Filter traffic from a site-to-site vpn with virtual hub, vwan and Azure firewall.

Edwin Omar Fonseca Padilla 65 Reputation points
2023-10-19T20:02:28.26+00:00

I have implemented a virtual hub, vwan and azure firewall, I need the traffic coming through a vpn site to site to be filtered by azure firewall.

I am not sure how to configure it, but I have checked in microsoft documentation and I see that I could solve it with the routing intent and routing policies.

I used the default route and added the vpn network address as example 172.16.34.0/24 and set as the next hop the Azure firewall ip, however, the test did not work for me.

Please send us your comments.

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
188 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
567 questions
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
84 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 35,001 Reputation points Microsoft Employee
    2023-10-24T03:16:23.7033333+00:00

    @Edwin Omar Fonseca Padilla

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    • You informed you are using secured vHub,
      • With routing intent, you do not have to manually configure any route
    • Go to the Firewall Manager, select Virtual hubs.
    • Select your Secured vHUB
    1. Under Settings, select Security configuration
    2. Under Private traffic, select Send via Azure Firewall
    3. Under Inter-hub, select Enabled to enable the Virtual WAN routing intent feature. Routing intent is the mechanism through which you can configure Virtual WAN to route branch-to-branch (on-premises to on-premises) traffic via Azure Firewall deployed in the Virtual WAN Hub. For more information regarding prerequisites and considerations associated with the routing intent feature, see Routing Intent documentation.

    Refer : Route traffic to your hub

    You informed the traffic coming from the VPNs is now filtered by Azure Firewall.

    Cheers,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful