Designed and implemented a secure Hub & Spoke network architecture on Microsoft Azure to host a production-ready web application using Azure App Service.
The architecture separates networking components for enhanced security and scalability. The Hub network contains shared services including Azure Firewall and routing components, while the Spoke network hosts the workload resources.
Deployed Azure Application Gateway (Layer 7 Load Balancer) with HTTPS listener and SSL certificate configuration to secure inbound web traffic. Configured HTTP to HTTPS redirection and implemented Web Application Firewall (WAF) policies for enhanced protection.
Integrated Private Endpoint to securely connect Azure App Service to the virtual network, preventing public exposure. Implemented custom Route Tables (UDR) to control traffic flow through Azure Firewall for inspection and monitoring.
Configured Azure Firewall rules (Network & Application rules) to manage outbound and inbound traffic securely. Ensured secure communication between subnets and enforced segmentation principles.
Tested connectivity scenarios, validated secure traffic flow, and verified end-to-end encrypted communication.