Supply each forced-tunnel Virtual WAN hub with its own default-route source

Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.

Potentially affected

Virtual WAN hubs using routing intent with private routing policies and forced-tunnel internet access.

DSE recommendation

Identify a supported local default-route source for each forced-tunnel hub and check the advertising connection's flags.

Source facts

The default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.

For the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. Microsoft Learn.

Applicability

Identify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source’s supported connection patterns rather than assuming every static or remote default route is eligible.

DSE recommendation

DSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection’s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub’s default will take over.

Verification

In an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.

Official references

Microsoft Learn: Securing Internet access with routing intent. Source retrieved September 9, 2026.

Primary reference

Review the official source

Securing Internet access with routing intent - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE