An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Hello @Hasan Tarık YILMAZ
Custom traffic selectors are supported on both policy-based and route-based Azure VPN gateways, and Microsoft supports updating an existing connection through the portal. The address ranges must be entered in CIDR notation.
The fact that the tunnel remains connected while the update fails is possible because the provisioning state represents the Azure Resource Manager control-plane operation and is independent of the resource’s current traffic-processing state.
Before retrying:
- Check the connection’s Activity log and record the failed operation’s timestamp, correlation ID, and complete error details.
- Verify that all local and remote selector ranges use valid CIDR notation and match the encryption domains configured on the on-premises VPN device.
- Confirm that no other write operation is running against the VPN gateway, local network gateway, or connection.
- Export or document the existing connection, IPsec/IKE policy, shared-key configuration, and selectors before making another change.
- Perform the retry during a maintenance window. Changing traffic selectors can affect IPsec security-association negotiation, particularly because Azure proposes the custom selectors when Azure initiates the connection.
If the connection resource enters a Failed provisioning state, refreshing it through a read followed by a write:
Get-AzVirtualNetworkGatewayConnection `
-Name "<connection-name>" `
-ResourceGroupName "<resource-group>" |
Set-AzVirtualNetworkGatewayConnection
Run this only after retrieving the complete current resource configuration, using an up-to-date Az PowerShell module. Take note that issuing a write with incomplete properties or an older API version can overwrite settings.
If the update fails again with valid selectors, open an Azure support request and provide the connection resource ID, gateway SKU, region, UTC timestamp, correlation ID, complete error response, current selectors, and intended selectors. Microsoft support will need to check the gateway-management operation on the service side.
References:
Custom traffic selectors for VPN Gateway
Troubleshoot Microsoft.Network failed provisioning states
Restore a Microsoft.Network connection to Succeeded
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.