azure vpn gateway bgp nat apipa

56789 5 Reputation points
2024-02-09T21:17:49.7366667+00:00

Hello, I have a two site to site vpn connection. Connection 1: Client A (Onprem DC with Palo alto) - Azure Vpn GW A. This is a route based vpn with bgp enabled on apipa. Connection 2: Vendor A (Vendor DC with Fortigate) - Azure Vpn GW A. This is a route based vpn with bgp enabled on apipa. VPN gw: VpnGw2 Requirement: 1)To create connection 3: Vendor B(Vendor DC with Palo) - Azure Vpn GW A. This will be route based vpn with bgp enabled on private ip. Can we use NATS on connection 3?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,543 questions
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 26,201 Reputation points Microsoft Employee
    2024-02-12T20:42:48.9033333+00:00

    @56789

    Thank you for getting back and sharing the additional details above.

    can you confirm if nat will work on connection 3 which will have private bgp ip at onprem and on azure vpn gateway. Since i want to do NAT only on connection 3,will NAT work on connection 3?

    The answer is Yes. As you are using a non-APIPA IP address to establish BGP peering, I think you should able to use NAT for the connection 3.

    If it helps just adding few points below for support/consideration for your scenario here

    • NAT is applied to the connections with NAT rules. If a connection doesn't have a NAT rule, NAT won't take effect on that connection. On the same VPN gateway, you can have some connections with NAT, and other connections without NAT working together. This is documented here
    • NAT is supported on the following VPN SKU VpnGw2~5 and VpnGw2AZ~5AZ.
    • Before you establish connection 3, you must create and save NAT rules on the VPN gateway. More information on the implementation can be found here.

    Hope this helps! Please let me know if you have any additional questions. Thank you!


    ​​Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.