Connection issue between Azure and UDM Pro using S2S VPN

Sumeet Lopes 0 Reputation points
2026-10-05T20:50:44.3733333+00:00

Hello,

I have setup a virtual network, virtual network gateway, public ip address, local network gateway and connection. But for some reason my S2S still shows Not connected. Can I get some support to check what am I doing wrong?

Thanks,

Sumeet

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-10-05T20:50:59.62+00:00

    For an Azure Site-to-Site VPN that stays Not connected, use this checklist in order:

    1. Confirm the VPN gateway type and SKU In the Azure portal, open the Virtual network gateway and check Overview for the Gateway type, VPN type, and gateway SKU.
    2. Verify the on-premises VPN device is supported and configured correctly Check whether the UDM Pro setup matches a validated VPN device configuration and that the device configuration is correct. If the device is not validated, compatibility issues can occur.
    3. Check the shared key on both sides In Azure portal:
      • Open the VPN Gateway
      • Go to Connections
      • Open the connection
      • Select Authentication Type
      • Verify the shared key matches the key configured on the UDM Pro
      PowerShell can also be used to view the Azure side key:
         Get-AzVirtualNetworkGatewayConnectionSharedKey -Name <Connection name> -ResourceGroupName <Resource group name>
      
    4. Verify the VPN peer IPs
      • The IP in the Local Network Gateway must match the public IP of the on-premises VPN device.
      • The Azure gateway public IP configured on the UDM Pro must match the Azure VPN gateway IP.
    5. Check the local network address spaces Make sure the address spaces and subnets defined in Azure match the on-premises network exactly. For policy-based gateways, subnet definitions must match exactly between Azure and the on-premises device.
    6. Remove UDRs or NSGs from the GatewaySubnet If a user-defined route or network security group is attached to the GatewaySubnet, remove it and test again. These can block or interfere with VPN traffic.
    7. Check the on-premises device external IP is not included in Azure local network definitions If the internet-facing IP of the VPN device is included in the Local network definition in Azure, intermittent or failed connectivity can occur.
    8. Test the Azure gateway health probe Browse to:
      • https://<YourVirtualNetworkGatewayIP>:8081/healthprobe
      • For active/active gateways: https://<YourVirtualNetworkGatewayIP2>:8083/healthprobe
      Click through the certificate warning. If a response is returned, the gateway is healthy. If no response is returned, the gateway may not be healthy or an NSG on the gateway subnet may be blocking it.
    9. Check Perfect Forward Secrecy settings If the on-premises VPN device has Perfect Forward Secrecy enabled, disable it and then update the VPN gateway IPsec policy.
    10. Reset the tunnel First reset the Azure VPN gateway and reset the tunnel from the on-premises VPN device. This is a disruptive action and can briefly interrupt connectivity.

    If the connection still does not come up after these checks, the next likely causes are device compatibility or mismatched IPsec/IKE settings on the on-premises VPN device.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.