Hi All,
I think im missing something fundamental here but i cant see where.
I have a vMX in Azure which is configured in VPN concentrator hub mode with 2 auto-vpn spoke sites connected. All good there. The two spoke sites are also connected to umbrella SIG.
The vMX is talking BGP to an azure route server to provide connectivity to back end servers in a handful of azure vnets. This is also working fine for auto-vpn clients at the spokes.
I have now configured the vMX Hub for anyconnect client connectivity which is working fine for access to auto-vpn prefixes (so internal stuff including the servers in azure), but the anyconnect clients cant get any traffic out to the internet via the vMX. I have configured the vMX to push out the SIG DNS servers (and tried it with googles DNS servers also) but it just seems that any internet bound traffic from the clients arrives at the vMX, but doesnt know where to go from there.
I cant see any default routing in the vMX route table either so that may well be the issue but i cant see any way of getting a def route in the route table at all so im at a bit of a loss as to how this is supposed to work.
Can anyone put me right here ? I cant see where to go next.
Cheers
Shaun