Branchoffice not available via ExpressRoute

Tom de Smidt | Hermac BV 20 Reputation points
2024-07-31T14:25:26.9433333+00:00

Infrastructure:
Azure - ExpressRoute Circuits (BGP)
Subnet 10.20.0.0/16
Main Office Sophos Firewall
Subnet 10.0.0.0/24
Branch Office Sophos Firewall
Subnet 192.168.110.0/23

Azure (AVD) is connected via ExpressRoute to the Main Office.
The Main- and Branch office are connected by IPSEC s2s vpn.

Problem: The client wants to connect from Azure AVD to a local server at the branch office.
We made all networks known on the firewalls but Azure seems to do nothing with the traffic from the 10.20.0.0/16 to the 192.168.110.0 subnet.
As I'm not sure if it's a routing issue I'm stuck at this point.

Traffic between branch and main office works fine.
Traffic between main and Azure also has no problems.

Hope somebody can help me!

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
365 questions
{count} votes

Accepted answer
  1. Andreas Baumgarten 107.9K Reputation points MVP
    2024-07-31T14:30:32.6233333+00:00

    Hi @Tom de Smidt | Hermac BV ,

    the IP address range of the Branch office is "known" by Azure infrastructure as well?

    For me it sounds like a routing issue.

    Azure needs to know the branch office networks and the main office networks.

    The main office needs to know the branch office and Azure networks.

    The branch office needs to know the main office and Azure networks.

    If I understand correctly the traffic between branch office and Azure will be routed via main office?

    This means the routing should be configured properly in all related networks.


    (If the reply was helpful please don't forget to upvote and/or accept as answer, thank you)

    Regards

    Andreas Baumgarten


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.