Type of VPN gateway that relies on routing tables and any-to-any traffic selectors. Point-to-site, BGP and gateway transit all need it, and it is the only type you can create in the portal.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Route-based VPN in context, with comparison tables and the common traps.
Terms in this definition
- VPN gateway
Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
- Geographic
A Traffic Manager routing method that picks the endpoint according to where the user is located geographically.
- BGP
Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
- Gateway transit
A peering option that lets spoke VNets use a hub's route-based VPN or ExpressRoute gateway, enabled with Allow gateway transit on the hub and Use remote gateways on the spoke.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
Related terms
- Default Site
In forced tunnelling, the route-based VPN gateway is pointed at one local network gateway as its default, and every internet-bound packet goes there. That on-premises device must permit 0.0.0.0/0 in its traffic selectors.
- ExpressRoute and S2S VPN coexistence
Running a route-based VPN gateway (VpnGw1 or above, never Basic) alongside the ExpressRoute gateway in one VNet, sharing a GatewaySubnet of at least /27; the VPN acts as backup or links other sites.
- Policy-based traffic selectors
Per-connection option allowing a route-based VPN gateway to work with policy-based devices on-premises. You must also define a custom IPsec/IKE policy, and IKEv2 support on the device is mandatory.
- Set-AzVirtualNetworkGatewayDefaultSite
On a route-based VPN gateway, this Az.Network cmdlet nominates which local network gateway forced-tunnelled traffic goes to, taking -VirtualNetworkGateway and -GatewayDefaultSite.
- VPN troubleshoot
Diagnoses a route-based VPN gateway or connection on demand from Network Watcher, storing logs in a storage account. Alerts aren't possible, and ExpressRoute isn't supported.