route table related to site-to-site vpn between on-prime and azure

Gongya Yu 190 Reputation points
2024-07-19T01:39:50.88+00:00

VPN-Topo

I have the topology above.
With the express router, I can see its route table with prefixes from both azure and on-prime, prefixes to on-prime with next-hop being on-prime bgp peer IP and prefixes to azure with next-hop being VGW peer IP. It seems automatic mutual-redistribution between azure and on-prime.

How does this work for site-to-site VPN?
I got VPN up and bgp up, but I can see VGW bgp peer table with the prefixes from on-prime.
vpn-bgp

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,543 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 46,016 Reputation points Microsoft Employee
    2024-07-19T05:09:47.38+00:00

    @Gongya Yu ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    From your verbatim, I see

    • You have a VPN Gateway in a HubVNET and this VNET is peered to multiple spokes.
    • You checked the BGP Peering view of the HubVNET and you do not see the VNET Spokes being advertised
    • But from a NVA in the HubVNET , you are able to see the routes for peered VNETs.

    Summary :

    • Seeing the NIC Effective routes in NVA and the VPN Gateway learned routes are not all related and you should not compare these two.
    • From the spokes, did you enable Gateway Transit on the peerings between the Spokes and the Hub?
    • Also your OnPrem should accept the traffic selector when Azure initiates a connection.

    Cheers,

    Kapil


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.