{"id":11737,"date":"2026-10-07T00:30:07","date_gmt":"2026-10-07T00:30:07","guid":{"rendered":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/"},"modified":"2026-10-07T00:30:07","modified_gmt":"2026-10-07T00:30:07","slug":"microsoft-az-104-vpn-gateway-design-on-azure","status":"publish","type":"post","link":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/","title":{"rendered":"Microsoft AZ-104: VPN Gateway Design on Azure"},"content":{"rendered":"<p>Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested failure path.<\/p>\n<p>Microsoft&#8217;s current VPN Gateway guidance recommends AZ-capable gateway SKUs for new deployments and documents active-active designs where both Azure gateway instances use separate public IPs. For maximum site-to-site reliability, Microsoft shows dual-redundancy active-active designs with two on-premises VPN devices and four IPsec tunnels\u2014two to each Azure gateway instance.<\/p>\n<p>VPN Gateway design belongs inside <a href=\"https:\/\/www.prepaway.com\/certification\/azure-architecture-in-practice\/\">Azure Architecture in Practice<\/a>.<\/p>\n<h3>Choose the gateway SKU from requirements<\/h3>\n<p>Gateway SKUs determine throughput benchmarks, connection counts, point-to-site scale, BGP support, and zone-redundant capability.<\/p>\n<p>Microsoft is simplifying the portfolio toward AZ-capable SKUs for new deployments.<\/p>\n<p>Size for peak and failure-state traffic rather than selecting the lowest tier that passes a pilot.<\/p>\n<h3>Use zone-redundant gateways where supported<\/h3>\n<p>AZ gateway SKUs can deploy gateway instances across Azure Availability Zones in supported regions.<\/p>\n<p><a href=\"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-availability-zones-and-failure-domains\/\">Zone resilience<\/a> protects the Azure gateway layer from one zone failure, while the on-premises VPN devices and provider paths still need independent redundancy.<\/p>\n<p>A zone-redundant gateway attached to one customer firewall is not an end-to-end resilient design.<\/p>\n<h3>Use active-active for higher resilience<\/h3>\n<p>Active-active mode uses both Azure gateway instances concurrently and provides a public IP for each instance.<\/p>\n<p>For S2S connectivity, on-premises devices should establish tunnels to both instances to preserve connectivity during gateway maintenance or instance failure.<\/p>\n<p>Microsoft&#8217;s current guidance shows a four-tunnel full mesh when two on-premises devices participate.<\/p>\n<h3>Use BGP for dynamic route exchange<\/h3>\n<p>BGP can reduce static route management and support failover when multiple paths advertise the same prefixes.<\/p>\n<p><a href=\"https:\/\/www.prepaway.com\/certification\/expressroute-vs-vpn-choosing-the-right-azure-hybrid-connection\/\">Hybrid connectivity<\/a> should define ASN, advertised prefixes, route preference, and fallback rather than enabling BGP without a routing plan.<\/p>\n<p>Summarize where possible and monitor route count so the design stays within gateway limits.<\/p>\n<h3>Keep active-standby only for a real compatibility reason<\/h3>\n<p>Some on-premises VPN devices or legacy designs cannot maintain tunnels to both Azure gateway instances.<\/p>\n<p>Microsoft notes that active-standby remains an option in such cases.<\/p>\n<p>Document the maintenance\/failover impact and plan a future path toward active-active where the business requires higher resilience.<\/p>\n<h3>Design point-to-site separately<\/h3>\n<p>P2S VPN serves individual clients and has separate protocol, authentication, and scale considerations from S2S.<\/p>\n<p>Use Microsoft Entra ID, certificates, or RADIUS according to the supported protocol and security requirement.<\/p>\n<p>Remote-user VPN should not inherit broad network reach simply because the site-to-site gateway connects to many private networks.<\/p>\n<h3>Plan address space and routing before deployment<\/h3>\n<p>Overlapping on-premises and Azure prefixes complicate or prevent straightforward routing.<\/p>\n<p><a href=\"https:\/\/www.prepaway.com\/certification\/why-azure-vnets-fail-address-spaces-routes-and-dns\/\">VNet design<\/a> should reserve address space and document routes before connecting branches.<\/p>\n<p>NAT features can solve selected overlap scenarios, but avoiding overlap through address planning is simpler when possible.<\/p>\n<h3>Monitor tunnels and effective routes<\/h3>\n<p>Operations should track connection status, BGP peer state, tunnel throughput, packets dropped, learned routes, and recent changes.<\/p>\n<p><a href=\"https:\/\/www.prepaway.com\/certification\/troubleshooting-azure-network-paths-end-to-end\/\">Network troubleshooting<\/a> should confirm effective routes and packet flow before administrators regenerate keys or rebuild a gateway.<\/p>\n<p>Hybrid outages often come from route or on-premises changes while the VPN tunnel itself remains up.<\/p>\n<h3>Test maintenance and failure<\/h3>\n<p>Disconnect one on-premises device, one ISP path, and one Azure tunnel in controlled tests.<\/p>\n<p>For <a href=\"https:\/\/www.prepaway.com\/az-700-exam.html\">AZ-700<\/a>, mature VPN design is AZ gateway \u2192 active-active \u2192 redundant customer devices \u2192 BGP where useful \u2192 capacity\/limits \u2192 monitored routes \u2192 measured failover.<\/p>\n<p>A tunnel is infrastructure; the user-visible requirement is reliable application connectivity through failure.<\/p>\n<p>IPsec parameters should be standardized where custom policy is required. Mismatched IKE version, encryption, integrity, DH group, lifetime, or traffic selectors can create brittle connections that fail after a device change. Prefer supported defaults unless compliance or interoperability requires customization.<\/p>\n<p>VPN Gateway is often a good backup to ExpressRoute when the business can tolerate the internet path and lower capacity. Preconfigure and test that backup before an ExpressRoute incident rather than building it during the outage.<\/p>\n<p>Forced tunneling, Azure Firewall, Route Server, and Virtual WAN can all change hybrid traffic paths. Keep the VPN gateway role clear so route propagation does not unintentionally bypass security inspection or create loops.<\/p>\n<p>Document tunnel ownership across cloud and network teams. One side should know which Azure connection maps to which customer device, provider circuit, peer IP, and BGP session so incidents do not become a two-team guessing exercise.<\/p><p>Gateway subnet design is part of the architecture. Reserve enough address space for the current SKU and future changes so the environment is not forced into a disruptive VNet redesign during a gateway migration. Keep unrelated workloads out of the GatewaySubnet.<\/p>\n<p>Active-active mode is most useful when the on-premises side is equally redundant. Two Azure gateway instances connected to one physical VPN appliance still leave a single customer-side failure point. The strongest pattern uses redundant customer devices, separate internet providers where justified, and tunnels to both Azure instances.<\/p>\n<p>BGP route design should include route filters and ownership. Advertising the entire corporate routing table can exceed limits or unintentionally make Azure a transit path. Send only the prefixes the connected workloads require and monitor changes in route count.<\/p>\n<p>Point-to-site architecture should consider split versus forced tunneling, DNS, client address pools, authentication, and device management. Remote-user connectivity is an identity and endpoint-security problem as well as a networking problem.<\/p>\n<p>Network address translation can help when acquired companies or partners use overlapping prefixes, but NAT adds translation state and troubleshooting complexity. Use it selectively and document which side sees original versus translated addresses.<\/p>\n<p>Gateway upgrades or SKU migrations should have maintenance and rollback plans. Some changes require public IP or gateway replacement behavior that affects tunnels. Read the current migration path before treating the gateway as easily mutable infrastructure.<\/p>\n<p>VPN monitoring should correlate Azure metrics with the customer device logs. A tunnel can appear connected while packet loss, negotiation churn, or route mismatch makes the application unusable. End-to-end probes provide stronger evidence than one green connection status.<\/p>\n<p>When VPN backs up ExpressRoute, route preference should be tested before a real circuit outage. The VPN path should become active automatically or through a documented process, carry the intended prefixes, and have enough capacity for the critical subset of traffic.<\/p>\n<p>Security policy should not assume IPsec alone provides authorization. The tunnel protects the path, but workload firewalls, NSGs, identity, and application authorization still decide what a connected branch or user may access.<\/p>\n<p>Document the complete hybrid path, including Azure gateway, connection, local network gateway, customer devices, provider links, BGP, routes, DNS, and inspection. This makes incident ownership and failover testing far more predictable.<\/p>\n<p>Gateway resiliency should be tested during planned Azure maintenance as well as simulated customer-side failure. Active-active designs should keep traffic flowing when one Azure instance or one customer device is unavailable, and monitoring should prove the alternate tunnel actually carried the session.<\/p>\n<p>Packet fragmentation and MTU can become important across IPsec, especially when applications send large packets or when additional encapsulation is present. A tunnel can appear healthy while certain workloads fail because path MTU is wrong. Include large-packet and application tests in validation.<\/p>\n<p>Gateway configuration should be deployed as code where feasible so connection objects, BGP settings, local network gateways, and diagnostic settings can be reviewed and reproduced. Manual portal-only configuration makes recovery and peer comparison harder.<\/p>\n<p>Point-to-site address pools must not overlap with VNet, on-premises, or other remote-user ranges. Plan these addresses centrally so a later merger or branch connection does not create ambiguous routing.<\/p>\n<p>The architecture is complete when the enterprise can lose one tunnel, one Azure gateway instance, one customer device, or one provider path and still understand exactly which route, tunnel, and security controls the application will use next.<\/p>\n<p>Authentication key rotation should be documented for site-to-site connections. Pre-shared keys, certificates, or device credentials need an agreed rotation process across Azure and the customer endpoint so a security change does not cause an avoidable outage.<\/p>\n<p>Use diagnostics and packet captures selectively when a tunnel is up but traffic fails. Check learned routes, effective routes, NSGs, firewall rules, NAT, and return path before assuming the IPsec negotiation is the problem.<\/p>\n<p>Availability tests should include planned gateway maintenance scenarios because Microsoft can service individual gateway instances. An active-active design with both customer tunnels established is specifically intended to reduce impact during those events.<\/p>\n<p>For global estates, multiple VPN gateways can be necessary because the service is regional. Place gateways near connected workloads and branches and decide whether Virtual WAN provides a simpler managed model once the number of branches and regions grows.<\/p>\n<p>VPN Gateway is mature when it is treated as a routable, monitored, redundant network service with capacity and ownership\u2014not as a one-time tunnel configuration.<\/p>\n<p>Document the gateway&#8217;s critical application prefixes and normal route preferences so failover tests can verify not only that tunnels remain established but that the same protected business traffic still follows the intended path.<\/p>\n<p>Review the design after new branches, mergers, address-space changes, or gateway SKU migrations because hybrid routing complexity tends to grow faster than the original tunnel diagram.<\/p>","protected":false},"excerpt":{"rendered":"<p>Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested failure path. Microsoft&#8217;s current VPN Gateway guidance recommends AZ-capable gateway SKUs for new deployments and documents active-active designs where both Azure gateway instances use separate public IPs. For maximum site-to-site reliability, Microsoft shows dual-redundancy active-active&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-11737","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"admin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"PrepAway - Fastest Way to Pass IT Certification Exams - PrepAway\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway\" \/>\n\t\t<meta property=\"og:description\" content=\"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-07T00:30:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-07T00:30:07+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#blogposting\",\"name\":\"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway\",\"headline\":\"Microsoft AZ-104: VPN Gateway Design on Azure\",\"author\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/wp-content\\\/uploads\\\/2017\\\/12\\\/logo.png\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#articleImage\",\"width\":186,\"height\":38},\"datePublished\":\"2026-10-07T00:30:07+00:00\",\"dateModified\":\"2026-10-07T00:30:07+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#listItem\",\"name\":\"Microsoft AZ-104: VPN Gateway Design on Azure\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#listItem\",\"position\":3,\"name\":\"Microsoft AZ-104: VPN Gateway Design on Azure\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#organization\",\"name\":\"PrepAway Certification\",\"description\":\"Fastest Way to Pass IT Certification Exams - PrepAway\",\"url\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/wp-content\\\/uploads\\\/2017\\\/12\\\/logo.png\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#organizationLogo\",\"width\":186,\"height\":38},\"image\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/author\\\/admin\\\/\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/69b3eaeff2d2bf70759f8c56ad9a52614771e4f88b2806c16f0a25cc297f9267?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"admin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#webpage\",\"url\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/\",\"name\":\"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway\",\"description\":\"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/microsoft-az-104-vpn-gateway-design-on-azure\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/author\\\/admin\\\/#author\"},\"datePublished\":\"2026-10-07T00:30:07+00:00\",\"dateModified\":\"2026-10-07T00:30:07+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#website\",\"url\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/\",\"name\":\"PrepAway Certification\",\"description\":\"Fastest Way to Pass IT Certification Exams - PrepAway\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.prepaway.com\\\/certification\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway","description":"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested","canonical_url":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#blogposting","name":"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway","headline":"Microsoft AZ-104: VPN Gateway Design on Azure","author":{"@id":"https:\/\/www.prepaway.com\/certification\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.prepaway.com\/certification\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png","@id":"https:\/\/www.prepaway.com\/certification\/#articleImage","width":186,"height":38},"datePublished":"2026-10-07T00:30:07+00:00","dateModified":"2026-10-07T00:30:07+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#webpage"},"isPartOf":{"@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/#listItem","position":1,"name":"Home","item":"https:\/\/www.prepaway.com\/certification\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/www.prepaway.com\/certification\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#listItem","name":"Microsoft AZ-104: VPN Gateway Design on Azure"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#listItem","position":3,"name":"Microsoft AZ-104: VPN Gateway Design on Azure","previousItem":{"@type":"ListItem","@id":"https:\/\/www.prepaway.com\/certification\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/www.prepaway.com\/certification\/#organization","name":"PrepAway Certification","description":"Fastest Way to Pass IT Certification Exams - PrepAway","url":"https:\/\/www.prepaway.com\/certification\/","logo":{"@type":"ImageObject","url":"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#organizationLogo","width":186,"height":38},"image":{"@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.prepaway.com\/certification\/author\/admin\/#author","url":"https:\/\/www.prepaway.com\/certification\/author\/admin\/","name":"admin","image":{"@type":"ImageObject","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/69b3eaeff2d2bf70759f8c56ad9a52614771e4f88b2806c16f0a25cc297f9267?s=96&d=mm&r=g","width":96,"height":96,"caption":"admin"}},{"@type":"WebPage","@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#webpage","url":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/","name":"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway","description":"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.prepaway.com\/certification\/#website"},"breadcrumb":{"@id":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/#breadcrumblist"},"author":{"@id":"https:\/\/www.prepaway.com\/certification\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.prepaway.com\/certification\/author\/admin\/#author"},"datePublished":"2026-10-07T00:30:07+00:00","dateModified":"2026-10-07T00:30:07+00:00"},{"@type":"WebSite","@id":"https:\/\/www.prepaway.com\/certification\/#website","url":"https:\/\/www.prepaway.com\/certification\/","name":"PrepAway Certification","description":"Fastest Way to Pass IT Certification Exams - PrepAway","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.prepaway.com\/certification\/#organization"}}]},"og:locale":"en_US","og:site_name":"PrepAway - Fastest Way to Pass IT Certification Exams - PrepAway","og:type":"article","og:title":"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway","og:description":"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested","og:url":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/","og:image":"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png","og:image:secure_url":"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png","article:published_time":"2026-10-07T00:30:07+00:00","article:modified_time":"2026-10-07T00:30:07+00:00","twitter:card":"summary_large_image","twitter:title":"Microsoft AZ-104: VPN Gateway Design on Azure - PrepAway","twitter:description":"Azure VPN Gateway provides encrypted connectivity for site-to-site, point-to-site, and VNet-to-VNet scenarios. A production design is not complete when one IPsec tunnel connects. The architecture needs an appropriate gateway SKU, zone strategy, active-active or active-standby mode, BGP where dynamic routing adds value, redundant on-premises VPN devices, connection and route limits, authentication choices, and a tested","twitter:image":"https:\/\/www.prepaway.com\/certification\/wp-content\/uploads\/2017\/12\/logo.png"},"aioseo_meta_data":[],"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.prepaway.com\/certification\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.prepaway.com\/certification\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tMicrosoft AZ-104: VPN Gateway Design on Azure\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.prepaway.com\/certification\/"},{"label":"Uncategorized","link":"https:\/\/www.prepaway.com\/certification\/category\/uncategorized\/"},{"label":"Microsoft AZ-104: VPN Gateway Design on Azure","link":"https:\/\/www.prepaway.com\/certification\/microsoft-az-104-vpn-gateway-design-on-azure\/"}],"_links":{"self":[{"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/posts\/11737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/comments?post=11737"}],"version-history":[{"count":0,"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/posts\/11737\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/media?parent=11737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/categories?post=11737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prepaway.com\/certification\/wp-json\/wp\/v2\/tags?post=11737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}