About This Architecture
Azure Hub-Spoke network topology with a central hub VNet (10.0.0.0/16) hosting Azure Firewall Premium, VPN Gateway, Azure Bastion, and Load Balancer Standard for centralized security and routing. Two production spokes—Spoke1 (10.1.0.0/16) with Application Gateway and compute VMs, and Spoke2 (10.2.0.0/16) with Azure SQL Database and Cosmos DB—connect through the hub for controlled inter-VNet communication. Internet traffic routes through Azure Firewall Premium; on-premises users connect via VPN Gateway; internal users access applications through the Application Gateway in the DMZ subnet. This architecture enforces least-privilege access, centralized threat protection, and scalable multi-tier workload isolation across production and data layers. Fork and customize this diagram on Diagrams.so to adapt subnetting, add additional spokes, or integrate Azure Policy and Network Security Groups for your environment.