Skip to content

Conversation

@brsteel
Copy link
Contributor

@brsteel brsteel commented Oct 10, 2025

Adds S2S VPN gateway add-on with forced tunneling through Azure Firewall. Key items: active-active VNet gateway (VpnGw2), local network gateway + IPsec connection, static route tables (vgw + hub overrides) enforcing firewall inspection, peerings updated for gateway transit, default VGW-OnPrem firewall rule group (override via customFirewallRuleCollectionGroups). Refactor replaces monolithic retrieve-existing.bicep with firewall-info, vnet-info, subnet-info, collect-spoke-addresses modules; removes BCP318 warnings. Expanded README: routing rationale, security, operations, custom rule examples (HTTPS only, deny-before-allow). Validation: successful what-if + deployment in usgovvirginia; expected resources present. Fixes #1235.

@brsteel brsteel requested a review from a team as a code owner October 10, 2025 18:46
Copy link
Contributor

@sedmonds22 sedmonds22 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approving

@sedmonds22 sedmonds22 merged commit cf59ec6 into main Oct 10, 2025
2 of 3 checks passed
@sedmonds22 sedmonds22 deleted the issue/1235-vgw-vpn-routing-fix branch October 10, 2025 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

VGW: the added override routes for hub traffic thru VPN breaks spoke routing

3 participants