Azure VPN Topology with multi-VRF and BGP
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2019 07:33 AM
Hello
I am looking into extending 2 VLAN separated in 2 VRF's on premise, to Azure using VTI based IKEv2 VPN with 2 routers (Cisco ISR), each connected to different ISP.
please refer to attached drawing...
I am unsure if this is possible - could someone please help on thoughts on this design ?
thanks.
- Labels:
-
ISR 4000 Series
-
Routing Protocols

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2019 10:48 AM
Hello,
I might be off here, but your design looks similar to Azure Stack with multiple clients...
https://docs.microsoft.com/en-us/azure-stack/operator/azure-stack-connect-expressroute?view=azs-1910
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2019 11:20 PM
hmn yes could like a bit like it... but this is like much smaller scale and just the same customer, wanting to connect their on-premise environment to Azure, while still maintaining the same separation between their 2 VRFs.
And they want to use 2 different ISP's (Internet), each connected to a separate router, and then establish VPN tunnels to the 2 separate VNETs/VPN Gateways in Azure with BGP failover...
Anyone tried a similar scenario?
They have ISR 4300 series routers
