ExpressRoute and FortiGate BGP Issue in a Azure Virtual WAN
Good evening. We have deployed an Azure virtual WAN with a secured hub. The Azure virtual WAN has a VPN and ExpressRoute gateway deployed. The Azure virtual WAN routing preference is configured as ASPATH. All internet and private traffic is routed…
Where can I find Azure (private) DNS / Network limitations and what are their consequences
Hi, some of the azure products form an important part of our infrastructure. There are a few, but most importantly a private DNS zone, a virtual WAN, a virtual network, a MSSQL database, a private DNS resolver, and a couple of VMs for DNS forwarding via…
Virtual Wan Site to Site VPN Tunnel stops working after a couple days
Hello, i have a VPN site-to-site tunel between virtual wan and a fortigate appliance. Both sides show the tunel as UP and Connected, traffic flows in both directions and after a couple days it stops. Local Network: 172.24.8.0/21 Remote Network:…
Vnet peering
Is it possible to peer two vnet in the same region directly along with the vWan peering it already has. I need to make services between the vnet work while resolving vnwan route issues. Adding direct peering while it has a vWan peering should not cause…
Azure Wan VPN Azure Firewall Routing Issue
I have a secured WAN with firewall and routing intent configured (internet and private ) traffic going through firewall. After creating a VPN site and connection to the HUB, i can confirm that the tunnel is UP and i see the on-premise's subnets…
P2S Internet Access with ALZ Architecture (vWan)
I'm doing a POC learning a bit more about Azure vWAN. The infrastructure is based on the ALZ architecture (with minor adjustments). No ER, just using S2S and P2S VPN (only P2S configured at this stage - OpenVPN w/ AAD + address pools). Have a few spokes…
NVA firewalls in availability set, how to prefer one over the other for outbound traffic
I have a standard load balancer sandwich design, with two NVA firewalls in an availability set, with spoke vNets peered to the NVA vNet. UDR's have static routing towards the internal load balancer. it all works well enough I have a requirement to prefer…
Azure route server causes loss of connectivity from on-prem to azure
On prem network connectivity into azure is by means of Cisco SDWAN terminating in virtual wan hub which routes into azure vnets via Palo Alto NVA's. Deploying an Azure route server in the NVA vnet causes loss of connectivity from on prem to azure. Loss…
P2S VPN in Hub
We have created Virtual WAN, and added connectivity HUB and Hub has been configured Point to site VPN, now we have multiple VNET's added to HUB. Please let me know whether below scenarios are expected behavior in HUB and why? 1.Once I added VNET into…
VM Secure access using WAN & HUB(P2S VPN access)
Hello Team, We have created Virtual WAN, and added connectivity HUB and Hub has been configured Point to site VPN, now we have multiple VNET's need to add into HUB. While adding the VNET connections, what is the recommended settings of "Associate…
VM Secure Access from Workstations
Hello Team, We have created Virtual WAN, and added connectivity HUB and Hub has been configured Point to site VPN, now we need to access our VM's which is hosted in different resource groups with Private IP from workstations when we connected to Azure…
China user unable to connect to Point to Site User VPN
Hi All , Have a site of users from china that was not able to connect to the P2S network created in Azure vwan .Need some help on this
Cannot Connect Site-to-site VPN between Azure vWAN and On-premise Zyxel SBG3300-N
I have created Azure virtual WAN then create virtual hub and the create site-to-tie VPN inside the Azure virtual hub. For VPN connection, I am setting IPsec to default but cannot connect to on-premise VPN device Zyxel SBG3300-N. I try to change IPsec…
Virtual WAN
Is it true that Connection between the virtual hub cannot be secured by Azure firewall and only the traffic between the spoke and vhub is secured by Az firewall premium? Or this limitation has been fixed now
VWAN Migration
My client is about doing a POC for VWAN before migration current VNET hub to VWAN. We would like a better explanation and guide. BGP/IPSEC setup between Virtual Wan and on-premises and setting up BGP neighbor. Create second link to on-premises, second…
Vwan and secured hub
Does virtual WAN and secured hub need to be in same subscription? How do we plan for resources across continental regions?
Azure virtual WAN
For a multi-continental region deployment what is the benefit of using - Three virtual WAN with secured hub with two region in each subcontinent over Single virtual WAN with secured virtual hub. Most of the MS docs diagram depicts single VWAN with…
How to manage firewall public ips for secure virtual hub?
Hi all, I've created a virtual hub in my environment, and now I'm trying to make it a secure virtual hub by adding an Azure Firewall instance. For the firewall I want to use two public ips that I have created previously. From looking at the…
One of the IP addresses for the P2S VPN does not work.
I have set up an Azure VWAN, with a P2S VPN gateway, with AzureAD Authentication. This works fine, half the time. Digging into packet captures and for about half the connection attempts we are getting http/400 error returns when attempting to connect to…
Virtual WAN Hub BGP peer limit
I have seen articles calling out the Azure Route Server only supports 8 BGP Peers, but I couldn't find anything specific to Virtual WAN Hub. What is the maximum number of BGP Peers Virtual WAN Hub can support?