Configuring route based VPN using virtual WAN
For a route-based VPN I would typically see config for a VTI, I don't see that anywhere in the virtual wan config for this so im not sure what the IP address of my VTI should be on the other end.
Azure VPN / Vhub P2S Advertised routes troubleshooting
Good afternoon all, I am having some issues with a VPN P2S i have set up within a vHub, whereby the Azure VPN client is not populating the custom advertised routes listed in the Default route table, and thus the traffic is not routing correctly unless i…
BGP sessions over dual VPN Ipsec tunnels only work on Instance 0, Instance1 stays in connecting status, resulting in lost packets
Standard dual-path VPN from Virtual WAN hub to single virtual FortiGate with two public IPs in AWS, using BGP routing. Azure side shows only half of the BGP paths connected (ones related to Instance0 via both VPN tunnels) while virtual FortiGate in AWS…
Using BGP peering with Azure route server for hub and spoke model vs Azure VWAN
Our scenario - We have two separate environments setup on Azure as below: 1. Hub and spoke model with third party NVA connected to on-prem with ExpressRoute connection 2. Azure Virtual WAN integrated with Azure firewall, connected to on-premise…


Express Route and VPN together
Our scenario: We are planning to use Express Route, VWAN integrated with Azure Firewall in East US (primary site) and West US (secondary/DR site) and we will be connecting the on-premise data center with Express Route. Questions: If we are using the…


How many public IP addresses can be attached to a FortiGate NVA deployed in Azure VWAN?
The team is deploying a FortiGate Firewall as a Network Virtual Appliance (NVA) in Azure VWAN architecture. The FortiGate firewall will serve as a centralized firewall to inspect traffic from other subscription VNets. Additionally, there is a need to…
is Microsoft peering supported on vwan express route circuit and VNG ?
There is no mention of MS public peering on vWAN documentation. So trying to figure out. does vWAN express route support MS peering (to inject MS public IPs into on-prem Networks connected via express route circuit MS peering). If this is supported…
Virtual Network having Azure Bastion peered with vWAN Hub
Following is the Scenario. Would like to connect Spoke virtual network which has Azure Bastion resource to Azure Virtual WAN. As per Bastion FAQ, we need to disable default route propagation at 'virtual network connection' level when we do virtual…
clarification on "bypass next hop ip for workloads within this vnet"
I am referring to the diagram attached (which is taken from Azure doc - route through an NVA) Here is my understanding of the routing : The 10.20.0.0/24 VNET is going to propagate the route to HUB default route table. This route will have a longer…
Question on Azure Virtual WAN w/ P2S Configuration
I'm in the process of looking at and building out an Azure Virtual WAN. Before doing this, I have previously tested creating an Azure Virtual Network Gateway and successfully connected via a standard Site-to-Site VPN tunnel as well as Point-to-Site…
Virtual Hub - VPN Gateway - IKE Lifetime
Hello, In a custom IPsec configuration there is only one lifetime setting defined as: 'SA Lifetime in seconds' - I understand this is the Phase 2 lifetime from the description. What is then the lifetime for the IKE Phase 1 tunnel ? How can I check these…
Azure Network Connectivity Issue between vWAN and VPN Gateway
Good day, Azure community I’m facing network connectivity issue with my current setup, I can’t ping between two Azure VMs (native vm) the network setup as following: 2x VMs each VM on different vNet, (vNet1=10.194.0.0/24) & (vNet2=10.1.0.0/24) …
How to backup the existing config in VHUB and VPN sites to be restored?
Hello, I need some guidance on how to fully export the existing config of a virtual wan resource with its virtual hub and vpn sites already configured, and a clear mechanism in how to use those templates to restore the config in case of any human error…
Automating IPSec Connections: Retrieving vWAN Hub Public IP with Terraform
I want to implement a Terraform module to create an IPSec connection between a vWAN Hub and my on-premises site. To automate this process, I need to retrieve the public IP address of the vWAN Hub. Is it possible to retrieve the hub's public IP using…
We have an Azure Virtual WAN deployement secure by Azure Firewall High Availability
Do i understand correctly that everthing inside virtual WAN is deployed automaticaly in Availability zones? Besides the Azure Firewall components for this you need to redeploy them. https://learn.microsoft.com/en-us/azure/virtual-wan/virtual-wan-faq I…
vWAN - azure verified module for terraform
Description I am trying to use AVM virtual WAN pattern module for terraform using with long variables.tf and local.tf. In order to pass values to object variables in specific object variable I created separate auto.tfvars for the vhub, firewall,…

How do we resolve ConnectionRoutingConfigConflictsWithRoutingIntent Error?
I have a hub virtual network connection with the routing configurations enabled with defaultRouteTable and when we associate this connection with a Secured Virtual WAN Hub (routing Intent Enabled), the error observed is…
How to create an effective route for Virtual HUB with type VPN_S2S_Gateway with out AS PATH field
Hi, We are trying to recreate a situation we saw previously on our system, which is inside the effective routes of a Virutual HUB with Azure Firewall and Routing Intent enabled. The case was an effective route in the default routing table we had a…
Azure VWan hub to hub connect across two tenants in same region
Hi Team, I have Two azure tenants in same azure region. In both the tenants I have a dedicated Azure VWAN with one hub in it. I am trying to connect this two hubs across tenant so resources under both hub's spoke can talk to each other. I am not able to…
Cross Tenant Network integration over Azure VWAN in same Azure region
I have Two azure tenants in same azure region. In both the tenants I have a dedicated Azure VWAN with one hub in it. I am trying to connect this two hubs across tenant so resources under both hub's spoke can talk to each other. We found that Azure…