AZURE

Azure Hybrid ExpressRoute Architecture

This Azure hybrid architecture diagram documents a private path from an on-premises router to Azure workloads. ExpressRoute terminates at an Azure gateway, and Azure Firewall inspects traffic before it enters the virtual network. The virtual network contains an application VM and Azure SQL Managed Instance. Azure Monitor receives telemetry from the workloads. It is useful for discussing where private connectivity, inspection and application services fit in a hybrid design.

UPDATED 2026-09-24
EXAMPLEAzure Hybrid ExpressRoute Architecture
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

An on-premises application extended into Azure.

Key decisions

  • Private connectivity: ExpressRoute links the on-premises router to Azure.
  • Central inspection: Azure Firewall sits between the gateway and virtual network.
  • Shared monitoring: Azure Monitor receives telemetry from the workloads.

When to reuse this

Use this pattern when documenting a simple private connection between an on-premises network and Azure workloads.

FAQ

Frequently asked questions

What is ExpressRoute?01
ExpressRoute is a private connectivity option between an on-premises network and Azure.
Where is Azure Firewall placed?02
In this example it is between the ExpressRoute gateway and the Azure virtual network.
What does the virtual network contain?03
The example virtual network contains an application VM and Azure SQL Managed Instance.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.