Virtual Wan Site to Site VPN Tunnel stops working after a couple days

Diego Fernandes Spinola Castro 0 Reputation points
2023-09-19T12:20:51.36+00:00

Hello, i have a VPN site-to-site tunel between virtual wan and a fortigate appliance.

Both sides show the tunel as UP and Connected, traffic flows in both directions and after a couple days it stops.

Local Network: 172.24.8.0/21

Remote Network: 172.17.16.0/22

1 - We have Virtual Hub and Azure Firewall with routing intent enabled for internet and private traffic

2 - packet capture confirms that packets are coming from fortigate and firewall logs show the same traffic being Allowed into network rules but i can´t see the traffic going back to vpn gateway.

  • Inbound Traffic

Traffic from 172.17.19.127 (remote) to 172.24.11.4 (local) port 5060 (sip)

Packet capture:

User's image

Firewall Network Rule Hit:

User's image

  • Outbound Traffic

Traffic from 172.24.13.16 (local) and 172.24.9.4 (local) to 172.17.19.127 port 5060

User's image

At the same time frame the packets never reach the vpn gateway:

User's image

Traceroute:

User's image

The only way to get the traffic back is reseting the VPN Gateway, as i already said the traffic goes back to normal for a couple days and then stops again.

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
197 questions
{count} votes