Site-to-site VPN: an internet-based IPsec/IKE tunnel linking an on-premises VPN device with the VPN gateway of a VNet. It needs a local network gateway plus a connection and costs less than ExpressRoute.
Also called site-to-site VPN.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains S2S VPN in context, with comparison tables and the common traps.
Terms in this definition
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
- IPsec/IKE
Together, Internet Protocol Security and Internet Key Exchange form the protocol suite that sets up and encrypts site-to-site and VNet-to-VNet VPN tunnels.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- VPN gateway
Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- Local network gateway
Represents the on-premises site in Azure, recording the VPN device's public IP and the address prefixes behind it, for use by site-to-site VPN connections. Point-to-site doesn't use it.
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.