Do not use missing Virtual WAN propagation as proof of network isolation

Can two secured-hub virtual networks still communicate when their routes are not propagated to each other?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Can two secured-hub virtual networks still communicate when their routes are not propagated to each other?

Potentially affected

Apply this check to the documented secured-hub Azure Firewall static-route design without routing intent. Identify aggregate routes as well as specific prefixes before declaring two connected virtual networks isolated.

DSE recommendation

Express the intended denial in the firewall policy and validate the complete path.

Source facts

Microsoft warns that Virtual WAN route associations and propagation settings do not guarantee isolation between virtual networks in a secured hub. An aggregate static route pointing to Azure Firewall can still provide a path between networks that do not propagate to each other. The source directs administrators to firewall network rules for the required block. Its Azure Firewall static-route pattern excludes hubs with routing intent enabled. Microsoft Learn.

Applicability

Apply this check to the documented secured-hub Azure Firewall static-route design without routing intent. Identify aggregate routes as well as specific prefixes before declaring two connected virtual networks isolated.

DSE recommendation

Express the intended denial in the firewall policy and validate the complete path. Have the network and security owners review the associated route tables, propagated prefixes and aggregate next hops together. Document which traffic must be denied and which neighboring traffic must remain permitted. Keep a routing omission separate from a reviewed security rule. Propose only the required policy change and preserve the existing route and rule state for the authorized test.

Verification

From approved endpoints, test both the intended denied connection and an explicitly allowed control flow. Retain the actual route and firewall decision with the result. Include destinations covered by a broader static prefix, not only directly listed routes. If traffic still passes through the firewall, investigate the matching rule instead of treating absent peer propagation as proof that the observation is impossible.

Official references

Microsoft Learn: Static routes in Azure Virtual WAN.

Primary reference

Review the official source

Static routes in Azure Virtual WAN - Azure Virtual WAN | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE