# Place NAT Gateway behind Azure Firewall without bypassing spoke inspection

> Keep the spoke route, firewall policy, and NAT association aligned when expanding outbound connectivity.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-014-place-nat-gateway-behind-azure-firewall-without-bypassing-spoke-inspection/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:42+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Keep the spoke route, firewall policy, and NAT association aligned when expanding outbound connectivity.

## Potentially affected

Azure Firewall hub-and-spoke networks considering NAT Gateway integration.

## DSE recommendation

Review spoke-to-firewall routing and the AzureFirewallSubnet NAT association as one egress change.

## Article

## Source facts

Microsoft’s example associates NAT Gateway with AzureFirewallSubnet. The spoke route table points to Azure Firewall’s private address, and firewall policy must permit the spoke traffic. NAT integration therefore accompanies an explicit route through the firewall.

This placement does not extend to a Virtual WAN hub: Microsoft says NAT Gateway is unsupported there and instead must be attached directly to the relevant spoke networks for that architecture. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/nat-gateway/tutorial-hub-spoke-nat-firewall).

## Applicability

Confirm that the design is a conventional hub-and-spoke network before adopting this tutorial. Record each spoke subnet, its route table, the firewall address, and the proposed NAT association; keep Virtual WAN designs in a separate review.

## DSE recommendation

DSE recommends treating this as an egress-path change, not just creation of a NAT resource. Obtain the application owner’s approved destinations and the network owner’s expected translated address. Compare the route and firewall policy before associating the gateway. Retain the previous configuration and an agreed rollback decision.

## Verification

From a test spoke, exercise an allowed internet destination and a deliberately prohibited one. Check the observed outbound address and firewall evidence together. A successful internet request alone should not satisfy acceptance; reconcile the actual next hop and policy result with the approved design.

## Official references

[Microsoft Learn: Integrate NAT Gateway with Azure Firewall in Hub and Spoke Network](https://learn.microsoft.com/en-us/azure/nat-gateway/tutorial-hub-spoke-nat-firewall). Source retrieved September 9, 2026.

## Primary reference

- Name: Integrate NAT Gateway with Azure Firewall in Hub and Spoke Network - Azure NAT Gateway | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/nat-gateway/tutorial-hub-spoke-nat-firewall
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Place NAT Gateway behind Azure Firewall without bypassing spoke inspection,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-014-place-nat-gateway-behind-azure-firewall-without-bypassing-spoke-inspection/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
