Represents the on-premises site in Azure, recording the VPN device's public IP and the address prefixes behind it, for use by site-to-site VPN connections. Point-to-site doesn't use it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Local network gateway in context, with comparison tables and the common traps.
Terms in this definition
- LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
Related terms
- BGP peer IP
IP address from which each router runs its BGP session. Azure allocates one to a VPN gateway when BGP is switched on, and you record the internal address of your on-premises router in the local network gateway.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Default Site
In forced tunnelling, the route-based VPN gateway is pointed at one local network gateway as its default, and every internet-bound packet goes there. That on-premises device must permit 0.0.0.0/0 in its traffic selectors.
- Get-AzLocalNetworkGateway
Az.Network cmdlet returning a local network gateway object; for forced tunnelling, that object can be passed as
-GatewayDefaultSite. - S2S VPN
Site-to-site VPN: an internet-based IPsec/IKE tunnel linking an on-premises VPN device with the VPN gateway of a VNet. It needs a local network gateway plus a connection and costs less than ExpressRoute.
- Set-AzVirtualNetworkGatewayDefaultSite
On a route-based VPN gateway, this Az.Network cmdlet nominates which local network gateway forced-tunnelled traffic goes to, taking -VirtualNetworkGateway and -GatewayDefaultSite.