Spread the word.

Share the link on social media.

Share
  • Facebook
Have an account? Sign In Now

Sign Up

Create your WindowsTechno Community account. It’s free and only takes a minute.

Have an account? Sign In
Continue with Facebook
Continue with Google
or use

Have an account? Sign In Now

Sign In

Continue with Facebook
Continue with Google
or use

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Continue with Facebook
Continue with Google
or use

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

WindowsTechno Community

WindowsTechno Community Logo WindowsTechno Community Logo

WindowsTechno Community Navigation

  • Home
  • About Us
  • Write For Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • About Us
  • Write For Us
Home/ Questions/Q 511
Next
Anonymous
  • 0
Anonymous
Asked: February 16, 20232023-02-16T00:44:20+05:30 2023-02-16T00:44:20+05:30In: Others

Azure Site to Site VPN with Transit Gateway

  • 0

Azure Site to Site VPN with Transit Gatewa

i am new to this networking stuff, been scratching my head over using one Virtual Gateway and one connection to connect to two different VNET that has been peered.

 

 

 

​

 

 

 

https://preview.redd.it/36ouid5c0bia1.jpg?width=621&format=pjpg&auto=webp&v=enabled&s=445bc91d0f0ed02790c3eae89e85698c569b5fff

 

 

 

What I want to achieve:

 

 

 

\- Able to connect from VM C On Prem to VNET-02 VM B passing through VNET-01 and vice versa

 

 

 

What I have done:

 

 

 

* VNET-01 Peered to VNET-02

 

* Traffic to remote virtual network: Allow

 

* Traffic forwarded from remote virtual network: Allow

 

* Virtual network gateway or Route Server: Use this virtual network’s gateway or Route Server

 

* VNET-02 Peered to VNET-01

 

* Traffic to remote virtual network: Allow

 

* Traffic forwarded from remote virtual network: Allow

 

* Use the remote virtual network’s gateway or Route Server

 

* On Prem Router (OpenWRT)

 

* Forwarded Port 500 and 4500 to Libreswan VM to [192.168.7.40](https://192.168.7.40)

 

* Added Static Route:

 

* Target: [10.17.5.0/24](https://10.17.5.0/24)

 

* Gateway: [192.168.7.40](https://192.168.7.40)

 

* Local Network Gateway

 

* Address Spaces: [192.168.7.0/24](https://192.168.7.0/24)

 

* Libreswan VM Con

 

 

 

​

 

 

 

conn some-tunnel

 

authby=secret

 

auto=start

 

dpdaction=restart

 

dpddelay=30

 

dpdtimeout=120

 

ike=aes256-sha1;modp1024

 

ikelifetime=3600s

 

ikev2=yes

 

keyingtries=3

 

pfs=yes

 

phase2alg=aes128-sha1

 

left=[Virtual Gateway Public IP]

 

leftsubnets=10.17.5.0/24

 

right=%defaultroute

 

rightsubnets=192.168.7.0/24

 

salifetime=3600s

 

type=tunnel

 

 

 

What is working:

 

 

 

* VM A on VNET 01 able to ping VM B on VNET 02 and vice versa

 

* On Prem VM C able to ping VM A on VNET 01 and vice versa

 

 

 

What is not working:

 

 

 

* On Prem VM C not able to ping VM B on VNET 02 and vice versa

 

 

 

Additional stuff tried:

 

 

 

* Added another Static Route

 

* Target: [10.17.5.0/24](https://10.17.5.0/24)

 

* Gateway: [192.168.7.40](https://192.168.7.40)

 

* Modified Libreswan Config File

 

* leftsubnets: {[10.17.5.0/24,10.17.4.0/24](https://10.17.5.0/24,10.17.4.0/24)}

 

* Outcome:

 

* When i check [ipsec.services](https://ipsec.services), I can see [10.17.4.0/24](https://10.17.4.0/24) failed to connect to the tunnel.

  • 0 0 Answers
  • 16 Views
  • 0 Followers
  • 0
Share
  • Facebook

    Leave an answer
    Cancel reply

    You must login to add an answer.

    Continue with Facebook
    Continue with Google
    or use

    Forgot Password?

    Need An Account, Sign Up Here
    Continue with Facebook
    Continue with Google

    Sidebar

    Ask A Question

    Stats

    • Questions : 119
    • Answers : 26
    • Posts : 15
    • Comment : 1
    • Best Answers : 4
    • Users : 8
    • Groups : 2
    • Group Posts : 0
    • Popular
    • Comments
    • Tags
    • Vipan Kumar

      DFSR no longer replicates files

      • 1 Comment
    • Vipan Kumar

      Wintel Administrator Interview Questions

      • 0 Comments
    • Vipan Kumar

      What is Active Directory?

      • 0 Comments
    • Vipan Kumar

      Active Directory Domain Services Overview

      • 0 Comments
    • Vipan Kumar

      How to fix the issue with the slow authentication

      • 0 Comments
    • Manoj
      Manoj added a comment Nice explanation ? February 4, 2023 at 11:21 am

    Users

    Shawn Davis

    Shawn Davis

    • 0 Questions
    • 0 Answers
    Manoj Kumar

    Manoj Kumar

    • 0 Questions
    • 0 Answers
    Vipan Thakur

    Vipan Thakur

    • 0 Questions
    • 0 Answers

    Explore

    • Home
    • Questions

    Footer

    © 2023 WindowsTechno. All Rights Reserved
    by WindowsTechno.