OPNsense Forum

Archive => 19.7 Legacy Series => Topic started by: bigops on August 19, 2019, 04:34:57 am

Title: [Solved] Is Azure S2S VPN Broken??
Post by: bigops on August 19, 2019, 04:34:57 am
I have been trying to setup a routed VPN to Azure with no success whatsoever.  I followed the steps given in https://docs.opnsense.org/manual/how-tos/ipsec-s2s-route-azure.html.  The tunnel is shown as UP from both Azure side and Opnsense side.  But not traffic is flowing in the tunnel.  I am not able to RDP into any servers in Azure. 

If I change the VPN type from Routed to Policy based VPN then there is no issue and everything works as expected. 

When I check the traffic in the tunnel interface it shows as zero. 

Has anyone been able to get Azure working in t he latest firmware?
Title: Re: Is Azure S2S VPN Broken??
Post by: bigops on August 19, 2019, 11:59:20 pm
Hi

Does anyone have faced this issue with OPNsene on configuring a s2s tunnel to azure?
Title: Re: Is Azure S2S VPN Broken??
Post by: mimugmail on August 20, 2019, 06:44:34 am
Set outbound Nat to manual and add the rules you need for internet access etc.
Title: Re: Is Azure S2S VPN Broken??
Post by: bigops on August 24, 2019, 07:19:14 pm
Hi

Thanks for the reply.  Could you please specify on what the configuration for outbound nat should be?
Title: Re: Is Azure S2S VPN Broken??
Post by: mimugmail on August 24, 2019, 07:26:13 pm
If you have none then just your LAN, direction any on Interface WAN
Title: Re: Is Azure S2S VPN Broken??
Post by: bigops on August 26, 2019, 02:45:47 pm
That worked like a charm.  Now I am able to connect to Azure from my on premises systems.   Thanks for helping out

So it appears that there is indeed a bug in OpnSense when Azure is configured as the NAT rules get automatically generated.   

Is there a fix in the horizon where we do not need to manually change the configuration?  Else it may be a good idea to get the configuration guide updated.
Title: Re: [Solved] Is Azure S2S VPN Broken??
Post by: mimugmail on August 26, 2019, 04:17:54 pm
https://github.com/opnsense/docs/pull/195/files
Title: Re: [Solved] Is Azure S2S VPN Broken??
Post by: mimugmail on August 27, 2019, 02:08:32 pm
Sorry, can you test this patch?
https://github.com/opnsense/docs/pull/195#issuecomment-525269417
Title: Re: [Solved] Is Azure S2S VPN Broken??
Post by: bigops on August 31, 2019, 02:52:06 pm
I updated to 19.7.3 and it seems to have solved the issue
Title: Re: [Solved] Is Azure S2S VPN Broken??
Post by: mimugmail on September 01, 2019, 07:26:48 am
Hooray  8)