Site to Site Azure VPN with 2 VNET's

allenage seo 21 Reputation points
2022-02-21T13:38:07.91+00:00

176429-are.png
I have 2 VNETs in Azure.

Vnet1 -10.0.0./24 -- Peered
Vnet2- 10.10.0.0/24 -- Peered.

Gateway transit is allowed on Vnet1 and use remote gateway is selected on Vnet2
Firewall Sonic wall. Current status: VPN tunnel is created(route-based) and connected from on-prem to Vnet1 and VM's on Vnet1 to On-prem

peering is completed, DBvnet used a remote virtual network, and it connects with Vnet1.

The challenge.Vnet2 cannot connect with on-prem and on-prem cannot connect with Vnet2

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,436 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
342 questions
0 comments No comments
{count} votes

Accepted answer
  1. risolis 8,701 Reputation points
    2022-02-21T20:18:57.47+00:00

    @allenage seo

    You direct yourself to the Virtual network and then click on the NIC interface for your resource.... After that you will find the following options:

    176573-image.png


4 additional answers

Sort by: Most helpful
  1. Alan Kinane 16,806 Reputation points MVP
    2022-02-21T14:20:58.19+00:00

    Have you advertised the DBvnet address space to your Sonicwall and have you defined the DBvnet address space in your local network gateway?

    https://video2.skills-academy.com/en-us/azure/vpn-gateway/tutorial-site-to-site-portal

    176426-image.png


  2. risolis 8,701 Reputation points
    2022-02-21T14:36:18.837+00:00

    @allenage seo

    I wonder if this topology is Hub and spoke since you mentioned that your Firewall Sonic wall is the one running IPsec protocol(Facing your on-premises FW).

    If you have an overlapping allocation issue between on-premises and your Vnets, you can think of using NAT(If any of your resources hosted on those Vnets and are using an FQDN you can set up DNAT using a FQDN as destination ip.

    If you want to gather more details perphas we can help...

    Cheers,

    0 comments No comments

  3. risolis 8,701 Reputation points
    2022-02-21T17:04:44.043+00:00

    @allenage seo

    Have you checked your effective routes vs UDR routes(User defined routes table)?


  4. allenage seo 21 Reputation points
    2022-02-22T04:31:09.363+00:00

    Resolved added address objects of both the Vnet's in-group and added the Tunnel interface on routing policies

    0 comments No comments