What you need to know
Review appliance subnet placement and direct next-hop connectivity before accepting a virtual-appliance route.
Potentially affected
Azure virtual-network subnets routing traffic through network virtual appliances.
DSE recommendation
Validate the appliance's subnet and direct next-hop path before associating its route table with workload subnets.
Source facts
Microsoft advises placing a virtual appliance in a different subnet from the resources routed through it. Applying a route back through an appliance in the same subnet can create a loop that prevents traffic from leaving.
The next-hop private address must be directly reachable; a path that first traverses ExpressRoute or Virtual WAN does not satisfy this requirement. Microsoft describes such an indirect next hop as an invalid UDR configuration. Microsoft Learn.
Applicability
Identify the workload subnet, associated route table, destination prefix, appliance subnet, and proposed next-hop address. Review the actual Azure topology rather than treating a reachable address from an administrator’s device as sufficient evidence.
DSE recommendation
DSE recommends drawing the first hop and return path before changing subnet routing. Have the network owner identify any same-subnet loop or gateway dependency explicitly. Preserve the previous route association and define the traffic that must remain available during the change, including appliance management access.
Verification
On an approved test subnet, inspect effective routes and exercise the intended application flow in both directions. Confirm that the observed next hop matches the reviewed topology. Include an excluded destination and investigate looping or unexpected detours before applying the table to additional workloads.
Official references
Microsoft Learn: Azure virtual network traffic routing. Source retrieved September 9, 2026.
Review the official source
Azure virtual network traffic routing | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE