An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
For an Azure Site-to-Site VPN that stays Not connected, use this checklist in order:
- Confirm the VPN gateway type and SKU In the Azure portal, open the Virtual network gateway and check Overview for the Gateway type, VPN type, and gateway SKU.
- Verify the on-premises VPN device is supported and configured correctly Check whether the UDM Pro setup matches a validated VPN device configuration and that the device configuration is correct. If the device is not validated, compatibility issues can occur.
- Check the shared key on both sides
In Azure portal:
- Open the VPN Gateway
- Go to Connections
- Open the connection
- Select Authentication Type
- Verify the shared key matches the key configured on the UDM Pro
Get-AzVirtualNetworkGatewayConnectionSharedKey -Name <Connection name> -ResourceGroupName <Resource group name> - Verify the VPN peer IPs
- The IP in the Local Network Gateway must match the public IP of the on-premises VPN device.
- The Azure gateway public IP configured on the UDM Pro must match the Azure VPN gateway IP.
- Check the local network address spaces Make sure the address spaces and subnets defined in Azure match the on-premises network exactly. For policy-based gateways, subnet definitions must match exactly between Azure and the on-premises device.
- Remove UDRs or NSGs from the GatewaySubnet If a user-defined route or network security group is attached to the GatewaySubnet, remove it and test again. These can block or interfere with VPN traffic.
- Check the on-premises device external IP is not included in Azure local network definitions If the internet-facing IP of the VPN device is included in the Local network definition in Azure, intermittent or failed connectivity can occur.
- Test the Azure gateway health probe
Browse to:
-
https://<YourVirtualNetworkGatewayIP>:8081/healthprobe - For active/active gateways:
https://<YourVirtualNetworkGatewayIP2>:8083/healthprobe
-
- Check Perfect Forward Secrecy settings If the on-premises VPN device has Perfect Forward Secrecy enabled, disable it and then update the VPN gateway IPsec policy.
- Reset the tunnel First reset the Azure VPN gateway and reset the tunnel from the on-premises VPN device. This is a disruptive action and can briefly interrupt connectivity.
If the connection still does not come up after these checks, the next likely causes are device compatibility or mismatched IPsec/IKE settings on the on-premises VPN device.