snagrat Posted April 15, 2016 Posted April 15, 2016 We are looking at creating a DC in Azure which to connect to we need to have a Site-to-Site VPN. The MS tech articles state that the VPN device must have a internet facing IP and not be located behind a NAT. Now I know what NAT is but how would I go about installing the VPN device so it is not behind one? And on a different note, @SchoolsBroadband can we use the Fortinet firewalls to establish a Site-to-Site direct to Azure without the need to buy additional hardware?
plexer Posted April 15, 2016 Posted April 15, 2016 Technically possible to do fortinet to azure http://docs.fortinet.com/uploaded/files/2068/IPsec-VPN-Azure.pdf Ben
SchoolsBroadband Posted April 17, 2016 Posted April 17, 2016 @snagrat yes you 100% can. It's just a site to site ipsec vpn. Quite easy to setup. Call the support guys or alternatively why not beta test our iaas/ vm platform to do the same thing? No need for vpns. It's all layer 2 and on net! Dave
Tallwood_6 Posted April 17, 2016 Posted April 17, 2016 Lol love the number of providers who are now doing supposed iaas. In reality there are about 5 providers doing true iaas everyone is is just doing offsite virtualization.
Tallwood_6 Posted April 17, 2016 Posted April 17, 2016 Phone up schools broadband get them to sort out the site to site VPN and be glad that in 5 years you are still with an iaas, saas and pass provider that is still going if that's where your backups are. 1
snagrat Posted April 17, 2016 Author Posted April 17, 2016 @snagrat yes you 100% can. It's just a site to site ipsec vpn. Quite easy to setup. Call the support guys or alternatively why not beta test our iaas/ vm platform to do the same thing? No need for vpns. It's all layer 2 and on net! Dave Thanks Dave, I'll drop Support an email and get them on it. 1
SchoolsBroadband Posted April 17, 2016 Posted April 17, 2016 Interestingly you can also run a Fortinet vm on azure if you wanted to protect your remote servers in the same way as our lan with them. Email your account manager if you want pricing. Thanks Dave
snagrat Posted April 17, 2016 Author Posted April 17, 2016 Going back to my original question, as not all the schools use SchoolsBroadband yet. How would I install a device so it is not behind a NAT. Would I need to use another port on the router so it has an Internet facing IP?
SchoolsBroadband Posted April 18, 2016 Posted April 18, 2016 Yes. It's been a little while since I've done it but you can still do an IPSEC to IPSEC tunnel with one end behind NAT so long as it makes the initial outgoing connection, you use aggressive mode in the setup and you port forward the required ports such as 500 for IKE key exchange. If your default gateway isn't going to be the IPSEC terminator then you'll also have to put in static routes on each PC or a static route on the current gateway device to point to the IPSEC gateway device for the remote IP subnet otherwise it won't work too. Thanks Dave
snagrat Posted June 6, 2016 Author Posted June 6, 2016 Unfortunately this is proving hard than first though. SchoolBroadband seem to be having trouble getting the VPN to Azure working. As such my trial has nearly expired and not had nothing to test out yet! SWGfL have managed to get theirs connected and successfully testing that on another trial
Tallwood_6 Posted June 6, 2016 Posted June 6, 2016 Not sure what firewall your using but I found watchguard had a setup guide on there support site which I just passed to our firewall guys
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now