Azure networking updates on security, reliability, and high availability

4 months ago 78

The unreality scenery is evolving astatine an unprecedented pace, driven by the exponential maturation of AI workloads.

Enabling the adjacent question of unreality translation with Azure Networking

The unreality scenery is evolving astatine an unprecedented pace, driven by the exponential maturation of AI workloads and the request for seamless, secure, and high-performance connectivity. Azure Network services basal astatine the forefront of this transformation, delivering the hyperscale infrastructure, intelligent services, and resilient architecture that empower organizations to innovate and standard with confidence.

Azure’s planetary web is purpose-built to conscionable the demands of modern AI and unreality applications. With implicit 60 AI regions, 500,000+ miles of fiber, and much than 4 petabits per 2nd (Pbps) of WAN capacity, Azure’s backbone is engineered for monolithic standard and reliability. The web has tripled its wide capableness since the extremity of FY24, present reaching 18 Pbps, ensuring that customers tin tally the astir demanding AI and information workloads with uncompromising performance.

In this blog, I americium excited to stock astir our advancements successful information halfway networking that provides the halfway infrastructure to tally AI grooming models astatine monolithic scale, arsenic good arsenic our latest merchandise announcements to fortify the resilience, security, scale, and the capabilities needed to tally unreality autochthonal workloads for optimized show and cost.

AI astatine the bosom of the cloud

AI is not conscionable a workload—it’s the motor driving the adjacent procreation of unreality systems. Azure’s web cloth is optimized for AI astatine each layer, supporting long-lasting, high-bandwidth flows for exemplary training, low-latency intra-datacenter fabrics for GPU clusters, and secure, lossless postulation management. Azure’s architecture integrates InfiniBand and high-speed Ethernet to present ultra-fast, lossless information transportation betwixt compute and storage, minimizing grooming times and maximizing efficiency. Azure’s web is built to enactment workloads with distributed GPU pools crossed datacenters and regions utilizing a dedicated AI WAN. Distributed GPU clusters are connected to the services moving successful Azure regions via a dedicated and backstage transportation that uses Azure Private Link and hardware based VNet appliance moving precocious performant DPUs.

Diagram showing the narration   betwixt  beforehand   extremity  and backmost  extremity  services successful  the unreality

Azure Network services are designed to enactment users astatine each stage—from migrating on-premises workloads to the cloud, to modernizing applications with precocious services, to gathering cloud-native and AI-powered solutions. Whether it’s seamless VNet integration, ExpressRoute for backstage connectivity, oregon precocious instrumentality networking for Kubernetes, Azure provides the tools and services to connect, build, and unafraid the unreality of tomorrow.

Resilient by default

Resiliency is foundational to Azure Networking’s mission. We proceed to execute connected the extremity to supply resiliency by default. In continuing with the inclination of offering portion resilient SKUs of our gateways (ExpressRoute, VPN, and Application Gateway), the latest to articulation the database is Azure NAT Gateway. At Ignite 2025, we announced the nationalist preview of Standard NAT Gateway V2 which offers portion redundant architecture for outbound connectivity astatine nary further cost. Zone Redundant NAT gateways automatically administer postulation to disposable zones during an outage of a azygous zone. It besides supports 100 Gbps of full throughput and tin grip 10 cardinal packets per second. It is IPv6 acceptable retired of the gross and provides postulation insights with travel logs. Read the NAT Gateway blog for much information.

Pushing the boundaries connected security

We proceed to beforehand our level with information arsenic the apical mission, adhering to the principles of Secure Future Initiatives. Along these lines, we are blessed to denote the pursuing capabilities successful preview oregon GA:

DNS Security Policy with Threat Intel: Now mostly available, this diagnostic provides astute extortion with continuous updates, monitoring, and blocking of known malicious domains.

Threat Intelligence travel  illustration  for Azure DNS information    argumentation

Private Link Direct Connect: Now successful nationalist preview, this extends Private Link connectivity to immoderate routable backstage IP address, supporting disconnected VNets and outer SaaS providers, with enhanced auditing and compliance support.

JWT Validation successful Application Gateway: Application Gateway present supports JSON Web Token (JWT) validation successful nationalist preview, delivering native JWT validation astatine Layer 7 for web applications, APIs, and service-to-service (S2S) oregon machine-to-machine (M2M) communication. This diagnostic shifts the token validation process from backend servers to the Application Gateway, improving show and reducing complexity. This capableness enables organizations to fortify information without adding complexity, offering consistent, centralized, secure-by-default Layer 7 controls that let teams to physique and innovate faster portion maintaining a trustworthy information posture.​

Forced tunneling for VWAN Secure Hubs: Forced Tunnel allows you to configure Azure Virtual WAN to inspect Internet-bound postulation with a information solution deployed successful the Virtual WAN hub and way inspected postulation to a designed adjacent hop alternatively of straight to the Internet. Route Internet postulation to borderline Firewall connected to Virtual WAN via the default way learnt from ExpressRoute, VPN oregon SD-WAN. Route Internet postulation to your favourite Network Virtual Appliance oregon SASE solution deployed successful spoke Virtual Network connected to Virtual WAN.

Providing ubiquitous scale

Scale is of utmost value to customers looking to good tune their AI models oregon debased latency inferencing for their AI/ML workloads. Enhanced VPN and ExpressRoute connectivity, and scalable backstage endpoints further fortify the platform’s reliability and future-readiness.

ExpressRoute 400G: Azure volition beryllium supporting 400G ExpressRoute nonstop ports successful prime locations starting 2026. Users tin usage aggregate of these ports to supply multi-terabit throughput via dedicated backstage transportation to on-premises oregon distant GPU sites.

ExpressRoute representation  shows up   to 400G connectivity.

High throughput VPN Gateway: We are announcing GA of 3x faster VPN gateway connectivity with enactment for azygous TCP travel of 5Gbps and a full throughput of 20 Gbps with 4 tunnels.

High standard Private Link: We are besides expanding the full fig of backstage endpoints allowed successful a virtual web to 5000 and a full of 20,000 transverse peered VNets.

Advanced postulation filtering for retention optimization successful Azure Network Watcher: Targeted postulation logs assistance optimize retention costs, accelerate analysis, and simplify configuration and management.

Enhancing the acquisition of unreality autochthonal applications

Elasticity and the quality to standard seamlessly are indispensable capabilities Azure customers who deploy containerized apps expect and trust on. AKS is an perfect level for deploying and managing containerized applications that necessitate precocious availability, scalability, and portability. Azure’s Advanced Container Networking Service is natively integrated with AKS and offered arsenic a managed networking add-on for workloads that necessitate precocious show networking, indispensable information and pod level observability.

We are blessed to denote the merchandise updates beneath successful this space:

  • eBPF Host Routing successful Advanced Container Networking Services for AKS: By embedding routing logic straight into the Linux kernel, this diagnostic reduces latency and increases throughput for containerized applications.
  • Pod CIDR Expansion successful Azure CNI Overlay for AKS: This caller capableness allows users to grow existing pod CIDR ranges, enhancing scalability and adaptability for ample Kubernetes workloads without redeploying clusters.
  • WAF for Azure Application Gateway for Containers: Now mostly available, this brings secure-by-design web exertion firewall capabilities to AKS, ensuring operational consistency and seamless argumentation absorption for containerized workloads.
  • Azure Bastion present enables secure, simplified entree to backstage AKS clusters, reducing setup effort and maintaining isolation and providing outgo savings to users.

These innovations bespeak Azure Networking’s committedness to delivering secure, scalable, and future-ready solutions for each signifier of your unreality journey. For a afloat database of updates, sojourn the authoritative Azure updates page.

Get started with Azure Networking

Azure Networking is much than infrastructure—it’s the catalyst for foundational integer transformation, empowering enterprises to harness the afloat imaginable of the unreality and AI. As organizations navigate their unreality journeys, Azure stands acceptable to connect, secure, and accelerate innovation astatine each step.

Read Entire Article