RoutesTo

Routing fact feeding CanNetworkReach derivation.

network NETWORK nature: explicit not walkable
Route, Subnet, TransitGateway  ── RoutesTo ──▸  Network, Subnet

Target types

NetworkSubnet

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit RoutesTo 16

An enabled AFD routing rule (route) linking a front door endpoint to an origin group with at least one enabled origin is a RoutesTo fact: the AFD route object (generic_type: Route, provider_type: Microsoft.Cdn/profiles/afdEndpoints/routes) routes matched internet requests to that origin resource. This is derived from the explicit normalization rule azure-frontdoor-origin-record.
azurederived
A private or transit Direct Connect Virtual Interface in AVAILABLE state routes the on-premises network into the attached VGW or DXGW, establishing a non-internet routed path from on-prem into AWS private address space.
awsexplicit
A Direct Connect Gateway with an accepted association to a TransitGateway routes on-premises traffic to the TGW and its attached VPCs.
awsexplicit
Azure Firewall DNAT rule (classic natRuleCollections model) is ingested as a synthetic Route node encoding (firewall_id, rule_name). The route is linked to the internal destination subnet via RoutesTo edge.
azureexplicit
Azure Firewall Policy DNAT rule (firewallPolicies/ruleCollectionGroups model) is ingested as a synthetic Route node. The route is linked to the internal destination subnet via RoutesTo edge. Target is the Firewall that references this policy.
azureexplicit
azureexplicit
An active hub VNet connection (hubVirtualNetworkConnections, provisioningState=Succeeded) is an explicit routing fact: the Virtual Hub routes traffic to and from the connected spoke VNet.
azureexplicit
An active S2S VPN connection (vpnConnections, connectionStatus=Connected) is an explicit routing fact: the Virtual Hub routes traffic to and from the on-premises branch via the VPN tunnel.
azureexplicit
An active ExpressRoute connection (expressRouteConnections, provisioningState=Succeeded) is an explicit routing fact: the Virtual Hub routes traffic to and from the on-premises network via the ExpressRoute circuit. NOTE - Semantic Extension: RoutesTo normally targets [Network, Subnet]. On-premises networks may not exist as discrete nodes in the collected inventory if they are not explicitly modeled as Network nodes. In this case, the target is the ExpressRoute Circuit (TransitGateway) representing the on-premises reachability point. The network-chains linchpin must handle TransitGateway targets of RoutesTo as a special case distinct from Network/Subnet targets, treating them as proxies for external networks.
azureexplicit
move · open · esc close