{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
        "slug": "dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/"
        },
        "title": "Supply each forced-tunnel Virtual WAN hub with its own default-route source",
        "summary": "Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:47+00:00",
        "modified_at": "2026-09-10T00:55:36+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 221,
        "potentially_affected": "Virtual WAN hubs using routing intent with private routing policies and forced-tunnel internet access.",
        "dse_recommendation": "Identify a supported local default-route source for each forced-tunnel hub and check the advertising connection's flags.",
        "primary_source": {
            "name": "Securing Internet access with routing intent - Azure Virtual WAN | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.</p>\n<p>For the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source&#8217;s supported connection patterns rather than assuming every static or remote default route is eligible.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection&#8217;s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub&#8217;s default will take over.</p>\n<h2>Verification</h2>\n<p>In an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Securing Internet access with routing intent</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nThe default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.\nFor the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. Microsoft Learn.\nApplicability\nIdentify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source’s supported connection patterns rather than assuming every static or remote default route is eligible.\nDSE recommendation\nDSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection’s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub’s default will take over.\nVerification\nIn an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.\nOfficial references\nMicrosoft Learn: Securing Internet access with routing intent. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nThe default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.\n\nFor the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing).\n\n## Applicability\n\nIdentify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source’s supported connection patterns rather than assuming every static or remote default route is eligible.\n\n## DSE recommendation\n\nDSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection’s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub’s default will take over.\n\n## Verification\n\nIn an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.\n\n## Official references\n\n[Microsoft Learn: Securing Internet access with routing intent](https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Supply each forced-tunnel Virtual WAN hub with its own default-route source",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/",
                "headline": "Supply each forced-tunnel Virtual WAN hub with its own default-route source",
                "description": "Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.",
                "abstract": "Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.",
                "articleBody": "Source facts\nThe default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.\nFor the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. Microsoft Learn.\nApplicability\nIdentify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source’s supported connection patterns rather than assuming every static or remote default route is eligible.\nDSE recommendation\nDSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection’s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub’s default will take over.\nVerification\nIn an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.\nOfficial references\nMicrosoft Learn: Securing Internet access with routing intent. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:28:47+00:00",
                "dateModified": "2026-09-10T00:55:36+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Supply each forced-tunnel Virtual WAN hub with its own default-route source"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 221,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Securing Internet access with routing intent - Azure Virtual WAN | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing"
                }
            }
        ]
    }
}