Worked example · Azure VNet · hub and spokes
Azure Hub-Spoke Subnet Plan
A hub VNet with the reserved gateway and firewall subnets plus shared services, and a spoke template for application and data tiers, sized under Azure reservations.
Hub VNet 10.0.0.0/16
parent 10.0.0.0/16 subnets 3 allocated 352 of 65,536 (0.5%) free 65,184
Largest first: SharedServices takes the first /24 (256 addresses), so every smaller block that follows starts on a multiple of its own size with no gaps.
| Name | Hosts | Subnet | Netmask | Usable range | Broadcast | Usable | Unused |
|---|---|---|---|---|---|---|---|
| SharedServices | 200 | 10.0.0.0/24 | 255.255.255.0 | 10.0.0.4 – 10.0.0.254 | 10.0.0.255 | 251 | 51 |
| AzureFirewallSubnet | 59 | 10.0.1.0/26 | 255.255.255.192 | 10.0.1.4 – 10.0.1.62 | 10.0.1.63 | 59 | 0 |
| GatewaySubnet | 27 | 10.0.1.64/27 | 255.255.255.224 | 10.0.1.68 – 10.0.1.94 | 10.0.1.95 | 27 | 0 |
Free blocks: 10.0.1.96/27 10.0.1.128/25 10.0.2.0/23 10.0.4.0/22 10.0.8.0/21 10.0.16.0/20 10.0.32.0/19 10.0.64.0/18 10.0.128.0/17
Spoke VNet 10.1.0.0/16
parent 10.1.0.0/16 subnets 2 allocated 384 of 65,536 (0.5%) free 65,152
Largest first: app takes the first /24 (256 addresses), so every smaller block that follows starts on a multiple of its own size with no gaps.
| Name | Hosts | Subnet | Netmask | Usable range | Broadcast | Usable | Unused |
|---|---|---|---|---|---|---|---|
| app | 200 | 10.1.0.0/24 | 255.255.255.0 | 10.1.0.4 – 10.1.0.254 | 10.1.0.255 | 251 | 51 |
| data | 100 | 10.1.1.0/25 | 255.255.255.128 | 10.1.1.4 – 10.1.1.126 | 10.1.1.127 | 123 | 23 |
Free blocks: 10.1.1.128/25 10.1.2.0/23 10.1.4.0/22 10.1.8.0/21 10.1.16.0/20 10.1.32.0/19 10.1.64.0/18 10.1.128.0/17
Why this layout
- Reserved subnet names and sizes. Azure looks for a subnet named exactly
GatewaySubnetfor VPN and ExpressRoute gateways and recommends /27 or larger;AzureFirewallSubnetis reserved for Azure Firewall with a recommended /26. The planner sizes both from the host counts 27 and 59. - Shared services next to the gateway. A /24 holds monitoring, DNS forwarders, jump hosts and other central services without borrowing space from the spokes.
- Spokes do not overlap. Peering needs distinct address space, so the hub is 10.0.0.0/16, spoke one is 10.1.0.0/16 and spoke two would be 10.2.0.0/16. Each VNet can be advertised to on-premises as one summary route.
- Azure reservations are part of the math. Capacity rule “Azure VNet” reserves the first four and the last address and enforces the /29 minimum, so the table, the Bicep export and the Azure CIDR list agree.
Inspect a finished subnet in the subnet calculator, or check that the three VNets cannot collide with the overlap checker. The AWS version of this exercise is the three-tier VPC example.
Questions
Why is the gateway subnet a /27?
Azure requires a subnet named exactly GatewaySubnet for a VPN or ExpressRoute gateway, and recommends /27 or larger so the gateway can scale. A /27 has 27 usable addresses after Azure reserves five, which is the request this plan gives it.
Why does the firewall subnet use a /26?
AzureFirewallSubnet is the reserved name for Azure Firewall, and /26 is the recommended size so the firewall can scale with traffic. A /26 leaves 59 usable addresses under Azure reservations.
Why do the spoke VNets use different address ranges?
VNet peering requires non-overlapping address space. The hub uses 10.0.0.0/16, the first spoke 10.1.0.0/16 and the second 10.2.0.0/16, so every spoke can peer with the hub and be summarized with one route.
How many addresses does Azure reserve in a subnet?
Azure reserves the first four addresses and the last one in every subnet, the same five as AWS: network, default gateway, two for DNS, and broadcast. The smallest subnet Azure allows is /29, and the planner enforces both bounds in Azure mode.