I have a VPN but the other end requires a specific private IP to allow traffic throughout

Oliver Centeno 0 Reputation points
2024-08-27T06:59:01.72+00:00

Hello,

I configured a site-to-site VPN with a client using a public IP, a virtual network gateway with its gateway subnet and the connection gets stablished.

Screenshot 2024-08-27 at 08.51.55

But the client has assigned an specific IP for the traffic from this VPN to be allowed. That IP belongs to the gateway subnet and I tried to get a private IP for the virtual network gateway, but it is assigned automatically and I get precisely the next IP from the one I shall get (.99). I tried many times and it is consistently giving me the same IP (.100).

Screenshot 2024-08-27 at 08.56.00

I also tried an Active-Active mode but that gives as the second private the IP .103

Is there any way to force the IP that I need to be assigned? Shall I proceed in a different way?

Thanks

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,514 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,401 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Ganesh Patapati (Quadrant Resource LLC) 175 Reputation points Microsoft Vendor
    2024-08-27T15:44:46.9366667+00:00

    Hi Oliver Centeno,

    Thank you for reaching out to the Microsoft Q&A Platform.

    We understand from your query that you are experiencing an issue while trying to allow traffic to VPN, but the other end requires a specific private IP for these queries,

    here are the following major reasons to follows-

    NOTE: Unfortunately, it's not possible to manually assign a specific IP address to a virtual network gateway in Azure. The IP address is automatically assigned by Azure from the gateway subnet, and it's not configurable.

    • For S2S connections with an active-active mode VPN gateway, ensure tunnels are established to each gateway VM instance. If you establish a tunnel to only one gateway VM instance, the connection will go down during maintenance. If your VPN device doesn't support this setup, configure your gateway for active-standby mode instead.
    • It would be best to use an Egress SNAT rather than an Ingress SNAT for applying NAT to the connection.

    Refer: https://video2.skills-academy.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings#gwsub

    As this something which is not supported. We encourage customers to create a feedback item for this request on the feedback forum

    https://feedback.azure.com/d365community


    If you are still facing any further issues, please don't hesitate to reach out to us. We are happy to assist you.

    If the above response helps to address your concern, please remember to "Accept Answer" so that others in the community experiencing similar problems can easily find a solution.

    Your contribution is greatly appreciated.

    Regards,

    Ganesh Patapati

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.