Azure Hub and Spoke VNets - Private Endpoints and Private DNS Zones
Azure makes it simple to access Azure Cloud Services from your processes in Azure over the public network. Things become a little more complicated when you implement the best practice of restricting access to your Azure Services to only your Azure networks (VNets). This simple action drags in Private Link Endpoints and Private DNS Zones . Enterprises typically then layer on multiple Virtual Networks (VNets) for management and control purposes. This VNET Hub and Spoke architecture is pretty common though Microsoft has recently been advising customers to implement HUB and Spoke more through subnets than VNets. This reduces VNet sprawl and the amount of peering and other network magic required See YouTube video links below Private Endpoints / Private DNS Zones Azure Standard Sevices can be restricted from the Public Internet to your private Virtual Network (VNet) through the use of Private Link Endpoints (PLE). The PLEs essentially creat...