What you need to know
Check the local default-route advertisement and connection flags before relying on hub-to-hub internet transit.
Potentially affected
Virtual WAN hubs using routing intent with private routing policies and forced-tunnel internet access.
DSE recommendation
Identify a supported local default-route source for each forced-tunnel hub and check the advertising connection's flags.
Source facts
The default route does not propagate between Virtual WAN hubs, so a forced-tunnel hub requires a local connection to supply it. The documented forced-tunnel mode applies to routing intent with private routing policies, not an internet routing policy.
For the connection advertising that default route, Microsoft says to disable Enable internet security or propagate default route. That permits the hub to learn the advertised default and avoids unexpected routing loops. Microsoft Learn.
Applicability
Identify the forced-tunnel hub, its private routing policy, security next hop, and actual local route source. Check the source’s supported connection patterns rather than assuming every static or remote default route is eligible.
DSE recommendation
DSE recommends a per-hub route record showing where the default originates, which connection advertises it, and where internet traffic should exit. Review the advertising connection’s flags alongside the return path. Keep a separate plan for loss of that local route source instead of assuming another hub’s default will take over.
Verification
In an approved test, inspect the learned default route and effective routes, then trace an allowed internet transaction through the intended exit. Exercise the planned loss-of-route scenario and record what actually happens. Confirm no unexpected loop or direct exit appears before extending the configuration to other hubs.
Official references
Microsoft Learn: Securing Internet access with routing intent. Source retrieved September 9, 2026.
Review the official source
Securing Internet access with routing intent - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE