Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.1.2. Subnet Design Patterns

Subnets segment your VNet for organization, security, and service requirements. Some Azure services require dedicated subnets with specific names.

Required Dedicated Subnets:
Subnet NamePurposeMinimum Size
GatewaySubnetVPN/ExpressRoute gateways/27 (recommend /26)
AzureFirewallSubnetAzure Firewall/26
AzureFirewallManagementSubnetFirewall forced tunneling/26
AzureBastionSubnetAzure Bastion/26
RouteServerSubnetAzure Route Server/27
Subnet Design Decision Tree:

Subnet Delegation: Some PaaS services require subnet delegation, which grants the service permission to inject resources into your subnet.

ServiceDelegation RequiredWhat It Does
Azure Container InstancesYesInjects containers
Azure App ServiceYesVNet integration
Azure SQL Managed InstanceYesDeploys managed instance
Azure NetApp FilesYesStorage injection
Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications