data:image/s3,"s3://crabby-images/da148/da1480f8128506fa9e2d97b4b110c94fd7c43333" alt=""
Hello and welcome to today’s post! In this one, I will show how to create a Site-to-Site connection between an Azure Network and one that is On-Prem.
In order to complete these following steps, you will need to have some prerequisite:
- An Azure Virtual Network
- An Azure Windows Virtual Machine
- An up and running Windows Server
This is the plan for today’s post:
- Part 1: Create a Gateway subnet
- Part 2: Create a Network Gateway
- Part 3: Create a Local Network Gateway
- Part 4: Configure Server for connection
- Part 5: Create an Azure connection and verify connectivity
Part 1: Create a Gateway subnet
- Go to your Azure Virtual Network page. Under settings, click subnets.
- Click + Gateway subnet.
data:image/s3,"s3://crabby-images/b12f2/b12f2f935718c94148849e5526ecd34d559fe0be" alt=""
- Enter a subnet address range and click Save.
data:image/s3,"s3://crabby-images/d685e/d685e8045c2757b9115846e509952d14e669308d" alt=""
Part 2: Create a Network Gateway
- In the search bar, enter virtual network gateways and click on the choice given as shown below.
data:image/s3,"s3://crabby-images/d7e19/d7e194365f9fc0c2b97aa75607693abc9bbeb398" alt=""
- Click Create.
data:image/s3,"s3://crabby-images/a2a48/a2a4838aa269487c57adba721bb2d5b819e2feca" alt=""
- Enter the Name for the gateway.
- In the SKU field, enter VpnGw1.
- In the Virtual network field, select the appropriate network that you want to connect. That network is the same that contains the Gateway subnet that we created earlier.
data:image/s3,"s3://crabby-images/58497/5849702643054183a1afc6315ed6a563c867be8c" alt=""
- In the Public IP address field select Create new.
- In the Public IP address name, enter a name recognizable name.
- Click Review + Create, then Create.
data:image/s3,"s3://crabby-images/5b510/5b510b51634ac67a77dd12170e11e1306735feb5" alt=""
Part 3: Create a Local Network Gateway
- In the search bar, type Local network gateways as shown below.
data:image/s3,"s3://crabby-images/6af50/6af50fd0f463d29765d909527fa85cf9281fa1d4" alt=""
- Click Create
data:image/s3,"s3://crabby-images/b12b2/b12b2a24d59a0cc5d7ebcc940642bd5869bbc3c3" alt=""
- Enter Name.
- Enter the IP address of your Router.
- Enter the Address Space of you local network.
- Click Review + Create, then Create.
data:image/s3,"s3://crabby-images/14ad1/14ad10fde6e1484f77ce35d6f92fe56d2ec056b4" alt=""
Part 4: Configure Server for connection
Part 4.a: Add Remote Access feature
- In your server manager dashboard top bar, click Manage then Add Roles and Features.
data:image/s3,"s3://crabby-images/d97bd/d97bdaf55d82fbd00e1df08a67c11c35f08c955b" alt=""
- Click Next until the Server Roles page then check Remote Access.
- Click next until you get to Select Role services page.
data:image/s3,"s3://crabby-images/604e4/604e42afe1a3fccb25532417f23175a942a305d5" alt=""
- Check Routing. (DirectAccess and VPN (RAS) will be automatically selected.)
data:image/s3,"s3://crabby-images/44362/4436200258a14ef8dde12a6815b5c46431449781" alt=""
- Click Add Features then click next until you get to the confirmation page.
data:image/s3,"s3://crabby-images/6e0bd/6e0bd3688c846511129053f41e7602be36c86b74" alt=""
- Click Install
data:image/s3,"s3://crabby-images/63b25/63b25a4e23f99a974a0b66a079ffc62d1fd79ab0" alt=""
- When the installation is complete, click Close.
data:image/s3,"s3://crabby-images/1b139/1b1396ff365a15bbcef27685eb647e9bb42a4190" alt=""
Part 4.b: Configure Routing and Remote Access
- On the top bar of the server manager, click Tools, then Routing and Remote Access.
data:image/s3,"s3://crabby-images/0622f/0622f81c8f40848532a0e797a8dac90e7b8ce0cb" alt=""
- On the Routing and Remote Access, right click on the Server icon then click Configure and Enable Routing and Remote Access.
data:image/s3,"s3://crabby-images/50a0b/50a0b26f499022c27e3b387e569e0ef317e151ac" alt=""
- Select Custom configuration, then click next.
data:image/s3,"s3://crabby-images/f1d19/f1d19982e3bd3b32c00dc1aa5215c03373fdc559" alt=""
- Check VPN access and LAN routing then click next.
data:image/s3,"s3://crabby-images/a6e35/a6e358b328d11de8b90abc8a65fe240331ae11b4" alt=""
- Click Finish.
data:image/s3,"s3://crabby-images/6d0d3/6d0d3158bf79bc663a020cee3289982cc783484b" alt=""
- Click Start service.
data:image/s3,"s3://crabby-images/7afe3/7afe3d24ebde35400b994e6252637a20c8f28f55" alt=""
Part 4.c: Create a new Network Interface
- Back on the Routing and Remote Access window, right click Network Interface, then New Demand-dial Interface.
data:image/s3,"s3://crabby-images/70549/70549fc8846ef4c0316f28105fe5de031bc86cb8" alt=""
- Enter a Name for the interface then click next.
data:image/s3,"s3://crabby-images/290a8/290a804bc40b23ee847d99af6e4d092aeee20e07" alt=""
- Select Connect using virtual networking (VPN) then click Next.
data:image/s3,"s3://crabby-images/3540a/3540aeebf0cf66eafb89f7ab91a74a37206913c0" alt=""
- Select IKEv2 then click next.
data:image/s3,"s3://crabby-images/bb919/bb919c1bf7972dce029defb4ee4eb1857596992c" alt=""
- Enter the public IP address of the Virtual Network Gateway that we created earlier then click Next.
data:image/s3,"s3://crabby-images/12b23/12b23695904c0dd095b478d512f2cd52c6ec2bd4" alt=""
- Check Route IP packets on this interface, then Next.
data:image/s3,"s3://crabby-images/d43dd/d43ddc9051b5002d267597c3a0b391619827fda0" alt=""
- Click Add.
data:image/s3,"s3://crabby-images/8d567/8d56720655d2f7399c21e684cefbe27cfcf99927" alt=""
- Enter the Cloud Destination address and Mask.
- Enter 10 for Metric, then click OK. (Metric specifies the priority)
data:image/s3,"s3://crabby-images/dcf10/dcf105a571a970a585f4c32b81a872f3f4484142" alt=""
- Click Finish
data:image/s3,"s3://crabby-images/78e1e/78e1eb29e38addfe1269a243c7efeab246e73931" alt=""
- Right Click on the newly created interface, then click Properties.
data:image/s3,"s3://crabby-images/03935/03935b0c350ee187a770bab94613d40eb9e4a042" alt=""
- In the Option tab, select Persistent connection
data:image/s3,"s3://crabby-images/28376/28376d5c358acad80bcc1bca2be0c8808d1a8144" alt=""
In the Security tab, select Use preshared key for authentication and enter a Key that we will use later, then click OK.
data:image/s3,"s3://crabby-images/47541/4754145555ea95f5a88339d5dea51202efc57dda" alt=""
Part 5: Create an Azure connection and verify connectivity
- Back in Azure, search for Connections.
data:image/s3,"s3://crabby-images/913f0/913f0473575598d9c38fa5ca5a4e78f60e1b2e01" alt=""
- Click Create
data:image/s3,"s3://crabby-images/fec27/fec279f7468a89e06ffab8d19511f34e22212e30" alt=""
- Select Site-to-site (IPsec) for Connection type.
- Enter a Name for the connection and click Next.
data:image/s3,"s3://crabby-images/68274/68274ddc6c32a8c36e0eddc6e7061f832cfed221" alt=""
- Select the appropriate Virtual network gateway and Local network gateway that we created at the beginning.
- In the Shared key field, enter the Preshared Key that we created earlier and click Review + create, then Create.
data:image/s3,"s3://crabby-images/e4276/e4276d5781f8a369cc05f2f472028121f797c8e0" alt=""
- After the deployment is complete, click Go to resource.
data:image/s3,"s3://crabby-images/d5be5/d5be5526405645591bff3203c1759c49f72e1620" alt=""
- Notice the status says Not Connected.
data:image/s3,"s3://crabby-images/56eaa/56eaa0bad19a55b085bdc172550c067527740ec1" alt=""
Back in the Server manager Routing and Remote Access window, right click the Interface that we created earlier and click Connect.
data:image/s3,"s3://crabby-images/b4b1f/b4b1f8afc1e37e7f58e701223d09386586e123fa" alt=""
data:image/s3,"s3://crabby-images/4fd1d/4fd1d579d27eb1029c9119fde1747d1ab20d3fc0" alt=""
- Back in the Connection page on Azure, click Refresh and notice the status says Connected. (It might take a few minutes to update).
data:image/s3,"s3://crabby-images/a2bee/a2bee644c1a6034d07d6c5f209bb1bcca8b17c8c" alt=""
- Test the connection by Pinging the cloud machine with its private IPv4 address to test the connection. (Make sure the cloud machine firewall allows Pings from the internal network.)
data:image/s3,"s3://crabby-images/b267f/b267fc9822aeccf87f9543dd2f65fb8eb608cf93" alt=""
This wraps up this post on Setting up a Site-to-Site connection between an on-prem network and an Azure network.
Thank you for reading!
'IT이야기 > Azure' 카테고리의 다른 글
Azure 가상 네트워크 피어링 개요 (0) | 2024.12.13 |
---|---|
Azure Routing Table: Azure Route & Next-Hop Types (0) | 2024.12.12 |
Azure VMware Solution (AVS) Deep Dive (0) | 2024.12.04 |
The 7 R Considerations for Migration – Modernization process (4) | 2024.12.03 |
Azure Virtual Desktop에 대한 Zero Trust 보안 모델 구현 (1) | 2024.12.03 |