Azure Network Advanced Solution

René Braga 0 Reputation points
2023-05-29T18:44:17.7733333+00:00

Hello There, is someone that already redirected the traffic coming by VPN Ipsec to another side by ExpressRoute

The Flow IS ( On-Prem1) <IPSEC>(Azure)<ExpressRoute>(On-prem2)

The traffic From On-Prem1 to Azure Works Fine , and the traffic from Azure to On-prem2 also works,, the last needed solution is the traffic from On-prem1 to OnPrem2 By Azure

thanks in advanced any help

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth 49,846 Reputation points Moderator
    2023-06-06T04:40:31.7933333+00:00

    @René Braga

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    You would like to transit traffic coming from VPN Ipsec to Another site by ExpressRoute

    The Flow IS ( On-Prem1) <IPSEC>(Azure)<ExpressRoute>(On-prem2).

    For this configuration to work, you will be required to enable BGP in the,

    • VPN Connection between OnPrem1 and Azure VPN Gateway
    • Azure ExpressRoute to OnPrem2 (This should be already enabled)

    For a Non - vWAN scenario

    And, also, there are other requirements,

    • If you want to use transit routing between ExpressRoute and VPN, the ASN of Azure VPN Gateway must be set to 65515 and Azure Route Server should be used.
    • For ExpressRoute and Azure VPN to work together, you must keep the Autonomous System Number of your Azure VPN gateway at its default value, 65515

    Refer : Azure Route Server support for ExpressRoute and Azure VPN

    User's image

    For a vWAN scenario

    With Azure vWAN, you can do this directly.

    No need for Azure Route server, but BGP would be required.

    Consider the scenario : Any-to-Any,

    User's image

    Make sure you enable Branch-to-Branch in vWAN's configuration blade.

    Refer: Is branch-to-branch connectivity allowed in Virtual WAN?

    Kindly let us know if this helps or you need further assistance on this issue.

    Thanks,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.