Simultaneous VPN termination to Azure FortiGate VM - GLB and ILB
Hello,
We have an HA pair of FortiGate VM04s in our Azure development environment that we are using to test for a redesign. The FortiGates were built with the "ELB/ILB Sandwich", as Azure/Fortinet documentation outlines. We also have a GLB placed in front of the ELB, in order to gain the flexibility a global IP provides. The backend IP of the GLB is the single ELB public IP.
We have tested the following successfully:
- We can terminate an IPSec VPN to the ELB, directly connected to the two outside FortiGate vNICs
- We can terminate an IPSec VPN to the GLB
However, we have not been able to successfully terminate separate VPN tunnels to the GLB and ELB simultaneously. The ability to do so would greatly ease our cutover process, as we currently have a standalone FortiGate-VM in production with a regional IP and dozens of vendor IPSec tunnels terminating to it. If we can prove that it's possible to terminate to the GLB and ELB simultaneously, we can slide our production regional IP over to the prepped ELB + HA stack, and slowly move tunnels over to the GLB, vendor meeting by vendor meeting.
All of this to say, has anybody built a similar setup before? Particularly in regard to simultaneous VPN terminations to a GLB and ELB, upstream from the same FortiGate stack? We'd love to know if it's feasible before we sink any additional hours/days into troubleshooting.
Thank you in advance!
