Azure azurerm_virtual_network_gateway的bgp_settings块配置报错求助
正确配置Azure虚拟网络网关BGP APIPA地址的Terraform示例
你代码报错的核心原因是peering_addresses子块的ip_configuration_name参数取值错误——这个参数需要关联虚拟网络网关自身的ip_configuration块名称,而非公网IP资源的名称。
修正后的完整代码如下:
resource "azurerm_virtual_network_gateway" "Customer" { name = var.vng_name location = var.location resource_group_name = var.resource_group_name type = "Vpn" vpn_type = "RouteBased" active_active = true enable_bgp = true sku = "VpnGw1" generation = "Generation1" ip_configuration { name = "vnetGatewayConfig1" public_ip_address_id = azurerm_public_ip.Customer_IP1.id private_ip_address_allocation = "Dynamic" subnet_id = azurerm_subnet.gateway_subnet.id } ip_configuration { name = "vnetGatewayConfig2" public_ip_address_id = azurerm_public_ip.Customer_IP2.id private_ip_address_allocation = "Dynamic" subnet_id = azurerm_subnet.gateway_subnet.id } bgp_settings { asn = 65000 peering_addresses { apipa_addresses = ["169.254.21.1"] ip_configuration_name = "vnetGatewayConfig1" # 关联网关自身的第一个ip_configuration名称 } peering_addresses { apipa_addresses = ["169.254.21.5"] ip_configuration_name = "vnetGatewayConfig2" # 关联网关自身的第二个ip_configuration名称 } } }
关键配置要点:
- 启用Active-Active模式时,两个IP配置必须指定不重复的APIPA地址,建议使用Azure官方推荐的
169.254.21.0/24或169.254.22.0/24网段内的地址 enable_bgp必须设为true,否则bgp_settings块不会被Terraform处理- 所选SKU(如VpnGw1)需支持BGP和Active-Active部署模式,低阶SKU可能不兼容该配置
内容的提问来源于stack exchange,提问作者Nico
相关产品推荐
相关产品推荐

