---
title: "Azure VPN"
canonical: "https://docs.aryaka.com/space/KNOW/1291944064/Azure%20VPN"
format: markdown
---
Microsoft Azure is an internet-scale computing and services platform hosted in data centers managed or supported by Microsoft. Aryaka customers can optimize their connectivity to Azure datacenter locations outside of the US, Singapore, and Amsterdam by connecting these datacenters to Aryaka using a route-based VPN. This document describes the steps that Aryaka customers must perform to enable route-based VPN for their configuration instance. Topology Private customer sites connect to Aryaka at their nearest geographic  point of presence  (POP). These POPs are then linked to the Aryaka POP nearest to their Azure datacenter. Aryaka POPs connect to the Azure datacenter using an IPSec tunnel. Prerequisites To configure an Azure instance to connect to Aryaka using VPN, the following information must be shared with the Aryaka Provisioning Team: Azure location Azure local subnets After receiving this information, the Aryaka Provisioning Team returns an IP address, which becomes the VPN peer for the Azure instance. Create a VPN gateway The following procedure describes the creation of a VPN gateway to use between Aryaka and Azure. The process includes creating a virtual network (VNet) then creating a gateway and associating it with the VNet. If you want to use an existing VNet for your VPN gateway, verify the Status column of the VNet appears as Created, and the VNet that must have all the subnets—local and remote to Azure—configured as described in step 4. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. To create a VPN gateway Login to the Azure management portal. Click  Networks  in the left navigation pane. A list all existing virtual networks (VNets) appears.  Click  New  >  Networks Services  >  Virtual Network  >  Create Custom . Enter a descriptive name and location for the VNet, then click  Next . Enable the  Configure a site to site VPN  option  in the Site-to-Site Connectivity section. Click the  Next  > arrow at the bottom of the page. Select a local network. If the local network is not already created, create one as follows:  Click the  Specify a New Local Network  option.  In the Site-to-Site Connectivity settings, enter a name for the local network in the Name field (for example Aryaka Azure Config). Enter the Aryaka POP IP (the Aryaka peer IP returned by Aryaka Support) in the VPN Device IP Address field.  Click  Add Address Space  and add all the address spaces remote to Azure (that is, the remote offices’ subnets).  Click the  Next  > arrow at the bottom of the page.  Configure the address spaces local to Azure and the also subnets that could be derived. Click the  check mark  at the bottom of the page. The VNet is created and the status now appears as Created. Associate the new VNet with the gateway: Click the  <VNet_name> . The VNet's Dashboard appears. Click  Create Gateway  (bottom of the page), then select  Dynamic Routing . Click  Yes  when the system prompts you to confirm that you want the gateway created. The creation process can take 15 to 20 minutes during which time, the gateway's status appears as Creating Gateway and the gateway line is yellow. Download the VPN configuration file that you must share with Aryaka Support (as described in the next section): Click  Download VPN Device Script  in the Quick Glance section or click  Networks  >  VNet  >  Dashboard  > Export  (at the bottom of the page). A dialog that appears. Click the Vendor drop-down list, then select  Cisco .  Click the Platform drop-down list, then select  ISR Series Integrated Services Routers – Dynamic Routing .  Click the Operating System drop-down list, then select  IOS 15.1   or above . Click the  check mark  to initiate the download. Ensure that the gateway has been created successfully (the gateway color code changes from yellow to blue). Send the downloaded configuration file to Aryaka After the VPN gateway has been created and the router configuration file downloaded, share it with Aryaka Support and complete the configuration as follows. Send the downloaded file (from step 8 in the previous section) to  support@aryaka.com . Aryaka configures the VPN per the file's contents and responds to you when the configuration is complete. After receiving confirmation from Aryaka, log in to the Azure management portal, then navigate to  Networks  >  VNet  >  Dashboard . Click  Connect  (bottom of the page) to initiate VPN negotiation. If the VPN fails to connect, contact Aryaka support for troubleshooting. In this topic Related topics Azure ExpressRoute Portal Azure ExpressRoute Power Shell Microsoft References: Manage VNet Settings Configure a VPN gateway in the Azure portal Create a site-to-site connection Azure documentation