I’m not aware that Ip Sec tunnels advertise their routes through second hops. You could add a static route for the Azure subnet on the sattelites, pointing to the 508. You may also have firewall issues on both the satellites and Azure, not allowing exchange from the other.
Yes and no. I love pepvpn and speedfusion but when working with 3rd party vendors this doesn’t always work.
Microsofts best practice for Azure is to connect to it using an “Azure VPN gateway” which supports IPsec and BGP over IPsec. They have a support/compatibly list which the vendors look at and go with when looking to connect customer premises to Azure.
Partners can go in and argue for Peplink to be used instead of a $100 UBNT edge router but can’t win the argument if the tools aren’t even there to let them use Peplink.
Adding dynamic routing for IPsec on Peplink (i imagine) shouldn’t be too tough to do given it is already available over speedfusion, but would give partners a lot more ammo when going in to battle with other providers. Once the peplink devices are in then it makes it easier to sell them on the idea of pepvpn and speedfusion.
We have just gone through this exact situation and ended up having to go with the customer and provider and use a supported IPsec vpn endpoint instead of Peplink devices.
I don’t understand why you can’t write static routes for this?
On B305, destination Azure subnet, gateway B508
On Azure, destination B305 subnet, gateway B508
Once the traffic is routed onto the B508, that device already knows where to send it. As I said you’ll also need to be sure firewall rules on each end also permit the routing.
Hi Masterofabcs, looks like you got this working and that was great. I was just wondering if you know if the Balance 305 works directly with the Azure Virtual Network Gateway.
When I tested I could establish an IPSEC vpn tunnel and use static routing to make it work.
Peplink devices don’t support dynamic routing over IPSEC at the moment though so you can’t leverage the BGP features of the Azure VPN gateway and as such can’t build in redundant links so easily.