Fusion – Set up VPN to AVD
In Object à General à Address book, add 3 address folders (LAN_NETWORKS, REMOTE_NETWORKS, PUBLIC_IPs)
In the folders add the following IPv4 addresses
LAN_NETWORKS – LAN subnet/24
REMOTE_NETWORKS – Azure subnet/24
PUBLIC_IPs – Azure wan
Add the algorithms
Go Object, IKE Algorithms
Add new algorithm called AZURE_PHASE1 and set up like below
Add a new IPSEC algorithm called AZURE_PHASE2 and set up like below
Creating the PSK
Go objects à General à keyring, add a pre-shared key called AZURE_PSK, just use a strong password for now as we will get the key from pfsense
Create the IPSEC like below
Go to Network à interfaces and group add a new group called IPSEC_LAN_GRP, like below
Split ICMP
Go to policies, right click ICMP_Allow_traceroute and edit it to be the same as below
Back on the policies page, right click à leave group à drag it to the top
Create the IPSEC as below
Policies screen should look below
Save activate
Log onto the avd and head to pfsense, usually .5
Go to vpnà ipsec, add p1, like below (grab remote gateway from fusion CGE-NAT
Generate new key and save it
Change phase 1 encryption to below and save
Disable that and create a new P2, set up like below, obviously changing the lan subnet to match
Go back to clav objects à general à key rings back into the PSK and change it to what Pfsense gave us, add it to the notes too.
