Implementing Secure VNet Peering Between Departmental Networks
Pluralsight Hands-On Lab — Networking
At a Glance
| Platform | Pluralsight |
| Category | Azure Networking & Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal |
| Completed | 2026 |
Overview
This lab demonstrates a layered network security architecture connecting two departmental virtual networks — Finance and HR — with precisely scoped access controls. I created the Finance VNet with a non-overlapping address space, established VNet peering between the two networks, configured NSG rules on both sides to allow only SQL traffic on TCP port 1433 while blocking all other cross-departmental traffic, and applied a custom route table to the HR subnet to block direct internet egress while preserving private peering connectivity.
What I Did
- Reviewed the existing HR virtual network (vnet-hr, 10.1.0.0/16, subnet snet-hr at 10.1.0.0/24) and noted the region for all new resources
- Created a Finance virtual network (vnet-finance, 10.2.0.0/16, subnet snet-finance at 10.2.1.0/24) with a non-overlapping address space to satisfy Azure peering requirements
- Created bidirectional VNet peering between vnet-finance and vnet-hr (link names: finance-to-hr and hr-to-finance) and confirmed Connected status
- Created an NSG (nsg-finance) and associated it with the Finance subnet, adding two outbound rules: Allow SQL (TCP 1433) to 10.1.0.0/24 at priority 100, and Deny all traffic to 10.1.0.0/24 at priority 200
- Configured the pre-deployed HR NSG (nsg-snet-hr-predeployed) with two inbound rules: Allow SQL (TCP 1433) from 10.2.1.0/24 at priority 100, and Deny all traffic from 10.2.1.0/24 at priority 200 — enforcing least-privilege access on both ends
- Created a route table (rt-hr-block-internet) with a single route named Block-Internet targeting 0.0.0.0/0 with next hop type None, dropping all internet-bound traffic from the HR subnet
- Associated the route table with snet-hr, confirming that peered VNet traffic is unaffected (Azure uses more specific system routes for peering) while direct internet egress from HR is blocked
← Back to Pluralsight Labs