SOLVED

On-prem connect with S2S VPN to Azure - Mobile users on P2S to Azure cannot connect to on-prem

%3CLINGO-SUB%20id%3D%22lingo-sub-1593290%22%20slang%3D%22en-US%22%3ERe%3A%20On-prem%20connect%20with%20S2S%20VPN%20to%20Azure%20-%20Mobile%20users%20on%20P2S%20to%20Azure%20cannot%20connect%20to%20on-prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593290%22%20slang%3D%22en-US%22%3E%3CP%3EI%20was%20able%20to%20figure%20this%20out%20in%20the%20end%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20you%20download%20the%20P2S%20(Client)%20VPN%20Config%20file%20from%20the%20Azure%20Portal%2C%20and%20install%20it%20to%20set%20up%20your%20P2S%20VPN.%3CBR%20%2F%3E%3CBR%20%2F%3EYou're%20able%20to%20see%20that%20the%20routes%20that%20Azure%20VPN%20can%20connect%20to%20by%20finding%20this%20TXT%20file%20in%3A%26nbsp%3B%3C%2FP%3E%3CDIV%3E%3CSTRONG%3E%25appdata%25%5CMicrosoft%5CNetwork%5CConnections%5CCm%5C%3CSOME%20id%3D%22%22%3E%5Croutes.txt%26nbsp%3B%3CBR%20%2F%3E%3C%2FSOME%3E%3C%2FSTRONG%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSTRONG%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222020-08-17%2016_21_08-James%20and%20Niels%20_%20Microsoft%20Teams.png%22%20style%3D%22width%3A%20733px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F212752iFC036BB87F964436%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%222020-08-17%2016_21_08-James%20and%20Niels%20_%20Microsoft%20Teams.png%22%20alt%3D%222020-08-17%2016_21_08-James%20and%20Niels%20_%20Microsoft%20Teams.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CSTRONG%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222020-08-17%2016_22_41-James%20and%20Niels%20_%20Microsoft%20Teams.png%22%20style%3D%22width%3A%20647px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F212753iB9A218E9D1BEB7F6%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%222020-08-17%2016_22_41-James%20and%20Niels%20_%20Microsoft%20Teams.png%22%20alt%3D%222020-08-17%2016_22_41-James%20and%20Niels%20_%20Microsoft%20Teams.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3EOur%20on-prem%20route%20was%20not%20inside%20this%20text%20file%20-%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3COL%3E%3CLI%3EWe%20could%20manually%20add%20the%20on-prem%20route%20to%20this%20file%20and%20our%20P2S%20VPN%20would%20be%20able%20to%20then%20contact%20on-premise%20-%20However%20we%20needed%20a%20way%20to%20always%20include%20this%20route%2C%20as%20if%20a%20new%20user%20installs%20this%20(or%20you%20deploying%20to%20a%20lot%20of%20users)%20it%20would%20make%20sense%20to%20try%20have%20it%20in%20there%20before.%26nbsp%3B%3C%2FLI%3E%3CLI%3ETo%20then%20include%20our%20route%20automatically%20we%20advertised%20the%20route%20(with%20the%20local%20IP%20of%20the%20on-prem)%20to%20the%20Virtual%20Network%20gateway.%20To%20do%20this%3A%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3COL%3E%3CLI%3EConnect%20to%20Azure%20PowerShell%20(I%20use%20cloud%20shell%20as%20work%20in%20different%20tenants)%26nbsp%3B%3C%2FLI%3E%3CLI%3ERun%20the%20following%20below%3A%26nbsp%3B%3C%2FLI%3E%3C%2FOL%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CPRE%20class%3D%22lia-code-sample%20language-bash%22%3E%3CCODE%3E%24gw%20%3D%20Get-AzVirtualNetworkGateway%20-Name%20%3CNAME%20of%3D%22%22%20gateway%3D%22%22%3E%20-ResourceGroupName%20%3CNAME%20of%3D%22%22%20resource%3D%22%22%20group%3D%22%22%3E%0A%0ASet-AzVirtualNetworkGateway%20-VirtualNetworkGateway%20%24gw%20-CustomRoute%20xx.xx.xx.xx%2Fxx%20%3C%2FNAME%3E%3C%2FNAME%3E%3C%2FCODE%3E%3C%2FPRE%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20took%20about%205%20mins%20to%20run.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EOnce%20it%20has%20run%2C%20we%20deleted%20the%20current%20VPN%20on%20the%20machine%2C%20downloaded%20the%20new%20VPN%20profile%20and%20installed%20it.%20When%20we%20then%20checked%20the%20txt%20file%2C%20the%20new%20route%20was%20inside%20of%20the%20.txt%20file.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThis%20article%20helped%20me%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-p2s-advertise-custom-routes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fvpn-gateway-p2s-advertise-custom-routes%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps%20someone%20who%20comes%20across%20the%20same%20problem%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAdam.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1592688%22%20slang%3D%22en-US%22%3EOn-prem%20connect%20with%20S2S%20VPN%20to%20Azure%20-%20Mobile%20users%20on%20P2S%20to%20Azure%20cannot%20connect%20to%20on-prem%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1592688%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20taking%20your%20time%20to%20read%20this%20if%20you've%20got%20this%20far%26nbsp%3B%3A)%3C%2Fimg%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSTRONG%3ECURRENT%20SETUP%3C%2FSTRONG%3E%3CBR%20%2F%3EWe%20have%20a%26nbsp%3B%3CSTRONG%3Eon-prem%3C%2FSTRONG%3E%20network%20that%20is%20connected%20to%20Azure%20using%20a%26nbsp%3B%3CSTRONG%3ESite%20to%20Site%3C%2FSTRONG%3E%20%3CSTRONG%3EVPN%20%3C%2FSTRONG%3E%26nbsp%3B%3CBR%20%2F%3EOn-prem%20can%20communicate%20with%20Azure%2C%20and%20Azure%20back%20to%20on-prem.%20No%20worries.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20mobile%20users%20(out%20of%20the%20office%20where%20the%20above%20S2S%20is%20configured)%20that%20connect%20to%20Azure%20using%26nbsp%3B%3CSTRONG%3EPoint%20to%20Site%20VPN%3C%2FSTRONG%3E.%20-%20Point%20to%20Site%20users%20can%20access%20Azure%20no%20worries.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EPROBLEM%26nbsp%3B%3CBR%20%2F%3E%3C%2FSTRONG%3EUsers%20that%20are%20using%20the%26nbsp%3B%3CSTRONG%3EP2S%20VPN%3C%2FSTRONG%3E%20cannot%20communicate%20through%20the%20VPN%20down%20to%20the%20on-prem%20network%20resources%20(which%20are%20connected%20using%26nbsp%3B%3CSTRONG%3ES2S%20VPN%26nbsp%3B%3C%2FSTRONG%3Eas%20described%20above.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E---------------------%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20something%20obvious%20that%20is%20missing%3F%26nbsp%3B%20We%20have%20not%20put%20in%20a%20route%20table%2C%20we%20have%20not%20set%20any%20static%20routes%20either.%26nbsp%3B%20As%20per%20this%20article%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fwork-remotely-support%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvpn-gateway%2Fwork-remotely-support%3C%2FA%3E%26nbsp%3B%3CSTRONG%3EScenario%202%3C%2FSTRONG%3E%20-%20We%20would%20assume%20it%20would%20just%20work%2C%20but%20I%20am%20guessing%20we%20need%20to%20add%20some%20sort%20of%20static%20route%20somewhere.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EJust%20not%20sure%20where%20I%20should%20be%20looking%20to%20be%20able%20to%20communicate%20all%20the%20way%20through%20from%20mobile%20user%20on%20P2S%20to%20on-prem%20connect%20via%20S2S.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1592688%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Evpn%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Contributor

