Home > Glossary > Microsoft Azure Fundamentals > Azure VPN Gateway

📖 What is Azure VPN Gateway?

Azure VPN Gateway creates secure, encrypted connections between on-premises networks and Azure virtual networks over the public internet. It supports site-to-site and point-to-site VPN connections, enabling hybrid cloud scenarios and secure remote access to Azure resources.

🥋 Sensei Says:

"VPN Gateway is a cost-effective hybrid connectivity solution. Recognize its reliance on the public internet and potential bandwidth limitations compared to ExpressRoute. Exam questions may ask you to identify scenarios where a VPN Gateway is sufficient versus requiring ExpressRoute’s dedicated connection."

📚 Certification: Microsoft Azure Fundamentals (AZ-900)

🔑 What are the Key Concepts of Azure VPN Gateway?

  • VPN Gateway uses IPsec protocols to create encrypted tunnels, ensuring data confidentiality and integrity during transit between networks.
  • It supports both Route-Based and Policy-Based VPNs; Route-Based is generally preferred for scalability and dynamic routing with BGP.
  • Point-to-Site VPNs allow individual users to connect securely to Azure, while Site-to-Site connects entire networks together.
  • VPN Gateways require a Public IP address and a Virtual Network Gateway subnet within the Azure VNet for proper operation.
  • Consider bandwidth limitations and potential latency due to reliance on the public internet when choosing between VPN Gateway and ExpressRoute.

🎯 How does Azure VPN Gateway appear on the AZ-900 Exam?

You may be asked to identify the Azure service that would allow a company to securely connect their on-premises network to an Azure Virtual Network without establishing a dedicated physical connection.

A scenario might describe a need for secure remote access for developers to Azure resources; expect questions about configuring a Point-to-Site VPN Gateway.

Expect questions about comparing and contrasting VPN Gateway and ExpressRoute, focusing on cost, bandwidth, and latency requirements for different workloads.

❓ Frequently Asked Questions

When would I choose a VPN Gateway over Azure ExpressRoute?

VPN Gateway is suitable for cost-sensitive scenarios with moderate bandwidth needs and acceptable latency. ExpressRoute is preferred for high bandwidth, low latency, and mission-critical applications.


What is the difference between Route-Based and Policy-Based VPN Gateways?

Route-Based VPNs use routing protocols like BGP for dynamic route propagation, offering scalability. Policy-Based VPNs rely on static access lists and are less flexible for complex networks.


Can I use a VPN Gateway to connect multiple on-premises networks to a single Azure VNet?

Yes, a single VPN Gateway can support multiple Site-to-Site connections, allowing you to connect several on-premises locations to your Azure virtual network. Each connection requires its own configuration.

Related Terms from Microsoft Azure Fundamentals

📝 Related Study Guides

Study Guide 10 min read

Azure Fundamentals (AZ-900): How to Pass on Your First Try

To pass the Azure AZ-900 exam, focus on the three core domains: Cloud Concepts, Azure Architecture, and Management and Governance. Combine Microsoft Learn's free modules with high-volume practice exams—like the 1,000 questions at Cert Sensei—to master service distinctions and governance tools. Aim for a 700/1000 score across 40-60 questions.

Deep Dive 8 min read

What is an Azure Resource Group? AZ-900 Governance Guide

An Azure Resource Group is a logical container that holds related resources for an Azure solution. It enables efficient lifecycle management, allowing you to deploy, update, and delete a group of resources as a single unit, while providing a centralized point for applying governance, security policies, and Role-Based Access Control (RBAC).

Comparison 7 min read

Azure Data Lake vs Blob Storage: AZ-900 Explained

Azure Blob Storage is object storage for unstructured data using a flat namespace. Azure Data Lake Storage Gen2 builds on Blob storage by adding a hierarchical namespace, making it optimized for big data analytics and high-performance Hadoop workloads. For AZ-900, choose Data Lake when you see "hierarchical" or "analytics."

🧠

Test Your Knowledge

Think you understand Azure VPN Gateway? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium