Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Azure vWAN Multiple hubs #387

Closed
gerrynicol opened this issue Nov 14, 2022 · 11 comments · Fixed by #456
Closed

Azure vWAN Multiple hubs #387

gerrynicol opened this issue Nov 14, 2022 · 11 comments · Fixed by #456

Comments

@gerrynicol
Copy link

gerrynicol commented Nov 14, 2022

Question/Feedback

AB#25156

Hi there, can any guidance be provided for creating multiple vWAN hubs. At the moment the modules only create one vWAN hub in a single region.

Possible Answers/Solutions?

Just want us to confirm your thinking, let us know any possible answers you've considered and we can confirm 👍

@ghost ghost added the Needs: Triage 🔍 Needs triaging by the team label Nov 14, 2022
@jtracey93
Copy link
Collaborator

Hey @gerrynicol,

Would you be looking for multiple hubs in the same region or multiple hubs across various regions?

Let us know

Thanks

Jack

@jtracey93 jtracey93 added Needs: Author Feedback and removed Needs: Triage 🔍 Needs triaging by the team labels Nov 14, 2022
@gerrynicol
Copy link
Author

Hi @jtracey93. Apologies, should have been more specfic. It would be single hubs deployed in multiple regions, all in the same vWAN.

@ghost ghost added Needs: Attention 👋 Needs attention from the maintainers and removed Needs: Author Feedback labels Nov 14, 2022
@jtracey93
Copy link
Collaborator

Hey @gerrynicol,

No worries thanks for coming back to me.

Today the modules don't support this via input parameters. However you could take the VWAN module and customise it as per https://github.com/Azure/ALZ-Bicep/wiki/ConsumerGuide#customizing-the-alz-bicep-modules

However, your ask is valid and this could be something we look to add to ALZ Bicep.

Would you want it also to optionally have a FW in the other hub?

Really looking for what you would/wouldn't want it to do for a multi hub deployment.

We can then look to get this on the backlog and maybe start development soon.

Let us know

Cheers

Jack 👍

@jtracey93 jtracey93 added Needs: Author Feedback and removed Needs: Attention 👋 Needs attention from the maintainers labels Nov 14, 2022
@gerrynicol
Copy link
Author

gerrynicol commented Nov 15, 2022

Hi @jtracey93,
Thanks for looking at this and considering it. Yes indeed, the ask would indeed be for an optional firewall in the second\third Hub. I would say the requirements would be as follows

  • Deploy a vWAN
  • Keep existing module options of Gateways\scale units, firewall, firewall policy's, DDOS, private DNS Zones
  • Deploy a vWAN Hub in Region1, Region2, Region3 etc (optionally to be a secure hub-i.e az firewall)
  • Hub routing and intent policies (https://learn.microsoft.com/en-us/azure/virtual-wan/about-virtual-hub-routing)
  • (Edit - Just read that these routing policies currently dont support inter-regional traffic going via AZfw)

Cheers
Gerry

@ghost ghost added Needs: Attention 👋 Needs attention from the maintainers and removed Needs: Author Feedback labels Nov 15, 2022
@jtracey93 jtracey93 added enhancement and removed Needs: Attention 👋 Needs attention from the maintainers labels Nov 15, 2022
@jtracey93
Copy link
Collaborator

Hey @gerrynicol,

Thanks for the info, really useful :)

Ill add it to our internal backlog and add a feature for this. Im thinking i'll just add a feature for enabling to deploy additional hubs with firewall etc. to an existing VWAN resource.

The other part around routing intent etc. we will leave off for now as you noted.

Sound good?

@gerrynicol
Copy link
Author

Hi @jtracey93,

Yip. thats sound perfect. Would be great to see this available. And again, thanks for looking into it. :)

Cheers
Gerry

@ghost ghost added Needs: Attention 👋 Needs attention from the maintainers and removed Needs: Author Feedback labels Nov 15, 2022
@jtracey93
Copy link
Collaborator

For completeness this has been created as a feature in our backlog. ADO WIT: 25156

@jtracey93
Copy link
Collaborator

Just an update this made it into the December sprint, so stay tuned

@gerrynicol
Copy link
Author

Excellent. Looking forward to testing it

@jtracey93 jtracey93 removed the Needs: Attention 👋 Needs attention from the maintainers label Nov 26, 2022
@gerrynicol
Copy link
Author

Just a quick one on the options for creating the vWAN Hubs in different resource Groups. Would be good to have this option available as per extract from this link - https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-faq

Can hubs be created in different resource groups in Virtual WAN?
Yes. This option is currently available via PowerShell only. The Virtual WAN portal requires that the hubs are in the same resource group as the Virtual WAN resource itself.

@jtracey93
Copy link
Collaborator

jtracey93 commented Dec 16, 2022

Just a quick one on the options for creating the vWAN Hubs in different resource Groups. Would be good to have this option available as per extract from this link - https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-faq

Can hubs be created in different resource groups in Virtual WAN? Yes. This option is currently available via PowerShell only. The Virtual WAN portal requires that the hubs are in the same resource group as the Virtual WAN resource itself.

Good idea. @lachaves lets include this into the ADO work item you have for this AB#25156

@jtracey93 jtracey93 linked a pull request Feb 28, 2023 that will close this issue
10 tasks
@ghost ghost locked as resolved and limited conversation to collaborators Mar 30, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants