VMware SASE Orchestrator supports integration and automation of Azure Virtual WAN from VMware SD-WAN Gateway and VMware SD-WAN Edge to enable Branch-to-Azure VPN Connectivity.
What to read next
Azure Virtual WAN IPsec Tunnel Automation Overview Azure Virtual WAN is a network service that facilitates optimized and automated Virtual Private Network (VPN) connectivity from enterprise branch locations to or through Microsoft Azure. Azure subscribers provision Virtual Hubs corresponding to Azure regions and connect branches (which may or may not be SD-WAN enabled) through IP Security (IPsec) VPN connections.
Prerequisite Azure Configuration Enterprise network administrators must complete the following prerequisite configuration tasks at the Azure portal to ensure that the SASE Orchestrator application can function as the Service Principal (identity for the application) for the purposes of Azure Virtual WAN and SD-WAN Gateway integration.
Configure Azure Virtual WAN for Branch-to-Azure VPN Connectivity This section describes the procedures to configure Azure for integrating Azure Virtual WAN and SD-WAN Gateway to enable the branch-to-Azure VPN connectivity.
Configure SASE Orchestrator for Azure Virtual WAN IPsec Automation from SD-WAN Gateway You can configure SASE Orchestrator for integrating Azure Virtual WAN and SD-WAN Gateway to enable the branch-to-Azure VPN connectivity.
Synchronize VPN Configuration After successful Non SD-WAN Destination provisioning, whenever there are changes in the endpoint IP address of the Azure Hub or static routes, you need to resynchronize Azure Virtual Hub and Non SD-WAN Destination configurations. Clicking the Resync configuration button in the Non-VeloCloud Sites area will automatically fetch the VPN configuration details from the Azure portal and will update the SASE Orchestrator local configuration.
Configure SASE Orchestrator for Azure Virtual WAN IPsec Automation from SD-WAN Edge You can configure SASE Orchestrator for integrating Azure Virtual WAN and SD-WAN Edge to enable the branch-to-Azure VPN connectivity directly from SD-WAN Edge .
Monitor Non SD-WAN Destinations You can view the details of Non SD-WAN Destinations configured for the Enterprise from the page in the SD-WAN service of the Enterprise portal.