VPN Gateway documentation
Learn how to configure, create, and manage an Azure VPN gateway. Create encrypted cross-premises connections to your virtual network from on-premises locations, or create encrypted connections between VNets.
- VPN Gateway documentation
- Get started
- What is VPN Gateway?
- What's new?
- VPN Gateway FAQ
- What is hybrid connectivity?
- Quickstarts & Tutorials
- Create and manage a VPN gateway
- Configure a site-to-site connection
- Configure a point-to-site connection
- Design & architecture
- Design & topology
- Design highly available gateway connections
- Backend connectivity interoperability
- Work remotely
- Configuration settings, SKUs & gateways
- Gateway SKUs
- Public IP address SKUs
- About active-active mode gateways
- VPN Gateway configuration settings
- About site-to-site VPN connections with certificate authentication
- Create & manage a VPN gateway
- Create a VPN gateway
- Manage gateway SKUs
- Migrate classic gateways to Resource Manager
- Active-active mode gateways
- Delete a VPN gateway
- Verify a gateway connection
- Reset a gateway or gateway connection
- Configure gateway maintenance
- Site-to-site S2S VPN
- Configure site-to-site connections - shared key
- Configure site-to-site connections - certificate
- Connect AWS and Azure using a BGP-enabled VPN gateway
- Site-to-site with ExpressRoute connections
- Coexisting connections
- VPN over private peering
- Add or remove a site-to-site connection
- Forced tunneling
- Custom traffic selectors
- Configure custom IPsec/IKE connection policies
- Modify a local network gateway
- Advanced Connectivity
- VPN devices
- Point-to-site P2S VPN
- About point-to-site VPN
- About point-to-site VPN routing
- Migrate from Azure VPN Client for Linux
- Configure P2S - certificate authentication
- P2S gateway configuration
- VPN client configuration
- Generate self-signed certificates
- .cer and .pfx files
- .pem files
- Install VPN client certificates
- Configure P2S - Microsoft Entra ID authentication
- P2S gateway configuration
- VPN client configuration
- Configure P2S - RADIUS authentication
- P2S gateway configuration
- Assign IP addresses to specific User Groups
- About User Groups and client address pools
- Configure groups and client address pools
- RADIUS - Configure NPS and user groups
- Configure Always On tunnels
- Gateway root certificate migration
- Move to OpenVPN or IKEv2 from SSTP
- P2S session management
- Advertise custom routes to P2S clients
- Create custom IPsec policies for P2S
- Update a P2S VPN Client profile
- Azure VPN Client versions, checks & settings
- Intune - Deploy VPN client profile
- IPv6 dual stack connections
- VNet-to-VNet VPN
- Configure VNet-to-VNet VPN connections
- Configure a VNet-to-VNet connection between deployment models
- Configure custom IPsec/IKE connection policies
- Security
- Reliability
- Routing
- Forced tunneling
- Gateway transit for VNet peering
- Use a VPN or ExpressRoute gateway in a different region
- BGP
- About BGP and VPN Gateway
- Configure BGP for a VPN gateway
- Connect AWS and Azure using a BGP-enabled VPN gateway
- NAT
- Custom traffic selectors
- Point-to-site routing
- Monitoring
- Support and troubleshooting
- Reference
- Resources