Express Route Routing Issues (Azure to On-premises route)

Jaykishan Bairagi 0 Reputation points
2024-06-30T00:32:00.81+00:00

Hi @GitaraniSharma-MSFT - We have performed the same setup from this article https://video2.skills-academy.com/en-us/answers/questions/860533/express-route-and-azure-firewall)

We have 2 express route premium circuits (East US & South-Central US) with 3 Azure firewalls premium per vNet; 3 Express route gateways (multi-AZ) (per vNet); 6 express route connections to 3 express route gateways (DR setup if incase circuit/region failure).

The identicial 10 prefixes were advertised from on-premises side without "0.0.0.0/0" and 3 virtual networks from Azure side (no hub-spoke approach) to on-premises. Also, outbound traffic of internet from Azure has to go through Azure firewall and not to On-premises.

  1. Traffic flow from On-Premises to Azure >> Working as expected and passing the traffic through Azure Firewalls as per environment.
  2. Traffic flow from Azure to On-Premises >> Intermittently working. Example - telnet/psping to on-premises destination on port is working on 1st or 2nd attempts and stuck after 3rd attempt and continues the same behavior for some attempts. It will work back after 10th attempt or so. Also, observed the INVALID flag on firewall traceflowlogs from on premise destination server to FW private IP. However, we need the firewall to filter both inbound/outbound traffic from on-premises and internet side.
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
598 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,256 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
340 questions
{count} votes