@SadiqhAhmed-MSFT Thank you for following up.
I am after a solution to perform,
"VM Test fail over to a Test fail over subnet” (a preferred subnet in Test fail over Virtual Network) when VM is being re-protected back in primary location (zone1) after VM failed over to secondary location (zone2),
*Test fail over Virtual Network is different virtual network to the source/target virtual network. It has multiple subnets.
- Test fail over subnet is not the first subnet in the “Test fail over Virtual Network”. A small sub range of IP address.eg: 3<sup>rd</sup> subnet in Test fail over Virtual Network.
Scenario:
Before Fail over:
VM - in Primary location Zone1, protected in Zone2.
*Source Network : vnet3 / subnet1
*Target Network : vnet3 / subnet1
- Test Fail over network: vnet1 / subnet3
As there is an option to pre-configure preferred test fail over network in "replicated items" available, we can pre-configure "Test fail over target subnet" to a "preferred subnet". Subnet can be any subnet in a Virtual network (Virtual Network can be any network other than the source virtual network).
-> This is working when VM is in primary location (before fail over initiated and re-protected back).
-> After pre-configuring, we can initiate test failover and test VM’s NIC connect to vnet1 / subnet3 as expected.
-> As we can control the inbound and outbound traffic on that subnet(vnet1 / subnet3) we can do test fail over any time without impacting the production system (Note: While VM is in primary location -Zone1). A convenient capability to run test failover any time.
After Failed over and Re-protected
VM - in secondary location Zone2, protected back in Zone1,
*Source Network : vnet3 / subnet1
*Target Network : vnet3 / subnet1
- Test Fail over network: I want to use vnet1 / subnet3 as "Test fail over target subnet" as it has necessary FW rules configured (Security Group) to block inbound and outbound traffic.
This is not possible in "replicated items" -"Network" page while VM is protected back in primary location. Previously configured setting for test fail over (subnet) is missing now and not inheriting from pre-failover replicated items config. I understand why we must reconfigure the Test Fail over network, but we can't save any changes in "replicated items" -"Network" page after VM re-protected back in primary zone (zne1) even for test fail over settings.
Also, while executing test fail over, there is no option to select subnet after selecting the virtual network. If I select virtual network vnet1 – Test Fail over successfully completing but test VM’s NIC is connecting to vnet1 /subnet1 not to vnet1/subnet3. No inbound or outbound traffic blocked for vnet1/subnet1. In this situation there is conflict as Test Failed over VM running in Zone1 is reachable from production network.
Is this a limitation of the product or I am missing something or test fail over network can be configured using CloudShell commands?
Why a capability available to run failover test with a preferred subnet while VM in primary location ( in source zone without impacting application availability) is not available when failed over VM is running in secondary location -failed over zone?