I have more of a generalized question. I currently have a virtual firewall in azure with 3 interfaces on it. I have a vm deployed that is sitting on the vnet with a udr pointing to the inside interface. Connections are working well, traffic is hitting the firewall, no issues. I was informed from the connection diagnostics I could have a potential localudr loop. I understand a vm and firewall on the same vnet pointing to the inside interface could cause a loop from an azure standpoint but, once the traffic hits my firewall the routes on the firewall carry the traffic to another interface then NAT out to the internet. The connection troubleshooter does not see that process of course. I opened a case with Microsoft and was told if things are working this could be ignored. My question is, if I remove the UDR, the default route sends the traffic to the internet.. How am i suppose to have these natively routing without a udr to the firewall? For context, I can’t re-ip the firewall or move the VMs at this time.<\/p>","upvoteCount":5,"answerCount":8,"datePublished":"2025-06-16T15:03:49.450Z","author":{"@type":"Person","name":"popeyesailzzz","url":"https://community.spiceworks.com/u/popeyesailzzz"},"suggestedAnswer":[{"@type":"Answer","text":"
Advertisement
Hello,<\/p>\n
I have more of a generalized question. I currently have a virtual firewall in azure with 3 interfaces on it. I have a vm deployed that is sitting on the vnet with a udr pointing to the inside interface. Connections are working well, traffic is hitting the firewall, no issues. I was informed from the connection diagnostics I could have a potential localudr loop. I understand a vm and firewall on the same vnet pointing to the inside interface could cause a loop from an azure standpoint but, once the traffic hits my firewall the routes on the firewall carry the traffic to another interface then NAT out to the internet. The connection troubleshooter does not see that process of course. I opened a case with Microsoft and was told if things are working this could be ignored. My question is, if I remove the UDR, the default route sends the traffic to the internet.. How am i suppose to have these natively routing without a udr to the firewall? For context, I can’t re-ip the firewall or move the VMs at this time.<\/p>","upvoteCount":5,"datePublished":"2025-06-16T15:03:49.702Z","url":"https://community.spiceworks.com/t/azure-vm-routing-question/1215602/1","author":{"@type":"Person","name":"popeyesailzzz","url":"https://community.spiceworks.com/u/popeyesailzzz"}},{"@type":"Answer","text":"