data:image/s3,"s3://crabby-images/fad3e/fad3ea1a66983b432751175a79e5b040bb1bf960" alt="Implementing Azure:Putting Modern DevOps to Use"
Azure VPN gateways
Azure VPN gateways are basically your core routers and firewalls within your Azure environment.
An Azure gateway can serve different purposes:
- Internet gateway
- Site-to-site VPN gateway
- Point-to-site VPN gateway
- ExpressRoute gateway
- VNet-to-VNet gateway
The following screenshot shows the Azure service you need to look for when you want to implement an Azure VPN gateway:
data:image/s3,"s3://crabby-images/aacd9/aacd9b8700204efb736aa68b46dbf873b7e7ac80" alt=""
Every VNet can have at least one VPN gateway. VPN gateways are available in different service offerings with different features and available services.
The following table shows a short summary:
data:image/s3,"s3://crabby-images/e073b/e073b52cce79d18b380c3bc846f487fbda77315d" alt=""
The following diagram shows how the basic VPN gateway is connected to your Azure network:
data:image/s3,"s3://crabby-images/ee59e/ee59e59199c599d0d152339f2b6ec6cb5c167619" alt=""
With the standard or performance gateway it would look like the following diagram:
data:image/s3,"s3://crabby-images/300b0/300b065d58aec273cf2b46041d84340ffb957063" alt=""
When you start the setup of a gateway, you need to decide what kind of gateway you want to deploy. The basic offering can be deployed via Azure GUI; for the other offerings, you need to do some PowerShell. The following screenshot shows the GUI version:
data:image/s3,"s3://crabby-images/e41d1/e41d105dc6c605071eb4243a99eb0fb27f4bdd2c" alt=""
Depending on your WAN solution, you choose either VPN or ExpressRoute. For ExpressRoute, you need an MPLS solution in place. I will explain that later. For the VPN solution, you need to decide between a Route-based or Policy-based VPN, which means you need to decide if you want to enable dynamic routing with IPSEC IKEv2 or static IPSEC IKEv1.
The decision as to which VPN type you need must be done based on your on-premises VPN device. Not every device can speak Route-based VPN. Microsoft has published a list of supported devices. You can see them here at https://azure.microsoft.com/en-us/documentation/articles/vpn-gateway-about-vpn-devices/.
There are also some more additional requirements you need to think of when choosing your VPN gateway in Azure. The following table shows you those provided by Microsoft:
data:image/s3,"s3://crabby-images/14196/141967f9be338deaec6e077c178d4e1374cf5f8b" alt=""
In summary, you can basically have the following gateway configurations:
- The policy-based basic VPN Gateway with site-to-site VPN is shown in the following diagram:
data:image/s3,"s3://crabby-images/0d270/0d2705c1940a9721ee63186053bcacde47bc3988" alt=""
- Route-based standard VPN gateway with ExpressRoute shown in the following diagram:
data:image/s3,"s3://crabby-images/d62a2/d62a244b772bc9475901072d3e7a8eceb9858844" alt=""
- Route-based basic VPN Gateway with a Site 2 Site VPN and Point 2 Site VPN or a Route-based standard or performance VPN gateway with a Site 2 Site VPN and Point 2 Site VPN in shown in the following diagram:
data:image/s3,"s3://crabby-images/9830b/9830b649b7eb4047abd55683279d4bb63c0abf5b" alt=""
- Route-based standard or performance VPN gateway with Site to Site or ExpressRoute in shown in the following diagram:
data:image/s3,"s3://crabby-images/29062/29062cc2050bb956de915d41ffcfaef6563aa30f" alt=""
- Route-based standard or performance VPN gateway with a site-to-site VPN and ExpressRoute:
data:image/s3,"s3://crabby-images/2b929/2b9297482e017b1b3d4af26014feec2316e7c007" alt=""
Later in the chapter, you will learn how to configure a VPN gateway with ExpressRoute and a basic VPN with a site-to-site VPN and how to upgrade that VPN to standard or performance. You will also learn what you need to do to implement a point-to-site VPN.