Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
Also called site-to-site VPN.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains S2S in context, with comparison tables and the common traps.
Terms in this definition
- Datacenter
A building packed with racked servers that has its own electricity supply, cooling and network links. Microsoft gathers these buildings into Azure regions, and as a customer you pick the region, never which building your resources land in.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- IPsec/IKE
Together, Internet Protocol Security and Internet Key Exchange form the protocol suite that sets up and encrypts site-to-site and VNet-to-VNet VPN tunnels.
- LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- Azure VPN Gateway
Encrypts traffic with IPsec/IKE so an Azure virtual network can connect securely to on-premises locations, remote users or other VNets, running across the public internet or Microsoft's own backbone.
Related terms
- AS Path (hub routing preference)
Routing preference for a Virtual WAN hub under which the shortest BGP AS path wins regardless of where the route came from. When local routes tie, ExpressRoute is chosen over site-to-site VPN.
- Branch-to-branch
Optional Azure Route Server feature, disabled by default, that passes routes among NVAs and the VPN and ExpressRoute gateways in its VNet, enabling transit between ExpressRoute and site-to-site VPN.
- ChecksFailedPercent
One of the Connection Monitor metrics, together with
RoundTripTimeMsand Test Result, on which Azure Monitor metric alerts can trigger, for instance when a site-to-site VPN goes down. - Forced tunnelling
Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (
AzureFirewallManagementSubnetand a management public IP) for it. - IKE
Negotiates keys for IPsec tunnels. Site-to-site VPN connections in Azure rely on it together with IPsec, and Basic policy-based gateways support only the older IKEv1.
- Local network gateway
Represents the on-premises site in Azure, recording the VPN device's public IP and the address prefixes behind it, for use by site-to-site VPN connections. Point-to-site doesn't use it.
- S2S VPN
Site-to-site VPN: an internet-based IPsec/IKE tunnel linking an on-premises VPN device with the VPN gateway of a VNet. It needs a local network gateway plus a connection and costs less than ExpressRoute.
- Scale unit
Capacity unit for Virtual WAN gateways, configured independently for each gateway type: a site-to-site VPN unit gives 500 Mbps, while an ExpressRoute unit gives 2 Gbps.