Open-standard IPsec key exchange protocol for site-to-site tunnels, also offered as a point-to-site tunnel type that authenticates with certificates or RADIUS. Authentication through Microsoft Entra ID is not possible with it.
Also called Internet Key Exchange version 2.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains IKEv2 in context, with comparison tables and the common traps.
Terms in this definition
- IPsec
Internet Protocol Security is the set of protocols that negotiates and encrypts the tunnels used by VNet-to-VNet and site-to-site VPNs.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Tunnel type
The point-to-site gateway choice of OpenVPN, IKEv2, SSTP or a mix, which has to suit the client software. Only OpenVPN connections can use Microsoft Entra ID authentication.
- RADIUS authentication
Way of authenticating point-to-site VPN users where the gateway passes credentials on to a RADIUS server, NPS for example, which validates them against on-premises AD DS.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.
Related terms
- Policy-based traffic selectors
Per-connection option allowing a route-based VPN gateway to work with policy-based devices on-premises. You must also define a custom IPsec/IKE policy, and IKEv2 support on the device is mandatory.
- SSTP
A Microsoft P2S tunnel type based on TLS, for Windows clients alone, capped at 128 connections and authenticating by RADIUS or certificate but not Entra ID. It is being retired in favour of OpenVPN or IKEv2: no new enablement after 31 August 2026, and connections cease on 31 March 2027.