Set of algorithms for IKE Phase 1 and IPsec Phase 2, together with DH and PFS groups and SA lifetimes, applied to one connection rather than the gateway; each connection takes one policy, and every parameter has to be filled in.
Also called IPsec/IKE connection policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Custom IPsec/IKE policy in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- IKE
Negotiates keys for IPsec tunnels. Site-to-site VPN connections in Azure rely on it together with IPsec, and Basic policy-based gateways support only the older IKEv1.
- IPsec
Internet Protocol Security is the set of protocols that negotiates and encrypts the tunnels used by VNet-to-VNet and site-to-site VPNs.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- State
A parameter in OAuth that carries custom data through the authorisation flow and back, as with the "Support state parameter" option in APIM.
Related terms
- DH group
The Diffie-Hellman group chosen for key exchange during IKE Phase 1 (Main Mode) in a custom IPsec/IKE policy, such as DHGroup24 or DHGroup14.
- New-AzIpsecPolicy
Cmdlet in Az.Network for defining a custom IPsec/IKE policy on a connection, covering IKE encryption and integrity, DH group, IPsec encryption and integrity, PFS group, and SA lifetime and size.
- Policy-based traffic selectors
Per-connection option allowing a route-based VPN gateway to work with policy-based devices on-premises. You must also define a custom IPsec/IKE policy, and IKEv2 support on the device is mandatory.