Access Internet through Azure Point to site VPN

%3CLINGO-SUB%20id%3D%22lingo-sub-135057%22%20slang%3D%22en-US%22%3EAccess%20Internet%20through%20Azure%20Point%20to%20site%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-135057%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20point%20to%20site%20VPN%20to%20Azure%20working%20with%20RADIUS%20auth%20and%20can%20access%20resources%20in%20the%20vNet.%20I%20would%20like%20to%20be%20able%20to%20route%20traffic%20out%20to%20the%20internet%20over%20that%20VPN%20connection.%20Can%20this%20be%20done%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20not%2C%20how%20would%20I%20replicate%20this%20with%20Azure%20services%20without%20deploying%20something%20like%20a%20Cisco%20virtual%20device%3F%3C%2FP%3E%0A%3CP%3Ethanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-135057%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Network%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-730088%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20Internet%20through%20Azure%20Point%20to%20site%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-730088%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F94808%22%20target%3D%22_blank%22%3E%40Ryan%20Clark%3C%2FA%3E%26nbsp%3Bwould%20you%20mind%20sharing%20how%20you%20did%20that%20exactly%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-206493%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20Internet%20through%20Azure%20Point%20to%20site%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206493%22%20slang%3D%22en-US%22%3E%3CP%3EIIRC%20I%20just%20had%20to%20add%20the%20internal%20interface%20to%20NAT.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-206451%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20Internet%20through%20Azure%20Point%20to%20site%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-206451%22%20slang%3D%22en-US%22%3EHi%20Ryan%2C%3CBR%20%2F%3E%3CBR%20%2F%3EI%20am%20having%20the%20same%20issue%2C%20can%20you%20give%20me%20guideline%20how%20you%20use%20RRAS%20in%20Azure%20to%20allow%20internet%20after%20P2S%3F%20What%20settings%20did%20you%20have%20to%20configure%3F%20(e.g.%20routing%3F)%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%2C%3CBR%20%2F%3E%3CBR%20%2F%3EDanny%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-136878%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20Internet%20through%20Azure%20Point%20to%20site%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-136878%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20but%20needs%20to%20P2S%2C%20site%20to%20site%20is%20not%20an%20option%20in%20this%20case.%3C%2FP%3E%0A%3CP%3EI%20have%20got%20a%20solution%20by%20putting%20RRAS%20in%20Azure.%20MS%20don't%20support%20RRAS%20in%20Azure%2C%20but%20it%20appears%20to%20be%20working%20at%20the%20moment.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-136875%22%20slang%3D%22en-US%22%3ERe%3A%20Access%20Internet%20through%20Azure%20Point%20to%20site%20VPN%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-136875%22%20slang%3D%22en-US%22%3E%3CP%3ENot%20the%20expert%2C%20but%20i%20believe%20what%20you%20are%20looking%20for%20is%20force%20tunneling.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-forced-tunneling-rm%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-forced-tunneling-rm%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDon't%20believe%20it%20can%20be%20done%20over%20a%20P2S%20connection%20though.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I have point to site VPN to Azure working with RADIUS auth and can access resources in the vNet. I would like to be able to route traffic out to the internet over that VPN connection. Can this be done?

 

If not, how would I replicate this with Azure services without deploying something like a Cisco virtual device?

thanks

5 Replies

Not the expert, but i believe what you are looking for is force tunneling.

 

https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm

 

Don't believe it can be done over a P2S connection though.

Thanks but needs to P2S, site to site is not an option in this case.

I have got a solution by putting RRAS in Azure. MS don't support RRAS in Azure, but it appears to be working at the moment.

Hi Ryan,

I am having the same issue, can you give me guideline how you use RRAS in Azure to allow internet after P2S? What settings did you have to configure? (e.g. routing?)

Thanks,

Danny

IIRC I just had to add the internal interface to NAT.

@Ryan Clark would you mind sharing how you did that exactly?