I seem to have an issue when we deploy a vMX at Azure.
It spins up without any issues and L2L auto VPN works fine, we deploy AnyConnect VPN at it and can reach all the spokes and hubs from it with no issues.... but....
When you try to reach any Azure resources I can't see the traffic ever leaving any other interface than the AnyConnect VPN interface when I do a packet capture, and the client doesn't get any replies... ( of course )
Is there some routing needed on the vMX to get that to work, or is it so that the 3rd part responsible for Azure setups have missed something in routing on Azure side... ( I don't have access to that part at this customer... )
eg.
Azure anyconnect VPN net 10.1.1.0/23
MX IP at azure ( 1 interface outside ) 10.2.0.4/24
Azure resources 172.16.100.0/24 ( .5 for target for testing)
( yeah fake IP series used for this example 😉 )