Also a newb at this, but have you looked at the firewalls on the nodes themselves?
I think VNets and the SDN stuff needs groups, pools, permissions, etc. to push the firewall config to a node.
Turn your logs on and start dropping less and widening subnets til it works, then work backwards.
"...