Not able to ping vm to vm in hub spoke with azure firewall

Piotr Szustakowski 0 Reputation points
2023-02-05T20:05:40.14+00:00

I have set up hub and 2 spokes using Azure Firewall to route traffic from spoke to spoke. I have set correct route to allow all to all

User's image

this is the only firewall rule I have

In both subnet I have set default route rule to Azure Firewall IP

User's image

there are no NSGs assigned to subnet nor the network interface

Hub is peered with spokes:

User's image

Was testing the setup connecting to 1 vm in spoke vnet and ping to vm in the other spoke but I have got no response.

I am able to ping in the same vnet so OS firewall is not the case.

I was also tried to do connection troubleshoot tool but it ends with status unreachable.

User's image

Supposed to work: should be able to ping spoke to spoke via azure firewall in hub

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
578 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
975 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Piotr Szustakowski 0 Reputation points
    2023-02-21T21:03:13.6333333+00:00

    Managed to fix it myself by enabling "Traffic forwarded from remote virtual network" on peerings setting hub<--->spoke.