Home > Storage > PowerFlex > White Papers > Dell APEX Block Storage for Azure: PostgreSQL Deployment and Performance on Kubernetes > Network architecture
The following figure shows the network architecture for Dell APEX block storage deployed in a multi-AZ within Azure region.
In this setup, APEX Block Storage for Azure is deployed with one Virtual Network across three availability zones within the single Azure resource group with one subnet. All Dell APEX Block Storage components use private Ip addresses. Network Security groups are created for Azure VM instances to provide an additional layer of security and control over inbound and outbound traffic at the subnet level.
We use Azure LB (LoadBalancer) for PFMP only to load balance traffic inside a virtual network. A network address translation (NAT) gateway is configured in the public routing table to enable access to the Azure VM instances in the public subnet over the Internet.
The Azure Network Watcher provides a visualization of the entire network for understanding Dell APEX Block Storage network configuration as shown in the following figure:
The following figure shows the Azure Network Watcher Load Balancer topology for PFMP: