# Preserve Route Server BGP communication when inserting a firewall route

> An inspection route can unintentionally divert the control-plane traffic needed by the gateway or peered appliance.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-290-preserve-route-server-bgp-communication-when-inserting-a-firewall-route/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:06+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

An inspection route can unintentionally divert the control-plane traffic needed by the gateway or peered appliance.

## Potentially affected

Azure Route Server deployments with inspection UDRs on GatewaySubnet or a BGP-peered NVA subnet.

## DSE recommendation

Review the RouteServerSubnet path separately from workload inspection before associating the route table.

## Article

## Source facts

Microsoft documents that a GatewaySubnet route intended to send on-premises traffic through a firewall can also divert BGP communication between the gateway and Route Server. This occurs when the inspection route covers traffic destined for the Route Server virtual network.

The same concern applies to an SD-WAN appliance subnet peered with Route Server. Microsoft’s documented exception uses the actual RouteServerSubnet prefix with VirtualNetwork as next hop, rather than sending that control-plane path through the firewall. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/route-server/troubleshoot-route-server).

## Applicability

Identify the gateway or appliance subnet, RouteServerSubnet range and proposed inspection route. Use the deployment’s actual addresses; the documentation’s example ranges are not configuration values for another network.

## DSE recommendation

DSE recommends drawing the BGP path separately from the workload path during route review. Decide how the control-plane session remains reachable before associating the inspection table. Review any exception with both routing and security owners so it is neither an accidental bypass nor an omitted dependency. Retain the previous route table and the agreed recovery trigger.

## Verification

During an approved test, confirm BGP adjacency and route learning as well as the intended inspected application connection. Compare the actual next hops with the reviewed paths. If workload forwarding changes while the control plane fails, stop and investigate before continuing the rollout. Record both outcomes; a successful firewall rule test alone does not establish that Route Server peering survived.

## Official references

[Microsoft Learn: Troubleshoot Azure Route Server issues](https://learn.microsoft.com/en-us/azure/route-server/troubleshoot-route-server). Source retrieved September 9, 2026.

## Primary reference

- Name: Troubleshoot Azure Route Server issues | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/route-server/troubleshoot-route-server
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve Route Server BGP communication when inserting a firewall route,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-290-preserve-route-server-bgp-communication-when-inserting-a-firewall-route/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
