Azure Virtual Wan with S2S VPN tunnel and Express Route

Steven J. Williams 25 Reputation points
2023-02-08T00:05:07.03+00:00

I currently have a virtual wan with a single hub that has connectivity of Express route and S2S vpn. The site to site vpn terminates to my on prem Palo Alto and my express route circuits come into my Datacenter switches and peers BGP with my core switches and those switches peer iBGP with my Palo Alto. The issue I am seeing is my Palo Alto is preferring S2S VPN tunnel routes over my express route. How can you use S2S vpn tunnel as back and not actively advertise routes over it until Express fails or how can make advertised routes over VPN tunnel look less preferred?

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
323 questions
{count} votes

Accepted answer
  1. Luke Murray 10,526 Reputation points MVP
    2023-02-08T03:10:31.4333333+00:00

    Try making the routes for the express route a bit more specific then the S2S routes.

    Also, take a look at the local preference:

    "The default local preference of the CE routers and firewalls in our on-premises setup is 100. So, by configuring the local preference of the routes that are received through the ExpressRoute private peerings greater than 100, we can make the traffic that is destined for Azure prefer the ExpressRoute circuit."


1 additional answer

Sort by: Most helpful
  1. Steven J. Williams 25 Reputation points
    2023-02-09T15:03:21.3133333+00:00

    The ultimate issue was, even after setting local pref, was an incorrect vnet peering to both Virtual Wan Hub and third-party vendor firewall vnet. Thanks for the help.