P2S VPN in Hub

PR 130 Reputation points
2023-08-18T13:45:47.6633333+00:00

We have created Virtual WAN, and added connectivity HUB and Hub has been configured Point to site VPN, now we have multiple VNET's added to HUB. Please let me know whether below scenarios are expected behavior in HUB and why?

1.Once I added VNET into HUB, cant we take RDP with Public IP address ? Note- I have added port -3389, protocol - TCP and Source - Any but not able to take RDP.

2.Even I have deleted RDP rule in security group from VM level NSG, able to take RDP with Private IP address when I connected to P2S VPN? How it is possible.

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
225 questions
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 26,216 Reputation points Microsoft Employee
    2023-08-21T23:03:31.11+00:00

    @PR

    Thank you for getting back.

    As the Virtual Machine has a public IP assigned, when you try to do RDP from your client machine, the traffic will directly go this public IP of the VM, and the return traffic will be directed as per the effective routes of the VM. You can check the effective routes as shown here. If there is route which directs all the traffic from the VM to the firewall in the hub, then this outgoing RDP packet will be directed to the firewall, and it will block the communication as per the rules set.

    I think the RDP communication should work if you can add a route to your VM which allows the outgoing RDP traffic directly to the internet unless if there is any other NSG which is not blocking this connectivity. You can use IP flow verify tool to diagnose any NSG issues. Just to clarify if you set such routing rule, the RDP traffic will bypass the firewall and this is not recommended as it is not secure.

    Based on your statement above

    2.Even I have deleted RDP rule in security group from VM level NSG, able to take RDP with Private IP address when I connected to P2S VPN? How it is possible.

    This is more secure way of establishing RDP session with your VM, as VPN provides additional security. Even when you deleted the RDP rule, the RDP session was not interrupted as the communication happens over private network and there is a default NSG rule (screenshot below) which allows communication between VirtualNetwork service tag. This service tag includes all Virtual network address space (all IP address ranges defined for the virtual network), all connected on-premises address spaces.

    User's image

    Hope this helps. Please let me know if you have any concerns or queries. Thank you!


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.