Hub and two Spoke vnets with AFW in Hub and traffic from Expressroute

Sepski, Krzysztof Antoni 20 Reputation points
2024-09-18T08:55:52.09+00:00

Hello,

I have got problem with not going traffic via Azure Firewall from ExpressRoute to one of two spoke vnets(I don't see any traffic on Firewall logs but I can see traffic with tcpdump on VM in spoke). Traffic to on-prem via ExpressRoute works fine from both spoke vnets(and I can see logs in Firewall)
Could You please provide me with exemplary configuration how to set UDRs?
I already set on GatewaySubnet UDR - prefixes of two spokes(tried also one wide mask) via Firewall, on both Spokes UDR - prefixes of on prem subnets via Firewall and can't find any solution.

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
660 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,425 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
369 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 44,691 Reputation points Microsoft Employee
    2024-09-18T11:56:28.9233333+00:00

    @Sepski, Krzysztof Antoni ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to use Azure Firewall as NVA for traffic to and fro OnPrem via ExpressRoute.

    From your verbatim,

    • Azure to OnPrem traffic passes via the Firewall
    • However, OnPrem to Azure traffic does not
    • Ideally, defining the Address space of the SpokeVNETs and nextHop as the Firewall's private IP should do the trick
      • See a similar set up here
    • Can you confirm Propagate gateway routes is set to "Enabled"?
    • May I ask if you are testing this by initiating traffic from OnPrem to the Azure?
      • Or you are worried that you are not seeing return traffic for Azure to OnPrem testing
    • Can you specify if you are using ExpressRoute FastPath?

    Cheers,

    Kapil


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.