VPN Gateway: Connection Update Fails with GwmOperationTimeOut

Hasan Tarık YILMAZ 0 Reputation points
2026-10-08T10:39:52.29+00:00

Problem description

I am experiencing an issue when attempting to update my Azure Site-to-Site VPN connection. Specifically, when I try to add a new custom traffic selector to the existing connection, the operation remains in 'Updating' status for a long time and then fails with a 'ResourceOperationFailure' error, citing 'GwmOperationTimeOut'. The existing VPN tunnel remains connected, and the gateway's provisioning state is 'Succeeded'. I have confirmed that the connection is still active, and the virtual network gateway is operational. The error occurs during the configuration update via the Azure portal.

Environment

Azure VPN Gateway in West Europe; existing production Site-to-Site VPN connection; policy-based traffic selectors enabled; attempting to add a custom traffic selector; tunnel remains connected; provisioning state: Succeeded.

What I've already tried

I attempted to update the VPN connection by adding a new custom traffic selector through the Azure portal. The update stays in 'Updating' status for an extended period before failing with a timeout error. I checked the current operational state and activity logs, noting the failure details. I have not tried using Azure CLI or ARM/Bicep templates to perform the update, as I want to avoid disrupting the active VPN connection in production.

Current status

I am seeking assistance to understand the cause of the timeout during the update, to determine if there are limitations or issues with adding custom traffic selectors, and to receive guidance on a safe remediation procedure that does not disrupt the existing active VPN connection.

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 10,305 Reputation points
    2026-10-08T18:19:28.7133333+00:00

    Hello @Hasan Tarık YILMAZ

    Custom traffic selectors are supported on both policy-based and route-based Azure VPN gateways, and Microsoft supports updating an existing connection through the portal. The address ranges must be entered in CIDR notation.

    The fact that the tunnel remains connected while the update fails is possible because the provisioning state represents the Azure Resource Manager control-plane operation and is independent of the resource’s current traffic-processing state.

    Before retrying:

    1. Check the connection’s Activity log and record the failed operation’s timestamp, correlation ID, and complete error details.
    2. Verify that all local and remote selector ranges use valid CIDR notation and match the encryption domains configured on the on-premises VPN device.
    3. Confirm that no other write operation is running against the VPN gateway, local network gateway, or connection.
    4. Export or document the existing connection, IPsec/IKE policy, shared-key configuration, and selectors before making another change.
    5. Perform the retry during a maintenance window. Changing traffic selectors can affect IPsec security-association negotiation, particularly because Azure proposes the custom selectors when Azure initiates the connection.

    If the connection resource enters a Failed provisioning state, refreshing it through a read followed by a write:

    Get-AzVirtualNetworkGatewayConnection `
      -Name "<connection-name>" `
      -ResourceGroupName "<resource-group>" |
    Set-AzVirtualNetworkGatewayConnection
    

    Run this only after retrieving the complete current resource configuration, using an up-to-date Az PowerShell module. Take note that issuing a write with incomplete properties or an older API version can overwrite settings.

    If the update fails again with valid selectors, open an Azure support request and provide the connection resource ID, gateway SKU, region, UTC timestamp, correlation ID, complete error response, current selectors, and intended selectors. Microsoft support will need to check the gateway-management operation on the service side.

    References:

    Custom traffic selectors for VPN Gateway

    Troubleshoot Microsoft.Network failed provisioning states

    Custom traffic selectors

    Restore a Microsoft.Network connection to Succeeded


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.