Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
Also called virtual private network.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-7002V0-17.25AZ-900DP-750SC-900SC-200SC-300AZ-400AZ-802SC-401MD-102ALZ
Each book explains VPN in context, with comparison tables and the common traps.
Terms in this definition
- Connection
Resource that attaches a virtual network gateway to its peer, which may be an ExpressRoute circuit, a second VNet gateway (Vnet2Vnet) or a local network gateway over IPsec. Resetting it recovers a single tunnel and avoids rebooting the whole gateway.
- VPN gateway
Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
- GatewaySubnet
The subnet reserved for ExpressRoute or VPN gateways, which should be at least /27.
Related terms
- Active Standby
An NSX gateway HA mode where one Edge node handles traffic while a second waits to take over. Stateful services such as NAT, VPN, load balancing and the stateful firewall depend on it, and VCF Automation 9.0 expects its Tier-0 to be set up this way.
- Always-on VPN
Ensures nothing leaves the device except over the VPN, at all times. This option isn't available with Microsoft Tunnel for MAM on Android.
- ASN
Short for autonomous system number, which identifies a BGP routing domain. Azure VPN gateways use 65515 by default, a reserved value on-premises peers must avoid; Defender EASM also discovers ASNs as an internet asset type.
- AZ SKU
Any VPN or ExpressRoute gateway SKU carrying the AZ suffix (VpnGw1AZ to 5AZ, ErGw1Az to 3Az). In regions with availability zones its instances spread across zones; in other regions it deploys regionally, becoming zone-redundant once zones are introduced there.
- Azure ExpressRoute
A private link, arranged with a connectivity provider, between an on-premises network and Microsoft's cloud that avoids the public internet. Compared with a VPN it offers better reliability, higher speeds and steadier latency.
- Azure Network Adapter
Windows Admin Center option for linking a single Windows Server to a VNet by point-to-site VPN. If the VNet has no VPN gateway it creates one, taking about 25 minutes, and no VPN hardware is needed on premises.
- Azure Relay
Messaging service connecting cloud and on-premises endpoints through outbound connections on port 443, without a VPN, inbound ports or VNet routing. The on-premises data gateway and App Service Hybrid Connections rely on it.
- Azure VPN Client
Microsoft's VPN app for Windows 11 and macOS, needed for point-to-site connections that authenticate with Entra ID; you set it up by importing the azurevpnconfig.xml file from the profile package.