{"id":511,"date":"2023-02-16T00:44:20","date_gmt":"2023-02-15T19:14:20","guid":{"rendered":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/"},"modified":"2023-02-16T00:44:20","modified_gmt":"2023-02-15T19:14:20","slug":"azure-site-to-site-vpn-with-transit-gateway","status":"publish","type":"question","link":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/","title":{"rendered":"Azure Site to Site VPN with Transit Gateway"},"content":{"rendered":"<p>Azure Site to Site VPN with Transit Gatewa<\/p>\n<p>i am new to this networking stuff, been scratching my head over using one Virtual Gateway and one connection to connect to two different VNET that has been peered.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#x200B;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>https:\/\/preview.redd.it\/36ouid5c0bia1.jpg?width=621&#038;format=pjpg&#038;auto=webp&#038;v=enabled&#038;s=445bc91d0f0ed02790c3eae89e85698c569b5fff<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>What I want to achieve:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\\- Able to connect from VM C On Prem to VNET-02 VM B passing through VNET-01 and vice versa<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>What I have done:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>* VNET-01 Peered to VNET-02<\/p>\n<p>&nbsp;<\/p>\n<p>* Traffic to remote virtual network: Allow<\/p>\n<p>&nbsp;<\/p>\n<p>* Traffic forwarded from remote virtual network: Allow<\/p>\n<p>&nbsp;<\/p>\n<p>* Virtual network gateway or Route Server: Use this virtual network&#8217;s gateway or Route Server<\/p>\n<p>&nbsp;<\/p>\n<p>* VNET-02 Peered to VNET-01<\/p>\n<p>&nbsp;<\/p>\n<p>* Traffic to remote virtual network: Allow<\/p>\n<p>&nbsp;<\/p>\n<p>* Traffic forwarded from remote virtual network: Allow<\/p>\n<p>&nbsp;<\/p>\n<p>* Use the remote virtual network&#8217;s gateway or Route Server<\/p>\n<p>&nbsp;<\/p>\n<p>* On Prem Router (OpenWRT)<\/p>\n<p>&nbsp;<\/p>\n<p>* Forwarded Port 500 and 4500 to Libreswan VM to [192.168.7.40](https:\/\/192.168.7.40)<\/p>\n<p>&nbsp;<\/p>\n<p>* Added Static Route:<\/p>\n<p>&nbsp;<\/p>\n<p>* Target: [10.17.5.0\/24](https:\/\/10.17.5.0\/24)<\/p>\n<p>&nbsp;<\/p>\n<p>* Gateway: [192.168.7.40](https:\/\/192.168.7.40)<\/p>\n<p>&nbsp;<\/p>\n<p>* Local Network Gateway<\/p>\n<p>&nbsp;<\/p>\n<p>* Address Spaces: [192.168.7.0\/24](https:\/\/192.168.7.0\/24)<\/p>\n<p>&nbsp;<\/p>\n<p>* Libreswan VM Con<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&#x200B;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>conn some-tunnel<\/p>\n<p>&nbsp;<\/p>\n<p>authby=secret<\/p>\n<p>&nbsp;<\/p>\n<p>auto=start<\/p>\n<p>&nbsp;<\/p>\n<p>dpdaction=restart<\/p>\n<p>&nbsp;<\/p>\n<p>dpddelay=30<\/p>\n<p>&nbsp;<\/p>\n<p>dpdtimeout=120<\/p>\n<p>&nbsp;<\/p>\n<p>ike=aes256-sha1;modp1024<\/p>\n<p>&nbsp;<\/p>\n<p>ikelifetime=3600s<\/p>\n<p>&nbsp;<\/p>\n<p>ikev2=yes<\/p>\n<p>&nbsp;<\/p>\n<p>keyingtries=3<\/p>\n<p>&nbsp;<\/p>\n<p>pfs=yes<\/p>\n<p>&nbsp;<\/p>\n<p>phase2alg=aes128-sha1<\/p>\n<p>&nbsp;<\/p>\n<p>left=[Virtual Gateway Public IP]<\/p>\n<p>&nbsp;<\/p>\n<p>leftsubnets=10.17.5.0\/24<\/p>\n<p>&nbsp;<\/p>\n<p>right=%defaultroute<\/p>\n<p>&nbsp;<\/p>\n<p>rightsubnets=192.168.7.0\/24<\/p>\n<p>&nbsp;<\/p>\n<p>salifetime=3600s<\/p>\n<p>&nbsp;<\/p>\n<p>type=tunnel<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>What is working:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>* VM A on VNET 01 able to ping VM B on VNET 02 and vice versa<\/p>\n<p>&nbsp;<\/p>\n<p>* On Prem VM C able to ping VM A on VNET 01 and vice versa<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>What is not working:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>* On Prem VM C not able to ping VM B on VNET 02 and vice versa<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Additional stuff tried:<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>* Added another Static Route<\/p>\n<p>&nbsp;<\/p>\n<p>* Target: [10.17.5.0\/24](https:\/\/10.17.5.0\/24)<\/p>\n<p>&nbsp;<\/p>\n<p>* Gateway: [192.168.7.40](https:\/\/192.168.7.40)<\/p>\n<p>&nbsp;<\/p>\n<p>* Modified Libreswan Config File<\/p>\n<p>&nbsp;<\/p>\n<p>* leftsubnets: {[10.17.5.0\/24,10.17.4.0\/24](https:\/\/10.17.5.0\/24,10.17.4.0\/24)}<\/p>\n<p>&nbsp;<\/p>\n<p>* Outcome:<\/p>\n<p>&nbsp;<\/p>\n<p>* When i check [ipsec.services](https:\/\/ipsec.services), I can see [10.17.4.0\/24](https:\/\/10.17.4.0\/24) failed to connect to the tunnel.<\/p>\n","protected":false},"author":0,"comment_status":"open","ping_status":"closed","template":"","question-category":[28],"question_tags":[],"class_list":["post-511","question","type-question","status-publish","hentry","question-category-others"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Azure Site to Site VPN with Transit Gateway - WindowsTechno Community<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Azure Site to Site VPN with Transit Gateway - WindowsTechno Community\" \/>\n<meta property=\"og:description\" content=\"Azure Site to Site VPN with Transit Gatewa i am new to this networking stuff, been scratching my head over using one Virtual Gateway and one connection to connect to two different VNET that has been peered. &nbsp; &nbsp; &nbsp; &#x200B; &nbsp; &nbsp; &nbsp; https:\/\/preview.redd.it\/36ouid5c0bia1.jpg?width=621&#038;format=pjpg&#038;auto=webp&#038;v=enabled&#038;s=445bc91d0f0ed02790c3eae89e85698c569b5fff &nbsp; &nbsp; &nbsp; What I want to achieve: &nbsp; &nbsp; [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/\" \/>\n<meta property=\"og:site_name\" content=\"WindowsTechno Community\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/\",\"url\":\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/\",\"name\":\"Azure Site to Site VPN with Transit Gateway - WindowsTechno Community\",\"isPartOf\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/#website\"},\"datePublished\":\"2023-02-15T19:14:20+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/community.windowstechno.com\/community\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Questions\",\"item\":\"https:\/\/community.windowstechno.com\/community\/questions\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Azure Site to Site VPN with Transit Gateway\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/#website\",\"url\":\"https:\/\/community.windowstechno.com\/community\/\",\"name\":\"WindowsTechno Community\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/community.windowstechno.com\/community\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/#organization\",\"name\":\"WindowsTechno Community\",\"url\":\"https:\/\/community.windowstechno.com\/community\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg\",\"contentUrl\":\"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg\",\"width\":335,\"height\":101,\"caption\":\"WindowsTechno Community\"},\"image\":{\"@id\":\"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Azure Site to Site VPN with Transit Gateway - WindowsTechno Community","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/","og_locale":"en_US","og_type":"article","og_title":"Azure Site to Site VPN with Transit Gateway - WindowsTechno Community","og_description":"Azure Site to Site VPN with Transit Gatewa i am new to this networking stuff, been scratching my head over using one Virtual Gateway and one connection to connect to two different VNET that has been peered. &nbsp; &nbsp; &nbsp; &#x200B; &nbsp; &nbsp; &nbsp; https:\/\/preview.redd.it\/36ouid5c0bia1.jpg?width=621&#038;format=pjpg&#038;auto=webp&#038;v=enabled&#038;s=445bc91d0f0ed02790c3eae89e85698c569b5fff &nbsp; &nbsp; &nbsp; What I want to achieve: &nbsp; &nbsp; [&hellip;]","og_url":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/","og_site_name":"WindowsTechno Community","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/","url":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/","name":"Azure Site to Site VPN with Transit Gateway - WindowsTechno Community","isPartOf":{"@id":"https:\/\/community.windowstechno.com\/community\/#website"},"datePublished":"2023-02-15T19:14:20+00:00","breadcrumb":{"@id":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/community.windowstechno.com\/community\/question\/azure-site-to-site-vpn-with-transit-gateway\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/community.windowstechno.com\/community\/"},{"@type":"ListItem","position":2,"name":"Questions","item":"https:\/\/community.windowstechno.com\/community\/questions\/"},{"@type":"ListItem","position":3,"name":"Azure Site to Site VPN with Transit Gateway"}]},{"@type":"WebSite","@id":"https:\/\/community.windowstechno.com\/community\/#website","url":"https:\/\/community.windowstechno.com\/community\/","name":"WindowsTechno Community","description":"","publisher":{"@id":"https:\/\/community.windowstechno.com\/community\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/community.windowstechno.com\/community\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/community.windowstechno.com\/community\/#organization","name":"WindowsTechno Community","url":"https:\/\/community.windowstechno.com\/community\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/","url":"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg","contentUrl":"https:\/\/community.windowstechno.com\/community\/wp-content\/uploads\/2023\/02\/WindowsTechnoLogo.jpg","width":335,"height":101,"caption":"WindowsTechno Community"},"image":{"@id":"https:\/\/community.windowstechno.com\/community\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question\/511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question"}],"about":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/types\/question"}],"replies":[{"embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/comments?post=511"}],"wp:attachment":[{"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/media?parent=511"}],"wp:term":[{"taxonomy":"question-category","embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question-category?post=511"},{"taxonomy":"question_tags","embeddable":true,"href":"https:\/\/community.windowstechno.com\/community\/wp-json\/wp\/v2\/question_tags?post=511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}