Cannot ping on-prem servers on other side of on-prem RRAS server from Azure vms on S2S VPN

Jay Jackson 21 Reputation points
2022-11-30T23:28:50.393+00:00

Cannot ping on-prem servers on other side of on-prem RRAS server from Azure vms over S2S VPN.

I can ping the RRAS server fine from Azure vms, but not other servers beyond it. I have a static route set on the on-prem RRAS server (a dedicated W2019 server) which allows for communication from Azure vms to on-prem servers, but the on-prem servers cannot respond. The NIC of the RRAS server is 172.1.1.9 (connected to the on-prem network).

Firewall rules are okay. What did I not do?

265932-screen-shot-2022-11-30-at-61722-pm.png

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,375 questions
Windows Network
Windows Network
Windows: A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.Network: A group of devices that communicate either wirelessly or via a physical connection.
645 questions
Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
512 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2022-11-30T23:43:39.647+00:00

    Shouldn't need the static route.
    https://www.dell.com/support/kbdoc/en-us/000118763/configuring-windows-server-2012-r2-as-a-router

    here's one I used a while back (but not anything to do with azure)

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    265808-image.png

    265760-image.png


  2. Limitless Technology 43,926 Reputation points
    2022-12-02T11:56:08.587+00:00

    Hello there,

    If Ping fails. It can be for many reasons, you can check your on-premise VPN device the tunnel is up and running or not, but probably you need to check the Azure VPN gateway status. If this is also running fine then we need to dig more into it and will have to pull logs to verify and everything.

    And if possible, could you check by disabling your security appliance and connecting your on-premise to your Azure VNet directly using S2S. Also, though ICMP should work while connected via a VPN Gateway, it is suggested to use port pings instead of ICMP to test Azure VM connectivity.

    Also, you can check whether the Local network is defined properly.

    -------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept it as an answer–

    0 comments No comments

  3. msrini-MSFT 9,256 Reputation points Microsoft Employee
    2022-12-04T14:26:28.17+00:00

    Hi,

    I would suggest you to check if the Site to site is UP. If the tunnel is UP, then initiate ping and perform a packet capture on both ends and see if the ping is even reaching the other end. If it does and response is not reaching Azure, then check the Rras routing.

    If it's other way around that ping is dropping at Azure side, then check the effective routes of your VM and see if you can find the on-Prem routes to VPN gateway.

    Regards,
    Karthik Srinivas

    0 comments No comments