to your network group for use in your connectivity configuration, follow the steps below:
3738

3839
1. From the list of network groups, select your network group and select **Add virtual networks** under *Manually add members* on the network group page.
3940

40-
1. On the *Manually add members* page, select all the virtual networks and select **Add**.
41+
1. On the *Manually add members* pane, select all desired virtual networks and select **Add**.
4142

42-
1. To review the network group membership manually added, select **Group Members** on the *Network Group* page under **Settings**.
43+
1. To review the network group membership that you manually added, select **Group Members** on the *Network Group* page under **Settings**.
4344

44-
## Create a hub and spoke connectivity configuration
45+
## Create a hub-and-spoke connectivity configuration
4546

46-
This section guides you through how to create a hub-and-spoke configuration with the network group you created in the previous section.
47+
This section guides you through creating a hub-and-spoke configuration with the network group you created in the previous section.
4748

4849
1. Select **Connectivity configuration** from the drop-down menu to begin creating a connectivity configuration.
4950

@@ -52,28 +53,29 @@ This section guides you through how to create a hub-and-spoke configuration with
5253
| Setting | Value |
5354
| ------- | ----- |
5455
| Name | Enter a *name* for this configuration. |
55-
| Description | *Optional* Enter a description about what this configuration does. |
56+
| Description | *(Optional)* Enter a description about what this configuration does. |
5657

5758
1. On the **Topology** tab, select the **Hub and spoke** topology under *Topology*.
5859

59-
1. Select **Delete existing peerings** checkbox if you want to remove all previously created virtual network peering between virtual networks in the network group defined in this configuration, and then select **Select a hub**.
60-
1. On the **Select a hub** page, Select the virtual network that will be the hub virtual network and select **Select**.
60+
1. Select the **Delete existing peerings** checkbox if you want to remove all previously created virtual network peerings between virtual networks in the network groups included in this configuration. Then select **Select a hub**.
61+
62+
1. On the **Select a hub** pane, select the virtual network that will be the hub virtual network and select **Select**.
6163

62-
1. Then select **+ Add network groups**.
64+
1. Select **+ Add network groups**.
6365

64-
1. On the **Add network groups** page, select the network groups you want to add to this configuration. Then select **Add** to save.
66+
1. On the **Add network groups** page, select the network groups you want to add to this configuration as spokes. Then select **Add** to save.
6567

66-
1. Select the settings you want to enable for each network group. The following three options appear next to the network group name under **Spoke network groups**:
68+
1. Select the settings you want to enable for each spoke network group. The following three options appear next to each network group name under **Spoke network groups**:
6769

68-
- *Direct connectivity*: Select **Enable peering within network group** if you want to establish virtual network peering between virtual networks in the network group of the same region.
69-
- *Global Mesh*: Select **Enable mesh connectivity across regions** if you want to establish virtual network peering for all virtual networks in the network group across regions.
70-
- *Gateway*: Select **Use hub as a gateway** if you have a virtual network gateway in the hub virtual network that you want this network group to use to pass traffic to on-premises.
70+
- *Direct connectivity*: Select **Enable peering within network group** if you want to establish connectivity between virtual networks in the network group. By default, this connectivity will only be established between virtual networks in this network group that belong to the same region.
71+
- *Global Mesh*: This option is only selectable if *direct connectivity* is enabled. Select **Enable mesh connectivity across regions** if you want to establish connectivity across regions for all virtual networks in this network group.
72+
- *Gateway*: Select **Use hub as a gateway** if you have a virtual network gateway in the hub virtual network that you want the virtual networks of this spoke network group to use to pass traffic to on-premises.
7173

7274
1. Select **Review + Create > Create** to create the hub-and-spoke connectivity configuration.
7375

74-
## Deploy the hub and spoke configuration
76+
## Deploy the hub-and-spoke configuration
7577

76-
To have this configuration take effect in your environment, you need to deploy the configuration to the regions where your selected virtual networks are created.
78+
To have this configuration take effect in your environment, you need to deploy the configuration to the regions in which your selected virtual networks reside.
7779

7880
1. Select **Deployments** under *Settings*, then select **Deploy a configuration**.
7981
1. On the **Deploy a configuration** page, select the following settings:
@@ -82,23 +84,25 @@ To have this configuration take effect in your environment, you need to deploy t
8284
| ------- | ----- |
8385
| Configurations | Select **Include connectivity configurations in your goal state** . |
8486
| Connectivity configurations | Select the name of the configuration you created in the previous section. |
85-
| Target regions | Select all the regions that apply to virtual networks you select for the configuration. |
87+
| Target regions | Select all the regions that apply to virtual networks you select for the configuration. You might choose to select a subset of regions at a time if you want to gradually roll out this configuration. |
8688

8789
1. Select **Next** and then select **Deploy** to complete the deployment.
8890
1. The deployment displays in the list for the selected region. The deployment of the configuration can take a few minutes to complete.
8991

9092
:::image type="content" source="./media/how-to-create-hub-and-spoke/deployment-succeeded.png" alt-text="Screenshot of configuration deployment in progress status.":::
9193

9294
> [!NOTE]
93-
> If you're currently using peering and want to manage topology and connectivity with Azure Virtual Network Manager, you can migrate without any downtime to your network. Virtual network manager instances are fully compatible with pre-existing hub and spoke topology deployment using peering. This means that you won't need to delete any existing peered connections between the spokes and the hub as the network manager will automatically detect and manage them.
95+
> If you're currently using virtual network peerings created outside of Azure Virtual Network Manager and want to manage your topology and connectivity with Azure Virtual Network Manager, you can migrate without any downtime to your network. Azure Virtual Network Manager instances are fully compatible with pre-existing hub-and-spoke topology deployments using manual peerings. When you deploy a connectivity configuration, the connectivity established is additive by default. This means that you aren't required to delete any existing peered connections between the hub and spoke virtual networks while you verify the connectivity configuration is establishing connectivity as desired.
9496
9597
## Confirm configuration deployment
9698

9799
1. See [view applied configuration](how-to-view-applied-configurations.md).
98100

99-
1. To test *direct connectivity* between spokes, deploy a virtual machine into each spokes virtual network. Then initiate an ICMP request from one virtual machine to the other.
101+
1. To test *direct connectivity* between spoke virtual networks, deploy a virtual machine into each spoke virtual network. Then initiate an ICMP request from one virtual machine to the other.
100102

101103
## Next steps
102104

105+
- [Create a secured hub-and-spoke topology in this tutorial](./tutorial-create-secured-hub-and-spoke.md).
106+
- [Learn how to deploy a hub-and-spoke topology with Azure Firewall](./how-to-deploy-hub-spoke-topology-with-azure-firewall.md).
103107
- Learn about [Security admin rules](concept-security-admins.md)
104-
- Learn how to block network traffic with a [SecurityAdmin configuration](how-to-block-network-traffic-portal.md).
108+
- Learn how to block network traffic with a [Security admin configuration](how-to-block-network-traffic-portal.md).

0 commit comments

Comments
 (0)