AVS HCX Migration Connectivity via Azure VPN Gateway in Hub VNet—Supported Design

Paul 20 Reputation points
2025-07-07T15:46:51.58+00:00

I am planning to migrate my on-premises VMware workloads to Azure VMware Solution (AVS) using HCX. I want to confirm whether the following network design is fully supported and recommended by Microsoft:

Scenario:

  • My on-premises datacenter is connected to Azure via a Site-to-Site VPN that terminates on the Azure VPN Gateway deployed in the Hub VNet.

In the AVS Private Cloud, I will configure and deploy HCX for migration.

I will link the Hub VNet to the AVS ExpressRoute circuit using the “Add VNet Connection” option available in the AVS portal.

The Hub VNet is peered to multiple Spoke VNets where other Azure workloads reside.

Azure Firewall is deployed in the Hub VNet to inspect and control all traffic flows.

I plan to use manual UDRs to direct all on-premises and Spoke VNet traffic through Azure Firewall before it reaches AVS.

Questions for confirmation:

Is this architecture supported by Microsoft for AVS HCX migrations (Site-to-Site VPN → Hub VNet → Azure Firewall → AVS)?

Are there any known limitations or considerations when using Site-to-Site VPN (instead of ExpressRoute) to connect the on-premises environment to AVS for HCX migration?

Is it correct that BGP routes from the AVS ExpressRoute connection will propagate into the Hub VNet and, by extension, to Spoke VNets if peering is configured with route propagation?

Do you recommend any specific NSX-T or UDR configurations in AVS to ensure smooth HCX migration traffic flow over this setup?

  1. How AVS hosted VM will access Internet?

I want to be sure this design will not introduce unsupported configurations for HCX migrations or AVS connectivity.

Azure VMware Solution
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.