SOLVED

Need For Local Network Gateway when connecting Azure S2S tunnel to AWS

%3CLINGO-SUB%20id%3D%22lingo-sub-2276164%22%20slang%3D%22en-US%22%3ENeed%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2276164%22%20slang%3D%22en-US%22%3E%3CP%3EGreetings.%20%26nbsp%3BAccording%20to%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fitops-talk-blog%2Fstep-by-step-connect-your-aws-and-azure-environments-with-a-vpn%2Fba-p%2F339211%22%20target%3D%22_self%22%3Ethis%20article%3C%2FA%3E%26nbsp%3Band%20several%20others%20I've%20read%20on%20connecting%20Azure%20to%20AWS%20resources%2C%20a%20Local%20Network%20Gateway%20is%20required%20to%20be%20provisioned%20and%20configured%20%3CEM%3Ealong%20with%26nbsp%3B%3C%2FEM%3Ean%20Azure%20VPN%20Gateway%20on%20the%20Azure%20side.%20%26nbsp%3BMy%20question%20is%2C%20why%20is%20this%20the%20case%3F%20%26nbsp%3BI%20don't%20need%20to%20have%20a%20Local%20Network%20Gateway%20for%20any%20other%20S2S%20tunnels%20I've%20provisioned%20to%20on-prem%20locations%2C%20so%20why%20is%20this%20needed%20for%20connectivity%20to%20AWS%3F%20%26nbsp%3BIs%20it%20because%20of%20some%20compatibility%20issues%20between%20Azure%20and%20Amazon%20VPN%20gateways%2C%20or%20is%20it%20due%20to%20something%20else%3F%20%26nbsp%3BI'd%20just%20like%20to%20understand%20why.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%20for%20any%20light%20that%20can%20be%20shed!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBrian%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2282730%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2282730%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F17701%22%20target%3D%22_blank%22%3E%40Kenneth%20Meyer-Lassen%3C%2FA%3E%20and%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F540591%22%20target%3D%22_blank%22%3E%40ibrahimambodji%3C%2FA%3E.%20%26nbsp%3BThanks%20for%20your%20continued%20discourse%20on%20this.%20After%20reviewing%20your%20image%20and%20comparing%20with%20my%20setup%2C%20I%20think%20I%20left%20out%20an%20important%20detail.%20%26nbsp%3BMy%20Azure%20VPN%20Gateway%20is%20based%20on%20a%20%22classic%22%20Service%20Model%20based-VNET%2C%20rather%20than%20ARM-based.%20%26nbsp%3BPer%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-about-vpn-gateway-settings%23lng%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E%26nbsp%3B%2C%20in%20the%20classic%20deployment%20model%2C%20the%20LNG%20is%20called%20a%20%22Local%20Site%22%20and%20so%20the%20portal%20interface%20is%20different%20than%20what%20you%20see.%20%26nbsp%3BSo%2C%20I%20think%20that's%20my%20answer%20and%20that%20difference%20in%20terminology%20was%20what%20was%20throwing%20me%20off.%20%26nbsp%3BThanks%20again%20for%20your%20help%20in%20getting%20me%20to%20the%20answer!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBrian%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2282455%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2282455%22%20slang%3D%22en-US%22%3EThe%20reason%20why%20you%20need%20a%20local%20network%20gateway%20is%20this%20%3A%3CBR%20%2F%3E%22The%20local%20network%20gateway%20is%20a%20specific%20object%20that%20represents%20your%20on-premises%20location%20(the%20site)%20for%20routing%20purposes.%22%3CBR%20%2F%3EConsider%20on-premises%20location%20everything%20outside%20Azure%20even%20if%20it%20can%20be%20a%20public%20cloud%20like%20AWS%3CBR%20%2F%3ENow%20the%20use%20of%20VPN%20Gateway%20is%20not%20mandatory%20you%20can%20simply%20use%20a%20Network%20Virtual%20Appliance%20in%20Azure%20(%20Fortinet%20Palo%20Alto%20Checkpoint%20...)%20to%20establish%20your%20connectivity%20with%20AWS%20and%20on%20that%20side%20you%20need%20also%20an%20NVA%20.%20In%20that%20context%20LNG%20is%20not%20needed.%3CBR%20%2F%3E%3CBR%20%2F%3EREF%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Ftutorial-site-to-site-portal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Ftutorial-site-to-site-portal%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2282333%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2282333%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F589723%22%20target%3D%22_blank%22%3E%40AzureBrian%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Brian.%3CBR%20%2F%3EI%20am%20sorry%2C%20but%20you%20do%20need%20to%20define%20an%20Local%20Network%20Gateway%20in%20Azure%20to%20create%20a%20S2S%20VPN.%20Otherwise%20the%20S2S%20VPN%20connection%20doesn't%20know%20which%20host%20to%20connect%20to.%20If%20you%20have%20S2S%20VPN%20connections%20you've%20got%20to%20have%20defined%20LNGs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20use%20P2S%20(point%20to%20site)%20VPN%2C%20you're%20right%2C%20then%20you%20don't%20need%20to%20define%20a%20Local%20Network%20Gateway.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20attached%20an%20screenshot%20of%20a%20S2S%20connection%20definition%20between%20an%20Azure%20subscription%20and%20my%20home%20office%2C%20in%20the%20image%20you'll%20see%20a%20marking%20box%20showing%20the%20LNG%20definition%2C%20please%20disregard%20the%20connection%20is%20not%20established.%20I%20suggest%20you%20have%20a%20look%20at%20your%20own%20subscription%20and%20post%20an%20image%2C%20if%20you%20still%20don't%20see%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2281409%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2281409%22%20slang%3D%22en-US%22%3EHi%20Kenneth.%20Thanks%20again%20for%20your%20response.%20This%20still%20does%20not%20explain%20why%20an%20LNG%20is%20not%20needed%20for%20other%20connections.%20What's%20special%20about%20the%20connection%20to%20AWS%20that%20requires%20the%20LNG%3F%3F%3F%20As%20I%20mentioned%20above%2C%20I%20have%20S2S%20tunnels%20to%20many%20other%20on-prem%20locations%20and%20don't%20need%20an%20LNG.%20Why%20is%20this%20required%20for%20AWS%20and%20not%20others%3F%20Is%20it%20due%20to%20incompatibilities%20between%20AWS%20VPGs%20and%20Azure%20VPN%20GWs%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2281358%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2281358%22%20slang%3D%22en-US%22%3EHi%20Brian.%3CBR%20%2F%3EThe%20LNG%20in%20Azure%20is%20really%20just%20a%20pointer%20to%20the%20%22other%20side%22%2C%20this%20can%20be%20another%20Azure%20VNG%2C%20AWS%20VPG%20or%20on-premise%20gateway.%20In%20Azure%20you%20then%20define%20the%20connection%20between%20VNG%20and%20LNG.%20Does%20it%20make%20sense%3F%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2278885%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2278885%22%20slang%3D%22en-US%22%3EThanks%20Kenneth%20for%20your%20response.%20I%20guess%20what%20I'm%20missing%20is%20how%20this%20is%20different%20than%20other%20S2S%20VPN%20tunnels.%20For%20example%2C%20when%20I%20setup%20a%20tunnel%20to%20an%20on-prem%20location%2C%20the%20other%20end%20of%20the%20tunnel%20just%20terminates%20on%20the%20device%20(gateway)%20at%20the%20on-prem%20location.%20No%20local%20network%20gateway%20is%20needed%20on%20our%20end.%20Yet%2C%20with%20an%20AWS%20connection%2C%20this%20local%20network%20gateway%20is%20needed%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%2C%3CBR%20%2F%3E%3CBR%20%2F%3EBrian%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2278693%22%20slang%3D%22en-US%22%3ERe%3A%20Need%20For%20Local%20Network%20Gateway%20when%20connecting%20Azure%20S2S%20tunnel%20to%20AWS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2278693%22%20slang%3D%22en-US%22%3EHi%20Brian.%3CBR%20%2F%3EWhen%20you%20create%20a%20S2S%20VPN%20tunnel%2C%20you%20always%20need%20to%20have%202%20endpoints.%20In%20case%20of%20an%20Azure%20S2S%20VPN%2C%20one%20is%20the%20Azure%20VPN%20gateway%2C%20one%20is%20the%20Local%20Network%20Gateway.%20In%20Azure%2C%20the%20LNG%20is%20just%20a%20definition%20of%20where%20the%20S2S%20VPN%20tunnel%20is%20terminating.%3CBR%20%2F%3ESo%20when%20you%20create%20the%20LNG%20in%20Azure%2C%20you%20must%20point%20this%20to%20the%20IP%20address%20of%20the%20VPG%20in%20AWS%20and%20target%20the%20Azure%20VNG%20as%20the%20AWS%20Customer%20Gateway.%3CBR%20%2F%3E%2FKenneth%20ML%3C%2FLINGO-BODY%3E
Occasional Contributor

