Hi @KrzysztofChwedynaWellDone-7604,
Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
You informed us you would like to achieve:
Local Network <->s2s<->Virtual Hub<->Pfsense<->VM Azure
Local Network <->s2s<->Virtual Hub<->Pfsense<->Internet
I suggested you can do the routing updates in vWAN -> Hubs-> Route Tables -> Default.
However, adding 0.0.0.0/0 here will not advertise the 0.0.0.0/0 across the VPN/Express Route Tunnel
- You should configure your OnPremises Firewall/VPN device to send 0.0.0.0/0 traffic to Azure Gateway.
- This should be done on the OnPrem side only.
- Once the traffic reaches Azure gateway, then the routes in Route table will make the Gateway forward the traffic to the NVA (Pfsense)
- Refer:
Virtual hub routing preference
About virtual hub routing
How to configure virtual hub routing
Create a Virtual WAN hub route table for NVAs: Azure portal - For a custom NVA, you can refer: Workflow of Custom NVA
You informed you were able to configure this with the below architecture.
Cheers,
Kapil
----------------------------------------------------------------------------------------------------------------
Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.