---
title: "Azure site-to-site VPN"
canonical: "https://docs.aryaka.com/space/KNOW/1291911184/Azure%20site-to-site%20VPN"
format: markdown
---
Azure site-to-site VPN is a service that allows access to the Azure resources from your remote sites over a site-to-site IPsec tunnel between Aryaka’s POP and Azure’s virtual network gateway. Aryaka customers can optimize their access to the Azure resources by using the nearest Aryaka POP and a route-based or policy-based secured tunnel This document describes the procedure Aryaka customers must perform in the Azure portal to create an IPsec tunnel to connect to the Aryaka POP. Prerequisites Satisfy the following prerequisites before performing the IPsec configuration: You must be an administrator user on the Azure Portal. You must have already created a virtual network (VNet). Refer to  this document  (on microsoft.com) for information about creating one. You must provide the following information to Aryaka before configuring an IPsec connection: VNet region Local subnets list Tunnel type: policy-based or route-based IKE version: v1 or v2 Based on the information provided, Aryaka returns the following information to be used to configure Azure Cloud: Aryaka public endpoint IP Pre-shared keys for tunnels Route-based tunnels work with BGP/static routing and any IKE version. Policy-based tunnels work with static routing and IKEv1 only. Configure Azure’s site-to-site VPN Complete the following steps in the Azure portal to configure an IPsec connection with an Aryaka POP after Aryaka support provides you the public endpoint IP. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Login to the Azure portal at  https://portal.azure.com . The Azure Home page appears. Create a virtual network gateway (VNG) to serve as the IPsec endpoint: In the Marketplace Search field, type Virtual Network Gateways and press Enter. Click  Add  to create a new gateway. The Create Virtual Network Gateway page appears. It displays the Basics tab by default: Provide the following information on the Basics tab: Subscription—Select the appropriate subscription type. Name—Enter a descriptive name for your gateway. Region—Select the geographic region where the VNet is configured. Gateway Type—Click VPN. VPN Type—Select  Route-based  for BGP/static routing or  Policy-based  for static routing. SKU—Select the appropriate SKU. Virtual Network—Select the VNet that you need to access over IPsec. Gateway subnet address range—Define a /27 or larger subnet from your VNet’s subnet range. Public IP Address—Click  Create New . Enable active-active mode—Click  Disabled . Configure BGP—Click  Enabled  or  Disabled  as appropriate. If Enabled: Enter the custom Azure APIPA BGP IP address provided by Aryaka in the corresponding field. Accept the default number in the Autonomous System Number (ASN) field.  Click  Review + create . The Review tab appears. Verify the details, then click  Create . The virtual network gateway can take up to 45 minutes to complete configuration. While it processes, you can create the local network gateways, which include the Aryaka POP endpoint details. Create a local network gateway:  In the Marketplace search field, enter Local Network Gateway and press Enter. Click  Create  on the search results page. The Create local network gateway page appears: Provide following information: IP Address—Enter the public IP address provided by Aryaka. Address Space (Static routing only)—Enter remote site’s prefixes. Up to 4,000 prefixes can be configured. Configure BGP Settings—Click the checkbox to enable BGP for the local gateway. If enabled, enter the ASN and BGP Peer IP address provided by Aryaka in the corresponding fields that appear. Click  Create . The local gateway is created. After the VNG you created in step 2 is deployed by Azure, create the Primary IPsec connection: Navigate to Virtual Network Gateways page and click on the newly-created VNG. In the left navigation pane, click  Connections  >  Add . The Add connection page appears: Provide following information: Name—Enter the name of your IPsec connection based on its primary or secondary role. Connection type—Select  Site-to-site (IPsec) . Virtual Network Gateway—Select the VNG that you created in step 2. Local Network Gateway—Select the Aryaka-specific local gateway that you created in step 3. Shared key (PSK)—Enter the key provided by Aryaka support. Use Azure Private IP Address—Clear the checkbox. Enable BGP—Clear the checkbox if you are using static routing. IKE Protocol—Select one of the following options: If you are using a policy-based tunnel, click  IKEv1 . If you are using a route-based tunnel, click either  IKEv1  or  IKEv2 . Click  Create . The connection is create, and the the status of the new IPsec connection appears as Not Connected. Provide the following information to Aryaka support to establish VPN connectivity: Open the Virtual Network Gateway page, then select your VNG. Click  Connections  and select the newly-created IPsec VPN. Click  Download configuration  and select the following options: Device vendor—Juniper Device family—Juniper_SRX_GA Firmware version—Juniper_SRX_12.x_GA Click  Download Configuration  and share the downloaded text file with Aryaka support. After Aryaka completes the IPsec VPN configuration and the IPsec connection is established, the status now appears as Connected.  Repeat this procedure to create a backup (secondary) connection. In this topic Related topics Create a Site-to-Site connection in the Azure portal  ( microsoft.com )