Greetings.  According to this article and several others I've read on connecting Azure to AWS resources, a Local Network Gateway is required to be provisioned and configured along with an Azure VPN Gateway on the Azure side.  My question is, why is this the case?  I don't need to have a Local Network Gateway for any other S2S tunnels I've provisioned to on-prem locations, so why is this needed for connectivity to AWS?  Is it because of some compatibility issues between Azure and Amazon VPN gateways, or is it due to something else?  I'd just like to understand why.

 

Thanks in advance for any light that can be shed!

 

Brian

7 Replies
Hi Brian.
When you create a S2S VPN tunnel, you always need to have 2 endpoints. In case of an Azure S2S VPN, one is the Azure VPN gateway, one is the Local Network Gateway. In Azure, the LNG is just a definition of where the S2S VPN tunnel is terminating.
So when you create the LNG in Azure, you must point this to the IP address of the VPG in AWS and target the Azure VNG as the AWS Customer Gateway.
/Kenneth ML
Thanks Kenneth for your response. I guess what I'm missing is how this is different than other S2S VPN tunnels. For example, when I setup a tunnel to an on-prem location, the other end of the tunnel just terminates on the device (gateway) at the on-prem location. No local network gateway is needed on our end. Yet, with an AWS connection, this local network gateway is needed?

Thanks,

Brian
Hi Brian.
The LNG in Azure is really just a pointer to the "other side", this can be another Azure VNG, AWS VPG or on-premise gateway. In Azure you then define the connection between VNG and LNG. Does it make sense??
Hi Kenneth. Thanks again for your response. This still does not explain why an LNG is not needed for other connections. What's special about the connection to AWS that requires the LNG??? As I mentioned above, I have S2S tunnels to many other on-prem locations and don't need an LNG. Why is this required for AWS and not others? Is it due to incompatibilities between AWS VPGs and Azure VPN GWs?

@AzureBrian 

Hi Brian.
I am sorry, but you do need to define an Local Network Gateway in Azure to create a S2S VPN. Otherwise the S2S VPN connection doesn't know which host to connect to. If you have S2S VPN connections you've got to have defined LNGs.

 

If you use P2S (point to site) VPN, you're right, then you don't need to define a Local Network Gateway.

 

I have attached an screenshot of a S2S connection definition between an Azure subscription and my home office, in the image you'll see a marking box showing the LNG definition, please disregard the connection is not established. I suggest you have a look at your own subscription and post an image, if you still don't see it.

The reason why you need a local network gateway is this :
"The local network gateway is a specific object that represents your on-premises location (the site) for routing purposes."
Consider on-premises location everything outside Azure even if it can be a public cloud like AWS
Now the use of VPN Gateway is not mandatory you can simply use a Network Virtual Appliance in Azure ( Fortinet Palo Alto Checkpoint ...) to establish your connectivity with AWS and on that side you need also an NVA . In that context LNG is not needed.

REF: https://docs.microsoft.com/en-us/azure/vpn-gateway/tutorial-site-to-site-portal
best response confirmed by AzureBrian (Occasional Contributor)
Solution

Hi @Kenneth Meyer-Lassen and @ibrahimambodji.  Thanks for your continued discourse on this. After reviewing your image and comparing with my setup, I think I left out an important detail.  My Azure VPN Gateway is based on a "classic" Service Model based-VNET, rather than ARM-based.  Per this article , in the classic deployment model, the LNG is called a "Local Site" and so the portal interface is different than what you see.  So, I think that's my answer and that difference in terminology was what was throwing me off.  Thanks again for your help in getting me to the answer!

 

Brian