About Azure Virtual WAN
Azure Virtual WAN is a managed Azure networking service for organizations that need to connect branches, remote users, virtual networks and ExpressRoute circuits through Microsoft-managed virtual hubs. It is designed for larger hub-and-spoke and global transit architectures where centralized routing, connectivity and security services are easier to operate than many separately managed virtual network gateways. It does not replace every Azure networking service. Instead, it provides the hub framework that can bring VPN, ExpressRoute, VNet transit, routing and Azure Firewall integration together.
What is included
Architecture
| Network model | Microsoft-managed hub-and-spoke and global transit architecture using Azure virtual hubs. |
|---|
Connectivity
| Supported connectivity | Site-to-site VPN, point-to-site user VPN, ExpressRoute, VNet transit and inter-hub connectivity in Standard Virtual WAN. |
|---|
Tiers
| Virtual WAN types | Basic supports site-to-site VPN only; Standard adds broader transit, ExpressRoute, user VPN, firewall and NVA scenarios. |
|---|
Scale
| Site-to-site connections | Microsoft currently documents up to 1,000 site-to-site VPN connections per virtual hub. |
|---|---|
| Point-to-site users | Microsoft currently documents up to 100,000 point-to-site users per virtual hub depending on gateway scale. |
Routing
| Hub router throughput | Up to 50 Gbps aggregate VNet-to-VNet hub-router throughput when sufficient routing infrastructure units are configured. |
|---|---|
| Accepted routes | A virtual hub can accept up to 10,000 routes from connected resources. |
| Routing intent VNet address spaces | Up to 600 directly connected virtual network address spaces per hub when routing intent private policies are used. |
What is Azure Virtual WAN used for?
Azure Virtual WAN is used to build managed hub-and-spoke networks across Azure regions. A virtual WAN contains one or more virtual hubs, and those hubs can connect branch offices, remote users, Azure virtual networks and ExpressRoute circuits. In Standard Virtual WAN, Microsoft connects the hubs in a full mesh so traffic can move between connected spokes through the Azure backbone.
The service is useful when an organization has many branches, multiple Azure regions, hybrid connectivity or a mix of VPN and ExpressRoute. It can also reduce the amount of routing infrastructure that a team has to build manually. Smaller single-region environments with only a few spokes may find a traditional hub-and-spoke virtual network easier to understand and cheaper to operate.
Basic vs Standard Virtual WAN: what is the difference?
Microsoft currently offers Basic and Standard Virtual WAN. Basic is limited to site-to-site VPN connectivity. Standard adds point-to-site user VPN, ExpressRoute, VNet-to-VNet transit through the hub, inter-hub transit, Azure Firewall and supported network virtual appliances.
A Basic Virtual WAN can be upgraded to Standard, but Microsoft says the change cannot be reversed. Teams that expect to add remote users, ExpressRoute or transitive VNet connectivity should account for that before choosing Basic. Standard is the more capable design for enterprise and multi-region deployments.
How do virtual hubs and routing work?
A virtual hub is a Microsoft-managed virtual network that hosts routing and connectivity services. Site-to-site VPN, point-to-site VPN and ExpressRoute gateways are separate resources inside the hub and can be scaled independently. The hub router handles traffic between connected virtual networks, branches and other hubs.
Microsoft currently documents up to 50 Gbps aggregate throughput for the virtual hub router when enough routing infrastructure units are configured. The default hub capacity starts with two routing infrastructure units, which Microsoft documents as supporting 3 Gbps of aggregate router throughput and about 2,000 connected VM workloads across attached virtual networks. Capacity can be increased, but a single TCP flow can still see performance degradation above 1.5 Gbps.
What scale and connection limits matter?
Virtual WAN is intended for larger networks, but it still has service limits. Microsoft currently documents up to 1,000 site-to-site VPN connections per virtual hub, up to 100,000 point-to-site users per hub depending on gateway scale, and up to 20 Gbps aggregate throughput for the Virtual WAN site-to-site VPN and ExpressRoute gateways.
For routing, Microsoft documents a maximum of 10,000 routes accepted by a virtual hub from connected resources. With routing intent enabled, a hub can have up to 600 directly connected virtual network address spaces. Teams approaching those limits should plan additional hubs instead of assuming the limits can always be raised.
How does Azure Virtual WAN pricing work?
Virtual WAN does not have one simple monthly price. Microsoft describes pricing components for the managed virtual hub, routing infrastructure units, VPN or ExpressRoute gateway scale, data transfer and optional services that are added to the hub. Azure Firewall or third-party network appliances have their own charges.
The practical cost therefore depends on the number of hubs, regions, connected sites, gateway capacity, routing capacity and how much data crosses the architecture. A hub can create charges even before sites or gateways are attached, so teams should include the base hub cost in early estimates. Pricing was reviewed on August 26, 2026 using Microsoft's current Virtual WAN pricing concepts documentation.
How does Virtual WAN differ from VPN Gateway and ExpressRoute?
Azure VPN Gateway and Azure ExpressRoute are connectivity services for specific network paths. Virtual WAN is a broader managed network architecture that can contain Virtual WAN VPN gateways and Virtual WAN ExpressRoute gateways inside virtual hubs, then provide transit routing between branches, users, virtual networks and hubs.
For a small number of tunnels or one simple hybrid connection, a regular VPN Gateway or ExpressRoute design can be easier. Virtual WAN becomes more useful when there are many branches, multiple regions, transitive routing needs, remote users or a requirement to combine several connectivity types under one managed hub model.
What are the main operational limitations?
Virtual WAN reduces some routing work, but it also reduces direct control over the hub because the hub is Microsoft managed. Teams that need custom network appliances placed freely inside a customer-managed hub virtual network, or that rely heavily on manually designed user-defined routes, may prefer a traditional hub-and-spoke architecture.
Migration also needs planning. Microsoft's design guidance recommends a parallel-run approach when moving from a traditional hub-and-spoke design because existing user-defined route configurations are not simply imported into Virtual WAN. Teams should validate routing, security inspection, DNS and failover behavior as each connection is moved.
Who should choose something else?
Choose a simpler Azure networking design if the environment is small, single-region and has only a few branches or virtual networks. A standard hub virtual network with VPN Gateway, ExpressRoute, Azure Firewall or network appliances can give teams more direct control and may be easier to troubleshoot.
Organizations that only need one private circuit should evaluate ExpressRoute directly. Those that only need site-to-site or remote-user VPN may prefer VPN Gateway. Virtual WAN is strongest when the value comes from centralized multi-branch, multi-region and mixed-connectivity management rather than from one isolated network connection.
Reviews
No reviews yet
Nobody has reviewed Azure Virtual WAN here yet.