Can Only Ping After Setting up Azure VWAN VPN NAT

Danny Chuah 20 Reputation points
2024-04-20T15:36:11.0666667+00:00

I was able to connect 2 Azure Hub in different regions using Azure VPN Gateway,

I was able to establish ICMP and Windows RDP connections between VMs in both regions.

My issue is after introducing ingress NAT in site 1 I can ping from VMs in site 2 using the external mapping IP but can't RDP or access any other open ports. I can still ping and RDP using the non NAT IP i.e. accessing site 1 VMs using the internal mapping IP.

I have an Azure firewall in site 1 that allows ICMP, RDP and port 80 for testing for all traffic originating from a VM in site 2 to VMs in site1 and I can see from logs that traffic is allowed when site 2 VM is accessing site 1 VM using the external mapping IPs.

Am I missing something? Are there any other configuration required for Azure VPN Gateway NAT rules?

Thanks in advance.

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,389 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 35,246 Reputation points Microsoft Employee
    2024-04-22T06:11:59.1366667+00:00

    @Danny Chuah ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I am afraid I did not quite understand your setup here.

    I see you are planning to use NAT feature of VPN Gateway

    • Without understanding what Type and Mode of NAT you are using on either sides, it will be difficult to troubleshoot.
    • What are the original address ranges of both of the sites.
    • Are you using NAT on only one site (site1) or both the sites (site1 as well as site2)
    • I see site1 has Ingress NAT
      • What is the "Internal Mappings" and "External Mappings" for this site?
    • Are you using Static NAT or Dynamic NAT in site1?
    • If you are using NAT in site2 as well, what are the "Internal Mappings" and "External Mappings"?
    • Are you using Static NAT or Dynamic NAT in site2 (if you are using)?

    Cheers,

    Kapil

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful