Virtual network peering and VPN gateways - Azure Reference Architectures (2024)

This article compares two ways to connect virtual networks in Azure: virtual network peering and VPN gateways.

A virtual network is a virtual, isolated portion of the Azure public network. By default, traffic cannot be routed between two virtual networks. However, it's possible to connect virtual networks, either within a single region or across two regions, so that traffic can be routed between them.

Virtual network connection types

Virtual network peering. Virtual network peering connects two Azure virtual networks. Once peered, the virtual networks appear as one for connectivity purposes. Traffic between virtual machines in the peered virtual networks is routed through the Microsoft backbone infrastructure, through private IP addresses only. No public internet is involved. You can also peer virtual networks across Azure regions (global peering).

VPN gateways. A VPN gateway is a specific type of virtual network gateway that is used to send traffic between an Azure virtual network and an on-premises location over the public internet. You can also use a VPN gateway to send traffic between Azure virtual networks. Each virtual network can have at most one VPN gateway. You should enable Azure DDOS Protection on any perimeter virtual network.

Virtual network peering provides a low-latency, high-bandwidth connection. There is no gateway in the path, so there are no extra hops, ensuring low latency connections. It's useful in scenarios such as cross-region data replication and database failover. Because traffic is private and remains on the Microsoft backbone, also consider virtual network peering if you have strict data policies and want to avoid sending any traffic over the internet.

VPN gateways provide a limited bandwidth connection and are useful in scenarios where you need encryption but can tolerate bandwidth restrictions. In these scenarios, customers are also not as latency-sensitive.

Gateway transit

Virtual network peering and VPN Gateways can also coexist via gateway transit

Gateway transit enables you to use a peered virtual network's gateway for connecting to on-premises, instead of creating a new gateway for connectivity. As you increase your workloads in Azure, you need to scale your networks across regions and virtual networks to keep up with the growth. Gateway transit allows you to share an ExpressRoute or VPN gateway with all peered virtual networks and lets you manage the connectivity in one place. Sharing enables cost-savings and reduction in management overhead.

With gateway transit enabled on virtual network peering, you can create a transit virtual network that contains your VPN gateway, Network Virtual Appliance, and other shared services. As your organization grows with new applications or business units and as you spin up new virtual networks, you can connect to your transit virtual network using peering. This prevents adding complexity to your network and reduces management overhead of managing multiple gateways and other appliances.

Configuring connections

Virtual network peering and VPN gateways both support the following connection types:

  • Virtual networks in different regions.
  • Virtual networks in different Microsoft Entra tenants.
  • Virtual networks in different Azure subscriptions.
  • Virtual networks that use a mix of Azure deployment models (Resource Manager and classic).

For more information, see the following articles:

  • Create a virtual network peering - Resource Manager, different subscriptions
  • Create a virtual network peering - different deployment models, same subscription
  • Configure a VNet-to-VNet VPN gateway connection by using the Azure portal
  • Connect virtual networks from different deployment models using the portal
  • VPN Gateway FAQ

Comparison of virtual network peering and VPN Gateway

ItemVirtual network peeringVPN Gateway
LimitsUp to 500 virtual network peerings per virtual network (see Networking limits).One VPN gateway per virtual network. The maximum number of tunnels per gateway depends on the gateway SKU.
Pricing modelIngress/EgressHourly + Egress
EncryptionAzure Virtual Network Encryption can be leveraged.Custom IPsec/IKE policy can be applied to new or existing connections. See About cryptographic requirements and Azure VPN gateways.
Bandwidth limitationsNo bandwidth limitations.Varies based on SKU. See Gateway SKUs by tunnel, connection, and throughput.
Private?Yes. Routed through Microsoft backbone and private. No public internet involved.Public IP involved, but routed through Microsoft backbone if Microsoft global network is enabled.
Transitive relationshipPeering connections are non-transitive. Transitive networking can be achieved using NVAs or gateways in the hub virtual network. See Hub-spoke network topology for an example.If virtual networks are connected via VPN gateways and BGP is enabled in the virtual network connections, transitivity works.
Initial setup timeFast~30 minutes
Typical scenariosData replication, database failover, and other scenarios needing frequent backups of large data.Encryption-specific scenarios that are not latency sensitive and do not need high throughout.

Contributors

This article is maintained by Microsoft. It was originally written by the following contributors.

Principal author:

  • Anavi Nahar | Principal PDM Manager

Next steps

  • Plan virtual networks
  • Choose a solution for connecting an on-premises network to Azure
Virtual network peering and VPN gateways - Azure Reference Architectures (2024)
Top Articles
City and Lime launch innovative 'micromobility' initiative - Grand Rapids Magazine
Grand Rapids partners with Lime to provide free scooter rides for those in need | The Rapidian
# كشف تسربات المياه بجدة: أهمية وفوائد
Craigslist Bellmore
Botw Royal Guard
Amerideck Motorcycle Lift Cost
El Patron Mexican Restaurant New Ellenton Menu
Savory Dishes Made Simple: 6 Ingredients to Kick Up the Flavor - MSGdish
Salon Armandeus Nona Park
Delta Air Lines - Login
Jocko Joint Warfare Review
Enneagram Test Eclecticenergies Spotify
What to see and do in Spokane, Washington
Rick Lee Oaklawn Park Picks Today
Does Teddy Swims Have A Wife? Exploring The Life Of The Rising Star
My Happy Feet Shoes Review: How I Finally Got Relief from Years of Heel Pain - 33rd Square
Muckleshoot Bingo Calendar
Elgin Il Building Department
Bekijk hier het rouwregister van Uitvaartzorg FSK
Swap Shop Elberton Ga
Sinai Web Scheduler
5 Best Brokerage Accounts for High Interest Rates on Cash Sweep - NerdWallet
Rogers Breece Obituaries
Jacy Nittolo Ex Husband
Craigslist Columbus Ohio Craigslist
Metoprolol  (Kapspargo Sprinkle, Lopressor) | Davis’s Drug Guide
Craigs List Duluth Mn
Fastest Lovakengj Favour
About Us - Carrols Corporation
O'reilly's Los Banos
Look Who Got Busted New Braunfels
Valentino Garavani Flip Flops
Craigslist Palm Desert California
Www Muslima Com
Bella Isabella 1425
Www.publicsurplus.com Motor Pool
Philasd Zimbra
Horseheads Schooltool
MAELLE MAGNETISEUSE A ST-MALO ATTENUE VOTRE LUMBAGO
Magma Lozenge Location
Dumb Money Showtimes Near Cinemark Century Mountain View 16
SYSTEMAX Software Development - PaintTool SAI
Dinar Guru Recaps Updates
South Dakota Bhr
8 Common Things That are 7 Centimeters Long | Measuringly
The Spot Barbershop - Coconut Creek Reviews
Smartmove Internet Provider
Is The Rubber Ducks Game Cancelled Today
Southwest Flight 238
Online-Shopping bei Temu: Solltest du lieber die Finger davon lassen?
Unit 8 Homework 3 Trigonometry
Ap Bio Unit 2 Progress Check Mcq
Latest Posts
Article information

Author: Horacio Brakus JD

Last Updated:

Views: 6261

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Horacio Brakus JD

Birthday: 1999-08-21

Address: Apt. 524 43384 Minnie Prairie, South Edda, MA 62804

Phone: +5931039998219

Job: Sales Strategist

Hobby: Sculling, Kitesurfing, Orienteering, Painting, Computer programming, Creative writing, Scuba diving

Introduction: My name is Horacio Brakus JD, I am a lively, splendid, jolly, vivacious, vast, cheerful, agreeable person who loves writing and wants to share my knowledge and understanding with you.