Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains VPN gateway in context, with comparison tables and the common traps.
Terms in this definition
- IPsec
Internet Protocol Security is the set of protocols that negotiates and encrypts the tunnels used by VNet-to-VNet and site-to-site VPNs.
- Virtual network gateway
Lives in GatewaySubnet and comes in two types, ExpressRoute or VPN. Setting it as the next hop in a UDR routes traffic on-premises.
- GatewaySubnet
The subnet reserved for ExpressRoute or VPN gateways, which should be at least /27.
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
Related terms
- Active-active
A VPN gateway set-up where traffic flows through both instances simultaneously, each having a separate tunnel and public IP. Servicing one instance therefore disrupts connections less than under default active-standby.
- Allow gateway transit
Peering option set on the hub, which owns the gateway, so that peered VNets can share its ExpressRoute or VPN gateway. The spoke sets Use remote gateways to match; on a VNet lacking a gateway the option has no effect.
- Azure Network Adapter
Windows Admin Center option for linking a single Windows Server to a VNet by point-to-site VPN. If the VNet has no VPN gateway it creates one, taking about 25 minutes, and no VPN hardware is needed on premises.
- BGP peer IP
IP address from which each router runs its BGP session. Azure allocates one to a VPN gateway when BGP is switched on, and you record the internal address of your on-premises router in the local network gateway.
- BGP transit routing
Behaviour of a VPN gateway that passes prefixes learned from one BGP peer on to its other peers, letting chained BGP-enabled site-to-site and VNet-to-VNet connections reach one another; default routes are not passed on.
- Client address pool
Range of private addresses handed out to point-to-site VPN clients; it must not overlap on-premises or VNet ranges and is set once the VPN gateway has been created.
- GatewayDiagnosticLog
A resource log on VPN Gateway that keeps an audit trail of changes made to the gateway's configuration.
- IKEDiagnosticLog
A VPN Gateway resource log giving detailed IKE and IPsec negotiation information, including SAs, proposals and PSK failures. Check it first when a tunnel fails to come up or repeatedly drops.