Azure Hybrid ExpressRoute Architecture
This Azure hybrid architecture diagram documents a private path from an on-premises router to Azure workloads. ExpressRoute terminates at an Azure gateway, and Azure Firewall inspects traffic before it enters the virtual network. The virtual network contains an application VM and Azure SQL Managed Instance. Azure Monitor receives telemetry from the workloads. It is useful for discussing where private connectivity, inspection and application services fit in a hybrid design.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
An on-premises application extended into Azure.
Key decisions
- Private connectivity: ExpressRoute links the on-premises router to Azure.
- Central inspection: Azure Firewall sits between the gateway and virtual network.
- Shared monitoring: Azure Monitor receives telemetry from the workloads.
When to reuse this
Use this pattern when documenting a simple private connection between an on-premises network and Azure workloads.
Frequently asked questions
What is ExpressRoute?
Where is Azure Firewall placed?
What does the virtual network contain?
More azure examples
Try the diagram makers.
Tweak it with chat, export PNG/SVG, or fork it for your own use case.