Microsoft Docs – Azure VPN Gateway

Azure VPN Gateway – Overview

The Azure VPN Gateway connects your on‑premises networks to Azure through site‑to‑site (S2S), point‑to‑site (P2S), or VNet‑to‑VNet VPN connections. It provides secure, encrypted traffic over the public internet, enabling hybrid networking scenarios that extend your data center or remote offices to the Azure cloud.

Key Features

Gateway Types

Azure offers three primary gateway SKUs, each optimized for different workloads:

SKU          | Max Throughput | # of tunnels | Typical Use‑case
--------------------------------------------------------------
VpnGw1       |  650 Mbps      |     10       | Development / testing
VpnGw2       | 1.25 Gbps      |     30       | Production workloads
VpnGw3       | 1.75 Gbps      |     30       | High‑performance, large‑scale

Architecture Diagram

Azure VPN Gateway architecture
Typical VNet‑to‑VNet and site‑to‑site topology.

Common Scenarios

  1. Site‑to‑Site (S2S): Connect an on‑premises datacenter to an Azure VNet.
  2. Point‑to‑Site (P2S): Enable individual devices to connect securely from any location.
  3. VNet‑to‑VNet: Link multiple Azure VNets across regions.
  4. Hybrid with ExpressRoute: Use VPN as a failover for ExpressRoute.

Pricing

Pricing is based on the selected SKU, data transfer, and the number of active tunnels. See the Pricing page for a detailed breakdown.