An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Is it possible to connect the internet in vpn gateway forced tunneling
Hello, I deployed VM, VPN Gateway and Azure Firewall in virtual networks.
The subnet to which the VM belongs has a UDR set up, so all traffic is sent to the Azure Firewall. (0.0.0.0/0 -> NetworkVirtualAppliance[Firewall Private IP])
Azure Firewall has Management NIC, so I did UDR set up, in Management Subnet it sent to Internet. (0.0.0.0/0 -> Internet)
Azure Firewall Subnet sent to Virtual Gateway (0.0.0.0/0 -> VirtualNetworkGateway).
These settings are based on information from the official MS documentation. (https://learn.microsoft.com/ko-kr/azure/firewall/forced-tunneling)
Both Azure Firewalls are all allow the traffic from port 80, 8080, 443, 3389, 1433 by network rule.
The VPN gateway was connected site-to-site(so VPN Gateway Connection has Local Network Gateway) and BGP was enabled, It has Custom UDR for Private Network Routing(both).
I also followed the steps outlined in the official MS documentation to configure forced tunneling.
(https://learn.microsoft.com/ko-kr/azure/vpn-gateway/site-to-site-tunneling)
The final network traffic flow I derived is as follows:
HUB VM -> HUB FIREWALL ->(HUB/ONPREM) VPN GATEWAY -> ONPREM FIREWALL -> INTERNET
and
HUB VM -> HUB FIREWALL ->(HUB/ONPREM) VPN GATEWAY -> ONPREM FIREWALL -> PRIVATE WEB SERVER
At this moment, Private Routing successfully works, but the Internet is not working.
What went wrong?