Is it possible to connect the internet in vpn gateway forced tunneling

대진 최 0 Reputation points
2025-11-14T04:44:49.64+00:00

Hello, I deployed VM, VPN Gateway and Azure Firewall in virtual networks.

The subnet to which the VM belongs has a UDR set up, so all traffic is sent to the Azure Firewall. (0.0.0.0/0 -> NetworkVirtualAppliance[Firewall Private IP])

Azure Firewall has Management NIC, so I did UDR set up, in Management Subnet it sent to Internet. (0.0.0.0/0 -> Internet)

Azure Firewall Subnet sent to Virtual Gateway (0.0.0.0/0 -> VirtualNetworkGateway).

These settings are based on information from the official MS documentation. (https://learn.microsoft.com/ko-kr/azure/firewall/forced-tunneling)

Both Azure Firewalls are all allow the traffic from port 80, 8080, 443, 3389, 1433 by network rule.

The VPN gateway was connected site-to-site(so VPN Gateway Connection has Local Network Gateway) and BGP was enabled, It has Custom UDR for Private Network Routing(both).

I also followed the steps outlined in the official MS documentation to configure forced tunneling.

(https://learn.microsoft.com/ko-kr/azure/vpn-gateway/site-to-site-tunneling)

The final network traffic flow I derived is as follows:

HUB VM -> HUB FIREWALL ->(HUB/ONPREM) VPN GATEWAY -> ONPREM FIREWALL -> INTERNET

and

HUB VM -> HUB FIREWALL ->(HUB/ONPREM) VPN GATEWAY -> ONPREM FIREWALL -> PRIVATE WEB SERVER

At this moment, Private Routing successfully works, but the Internet is not working.

What went wrong?

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.