Understand how to configure an Azure site-to-site VPN tunnel between an Azure Private Network and Secure Access.
Overview of Azure Site to Site VPN
An Azure site-to-site (S2S) VPN tunnel between an Azure Virtual Network and Secure Access supports the following:
-
Tunnel redundancy with high availability for branch site connections to Secure Access and your Azure virtual network. For more information, refer to Tunnel throughput, capacity, and scaling and Failover for Branch Connections in Secure Access Data Centers.
-
Connection over IPsec (Internet Protocol Security) with authentication negotiated and traffic encrypted by IKEv2 (Internet Key Exchange, version 2). For more information, refer to Supported IPsec Parameters.
-
Static or dynamic (BGP) routing. For more information, refer to Routing Options and Guidelines.
Microsoft Azure supports several methods of connecting to its VPN Gateway. The S2S VPN topology depends on components configured in the following order. Components in the diagram are numbered by order of configuration.
-
An Azure virtual network with a VPN gateway in active-active mode for tunnel redundancy. In active-active mode, Azure provides two VPN gateway IPs that Secure Access can use to establish a network tunnel group. Traffic will use the primary tunnel. In the event of a tunnel failover, the switch to the secondary tunnel will be automatic, immediate, and without interruption.
-
A Secure Access network tunnel group with two IPsec/IKEv2 tunnels and a pre-shared key (PSK) for connection with the Secure Access cloud native head end (CNHE) service.
-
Two local network gateways in Azure that establish S2S connections between the Azure VPN Gateway client and the Secure Access DC.
-
Branch and internet routing.
-
The static routing use case requires an Azure VPN Gateway route table.
-
The dynamic routing use case requires an Azure VPN Gateway autonomous system number (ASN) and Azure local network gateway BGP peer IP addresses.
-
For more information about VPN and tunnels in Secure Access, refer to Manage Virtual Private Networks and Manage Machine Tunnels.
By default, the Perfect Forward Secrecy (PFS) setting is disabled in the Azure VPN portal; because the PFS is disabled, the Azure gateway client does not process the full proposal list as required by RFC 7296 when Secure Access is the platform to intiate the Child SA rekey. As a result the entire exchange is rejected and the CHILD SA rekey experiences a retry loop for a significant amount of time while the tunnel data plane is still active.
To safely incorporate the CHILD SA rekey we recommend following one of the following alternative configurations:
Shorten the Azure CHILD SA lifetime. In the Azure dashboard navigate to and select your connection, then select IPsec / IKE policy. Locate the Default setting to Custom and then change the IPsec SA lifetime in seconds value to <3000.
Configure an alternate PFS setting. In the Azure dashboard navigate to and select your connection, then select IPsec / IKE policy. Locate the Default setting to Custom and then change the PFS value. For example, set the new PFS value to a DH group.
More Information
For more information about Azure, refer to Microsoft documentation:
Microsoft may update their documentation without notice.