failover of VPN gateway to next region using Traffic manager / Azure Global Load Balancer.

rrr999 26 Reputation points
2022-11-22T16:07:15.457+00:00

we wanted to achieve failover for VPN from P2S and S2S to the secondary region in the event of the primary region being down, can it be achievable using traffic manager DNS load balancing (or) Global Azure Load Balancers (L4)? at the moment we don't want to opt for VWAN. Would like to seek some suggestions.

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,362 questions
Azure Traffic Manager
Azure Traffic Manager
An Azure service that is used to route incoming network traffic for high performance and availability.
110 questions
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
397 questions
0 comments No comments
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 34,601 Reputation points Microsoft Employee
    2022-11-23T13:23:07.523+00:00

    Hi @rrr999 ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
    I understand that you would like to know about failover of Azure VPN gateway from one region to another.

    Apologies for the delay, as I was doing a lab to replicate your requirement

    For P2S, I don't think the above solution would work. You will be required to manually switch to the other VPN gateway's FQDN
    Refer to this thread: Azure VPN with Azure Traffic Manager

    However, for a S2S, we would only require the IP of the VPN gateways.
    So, you should be able to configure a load balancing solution such as Traffic Manager to get this achieved.

    By Global Load Balancer, I believe you are referring to the Cross-region load balancer

    • You will only be able to add a Load Balancer behind a Cross-region load balancer
    • You will not be able to add a Public endPoint or a PaaS service behind a L4 Load Balancer.
    • So, using a Load Balancer might not suit your requirement

    With Traffic Manager, make sure you use Priority based routing so that the Primary Region is always prefered

    You can consider using Zone Redundant VPN gateways for Zonal Failures

    Thanks,
    Kapil

    ----------------------------------------------------------------------------------------------------------------

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.


0 additional answers

Sort by: Most helpful