惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
有赞技术团队
有赞技术团队
博客园 - 叶小钗
博客园 - Franky
博客园_首页
S
SegmentFault 最新的问题
阮一峰的网络日志
阮一峰的网络日志
博客园 - 司徒正美
罗磊的独立博客
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
B
Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Recent Announcements
Recent Announcements
V
Visual Studio Blog
J
Java Code Geeks
D
Docker
Martin Fowler
Martin Fowler
Blog — PlanetScale
Blog — PlanetScale
腾讯CDC
The Register - Security
The Register - Security
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
The GitHub Blog
The GitHub Blog
Microsoft Azure Blog
Microsoft Azure Blog
美团技术团队
博客园 - 【当耐特】
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Commits to openclaw:main
Recent Commits to openclaw:main
G
Google Developers Blog
S
Schneier on Security
Apple Machine Learning Research
Apple Machine Learning Research
AWS News Blog
AWS News Blog
N
Netflix TechBlog - Medium
量子位
爱范儿
爱范儿
D
Darknet – Hacking Tools, Hacker News & Cyber Security
MyScale Blog
MyScale Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Spread Privacy
Spread Privacy
V
Vulnerabilities – Threatpost
A
Arctic Wolf
C
Cisco Blogs
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
The Cloudflare Blog
C
CERT Recently Published Vulnerability Notes
L
LINUX DO - 最新话题
W
WeLiveSecurity
Hacker News: Ask HN
Hacker News: Ask HN

NetBird - Networking Knowledge Hub - RSS Feed

NetBird Is Now on the Vultr Marketplace Native NetBird on the GL.iNet Comet Pro (GL-RM10) NetBird v0.71 - IPv6 Overlay Addressing NetBird Exit Nodes - Appear at Home, or Anywhere Else Reporting Bugs and Requesting Features in NetBird Setup and Use Local AdGuard Home Anywhere with NetBird DNS How to Set Up NetBird on PiKVM for Secure Remote KVM Access NetBird v0.69 - CrowdSec IP Reputation for the Reverse Proxy Cloudflare Mesh vs NetBird vs Tailscale: Performance Compared Self-Hosting Nextcloud with Docker and NetBird Implementing Zero Trust with NetBird NetBird v0.67 - Layer 4 Proxy Support for TCP, UDP, and TLS Solwr Enhances Remote Connectivity with NetBird Self-Hosting NetBird with Authentik Jellyfin Media Server - Self-Host Your Movies, TV, and Music Cloudflare Tunnels vs. NetBird Reverse Proxy INFITX Builds Zero-Touch Kubernetes Networking with NetBird NetBird v0.66 - Expose Local Services to the Internet from the CLI Pangolin vs. NetBird Home Assistant Setup Guide with EASY Remote Access NetBird v0.65 - Built-in Reverse Proxy with Custom Domains Docker for Beginners - Everything You Need to Get Started NetBird for SOC 2 Compliance NetBird v0.63 - Custom DNS Zones for Private Network Resolution Vibecode This in a Weekend and Take 5% of the Company NetBird v0.62 - Built-in Local Users with Optional IdP Integration NetBird v0.61.0 - Granular SSH Access Control and Automatic Updates Top 5 Alternatives to OpenVPN Top 5 Open Source Alternatives to Tailscale Top 5 Alternatives to ZeroTier How to Set Up ZeroByte and REST Server for Backups with NetBird How to Install n8n v2.0 with NPM and PM2 ZeroTier vs. NetBird The Ultimate Immich Guide - Ditch Google and Amazon Photos for Good NetBird as Your Help with ISO 27001 Compliance NetBird and Huntress - Secure Network Access for MSPs How to Access Windows Shares from Anywhere with NetBird netgo Relies on Modern ZTNA with NetBird Connect to Your Homelab from Anywhere with a Raspberry Pi NetBird SSH - A New, Identity-Aware Approach The AI Mega Mesh: How to Connect 30+ GPU Cloud Providers Connect Multiple Ollama GPUs to OpenWebUI with NetBird Top 5 Tailscale Alternatives SSH and RDP, now in your browser NetBird–Acronis Integration: Empowering MSPs for Advanced Ransomware and Threat Defense Introducing the Control Center - Remote Access, Beautifully Visualized NetBird at MSP Global 2025 Understanding Overlay Networks - The Basics NetBird and SentinelOne Singularity™ - Automate Threat Response NetBird and Microsoft Intune - Enforcing Device Compliance for Zero Trust Rethinking Zero Trust Security with NetBird and pfSense Improving Unidirectional Access Control Proxmox VE for Beginners Guide with NetBird LXC Stronger Security: NetBird + GitHub Secure Open Source Fund NetBird's MSP Partner Program Signicat Enhances Cross-Cloud Accessibility with NetBird SonicWall SSL VPN NetExtender vs. NetBird NetBird Is Embracing the AGPLv3 License NetBird Profiles Have Landed - Manage Multiple Accounts Effortlessly Rethinking Access Control to Secure Your On-Premises SharePoint Servers Sport Alliance Increases Efficiency with Zero Trust Networking at Scale Rethinking Network Access: qwertiko Goes Zero Trust with NetBird Optimizing Network Efficiency with NetBird's Lazy Connections Use Port Ranges in Access Control Policies Generic HTTP Endpoint for Network Events Streaming NetBird’s Response to Spear-Phishing Campaign Targeting Financial Executives Zero-Trust Access to Internal Resources Without Installing Agents Enhance Network Visibility with NetBird’s Traffic Events Logging TrueNAS Made Easy - Install, Set Up, and Access From Anywhere Top 5 Alternatives for WireGuard Jump Hosts. Gateways for Remote Access NetBird Network Routes and Exit Nodes Security for All - SSO and MFA for Free Enhancing Network Access Control with NetBird's Identity Provider Feature Twingate vs. NetBird Limit Network Access Based on Running Applications FortiClient ZTNA vs. NetBird OpenVPN vs. NetBird Tailscale vs. NetBird Getting Started with an On-premise-to-AWS Site-to-Site VPN Secure Remote Access to VPCs, LANs, and Offices regreSSHion - A New OpenSSH Server Remote Code Execution Vulnerability Evolve Bank & Trust Data Breach. What Happened? What Is a Site-to-Site VPN? IPSec Tunneling Demystified. Enhancing Data Security Across Networks Understanding IPSec Tunnel and Transport Modes Understanding the Differences Between IKEv1 and IKEv2 Understanding the IKEv1 Protocol in IPSec ZeroTier versus NetBird - Which Should You Choose? AWS Lambda Serverless Security. Mistakes, Oversights, and Potential Vulnerabilities Using NetBird for Kubernetes Access Serverless Security Vulnerabilities and Best Practices to Mitigate Them Security Best Practices for Serverless Azure Functions A Guide to Remote Access Security for SMEs IoT Security Essentials. How to Achieve Secure Remote Access Open Source Zero Trust Networking Using SSH for Secure Remote Access How We Integrated Rosenpass in NetBird The First Quantum-Resistant Mesh VPN Using eBPF and XDP to Share Default DNS Port Between Multiple Resolvers
Getting Started with an Azure Site-to-Site VPN
Written byJoshua Marks · 2024-07-23 · via NetBird - Networking Knowledge Hub - RSS Feed

A site-to-site virtual private network (VPN) provides secure remote connectivity between private networks over public connections like the internet. This connectivity could be between two branches or data centers, or it could be from an on-premise network to a cloud network.

The Azure site-to-site VPN is one of the quickest methods to achieve secure remote connectivity between your on-premise network and Azure resources hosted in a virtual network. This is in comparison with a physical cross-connect using Azure ExpressRoute or a VPN based on a network virtual appliance (NVA).

In this article, you'll learn how to set up an Azure site-to-site VPN to provide secure remote connectivity between your on-premise network and a virtual network using the Azure portal. During this process, you'll create a virtual network, gateway subnet, VPN gateway, and a local network gateway. Then, you'll configure your VPN devices, create and verify those VPN connections, and finally, connect to a virtual machine.

What Is Azure Site-to-Site VPN

Azure site-to-site VPN is an encrypted connection from an Azure VPN Gateway to a remote VPN device that supports IP security (IPsec) as a tunneling protocol. An Azure VPN Gateway is a Microsoft Azure platform-as-a-service (PaaS) offering that provides reliable, redundant, and high-performance connectivity between an Azure virtual network and remote sites:

Azure site-to-site VPN architecture, courtesy of Joshua Marks

When configuring a site-to-site VPN over the internet, the VPN Gateway requires its own dedicated subnet and a public IP address. Azure offers multiple SKUs to facilitate specific performance and capacity requirements. As with most public cloud services, Azure site-to-site VPN incurs a cost for consumption that varies based on the SKU. Once the VPN Gateway is configured for an Azure site-to-site VPN, the Azure portal can produce a configuration template for the remote VPN device to simplify the on-premise part of the deployment.

In an Azure classic deployment model , each cloud resource exists independently, ungrouped, and unrelated from other resources. However, in its updated resource manager model , resource groups gather related resources. This latter model is recommended for all new deployments.

Using Azure Site-to-Site VPN

Before configuring an Azure site-to-site VPN, you need the following:

Create a Virtual Network

Once you have your prerequisites in place, it's time to create a virtual network (VNet) to connect the site-to-site VPN to private Azure resources. The virtual network contains subnets where you can deploy networking services, including the Azure VPN Gateway.

The following values are used in this guide, but you can adjust these values as needed:

  • Resource Group: dev-aue-net-rg
  • VNet Name: dev-aue-vnet-01
  • Region: Australia East (or your nearest geographic location)
  • IPv4 Address Space: 10.10.10.0/24
  • Subnet: WorkloadSubnet
  • Subnet Address Range: 10.10.10.0/26

Log in to the Azure portal, type "vnet" in the search bar, and select Virtual networks to open its menu:

Virtual network search results

Select Create to enter the virtual network creation workflow. In the Basics tab, enter the required values and create a new resource group if necessary. Click Next at the bottom of the page after completing this step:

Virtual network basics

In the Security tab, enter any required configuration or leave the default values. Then click Next when done.

In the IP addresses tab, enter the allocated VNet IP address space and create the subnet (ie WorkloadSubnet). This subnet hosts the virtual machine that connects to the Azure site-to-site VPN:

Virtual network IP addressing

When complete, click Review + create. Review the workflow configuration summary and select Create to deploy the virtual network:

Virtual network creation summary

Create a Gateway Subnet

Before deploying a VPN Gateway, you need to create a gateway subnet to host it. Within your newly created virtual network, navigate to Settings > Subnets and select the + Gateway subnet button at the top of the page to enter the subnet creation flow:

+ Gateway subnet button

The Subnet purpose should be set to Virtual Network Gateway. Make sure you don't change this setting. Note that the subnet is automatically named GatewaySubnet. This is required for it to be dedicated to a VPN Gateway.

Enter the subnet allocation for the gateway subnet in the IPv4 section, ensuring that the Size field matches the desired subnet mask as this cannot be changed once the VPN Gateway has been deployed in the subnet. The subnet mask must be a /27 at minimum to support Azure VPN Gateway. A /26 is used in this example to allow for expansion for future use cases.

You haven't specified IPv6 for this virtual network, so the IPv6 section is grayed out, and you don't need to worry about the remainder of the subnet options. Once complete, select Add to create the Gateway subnet:

Gateway subnet creation

Create a VPN Gateway

With a VNet and dedicated subnet created, it's time to deploy the VPN Gateway to host the Azure site-to-site VPN.

In the Azure portal search bar, type "virtual network gateway" and select the Virtual network gateway icon in the results. Hit Create to enter the virtual network gateway creation flow.

You'll use the following values in this tutorial, but you can adjust the values based on your own requirements:

  • Resource Group: dev-aue-net-rg
  • Gateway Name: dev-aue-vgw-01
  • Region: Australia East (or your nearest geographic location)
  • Gateway Type: VPN
  • SKU: VpnGw1 (use Microsoft's list of Gateway SKUs to determine the best option for your performance requirements)
  • Virtual Network: dev-aue-vnet-01
  • Subnet: GatewaySubnet (this should be the only option available)

Virtual network gateway instance details

In the Public IP address section, select Create new and name the new Azure public IP address to be assigned to the VPN Gateway. In this example, the remaining options have been disabled; however, if you wish to utilize an active-active mode VPN Gateway or explicitly require Border Gateway Protocol (BGP), you can enable them and complete the configuration:

Virtual network gateway public IP address details

Once complete, hit Review + create, validate your configuration settings, and select Create to deploy the VPN Gateway. Take note that the deployment of a VPN Gateway can take a while—nearly twenty minutes for this example and up to forty-five minutes according to the Microsoft documentation :

Virtual network gateway creation summary

Create a Local Network Gateway

A local network gateway represents the network properties of the on-premise VPN device, which connects to the Azure site-to-site VPN. You need to configure this so the VPN Gateway knows where to send IPsec connection traffic and what network destinations can be reached over the Azure site-to-site VPN.

In the Azure portal search bar, type "local network gateway" and select the Local network gateways icon in the results:

Local network gateway search results

Hit Create and enter the following details for the local network gateway creation flow:

  • Resource Group: dev-aue-net-rg
  • Gateway Name: dev-aue-lgw-01
  • Region: Australia East (or your nearest geographic location)
  • Endpoint: IP address
  • IP address: Input the public IP address of the on-premise VPN device
  • Address Space(s): Input the private IP address ranges that can be reached through the Azure site-to-site VPN

Local network gateway basics

If BGP routing is required, hit the Next: Advanced button to configure BGP settings. Since you're not using BGP routing in this example, hit Review + create, validate your configuration settings, and select Create to deploy the local network gateway:

Local network gateway creation summary

Create a VPN Connection

At this point, you've created all the dependencies, and it's time to deploy the Azure site-to-site VPN using a connection between the VPN Gateway and the on-premise VPN device.

Navigate to the VPN Gateway you deployed previously and select the Connections tab. Hit Add to enter the VPN connection creation workflow.

On the Basics page, enter the following required project details and instance details:

  • Resource group: dev-aue-net-rg
  • Connection type: Site-to-site (IPsec)
  • Name: dev-aue-vpn-01
  • Region: Australia East (or your nearest geographic location)

Then, select the Next: Settings button to configure the VPN connection settings:

VPN connection basics

On the Settings page, enter the required VPN details as follows:

  • Virtual network gateway: dev-aue-vng-01
  • Local network gateway: dev-aue-lng-01
  • Shared Key (PSK): Enter a sufficiently complex string
  • IKE Protocol: IKEv2
  • Use Azure Private IP Address: Disable
  • Enable BGP: Disable
  • IPsec / IKE Policy: Default (the current default policy settings are available in this documentation )
  • Use policy based traffic selector: Disable
  • DPD timeout in seconds: 45
  • Connection Mode: Default

Once the settings page is configured, select Review + create, validate your configuration settings, and select Create to deploy the VPN connection:

VPN connection settings

Configure the VPN Device and Verify the Connection

Now that the Azure side of the site-to-site VPN is configured, you need to set a matching VPN configuration on the on-premise VPN device. When you configure the on-premise VPN device, you have to use the same preshared key (PSK) that was configured on the VPN connection. The Azure VPN Gateway public IP address is configured as the remote tunnel address on the on-premise VPN device. Additionally, the IPsec parameters must match for tunnel negotiation to succeed.

Microsoft provides guidance to configure the VPN device for all enterprise networking vendors . On-premise VPN devices from some vendors can have a configuration template generated within the Azure portal to simplify the deployment process.

To download a configuration template, navigate to the site-to-site VPN connection created previously. Then, in the Overview tab, select the Download configuration button:

Download configuration button

Enter the VPN device details and download the configuration. You can then replace any generic configuration and apply the template to your on-premise VPN device:

VPN device template options

In this guide, you are configuring a remote VPN device to connect to the Azure VPN Gateway using the configuration guide provided by Microsoft in the "Validated VPN devices and device configuration guides."

After configuring your VPN device, you need to use the Azure portal to verify the VPN connection before attempting to consume the site-to-site VPN. Once the on-premise VPN device is configured, navigate back to the VPN connection you created previously, and in the Overview tab, confirm that the status shows Connected:

Verifying VPN connectivity

Connect to a VM

Now that the Azure site-to-site VPN is configured and established, you need to connect to a preexisting Windows Server VM in Azure over the VPN using Remote Desktop Protocol (RDP). In this example, you connect from a Linux desktop, but similar steps apply to a Windows desktop :

Opening remote desktop client

Use the remote desktop client to specify the connection parameters to an Azure VM using its private IP address. This ensures the RDP connection traverses the Azure site-to-site VPN. Connect to the Azure VM using the Connect button:

Configuring remote desktop parameters

If your Azure site-to-site VPN works, you will see a remote desktop session open to the Azure VM. PowerShell was used to confirm that the VM has a private IP address only. Open the Start menu, type "Windows PowerShell," and select Windows PowerShell. Type and hit the Enter key to view the Azure VM network information:

Successful RDP connection

Conclusion

In this tutorial, you used the Azure portal to configure Azure site-to-site VPN with an on-premise VPN device, and you connected to an Azure VM from on-premise over the site-to-site VPN.

While the Azure site-to-site VPN is effective for on-premise-to-Azure connectivity, you should consider using NetBird as an alternative method of remote connectivity as it is simpler, easier, and more scalable. NetBird uses lightweight client software to connect machines securely and directly without the need for a VPN device. By installing the client software on individual machines, you're not required to connect the entire network like with a traditional site-to-site VPN.

However, NetBird still provides the capability to connect on-premise devices to an entire Azure VNet and, in reverse, uses network routes . This provides a similar experience to Azure site-to-site VPN by installing the client on a device in the cloud or on-premise and advertising the target network to which all machines with the client installed can connect.

If you enjoyed reading this guide and want to learn how to use NetBird for more remote access use cases, check out this article that shows you how to use NetBird for Kubernetes Access .