Why have one layer of NAT when you can have four or five? Why not invent a bespoke addressing scheme? Why not cargo cult the documentation and/or scripts and config files from Stack Overflow or ChatGPT?
Under-engineering is an easier problem to solve than over-engineering.
I do find Azures implementation of this stuff pretty baffling. Just in, networking concepts being digested by software engineers, and then regurgitated into a hierarchy that makes sense to them. Not impermeable, just weird.
It's not hard, but it is a little bit different and there is a small learning curve to deploying it in non-trivial environments.
A superior alternative to DNS would help a lot, but getting adoption for something at that level of the stack would be very hard.
DNS just tends to be part that is visible to random desktop user when things fail
Depends on the network. If you are talking about a branch office, for sure.
>I find that a lot of "it's always DNS" falls down to "I don't know routing beyond default gateway"
I see it mostly with assumptions. Like DNS Server B MUST SURELY be configured the same as DNS Server A, thus my change will have no unexpected consequences.
I would say situation also changes a lot if you know/can deploy anycast routes for core network services - for example fc00::10-12 will always be recursive nameservers, and you configure routing so that it picks up the closest one, etc.
Yeah, we are kinda like that. So many toys...why can't I use them all.
Seriously, tho...the worst is when you go in and you can tell immediately "oh, the guy running this is trying to get his CCIE cert", because there's all sorts of weirdness you'd never/rarely do in a prod network, but it's on the cert test so lets try it out. YOLO!
But yeah, really nice guy but unable to expand beyond that paradigm.
I once helped him deal with a fibre ring, where there were 5 sites in the ring, but only 2 internet services. So sites 3, 4 and 5 had to communicate via sites 1 and 2.
His team had put a sophos firewall, with NAT, and no routing, on every fibre connection and called me when it didnt work.