Multiple on-premises VPN devices (two connections - Azure to two Forti)

Jose Luis Rodriguez Soriano 41 Reputation points
2024-05-13T14:11:37.1433333+00:00

I have a virtual network gateway in Azure with two local network gateways and two connections to two isp/firewall destinations in omprem. I have BGP enabled on the virtual network gateway with the ASN and the bgp peer, BGP enabled on the two local network gateways and on the two connections. My question is... should BGP also be enabled on both connections? The connection is established but I do not learn the bgp routes from onmprem and my azure routes cannot be seen from the forti. Thank you so much


Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,554 questions
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 26,216 Reputation points Microsoft Employee
    2024-05-14T23:06:56.1066667+00:00

    @Jose Luis Rodriguez Soriano

    Thank you for getting back and sharing additional details.

    Glad to know that you are able to see the routes from on-prem and azure

    Based on your question above

    My question is, would connection 2 (LNG) be valid with the same bgp peer? for both connections? or would we have to do an active active VNG?User's image

    In the architecture above you will have to create 2 LNGs for each on-prem device. Each LNG will establish connectivity with their specific on-prem device, so in the architecture you described above LNG will be valid with the same BGP peer. As documented here by default, VPN Gateway allocates a single IP address from the GatewaySubnet range for active-standby VPN gateways, or two IP addresses for active-active VPN gateways to use as BGP peer IP

    If you wish to have full mesh connectivity then the active-active scenario should be implemented.

    Hope this helps! Please let me know if you have any additional questions. Thank you!


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.