Cloud consultants beyond the ordinary.AZURE. DEVOPS. DATA.

Azure networking

Build your network
on solid foundations

We’re experts in Azure networking. We help you design, build and improve the connections your applications depend on, with clear routing, reliable DNS and security built into the architecture.

Your sites connect over VPN or ExpressRoute through a connectivity hub with routing and firewall controls to applications, data and shared services.

Your applications depend on the network underneath

A solid network does more than connect resources. It makes services reachable, keeps access controlled and gives your team a clear way to diagnose problems. Get the foundation right before complexity grows.

Keep services connected

Plan how workloads, private services and on-premises systems find and reach each other. Treat DNS, addressing and routing as one connected design.

Control what can connect

Set clear boundaries between workloads and environments. Allow the traffic you need, inspect it where required and make access decisions explicit.

Make changes with confidence

Understand the dependencies before adding a workload, changing a route or updating a rule. Keep the design, configuration and ownership clear as your network grows.

Your sites connect through a connectivity hub to application and data networks.Your sitesConnectivity hubAppsDataOffices and on-premises

Network design

Build a network that fits

Plan the connections, traffic paths and controls your workloads depend on.

  • Network architecture & addressing

    Choose a topology, plan IP ranges, and define connections between regions, subscriptions and sites. Account for growth, overlapping address spaces, VPN and ExpressRoute requirements.

  • Routing & traffic paths

    Make it clear where traffic goes and how it returns. Review peering, user-defined routes, BGP propagation and inspection paths to avoid unintended bypasses and asymmetric routing.

  • Firewall rules your team can manage

    Define allowed sources, destinations, ports and protocols. Review network, application and NAT rules, their processing order, logging and ownership. Keep changes traceable and remove access that is no longer needed.

Private access

Make private services easy to reach

Design name resolution and access controls together, so your teams can connect and troubleshoot with confidence.

  • DNS & private endpoints

    A private connection is only useful if clients resolve the right address. We design DNS so private services can be found reliably from both Azure and your on-premises environment.

  • Security & visibility

    Set clear boundaries for what can connect, and give your team a way to see when traffic is allowed, blocked, or failing.

Meet our team
An approved app reaches a private service while another request is blocked.

Network topology

Azure Virtual WAN or hub-and-spoke?

We often start with Azure Virtual WAN. It simplifies routing and works naturally with Azure Firewall. For more tailored requirements, we design a hub-and-spoke network.

Our usual starting point

Azure Virtual WAN

Bring your sites, security and workloads together.

Your sites
Virtual WAN
Azure Firewall
Your workloads
  • Simpler routing
  • Integrated security
  • Ready to grow

When you need more control

Hub-and-spoke

A tailored hub for specific integrations and network requirements.

We choose the architecture around your connectivity, security, resilience and cost requirements.

Firewall architecture

Choose the firewall that fits
your network and your team

The product is one part of the decision. Its placement, traffic paths, rules and day-to-day management matter just as much.

Azure Firewall

A managed Azure service with central policy, logging and built-in availability. We help you choose the right tier and design its placement, rules, DNS behaviour and traffic paths.

Match the inspection features and throughput to the workload. Network rules, application rules and NAT rules serve different purposes; broad permissions can undermine more specific controls.

Third-party firewalls

A network virtual appliance can fit an existing security platform, operational model or vendor-specific requirement. We assess the supported Azure architecture with your team and vendor.

Check licensing, sizing, upgrades, high availability and vendor support. In Virtual WAN, validate the supported appliance and integration model rather than assuming a virtual machine deployment can be moved into a managed hub.

Working together

Get a network your team can build on and run

Start with a review, a specific connectivity problem or a new architecture. We agree the scope and work with your platform, network and security teams through implementation and handover.

  1. 01

    Understand the environment

    Map workloads, sites, address ranges, DNS dependencies and traffic flows. Identify the constraints, risks and operational needs.

  2. 02

    Agree the design

    Compare topology and firewall options. Define routing, name resolution, security boundaries, resilience and ownership before building.

  3. 03

    Build and validate

    Implement the agreed design with repeatable configuration. Test name resolution, allowed and blocked connections, return paths and the agreed failover scenarios.

  4. 04

    Hand over the working network

    Walk through the architecture diagrams, address plan, DNS design, routes and firewall policies. Deliver the agreed code, monitoring guidance and operating documentation.

FAQ

Questions and answers

Can you review our existing Azure network?

Yes. We can start with the network you already have: its topology, IP ranges, DNS, routing, firewall rules and hybrid connections. We help identify what needs attention and agree practical changes with your team.

Is Virtual WAN always better than hub-and-spoke?

No. Virtual WAN provides Microsoft-managed hub connectivity and routing, while a customer-managed hub gives you more control over its components. The right choice depends on your sites, regions, security integrations, costs and the team operating the network.

Can we keep our third-party firewall?

We can assess how it fits your Azure design and work with your team or vendor on the supported deployment model. We consider availability, routing, licensing, management and inspection requirements. Appliance configuration and migration responsibilities are agreed in the scope.

Why does DNS need to be part of the network design?

An application can have a valid route and still fail if it resolves a service to the wrong address. Private endpoints and hybrid environments make DNS zones, forwarding and client resolver settings particularly important. We design and test name resolution alongside connectivity.

Can this be part of an Azure Landing Zone?

Yes. Networking is part of the Azure foundation, and we can design it alongside identity, governance and platform operations. We also take on standalone networking reviews and improvements to existing environments.

Let’s work through your network

Tell us what needs to connect, what needs to stay separate and where you need help.

Discuss your network

Let’s talk

What’s on your mind?

A project, a question or your next role. Tell us a little about it.

We use your details only to respond to your message. Read our privacy policy.

Prefer email? Write to info [at] unwonted [dot] se.