S2S VPN & Express route with Azure Firewall in the middle

RL 20 Reputation points
2024-12-05T12:48:14.9066667+00:00

Dear All,

I've a setup with a S2S vpn to reach on-prem ressource and UDR on vnet to force the traffic to use Azure Firewall (on hub subscription).

Recently we've configure express route circuit to replace the S2S vpn. Express route circuit & ER virtual network gaetway has been created on a new vnet (different of S2S FW and VPN Gateway).

Now, we would like migrate the traffic to express route circuit but we would like to keep the existing Azure firewall in place, but how to "connect" the Azure firewall to the ER circuit as they are on different vnets ? With vnet peerings ?

Thanks

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
399 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Ganesh Patapati 2,590 Reputation points Microsoft Vendor
    2024-12-05T15:36:45.6533333+00:00

    Hi RL

    Greetings!

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    Yes, your observation is correct. With the help of VNet peering, you will be able to establish a connection.

    1. Set up VNet peering between the VNet that contains the Azure Firewall and the VNet that contains the ExpressRoute Gateway. This allows resources in both VNets to communicate with each other.
    2. Ensure that you enable "Allow forwarded traffic" on the peering settings of the VNet that contains the Azure Firewall.
    3. After establishing VNet peering, you will need to configure the User Defined Routes (UDRs) in the VNet that contains the resources you want to route through the Azure Firewall.

    Please refer to the information below regarding virtual network traffic routing with (UDRs):

    Refer: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview

    Using VNet peering is a valid and effective way to connect your Azure Firewall to an ExpressRoute circuit when they are in different Vets.


    Hope this clarifies!

    If above is unclear and/or you are unsure about something add a comment below.

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    Regards,

    Ganesh


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.