# Supply each forced-tunnel Virtual WAN hub with its own default-route source

> Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:47+00:00
- Modified: 2026-09-10T00:55:36+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.

## Potentially affected

Virtual WAN hubs using routing intent with private routing policies and forced-tunnel internet access.

## DSE recommendation

Identify a supported local default-route source for each forced-tunnel hub and check the advertising connection's flags.

## Article

## Source facts

The default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.

For the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing).

## Applicability

Identify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source’s supported connection patterns rather than assuming every static or remote default route is eligible.

## DSE recommendation

DSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection’s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub’s default will take over.

## Verification

In an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.

## Official references

[Microsoft Learn: Securing Internet access with routing intent](https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing). Source retrieved September 9, 2026.

## Primary reference

- Name: Securing Internet access with routing intent - Azure Virtual WAN | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-wan/about-internet-routing
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Supply each forced-tunnel Virtual WAN hub with its own default-route source,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-189-supply-each-forced-tunnel-virtual-wan-hub-with-its-own-default-route-source/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
