On-premises expressroute BGP is advertising 0.0.0.0/0 and using Azure Firewall to control traffic (including internet)

romero 125 Reputation points
2024-09-18T03:07:24.1133333+00:00

hi

My environment is an on-premises expressroute BGP is advertising 0.0.0.0/0.

I want to use Azure Firewall to control all traffic (including internet).

See and discuss the architecture picture attached below.

My guess is that we need to send the route “172.16.0.0/16” to the Expressroute gateway from the UDR connected to the Azure Firewall subnet to the on-premises.

But according to the documentation below, you can't set up a UDR to point to the Expressroute gateway.

https://learn.microsoft.com/ko-kr/azure/virtual-network/virtual-networks-udr-overview#custom-routes

User's image

I question if this is possible.

I would like your knowledge or ideas.

Thank you.

Status

  1. On-premises and Azure are connected by an expressroute.
  2. Advertise 0.0.0.0/0 in on-premises BGP.
  3. Azure Firewall forced tunneling disable.

Conditions

  1. All traffic from on-premises passes through Azure Firewall.
  2. Traffic from all virtual networks to on-premises passes through Azure Firewall.
  3. Traffic between all virtual networks passes through Azure Firewall.
  4. Traffic from your virtual network to the internet passes through Azure Firewall.

Problem

  1. Communication between virtual networks is controlled by the Azure firewall.
  2. Communication from the virtual network to the Internet is controlled by Azure firewall.
  3. No communication with on-premises.

이미지 408

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
669 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
379 questions
{count} votes

Accepted answer
  1. Ganesh Patapati 810 Reputation points Microsoft Vendor
    2024-09-23T09:42:53.09+00:00

    Hi romero,

    Thank you for reaching out to us on the Microsoft Q&A forum.

    As an original poster cannot accept their own answer, I am reposting it so that you can accept it an answer. Accepted answer will help other community members navigate to the appropriate solutions.

    Issue: On-premises express route BGP is advertising 0.0.0.0/0 and using Azure Firewall to control traffic (including internet).

    Solution: I'm trying to understand that there is no better way to do this other than to fix it with the correct BGP on-premises and move on.

    Yes, there is a solution to the above concern, so I recommend you correct it from the On-premises end.


    Remember to "Accept Answer" so that others in the community who are experiencing similar challenges can easily find a solution.

    Your contribution is greatly appreciated.

    Regards,

    Ganesh

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.