Azure route server causes loss of connectivity from on-prem to azure

Steven Johnston 40 Reputation points
2023-08-16T12:40:17.19+00:00

On prem network connectivity into azure is by means of Cisco SDWAN terminating in virtual wan hub which routes into azure vnets via Palo Alto NVA's. Deploying an Azure route server in the NVA vnet causes loss of connectivity from on prem to azure. Loss of connectivity occurs precisely when the route server finishes deploying, don't even get the chance to add BGP peerings

Documentation states this..

"When you create or delete a Route Server in a virtual network that contains a virtual network gateway (ExpressRoute or VPN), expect downtime until the operation is complete. If you have an ExpressRoute circuit connected to the virtual network where you're creating or deleting the Route Server, the downtime doesn't affect the ExpressRoute circuit or its connections to other virtual networks."

Would a virtual wan hub connection fall under this caveat? Should i wait longer after deployment for connectivity to be restored?

thanks

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
189 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 35,336 Reputation points Microsoft Employee
    2023-08-18T09:22:53.44+00:00

    @Steven Johnston

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to deploy a Route Server in a VNET connected to a vWAN vHub.

    I checked this internally and our Product Group confirmed this is not a supported scenario.

    Deploying a Route Server into the Spoke VNET will stop the VNET from learning the routes from the Hub.

    I have created a request to update the FAQ section to highlight this here :

    Can a spoke VNet have a Azure Route Server

    If you could let us know the requirement for deploying a ARS into the SpokeVNET,

    • We could try and suggest some alternatives
    • In your case, I believe you were planning to eliminate UDRs and use BGP to route traffic from VNets VNET-1 and VNET-2
    • In this case, based on your architecture, I am afraid we should rely on the UDRs only

    NOTE

    Should there be any follow-up questions or concerns, please let us know and we shall try to address them.

    Thanks,

    Kapil


    Please Accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer.


0 additional answers

Sort by: Most helpful