Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Complex (to me) network redirections: Azure, Site-to-site, MPLS, Static route

Hi everyone,

I'm trying to do something new to me, and I'm loosing in it...

I'm trying Windows Virtual Desktop so with a partner have configured vpn site-to-site from my main office to Azure. It's works as aspected, I can ping from my local network to azure network and vice versa.

The complex start here: in my main office I got two ftth, one configured in MPLS and other "simple" with a static ip (the one with che vpn configured), we have other two branches offices, both over the MPLS. I need to let communicate azure subnet its with two branche offices.
In the vpn site-to-site configuration I've added the two subnet as local.
The three sites can communicate each other without problems over mpls.
In the main office, where the XG is, I have asymmetric rules configured.

I have asked to the MPLS provider to add a static route to their routers to point azure subnet to consider next hop the ip of my LAN interface's XG firewall.

Actually if I try to trace route from branch office to azure host the trace reach correctly the ip of XG but after that the packets start to drop.

Any idea/suggestions?

Thanks
Fabio



This thread was automatically locked due to age.
Parents Reply
  • Hi Toni, many thanks for your quick answer! I'm trying to understand hot to implements what you indicated, but if I don't misunderstood I should add BGP settings to BO offices's routers and that is not possibile cause those routers are managed by ISP... I attach a simple picture of the diagram of my network environment:

Children