Configuring a Second VPN Tunnel on Firewall for Azure Environment

Afram Vannessa 0 Reputation points
2024-12-11T14:39:00.46+00:00

I have added a second ISP in my network and need to create a second VPN tunnel on the firewall for the Azure environment. How can this be done? Additionally, I do not have the password, and will there be any charges incurred on Azure for this setup?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,593 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Ganesh Patapati 2,590 Reputation points Microsoft Vendor
    2024-12-13T19:17:10.9166667+00:00

    Hello Afram Vannessa

    We appreciate your patience!

    As previously mentioned, you can create a second VPN tunnel on the firewall for the Azure environment, based on your supported firewall configuration.

    Validated VPN devices and device configuration guides

    In partnership with device vendors, we have validated a set of standard VPN devices. All of the devices in the device families in the following list should work with VPN gateways. These are the recommended algorithms for your device configuration.

    Refer: https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices#devicetable

    Please review your firewall settings to ensure they align with the configurations outlined in the document.

    Pre-Shared Key

    The pre shared key is unique to each VPN connection and is configured in the Local Network Gateway settings in Azure. If you do not have the PSK, you can create a new one in the Azure portal when establishing the connection. Ensure that the Fortigate configuration is updated with the new PSK.

    Q. About the price? I see in the invoice there is fee for Leasing the IP address and another for Networking/VPN Gateway Basic.

    VPN Gateway Charges:

    • The cost for the VPN Gateway is based on the SKU you choose (e.g., Basic, VpnGw1, etc.). The Basic SKU is typically the least expensive option, but it will be retiring in 2025, I recommend updating it to the standard.

    Leasing IP Address:

    All Instance level public IP addresses are charged depending on what type of IP address you use:

    11565-ip-address-pricing.png

    More information here:

    Public IP Address pricing

    https://azure.microsoft.com/en-us/pricing/details/ip-addresses


    Hope this clarifies!

    If above is unclear and/or you are unsure about something add a comment below.

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    Regards,

    Ganesh


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.