Hello Guys,
Seek assistance in understanding how we can establish routes from our partner firewall to our Checkpoint firewall through an IPsec tunnel.
In our current environment, we have deployed the Checkpoint firewall on an Azure VM, and the subnets of our internal office locations are connected to an ISP SDWAN. The ISP SDWAN router is further connected to Azure Express Route.
We have successfully configured an IPsec tunnel between our Checkpoint firewall and the partner location. When accessing the partner subnets via the IPsec tunnel from our Azure Vnets, everything works flawlessly without any issues.
However, we have encountered a problem when attempting to announce the 3rd party partner subnet in Azure Express Route to the ISP SDWAN router. The routes are not being distributed between the ISP SDWAN and Azure Express Route. Consequently, any user trying to connect to the partner subnet from office location they experiences dropped traffic at the ISP SDWAN router. Even manually announcing the partner router in the ISP SDWAN router does not resolve the issue. Azure ExpressRoute follows a specific route propagation mechanism and only advertises the subnets associated with Azure resources.When using Azure ExpressRoute, the route propagation is typically automatic and based on the route filters and route table associations configured in Azure.
To address these challenges, we kindly request assistance in clarifying the following queries:
1. Is it possible to configure BGP peering and learn subnets in a policy-based VPN?
2. We currently have a policy-based VPN configuration. Is it feasible to convert it to a route-based VPN and establish BGP? If so, would this impact our existing traffic?
3. What are your thoughts on establishing a GRE tunnel between the Checkpoint and the partner in order to establish BGP peering and learn the subnets?
Our goal is to enable our office location subnets to connect with 3rd party partner subnets via the Checkpoint IPsec tunnel, following the path: Office Router -> ISP SDWAN Router -> Azure -> Checkpoint -> 3rd Party Server.
We planned to deploy Azure Route server (ARS), how effective that ?
We would greatly appreciate your guidance and expertise in finding a suitable solution for this traffic routing challenge.
Thank you in advance for your support.