ConfigShot: Configuring UDM SE with Azure Active-Active VPN Gateway

ConfigShot: Configuring UDM SE with Azure Active-Active VPN Gateway
Photo by Edgecore Marketing Team @ HsinChu, Taiwan

Recently, there happened to be an oppotunity to set up a network environment locally. Here's a post of the process of building it using UDM SE and Azure VPN Gateway

Environment

  • Dream Machine Special Edition (UDM SE)
    • UniFi OS 4.2.12
  • Azure VPN Gateway
    • SKU: VpnGW1
    • Enable Active-Active mode
    • Disable BGP
    • Location: TaiwanNorth

About Active-active Azure VPN Gateways

Active-active Azure VPN gateways

Regarding the setup and configuration of Azure VPN Gateway, please refer to the following article links.

  1. Create a Azure VPN Gateway
Tutorial – Create & manage a VPN gateway – Azure portal - Azure VPN Gateway
In this tutorial, learn how to create and manage an Azure VPN gateway by using the Azure portal.
  1. Create a Local Network Gateway: about configuring UniFi settings
Modify gateway IP address settings: Azure portal - Azure VPN Gateway
Learn how to change IP address prefixes and configure BGP Settings for your local network gateway using the Azure portal.
  1. Configure a site-to-site connection
Tutorial - Create S2S VPN connection between on-premises network and Azure virtual network: Azure portal - Azure VPN Gateway
In this tutorial, you learn how to create a VPN Gateway site-to-site IPsec connection between your on-premises network and a virtual network.

Set up Site-to-Site VPN on UniFi

Since I chose to use the Active-Active mode for Azure VPN Gateway, there will be 2 Azure Public IPs available for the UniFi WAN IP to establish IPsec connections. Therefore, the diagram below will show 2 IPsec connections that need to be configured.

site-to-site vpn view

Since Azure VPN Gateway supports ECMP (Equal-cost multi-path routing) in Active-Active mode, the Route Distance in both connections can remain the same value (30) here.

1st IPsec Connection Setup

1st IPsec Connection

2nd IPsec Connection Setup

Connectivity Result

deadman

Phil's memo

Unifi's interface is really well-designed; just a few clicks and it's done. Recently, in studying the 6GHz deployment methods, it is currently believed that those are quite similar to the deployment methods of 5GHz