vMX100 Azure VPN problems

Timura
Comes here often

vMX100 Azure VPN problems

Hello everyone

 

I am trying to set up vMX100 in Azure.

We have three MX64 firewalls with site-to-site VPN between all of them.

I've set up the vMX100 in Azure and here's the thing.

When I'm in the Dashboard of vMX, I can ping the servers in Azure, gateways of all MXs and all the devices on respective networks. However, the only thing I can ping from a device on any MX64 network or from the MX itself is the gateway of vMX100, nothing else. When I try to ping our AD in Azure for example, it's 100% packet loss.

 

Any ideas?

5 Replies 5
Spooster
Here to help

Hi Timura,

 

Have you checked the Azure routing table? From your description, it looks like you have missed the routes.

PhilipDAth
Kind of a big deal
Kind of a big deal

@Spooster sounds correct to me.

MRCUR
Kind of a big deal

Another vote for the Azure routing table not being set up. It's an easy step to miss or do incorrectly. 

MRCUR | CMNO #12
Timura
Comes here often

Thank you all so much for the replies! I can't yet confirm if it's the route tables (waiting for a good moment to cut off our networks for a while to test it), but I'm pretty sure I forgot to set at least one, so it's almost certain. Just in case it fails even after setting them up, is there any other usual mistake I could've done?

 

Thanks again, I will get back here as soon as I get it running (or fail to do so).

PhilipDAth
Kind of a big deal
Kind of a big deal

Potentially Azure firewall rules.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels