Default route advertisement from Azure to On Prem via express route

naresh rathore 0 Reputation points
2024-02-23T06:15:42.55+00:00

hi i have to deploy a setup in which Fortinet Firewall will be deployed in Azure. there is connectivity between Azure and customer branches via MPLS. customer wants Branches to use Azure Fortinet for internet access as there is no internet available locally. is there a way we can advertise default route from Azure Fortint to on-prem via express route?.

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
340 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 39,211 Reputation points Microsoft Employee
    2024-03-01T17:23:04.3+00:00

    @naresh rathore ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to route all Internet traffic from OnPrem to Azure NVA via ExpressRoute.

    • I wouldn't recommend this as a good practice.
    • Internet Routing via Azure is supported out of the box with Azure vWAN only See : How to configure Virtual WAN Hub routing intent User's image
    • With stand alone ExR Gateway - this is a complex set up and we do not have any documentations for this architecture.

    With that said,

    I came across this blog which is your exact requirement : https://blog.cloudtrooper.net/2021/03/16/azure-as-internet-breakout-from-on-premises-with-route-server/

    • I strongly advice you to do a test configuration / POC before moving to Production.
    • You can use a dummyVNET with dummyVM and dummyExRGateway and connect it to the ExR Circuit
    • Deploy NVA and ARS in this VNET and advertise 8.8.8.8/32 (or any Public IP) only
    • Check if the traffic to 8.8.8.8/32 from OnPrem actually reaches internet via the NVA in Azure or not.

    Again, consider using Virtual WAN Hub routing intent and routing policies

    Hope this helps.

    Cheers,

    Kapil

    0 comments No comments