Together, Internet Protocol Security and Internet Key Exchange form the protocol suite that sets up and encrypts site-to-site and VNet-to-VNet VPN tunnels.
Also called Internet Protocol Security / Internet Key Exchange.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains IPsec/IKE in context, with comparison tables and the common traps.
Terms in this definition
- IPsec
Internet Protocol Security is the set of protocols that negotiates and encrypts the tunnels used by VNet-to-VNet and site-to-site VPNs.
- IKE
Negotiates keys for IPsec tunnels. Site-to-site VPN connections in Azure rely on it together with IPsec, and Basic policy-based gateways support only the older IKEv1.
- VNet-to-VNet VPN
Links the VPN gateways of two VNets with an encrypted IPsec/IKE tunnel. Each VNet needs a gateway, and compared with VNet peering it is pricier and adds latency.
Related terms
- Azure VPN Gateway
Encrypts traffic with IPsec/IKE so an Azure virtual network can connect securely to on-premises locations, remote users or other VNets, running across the public internet or Microsoft's own backbone.
- New-AzVirtualNetworkGatewayNatRule
Cmdlet in Az.Network that adds a NAT rule to a VPN gateway to cope with overlapping address spaces. IPsec/IKE parameters are not part of it.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
- S2S VPN
Site-to-site VPN: an internet-based IPsec/IKE tunnel linking an on-premises VPN device with the VPN gateway of a VNet. It needs a local network gateway plus a connection and costs less than ExpressRoute.
- VNet-to-VNet connection
An IPsec/IKE link joining two Azure VPN gateways. Turning on BGP for it lets chained VNets and sites exchange their prefixes.