Forum Discussion
ratoor
Aug 23, 2022Copper Contributor
Backup Virtual Network Gateway - site to site
We have two ISP connections wired and wireless. Wireless is only used when wired goes down for both incoming and outgoing traffic. All our locations form 2 IPSEC tunnels across each connection separa...
ratoor
Aug 23, 2022Copper Contributor
KurtBMayer I have no problem selecting which route to take wired or wireless on the physical firewall, when there both are available or only on of the two(wired/wireless) is available.
I am thinking from the perspective of Azure. When same routes are being advertised on both tunnels,
When both links are available -
Will it load balance / round robin ? We don't want it to.
How can I make Azure prefer wired tunnel, when both tunnels are up?
When one link is available -
When wired goes down how can I make Azure switch traffic over to wireless tunnel?
How much time does it take to notice tunnel is down and switch traffic to other tunnel?
I am thinking from the perspective of Azure. When same routes are being advertised on both tunnels,
When both links are available -
Will it load balance / round robin ? We don't want it to.
How can I make Azure prefer wired tunnel, when both tunnels are up?
When one link is available -
When wired goes down how can I make Azure switch traffic over to wireless tunnel?
How much time does it take to notice tunnel is down and switch traffic to other tunnel?
tommykneetz
Aug 24, 2022Iron Contributor
"Because the Azure gateway instances are in active-active configuration, the traffic from your Azure virtual network to your on-premises network will be routed through both tunnels simultaneously, even if your on-premises VPN device may favor one tunnel over the other. For a single TCP or UDP flow, Azure attempts to use the same tunnel when sending packets to your on-premises network. However, your on-premises network could use a different tunnel to send packets to Azure."
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-highlyavailable#active-active-vpn-gateways
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-highlyavailable#active-active-vpn-gateways