question

SebSeb-1554 avatar image
0 Votes"
SebSeb-1554 asked GitaraniSharmaMSFT-4262 commented

Filter P2S traffic through Azure Firewall to spokes

Hello !

I'm trying to force all the P2S traffic through azureFirewall to be able to reach spokes vnets.


I have the following topology :
- 1 hub vnet (10.1.0.0/16)with 2 subnets (GatewaySubnet (10.1.1.0/27)/ AzureFirewallSubnet(10.1.2.0/24)) with one vpn gateway deployed and an AzureFirewall
- 1 spoke vnet (10.3.0.0/16)with one subnet 10.3.1.0/24 (one ubuntu vm connected to that subnet)
- AzureFirewall private ip address : 10.1.2.2/32
- P2S pool : 172.10.0.0/24

  • 1 UDR associated to the GatewaySubnet with the following routes

--> 10.3.0.0/16 next hop 10.1.2.2 (AzureFirewall)
--> 172.10.0.0/24 next hop 10.1.2.2 (AzureFirewall)

  • 1 UDR associated to the spoke vnet with the following route:

--> 0.0.0.0/0 next hop 10.1.2.2 (AzureFirewall)

I set on the firewall an network roule with Any to Any allow (for debug purposes).

When connected by using P2S, i'm not able to connect to the vm inside the spoke vnet using ssh and nothing shown in firewall logs.
When disassociating the UDR on the GatewaySubnet, i'm able to ssh the vm.

I'm not able to understand why nothing related to ssh is visible on the firewall logs.
The behavior is exactly the same by using a virtual wan (and for cost purposes, vWan is not possible in my case).

ANy help appreciated


azure-vpn-gatewayazure-firewall
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @SebSeb-1554 ,

Apologies for the delay in response.

Could you confirm if you have configured/enabled forced tunneling for your P2S clients?
Refer : https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-p2s-advertise-custom-routes#forced-tunneling

Regards,
Gita

0 Votes 0 ·

1 Answer

SebSeb-1554 avatar image
0 Votes"
SebSeb-1554 answered GitaraniSharmaMSFT-4262 commented

Dear @GitaraniSharmaMSFT-4262 ,

I finally make it working by playing with the UDR :)

Thanks for your help!

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello @SebSeb-1554 ,

Thank you for the update. Glad to hear that it worked.

Regards,
Gita

0 Votes 0 ·