Lives in GatewaySubnet and comes in two types, ExpressRoute or VPN. Setting it as the next hop in a UDR routes traffic on-premises.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Virtual network gateway in context, with comparison tables and the common traps.
Terms in this definition
- GatewaySubnet
The subnet reserved for ExpressRoute or VPN gateways, which should be at least /27.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- Next hop
For a destination you specify, returns the route table in use along with the next hop's type and IP. Only routing is checked.
- UDR
A static entry in a route table that takes precedence over Azure system routes, for instance sending traffic to a virtual appliance or virtual network gateway as next hop. BGP routes are learned dynamically; these are not.
Related terms
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- Gateway-required VNet integration
Legacy option letting App Service reach VNets located in a different region, by connecting over an SSTP point-to-site VPN into a route-based virtual network gateway. Because it carries extra gateway charges, it is being retired on 31 March 2027 and regional VNet integration replaces it.
- Get-AzVirtualNetworkGateway
Az.Network cmdlet used to fetch a virtual network gateway object. Setting the default site is outside what it does, as it only reads.
- Next hop type
Describes what a route forwards to. Options are Internet, Virtual network, Virtual network gateway, Virtual appliance (the private IP of an NVA or firewall) and None.
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- Virtual network connection
Connects a VNet to a Virtual WAN hub and carries its routing configuration: association, propagation and static routes. A connected VNet cannot have a virtual network gateway of its own.
- VPN gateway
Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
- Zone-redundant gateway
A virtual network gateway on an AZ SKU, paired with a Standard zone-redundant public IP, with instances across availability zones. Zone resilience comes from this rather than from adding ExpressRoute circuits.