Express Route Routing Issues (Azure to On-premises route)
Hi @GitaraniSharma-MSFT - We have performed the same setup from this article https://learn.microsoft.com/en-us/answers/questions/860533/express-route-and-azure-firewall)
We have 2 express route premium circuits (East US & South-Central US) with 3 Azure firewalls premium per vNet; 3 Express route gateways (multi-AZ) (per vNet); 6 express route connections to 3 express route gateways (DR setup if incase circuit/region failure).
The identicial 10 prefixes were advertised from on-premises side without "0.0.0.0/0" and 3 virtual networks from Azure side (no hub-spoke approach) to on-premises. Also, outbound traffic of internet from Azure has to go through Azure firewall and not to On-premises.
- Traffic flow from On-Premises to Azure >> Working as expected and passing the traffic through Azure Firewalls as per environment.
- Traffic flow from Azure to On-Premises >> Intermittently working. Example - telnet/psping to on-premises destination on port is working on 1st or 2nd attempts and stuck after 3rd attempt and continues the same behavior for some attempts. It will work back after 10th attempt or so. Also, observed the INVALID flag on firewall traceflowlogs from on premise destination server to FW private IP. However, we need the firewall to filter both inbound/outbound traffic from on-premises and internet side.