Azure VPN Gateway – Does a GatewaySubnet UDR Apply to Traffic Entering the VPN Gateway from the VNet Side?

Peter Stieber 70 Reputation points
2026-09-24T07:35:41.6433333+00:00

Azure VPN Gateway – Does a GatewaySubnet UDR Apply to Traffic Entering the VPN Gateway from the VNet Side?

I’m trying to clarify exactly when an Azure VPN Gateway respects a route table (UDR) associated with the GatewaySubnet.

Assume I have a VPN Gateway deployed in the GatewaySubnet of a hub VNet. The hub is peered with a spoke VNet, and the VPN Gateway provides connectivity to an on-premises network.

There is also a route table associated with the GatewaySubnet. For example, it contains a route for the spoke prefix with Azure Firewall/NVA as the next hop.

I understand the behavior in the on-premises-to-Azure direction:

On-premises → VPN tunnel → VPN Gateway → Azure Firewall/NVA → Spoke

Traffic arrives at the VPN Gateway from the VPN tunnel, and the GatewaySubnet UDR can influence where the gateway forwards that traffic inside Azure.

My question is about the opposite direction.

Suppose traffic originates from a subnet in the same VNet as the VPN Gateway, or from a peered VNet. The source subnet has an effective route for the on-premises prefix with VirtualNetworkGateway as the next hop.

For example:

Spoke VM → VPN Gateway → VPN tunnel → On-premises

The routing decision that sends the packet toward the VPN Gateway is made based on the effective routes of the source/workload subnet.

Once the packet reaches the VPN Gateway from the VNet side, does the VPN Gateway perform another route lookup using the effective routes/UDRs associated with the GatewaySubnet?

Or does the GatewaySubnet UDR only influence traffic that the VPN Gateway is forwarding from the VPN/tunnel side into Azure?

In other words, is the following understanding correct?

VPN → VPN Gateway → VNet: GatewaySubnet UDR can affect the forwarding decision.

VNet/Peered VNet → VPN Gateway → VPN: GatewaySubnet UDR is not evaluated to redirect traffic that is entering the VPN Gateway from the VNet side.

If that understanding is correct, symmetric firewall inspection would need to be controlled separately in each direction:

On-premises → VPN Gateway → Firewall → Spoke: controlled by the GatewaySubnet UDR.

Spoke → Firewall → VPN Gateway → On-premises: controlled by the spoke/workload subnet UDR.

I’m specifically trying to understand whether the Azure VPN Gateway performs a route lookup against the GatewaySubnet route table for packets it receives from the same VNet or a peered VNet before sending those packets into a VPN tunnel.

If anyone can confirm the behavior or point me to Microsoft documentation that describes this specific routing behavior, that would be appreciated.

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

2 answers

Sort by: Most helpful
  1. VIVEK DWIVEDI 270 Reputation points Microsoft Employee
    2026-09-29T06:43:07.24+00:00

    Hi @Peter Stieber,

    The reverse traffic to on-prem is not directed through UDR on gateway subnet, it is based on the underlying static routing by using LNG (Local Network Gateway) or by using BGP as the protocol to lean the route.

    If you have Route table on Spoke Vnet/Subnet pointed to NVA, it does the job to make the symmetric path.
    On-prem → VPN Gateway (Route table)→ Firewall → Spoke
    Spoke (Route table) → Firewall → VPN Gateway → On-prem

    Please upvote if it helps you!

    Was this answer helpful?

    0 comments No comments

  2. Allan Solomon Mejia 10,145 Reputation points
    2026-09-24T20:59:24.88+00:00

    Hi @Peter Stieber

    Your understanding aligns with Microsoft's documented hybrid-routing design.

    Place a UDR on the GatewaySubnet with the Azure Firewall/NVA as the next hop for spoke prefixes. This routes traffic arriving from on-premises through the VPN gateway to Azure workloads via the firewall.

    For the opposite direction, place the appropriate UDR on the spoke/workload subnet, pointing traffic toward the firewall. The firewall then forwards the on-premises-bound traffic toward the VPN gateway.

    So the documented symmetric inspection pattern is:

    On-prem → VPN Gateway → Firewall → Spoke

    and

    Spoke → Firewall → VPN Gateway → On-prem

    The first direction uses the GatewaySubnet UDR for the Azure/spoke destination, while the reverse direction requires routing on the workload/spoke side to send traffic through the firewall.

    Route tables define how traffic initiated in a subnet is routed, and the documented NVA/VPN Gateway scenario uses a GatewaySubnet route specifically for traffic coming from on-premises toward Azure.

    I cannot find verified Microsoft documentation stating that a VPN Gateway performs a second lookup against the GatewaySubnet UDR for packets it receives from the VNet side immediately before encapsulating them into the VPN tunnel.

    Therefore, don't rely on the GatewaySubnet UDR to provide the reverse-direction inspection path. Configure the workload/spoke routing explicitly, as shown in Microsoft's documented hybrid Azure Firewall architecture.

    References:

    Azure Firewall hybrid network

    Hybrid connection with NVA and VPN Gateway

    Azure virtual network traffic routing


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.