Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I understand that your S2S Connection gets established only when you set the Gateway as Responder only.
LNG is a virtual representation of your OnPremise Network.
- This means, this should ideally contain the on prem network address range
- To address your query, "LNG is sending all of the routes listed in the route table, plus all of the vnets that peer with the vnet the vpn gateway is connected to"
- This is incorrect
- VPN Gateway would send the address range of VNET where it is deployed, and the VNETs peered to this VNET to OnPrem
- LNG would not send anything, the actual OnPrem device is the one that would send the configuration settings.
NOTE : A VPN gateway accepts any traffic selectors proposed by a remote gateway (on-premises VPN device). This behavior is consistent among all connection modes (Default
, InitiatorOnly
, and ResponderOnly
).
If you use your own Custom IPsec/IKE policy with Azure VPN, you must make sure whatever policy you define is supported in the OnPrem device as well.
If you find that in this case, the connection is not getting established,
- You can leverage VPN Gateway diagnostic logs
- Especially, "IKEDiagnosticLog"
Cheers,
Kapil