SOLVED

VPN connection to a peered VNET

%3CLINGO-SUB%20id%3D%22lingo-sub-1846091%22%20slang%3D%22en-US%22%3EVPN%20connection%20to%20a%20peered%20VNET%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1846091%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI'm%20having%20a%20bit%20of%20an%20issue%20connecting%20to%20my%20servers%20after%20authenticating%20through%20a%20P2S%20VPN%20and%20was%20wondering%20if%20anyone%20had%20a%20solution.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMy%20environment%20is%20as%20follows%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E2x%20Azure%20servers%20in%20a%20VNET%20connected%20to%20my%20on-premise%20network%20using%20a%20S2S%20VPN.%20This%20part%20is%20all%20working%20fine.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI've%20created%20a%20new%20VNET%20and%20made%20a%20new%20P2S%20VPN%20using%20AD%20authentication.%20I've%20enabled%20peering%20between%20the%20networks%20and%20that%20bit%20seems%20to%20be%20OK.%20When%20I%20connect%20to%20my%20P2S%20VPN%20I%20cannot%20access%20either%20the%202x%20Azure%20servers%20or%20any%20of%20my%20resources%20on-prem.%20Any%20help%20will%20be%20gratefully%20received.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1847858%22%20slang%3D%22en-US%22%3ERe%3A%20VPN%20connection%20to%20a%20peered%20VNET%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1847858%22%20slang%3D%22en-US%22%3EHi%20Marky79%2C%3CBR%20%2F%3E%3CBR%20%2F%3EHow%20are%20you%3F%3CBR%20%2F%3E%3CBR%20%2F%3EHave%20you%20considered%20having%20your%20P2S%20connect%20to%20the%20same%20VPN%20Gateway%20as%20your%20S2S%3F%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20are%20wanting%20to%20do%20hit%20resources%20on%20the%20other%20end%20of%20a%20peering%20and%20a%20S2S%20VPN%20you%20will%20need%20to%20set%20%E2%80%9CAllow%20Gateway%20Transit%E2%80%9D%20on%20the%20VPN%20Gateway%20VNET%20side%20and%20%E2%80%9CUse%20Remote%20Gateway%E2%80%9D%20on%20the%20non-VPN%20Gateway%20side.%20These%20settings%20are%20within%20your%20VNET%20peering%20setup.%3CBR%20%2F%3E%3CBR%20%2F%3EI%E2%80%99d%20have%20to%20mock%20up%20your%20environment%20to%20test%20routing%20with%20the%20two%20vpn%20gateways%20in%20different%20vnets.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20the%20first%20tips%20don%E2%80%99t%20help%20you%2C%20I%E2%80%99ll%20build%20a%20mock%20up%20later%20tonight%20to%20test%20for%20you.%3CBR%20%2F%3E%3CBR%20%2F%3ELet%20me%20know.%3CBR%20%2F%3E%3CBR%20%2F%3EKarl%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1848948%22%20slang%3D%22en-US%22%3ERe%3A%20VPN%20connection%20to%20a%20peered%20VNET%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1848948%22%20slang%3D%22en-US%22%3EHi%20Karl%3CBR%20%2F%3E%3CBR%20%2F%3EThat%20was%20my%20first%20thought%20but%20it's%20not%20currently%20an%20option%20as%20whoever%20set%20this%20up%20originally%20created%20the%20s2s%20as%20a%20policy%20based%20VPN.%20If%20I%20can't%20get%20it%20working%20I%20may%20have%20to%20delete%20the%20existing%20connection%20if%20that%20will%20allow%20me%20to%20have%20the%20s2s%20and%20p2s%20using%20the%20same%20gateway.%20That%20would%20be%20a%20lot%20simpler%20but%20isn't%20something%20I've%20done%20before.%3CBR%20%2F%3E%3CBR%20%2F%3EI'll%20have%20a%20look%20at%20the%20other%20gateway%20settings%20today.%3CBR%20%2F%3E%3CBR%20%2F%3EMark%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1849275%22%20slang%3D%22en-US%22%3ERe%3A%20VPN%20connection%20to%20a%20peered%20VNET%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1849275%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F668493%22%20target%3D%22_blank%22%3E%40marky79%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Mark%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYeah%2C%20if%20you%20recreate%20as%20route-based%20you'll%20be%20able%20to%20add%20S2S%20and%20P2S.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELet%20me%20know%20how%20you%20get%20on%20with%20those%20options.%20I%20will%20try%20to%20get%20time%20this%20evening%20to%20mock%20it%20up%20to%20make%20sure%20the%20standard%20routing%20works%20or%20whether%20we%20might%20need%20to%20make%20some%20changes.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20a%20good%20day!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKarl%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi

 

I'm having a bit of an issue connecting to my servers after authenticating through a P2S VPN and was wondering if anyone had a solution.

 

My environment is as follows:

 

2x Azure servers in a VNET connected to my on-premise network using a S2S VPN. This part is all working fine.

 

I've created a new VNET and made a new P2S VPN using AD authentication. I've enabled peering between the networks and that bit seems to be OK. When I connect to my P2S VPN I cannot access either the 2x Azure servers or any of my resources on-prem. Any help will be gratefully received.

 

Thanks

4 Replies
Hi Marky79,

How are you?

Have you considered having your P2S connect to the same VPN Gateway as your S2S?

If you are wanting to do hit resources on the other end of a peering and a S2S VPN you will need to set “Allow Gateway Transit” on the VPN Gateway VNET side and “Use Remote Gateway” on the non-VPN Gateway side. These settings are within your VNET peering setup.

I’d have to mock up your environment to test routing with the two vpn gateways in different vnets.

If the first tips don’t help you, I’ll build a mock up later tonight to test for you.

Let me know.

Karl
Hi Karl

That was my first thought but it's not currently an option as whoever set this up originally created the s2s as a policy based VPN. If I can't get it working I may have to delete the existing connection if that will allow me to have the s2s and p2s using the same gateway. That would be a lot simpler but isn't something I've done before.

I'll have a look at the other gateway settings today.

Mark
best response confirmed by marky79 (Contributor)
Solution

@marky79 

 

Hi Mark,

 

Yeah, if you recreate as route-based you'll be able to add S2S and P2S. 

 

Let me know how you get on with those options. I will try to get time this evening to mock it up to make sure the standard routing works or whether we might need to make some changes.

 

Have a good day!

 

Karl

Hey Karl

I'll give this a go today and see how I get on. Changing the traffic options didn't do the trick so I'll just simplify it.

Thanks for your help.

Mark