Hello 

 

Thanks for taking your time to read this if you've got this far :) 

CURRENT SETUP
We have a on-prem network that is connected to Azure using a Site to Site VPN  
On-prem can communicate with Azure, and Azure back to on-prem. No worries. 

 

We have mobile users (out of the office where the above S2S is configured) that connect to Azure using Point to Site VPN. - Point to Site users can access Azure no worries. 

 

PROBLEM 
Users that are using the P2S VPN cannot communicate through the VPN down to the on-prem network resources (which are connected using S2S VPN as described above. 

---------------------

 

Is there something obvious that is missing?  We have not put in a route table, we have not set any static routes either.  As per this article https://docs.microsoft.com/en-us/azure/vpn-gateway/work-remotely-support Scenario 2 - We would assume it would just work, but I am guessing we need to add some sort of static route somewhere. 

Just not sure where I should be looking to be able to communicate all the way through from mobile user on P2S to on-prem connect via S2S.

1 Reply
Highlighted
Best Response confirmed by Adam Weldon-Ming (Contributor)
Solution

I was able to figure this out in the end: 

 

Once you download the P2S (Client) VPN Config file from the Azure Portal, and install it to set up your P2S VPN.

You're able to see that the routes that Azure VPN can connect to by finding this TXT file in: 

%appdata%\Microsoft\Network\Connections\Cm\<some id>\routes.txt 
 
2020-08-17 16_21_08-James and Niels _ Microsoft Teams.png
 
2020-08-17 16_22_41-James and Niels _ Microsoft Teams.png
 
Our on-prem route was not inside this text file - 
 
  1. We could manually add the on-prem route to this file and our P2S VPN would be able to then contact on-premise - However we needed a way to always include this route, as if a new user installs this (or you deploying to a lot of users) it would make sense to try have it in there before. 
  2. To then include our route automatically we advertised the route (with the local IP of the on-prem) to the Virtual Network gateway. To do this: 

    1. Connect to Azure PowerShell (I use cloud shell as work in different tenants) 
    2. Run the following below: 

 

$gw = Get-AzVirtualNetworkGateway -Name <name of gateway> -ResourceGroupName <name of resource group>

Set-AzVirtualNetworkGateway -VirtualNetworkGateway $gw -CustomRoute xx.xx.xx.xx/xx 

 

This took about 5 mins to run. 

Once it has run, we deleted the current VPN on the machine, downloaded the new VPN profile and installed it. When we then checked the txt file, the new route was inside of the .txt file. 


This article helped me: https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-p2s-advertise-custom-routes

 

Hope this helps someone who comes across the same problem :) 

 

Adam.