Azure VPN Gateway
A managed service that creates an encrypted IPsec/IKE tunnel over the public internet between an on-premises network (or another VNet) and an Azure Virtual Network, used when ExpressRoute's dedicated circuit isn't required.
Azure VPN Gateway
VPN Gateway encrypts traffic over the public internet between your on-prem network and Azure — cheaper and faster to set up than ExpressRoute, but subject to internet variability.
Why It Matters in Production
CRED's staging environment connects to its office network via a Site-to-Site VPN Gateway, since staging traffic doesn't need ExpressRoute's guaranteed low latency and dedicated bandwidth.
az network vnet-gateway create --resource-group cred-staging-rg \ --name cred-staging-vpngw --public-ip-address vpngw-pip \ --vnet cred-staging-vnet --gateway-type Vpn --sku VpnGw1Common MistakeChoosing VPN Gateway for latency-sensitive production workloads instead of ExpressRoute — internet-routed VPN traffic has unpredictable jitter compared to a dedicated circuit.
Frequently Asked Questions
When would you choose VPN Gateway over ExpressRoute?
VPN Gateway is the right call when you need encrypted connectivity quickly, don't have (or don't want to pay for) a dedicated physical circuit, or are connecting from a location where ExpressRoute isn't provisioned — like a branch office or a developer's site-to-site test setup. It runs over the public internet, so latency and throughput are less predictable than ExpressRoute's private circuit, but setup takes hours instead of the weeks ExpressRoute provisioning typically requires.
What throughput limitation catches teams off guard with VPN Gateway?
The SKU you provision caps aggregate throughput regardless of your internet bandwidth — a Basic or VpnGw1 SKU tops out well below what a modern office internet connection could otherwise push, and teams size the gateway based on their ISP link speed rather than Azure's per-SKU throughput ceiling. Under-provisioning shows up as inconsistent throughput during peak hours that looks like an ISP problem but is actually the gateway SKU being maxed out, requiring a resize (which causes brief downtime) to fix.