Routing External Subnets to Azure Firewall via NVA

Roshan Roy 0 Reputation points
Nov 23, 2024, 9:42 AM

Hi There,
In our current setup, we connect to the workload via ExpressRoute and VPN. Additionally, we plan to deploy a NVA firewall VM where the IPsec tunnel will terminate. The diagram below provides further details.

Diagram

All production vNets have their default route pointing to the Azure Firewall. Some of the prefixes advertised through the VPN tunnel need to access the production network. Our plan is for the NVA firewall to route those external subnets through the Azure Firewall, as the production vNets already have a return default route in place. As these subnets are external, we cannot use UDRs to route the traffic. Could you advise on an option to advertise these subnets to the Azure Firewall?

Thank You in Advance

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
687 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.