Azure firewall and Palo Alto NGFW( SaaS) implementation in Azure Virtual WAN Hub
Hi Microsoft team, Can we deploy both Azure firewall and Palo Alto NGFW( SaaS) implementation in Azure Virtual WAN Hub, and send private traffic through Azure firewall and Internet traffic through Palo Alto NGFW( SaaS Implementation)? Please advise.
How to associate an existent Public IP with Azure Firewall
Hey guys, Is it possible to use one or more existing/pre-defined IPs with the Azure Firewall? *The Firewall is in a secure hub environment There are documents/scripts to create new IPs and associate them with the Firewall, via portal as well, but none of…
VPN Connectivity to 150+ clients with Azure Infra
We have a requirement to connect around 150+ clients network to our Azure Infra. The communication needs to be both ways , with capability to send traffic to individual client location systems. We have explore site-to-site VPNGW with Static Nat , but it…
filter bgp virtualwan
Hi i have an issue on virtualwan i have vnet spoke that are 10.0.10.0/24 and another spoke 10.0.20.0/24, they can ping each other, but when i associate the route table from on prem wich advertise 10.0.0.0/16, everything stops working and thew two subnets…
![](https://techprofile.blob.core.windows.net/images/lvNaBJBqh0eurOu4q2bQSQ.png?8DA4E8)
Azure hub Effective Route s2s VPN | AS path
When configuring S2S VPN on Azure Virtual Hub, In some cases the output in the effective route table return different result's for example case 1 : (with dash) prefix next-hop type AS path 172.31.0.0/16 …
Different VPN point2site VPN server URL
Hi Team I am have exported VPN client profile from Azure portal for P2S azure vpn client. I found their 2 VPN server url in profile. wan.xxxxx.vpn.azure.com hub0.xxxxx.vpn.azure.com Do you anyone know what is the different? Which one should I perfer…
Need to setup IP SEC tunnel from Azure Virtual WAN and Cisco cEdge 8000v
I was trying to setup site to site IP SEC tunnel from Azure Virtual WAN and Cisco cEdge 8000v. I have tried checking the Azure tutorial but did not find any solution to this. referred Azure Doc:…
![](https://techprofile.blob.core.windows.net/images/Nd_pi7-IHkuDC3BVgl0RFQ.png?8D81F2)
Virtual WAN, vpn(site to site) there is no IP address for my on-prem vti tunnel
I'm trying to create Azure hub and spoke topology, my understanding is that I need to use Virtual Wan. my problem is with the VPN connection to the on-premise network. In the Virtual WAN -> Hub -> VPN (site-to-site), and then create a site-to-site…
![](https://techprofile.blob.core.windows.net/images/lvNaBJBqh0eurOu4q2bQSQ.png?8DA4E8)
Virtual WAN Internet traffic Routing via third party NVA but the spoke vnets should be directly connected to virtual hub
Scenario: spoke vnets svnet1 ,svnet2, svnet3 is connected to virtual hub NVA Vnet nvavnet is connected to virtual hub Expressroute connected to virtual hub svnet1 and svnet2 are isolated but should be reached by Express route Expectation: VM's…
Virtual WAN Internet traffic Routing via third party NVA
Our goal is to route all vnet-vnet, onprem-vnet traffic via Azure Firewall. Any outbound and inbound internet traffic in Azure should pass through palo alto. We are trying to setup the routing, but its not working. PFa the entire architecture. We are…
Azure P2S VPN Client disconnects frequently
Hi, we have the following problem, We are using Always on Azure VPN client with Azure Virtual WAN and AD authentication. The following problem: the VPN connection is interrupted at irregular intervals and then reconnects automatically. We get an…
Azure WAN and P2S VPN Forced Tunneling
I have setup Azure WAN with a secured hub(Azure Firewall). WAN also has a P2S VPN which am successfully able to connect to. I understand forced tunneling was not an option before Azure VWAN, but now can i do forced tunneling for my P2S clients and give…
Error selecting NetworkVirtualAppliance under vWAN/HUB
hello I'm trying to add a Cisco c8000v to my vWAN/HUB. vWAN and HUB is created. The next step "should be": create the Network Virtual Appliance in the vitualHUB. When i do that, i get the error "The extension encountered an unexpected…
DNS Resolution Issues across Hubs
I have an existing VWAN and single VHUb. The Existing setup. All that is shown here in Subscription A works great. The sub A hub does not have a Firewall at this time. The VNets that are peered with the existing Hub, all have their Vnet DNS set to…
![](https://techprofile.blob.core.windows.net/images/lvNaBJBqh0eurOu4q2bQSQ.png?8DA4E8)
Virtual WAN gateway fails to provision
For a couple of days now, I have been trying to provision a (VPN) gateway for a Virtual WAN hub in Azure. I have Owner roles on all available subscriptions and I am Global Administrator on the connected Entra tenant. The Virtual WAN and the hub are both…
![](https://techprofile.blob.core.windows.net/images/lvNaBJBqh0eurOu4q2bQSQ.png?8DA4E8)
vWAN for SDWAN and Firewall - critical design
@Anonymous If you can help Here, please. i have vWAN with multiple vHubs (assume vHubx and vHuby , each one in different region). vHubx and vHubY hosting SDWAN NVA that make fullmesh connection with all SDWAN sites. but vHubx and vHubY are not…
Connectivity between three different companies infra hosted on Azure
Dear Team, Existing Configuration: In the current setup, Company 2 has established a Site-to-Site (S2S) connectivity with Company 3, utilizing Virtual WAN. This arrangement allows Company 2 to access the SAP HANA application hosted by Company 3. Desired…
![](https://techprofile.blob.core.windows.net/images/DFUdJReiskW7xaWenka5lQ.png?8DAE8D)
vWAN vHub connection to another Subscription vNets
Hello, i am planning a vWAN (assume in Subscription X) , where all vHubs will be in the same subscription. and all vNets are in another subsctription (Y) so all connections from any vHub will be cross subscription (X < -- > Y) 1- is there…
Exporting static route between virtual hubs
Hi, We plan to deploy a network topology with three levels : first (top) level with a virtual wan and 2 virtual hubs, for two main Organisation Units, second level with 6 « second level » hubs, each one acting as a hub for a specific business unit,…
How to allow only people from Entra Group to connect to Azure VPN?
My company implemented Azure Virtual WAN with both site-to-site and point-to-site connections. Employees would use Azure VPN client to connect to Azure resources. Admins would download virtual hub User VPN profile and import it to user's VPN client and…