# Check Azure UDR next-hop reachability before routing through an appliance

> Review appliance subnet placement and direct next-hop connectivity before accepting a virtual-appliance route.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-143-check-azure-udr-next-hop-reachability-before-routing-through-an-appliance/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:33+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Review appliance subnet placement and direct next-hop connectivity before accepting a virtual-appliance route.

## Potentially affected

Azure virtual-network subnets routing traffic through network virtual appliances.

## DSE recommendation

Validate the appliance's subnet and direct next-hop path before associating its route table with workload subnets.

## Article

## Source facts

Microsoft advises placing a virtual appliance in a different subnet from the resources routed through it. Applying a route back through an appliance in the same subnet can create a loop that prevents traffic from leaving.

The next-hop private address must be directly reachable; a path that first traverses ExpressRoute or Virtual WAN does not satisfy this requirement. Microsoft describes such an indirect next hop as an invalid UDR configuration. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview).

## Applicability

Identify the workload subnet, associated route table, destination prefix, appliance subnet, and proposed next-hop address. Review the actual Azure topology rather than treating a reachable address from an administrator’s device as sufficient evidence.

## DSE recommendation

DSE recommends drawing the first hop and return path before changing subnet routing. Have the network owner identify any same-subnet loop or gateway dependency explicitly. Preserve the previous route association and define the traffic that must remain available during the change, including appliance management access.

## Verification

On an approved test subnet, inspect effective routes and exercise the intended application flow in both directions. Confirm that the observed next hop matches the reviewed topology. Include an excluded destination and investigate looping or unexpected detours before applying the table to additional workloads.

## Official references

[Microsoft Learn: Azure virtual network traffic routing](https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview). Source retrieved September 9, 2026.

## Primary reference

- Name: Azure virtual network traffic routing | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check Azure UDR next-hop reachability before routing through an appliance,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-143-check-azure-udr-next-hop-reachability-before-routing-through-an-appliance/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
