Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
Looking at the screenshots, it appears they are related to the 3rd party (FortiGate).
While the community members at Q&A may have expertise over Azure products, the same cannot be said for 3rd party solutions.
I would suggest you to reach out to the third party's support team or community to get more insights into this.
Wrt the Azure VPN Gateway configuration,
- I take it that the OnPrem address range is "192.168.16.0/24"
- And you are using a FQDN as remote IP Address (Modem's IP)
- These look fine
Only thing I find confusing is
- "non-routable IP address 1.XXX.XXX.XXX"
- Can you please elaborate - as this could be some term related to the 3rd party
- If so, you can ignore the consecutive points
- However, by "non-routable" if you mean this IP cannot be reached over Internet
- Then how will Azure be able to establish a S2S Connection ?
- Note that the S2S Tunnel is built over Internet and we expect the FQDN to be resolvable and the resolved remote IP Address reachable over Internet.
The best way to verify this would be to
- Have a planned maintenance and try the failover
- You can leverage the Azure VPN Gateway diagnostic logs, especially "TunnelDiagnosticLog" and "IKEDiagnosticLog" to understand if there are any issue
Hope this clarifies
Cheers,
Kapil.