Azure VPN Gateway – Does a GatewaySubnet UDR Apply to Traffic Entering the VPN Gateway from the VNet Side?
I’m trying to clarify exactly when an Azure VPN Gateway respects a route table (UDR) associated with the GatewaySubnet.
Assume I have a VPN Gateway deployed in the GatewaySubnet of a hub VNet. The hub is peered with a spoke VNet, and the VPN Gateway provides connectivity to an on-premises network.
There is also a route table associated with the GatewaySubnet. For example, it contains a route for the spoke prefix with Azure Firewall/NVA as the next hop.
I understand the behavior in the on-premises-to-Azure direction:
On-premises → VPN tunnel → VPN Gateway → Azure Firewall/NVA → Spoke
Traffic arrives at the VPN Gateway from the VPN tunnel, and the GatewaySubnet UDR can influence where the gateway forwards that traffic inside Azure.
My question is about the opposite direction.
Suppose traffic originates from a subnet in the same VNet as the VPN Gateway, or from a peered VNet. The source subnet has an effective route for the on-premises prefix with VirtualNetworkGateway as the next hop.
For example:
Spoke VM → VPN Gateway → VPN tunnel → On-premises
The routing decision that sends the packet toward the VPN Gateway is made based on the effective routes of the source/workload subnet.
Once the packet reaches the VPN Gateway from the VNet side, does the VPN Gateway perform another route lookup using the effective routes/UDRs associated with the GatewaySubnet?
Or does the GatewaySubnet UDR only influence traffic that the VPN Gateway is forwarding from the VPN/tunnel side into Azure?
In other words, is the following understanding correct?
VPN → VPN Gateway → VNet: GatewaySubnet UDR can affect the forwarding decision.
VNet/Peered VNet → VPN Gateway → VPN: GatewaySubnet UDR is not evaluated to redirect traffic that is entering the VPN Gateway from the VNet side.
If that understanding is correct, symmetric firewall inspection would need to be controlled separately in each direction:
On-premises → VPN Gateway → Firewall → Spoke: controlled by the GatewaySubnet UDR.
Spoke → Firewall → VPN Gateway → On-premises: controlled by the spoke/workload subnet UDR.
I’m specifically trying to understand whether the Azure VPN Gateway performs a route lookup against the GatewaySubnet route table for packets it receives from the same VNet or a peered VNet before sending those packets into a VPN tunnel.
If anyone can confirm the behavior or point me to Microsoft documentation that describes this specific routing behavior, that would be appreciated.