Virtual WAN VPN Gateway

This document provides comprehensive details about configuring and managing VPN gateways within Azure Virtual WAN. VPN gateways are essential components that enable secure and reliable connectivity between your on-premises networks and Azure, or between different Azure regions.

Overview

Azure Virtual WAN offers a highly scalable and global networking solution. VPN gateways in Virtual WAN act as the termination point for Site-to-Site VPN connections. They are managed by Microsoft and provide high availability and performance for your network connections.

Key Features

Deployment and Configuration

When you create a Virtual WAN hub, you can optionally deploy a VPN gateway. You can choose between a basic SKU for smaller deployments or a standard SKU for higher performance and features. The standard SKU offers active-active deployment and higher tunnel counts.

Steps to Create a VPN Gateway:

  1. Navigate to your Virtual WAN resource in the Azure portal.
  2. Select "VPN gateways" from the hub menu.
  3. Click "Create VPN gateway".
  4. Configure the gateway settings:
    • Gateway type: VPN.
    • SKU: Basic, VpnGw1, VpnGw2, etc.
    • Scale Unit: Determines the capacity.
    • Region: Should match your hub's region.
    • AS Number: Autonomous System number for BGP peering.
  5. Click "Review + create" and then "Create".

Connecting to On-Premises Networks

To connect your on-premises network, you'll need to configure a VPN device at your site. This involves defining the connection parameters such as:

You will then create a "Site-to-Site VPN connection" in your Virtual WAN hub, referencing your on-premises VPN device information. Azure will provide you with the gateway IP addresses and the necessary configurations to set up on your VPN device.

Important Note:

Ensure your on-premises VPN device is compatible with Azure VPN Gateway and supports the configured IPsec/IKE parameters. Refer to the Azure VPN device compatibility list for guidance.

BGP Peering

For dynamic route exchange, Virtual WAN VPN gateways support Border Gateway Protocol (BGP). This allows for automatic propagation of routes between your on-premises network and Azure. When creating a VPN gateway with a standard SKU, you can configure a BGP ASN and peers. The gateway will typically have a private IP address assigned for BGP peering.

BGP Configuration Details:

Monitoring and Troubleshooting

Azure Monitor provides extensive capabilities for monitoring the health and performance of your VPN gateways. You can view metrics such as:

For troubleshooting, you can leverage connection diagnostics, IP flow verify, and VPN connection monitor features available in Azure. Logs can be exported to Log Analytics for deeper analysis.

Pricing

The pricing for Virtual WAN VPN gateways depends on the SKU selected, the number of deployed gateways, and the amount of data processed. For detailed pricing information, please refer to the Azure Virtual WAN pricing page.

Pro Tip:

For optimal performance and reliability, consider using the standard SKU with active-active configuration for your production workloads.

Feature Basic SKU Standard SKU (e.g., VpnGw1)
Max Tunnels 10 30 (VpnGw1), 120 (VpnGw3)
Max Throughput ~100 Mbps ~650 Mbps (VpnGw1), ~2 Gbps (VpnGw5)
Active-Active Mode No Yes
BGP Support No Yes

For the most up-to-date information and advanced configuration options, please consult the official Azure Virtual WAN documentation.