Chapter Four

Networking & Content Delivery

Eight services for connectivity, traffic distribution, and edge delivery. Get the virtual network and its address space right first — overlapping ranges block peering later, with no fix but renumbering.

8 services

Core Terminology

Azure networking layers regional and global components. These terms recur across the chapter.

Virtual Network (VNet)
A regional, isolated private network you define with address space and subnets. The boundary almost everything else attaches to.
Network Security Group
A stateful set of allow/deny rules on a subnet or NIC, filtering traffic by port, protocol, and source. Azure's basic firewall primitive.
Peering
A private, low-latency connection joining two VNets. It refuses to establish across overlapping address ranges — the reason address planning comes first.
Layer 4 vs Layer 7
Load Balancer works at L4 (TCP/UDP); Application Gateway and Front Door work at L7 (HTTP), seeing URLs, headers, and cookies.
Private Endpoint
A private IP inside your VNet that maps to a PaaS service, keeping traffic to it off the public internet.
Hub-and-Spoke
A topology where shared services live in a hub VNet that spoke VNets peer into — the standard enterprise network shape on Azure.

Services in This Chapter