Can NVA be placed behind Azure load balancer and Load balancer Frontend IP can be used to exchange bgp routes?

Amol Admin account 11 Reputation points
2023-11-09T08:14:11.92+00:00

We are planning to implement Fortigate SDWAN devices in a spoke Vnet. They are in HA mode with Azure load balancer. We want to exchange the routes from SDWAN and Azure Virtual Hub. Can there be BGP setup between azure virtual hub to Azure load balancer front end IP?

Note -we are able to setup bgp peering directly with one of NVA (fortinet from azure vhub).

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
197 questions
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
416 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 39,211 Reputation points Microsoft Employee
    2023-11-12T05:33:28.9633333+00:00

    @Amol Admin account

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to configure BGP peering with a virtual hub and NVA

    As long as the HA ports are configured in the ILB, I do not see a reason as to why this would not work.

    And Azure Load Balancer can accept TCP and UDP traffic. Hence, this configuration should work.

    • Since the traffic would be load balanced, just make sure stateful inspection on the NVA or related firewall settings is turned off or asymmetric forwarding is turned on.
      • To give more details, the inbound traffic to NVA can come on any instance directly to NVA interface from on premises and then on the return if  the traffic is forwarded to ILB, the ILB will hash and distribute traffic to either instance of NVA.
    • Meanwhile, you can test this out by taking a maintenance period or in a lower Test/Dev environment.

    Should there be any issues, please do let us know.

    Cheers,

    Kapil


    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    0 comments No comments