Azure Site-2-Site VPN suddently has disconnected

Stephan Meyhoff Süberkrüb 20 Reputation points
2024-09-11T09:31:33.8033333+00:00

Hi

We have multiple customers with Site-2-Site VPN connection between Azure and their Offices. Today all of the sudden multiple customers complains that they can't reach resources in Azure. We can see that the VPN has been disconnected and is not getting back up.

A customer with multiple locations can have some VPN running just fine, and some are down. All are created the same way in Azure and in the on-prem firewalls, which all are the same model and firmware version.

I have tried to recreate the connection in the firewall and in Azure, but it just won't come up again. I can not find any status stating that there should be any problems, so do anyone else experience this issue, or have any idea how to troubleshoot this issue?

We are using West Europe as location
VPN has been created with SKU Basic or VpnGw1
Firewall is FortiGate or Zyxel

I have tried to run the VPN troubleshoot on 1 tenant with the following result for the Virtual Network Gateway which says Unhealthy:
Summary: Your VPN connectivity is impacted because the S2S VPN tunnels are disconnected
Detail: The S2S VPN tunnels could not connect because of IKE or connectivity issues

Also the connection in question in this tenant shows the following error/warning in Azure:
The connection cannot be established because the other VPN device is unreachable. If the on-premises VPN device is unreachable or not responding to the Azure VPN gateway IKE handshake, the VPN connection cannot establish.

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,803 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
    2024-09-12T06:05:23.77+00:00

    @Stephan Meyhoff Süberkrüb ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    From your verbatim, I see that there was a VPN Disconnect across connections and issue has been resolved now.

    Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others", I'll repost your solution in case you'd like to "Accept" the answer.

    Issue:

    VPN Disconnection across different locations/devices and issue has been resolved now.

    Observation:

    • Per the notification,

    The connection cannot be established because the other VPN device is unreachable. If the on-premises VPN device is unreachable or not responding to the Azure VPN gateway IKE handshake, the VPN connection cannot establish.

    As next steps,

    Kindly let us know if this helps or you need further assistance on this issue.

    Thanks,

    Kapil


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.