About This Architecture
Hybrid Azure Virtual Desktop network connecting Christchurch and Auckland on-premises sites via active-active Fortinet firewalls and S2S VPN to Azure VNet1 in New Zealand North region. Traffic flows from production LAN through VPN gateways, NAT gateway, and bastion host to AVD session hosts, SQL VMs, and supporting infrastructure across five resource groups. This architecture demonstrates enterprise-grade hybrid identity integration with Azure AD DS, Entra ID, and Key Vault for secure credential management. Fork this diagram on Diagrams.so to customize subnets, add additional regions, or adjust VM SKUs for your AVD deployment. The active-active VPN configuration with dual public IPs ensures high availability for remote desktop access across geographically distributed sites.