Use Azure as transit between site connected to Express route and SASE cloud

slacky 0 Reputation points
2023-02-02T23:45:25.7066667+00:00

Is it possible to use Azure as a transit between two sites connected to Azure via express route and an SDWAN cloud connecting via DTLS tunnel from a NVA firewall to cloud.

The hub vnet has route table with default route pointing at the firewall NVA LAN side with IP forwarding configured.

What is the best way to have sites A and B (connected to Azure with express route) communicate to site C and D using Azure as transit.

Can this be done with simple UDR routes or do I need a route server?

Appreciate your support

Thanks

Slacky

Blank diagram - Page 4

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,142 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
323 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 35,001 Reputation points Microsoft Employee
    2023-02-03T05:18:10.2333333+00:00

    @slacky

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to know if you could use Azure as a Transit between your OnPrem Sites.

    I believe you should go ahead with Route Server for the above configuration to work.

    Wrt SiteA and SiteB,

    Consider, ExpressRoute Global Reach

    User's image

    User's image

    San Francisco as SiteA, London as SiteB and 10.0.3.0/24 as Azure.

    In case you want Site A and Site B to directly talk with each other, you can go ahead with ExpressRoute Global Reach

    However, should you require connectivity across all the sites A,B,C,D to use Azure as Hub, I suggest you go ahead with Route Server or Virtual WAN (with Branch to Branch enabled).

    Thanks,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.