Place NAT Gateway behind Azure Firewall without bypassing spoke inspection

Keep the spoke route, firewall policy, and NAT association aligned when expanding outbound connectivity.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Keep the spoke route, firewall policy, and NAT association aligned when expanding outbound connectivity.

Potentially affected

Azure Firewall hub-and-spoke networks considering NAT Gateway integration.

DSE recommendation

Review spoke-to-firewall routing and the AzureFirewallSubnet NAT association as one egress change.

Source facts

Microsoft’s example associates NAT Gateway with AzureFirewallSubnet. The spoke route table points to Azure Firewall’s private address, and firewall policy must permit the spoke traffic. NAT integration therefore accompanies an explicit route through the firewall.

This placement does not extend to a Virtual WAN hub: Microsoft says NAT Gateway is unsupported there and instead must be attached directly to the relevant spoke networks for that architecture. Microsoft Learn.

Applicability

Confirm that the design is a conventional hub-and-spoke network before adopting this tutorial. Record each spoke subnet, its route table, the firewall address, and the proposed NAT association; keep Virtual WAN designs in a separate review.

DSE recommendation

DSE recommends treating this as an egress-path change, not just creation of a NAT resource. Obtain the application owner’s approved destinations and the network owner’s expected translated address. Compare the route and firewall policy before associating the gateway. Retain the previous configuration and an agreed rollback decision.

Verification

From a test spoke, exercise an allowed internet destination and a deliberately prohibited one. Check the observed outbound address and firewall evidence together. A successful internet request alone should not satisfy acceptance; reconcile the actual next hop and policy result with the approved design.

Official references

Microsoft Learn: Integrate NAT Gateway with Azure Firewall in Hub and Spoke Network. Source retrieved September 9, 2026.

Primary reference

Review the official source

Integrate NAT Gateway with Azure Firewall in Hub and Spoke Network - Azure NAT Gateway | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE