VPN Gateway
Azure VPN Gateway connects networks and individual clients to an Azure virtual network over an encrypted tunnel. The Azure Enterprise Baseline can add a point-to-site gateway to the hub with one switch, off by default, so engineers reach private endpoints with their Microsoft Entra identity and only the stages their groups allow.
What it does
A virtual network gateway of type VPN lives in the hub's GatewaySubnet. Point-to-site (P2S) connections come from individual clients: each client receives an address from a client address pool and reaches the virtual network, and its peers that allow gateway transit, through the tunnel. With Microsoft Entra ID authentication over OpenVPN, the user signs in with the Azure VPN Client, so multifactor authentication and Conditional Access apply to the connection. Policy groups assign users to different address pools by group membership, and client connection configurations tie each pool to its policy groups.
How BuiltForProd uses it
The switch and the access matrix are in network.hcl:
# ─── Point-to-site VPN ───────────────────────────────────────────────────────────────────────────
# VpnGw1AZ gateway with Entra ID authentication: ~$0.361/hour (~$263/month) plus P2S connection-hours. Read by
# client-vpn (gateway), firewall-policy (vpn-access rules) and vnet-peering (use_remote_gateways).
enable_client_vpn = false # @optional: true creates the gateway, the firewall rules and flips the spoke peerings to use the hub gateway
# Access profiles: pool name -> "all" (every plat VNet plus the core supernets) or the list of reachable stages.
# The pool CIDRs are reserved.client_vpn_pools in vnet_map.yaml (same keys).
vpn_access_profiles = { # @optional: what each address pool may reach
all = "all"
plat_all = ["plat-prod", "plat-staging", "plat-dev", "plat-sandbox"]
lower = ["plat-staging", "plat-dev", "plat-sandbox"]
dev_sandbox = ["plat-dev", "plat-sandbox"]
}
When enable_client_vpn = true, three units change together:
client-vpncreatesacme-eus2-network-vpngw, a zone-redundantVpnGw1AZgateway with a zone-redundant public IP, OpenVPN only and Entra ID authentication against the tenant. The comments list about $0.361 an hour (about $263 a month) plus P2S connection-hours;VpnGw2AZor larger is the option for more than 250 concurrent connections. It creates one policy group and one client connection configuration per pool, whose members are the Entra groups mapped to it, and sends gateway, tunnel, route, IKE and P2S logs to the audit workspace.firewall-policyadds thevpn-accessrule collection group: one rule per pool, from the pool's range to the stages its groups may reach and to the resolver's inbound address.vnet-peeringswitches every spoke side of the peering to use the hub's gateway.
| Pool | Range | Reaches | Groups (from vpn_group_access) |
|---|---|---|---|
all | 172.16.0.0/23 | every plat network and the core ranges | Platform Leads, Platform Engineers, Lead Security Auditors, Security Auditors |
plat_all | 172.16.2.0/24 | the four plat stages | DevOps Leads |
lower | 172.16.3.0/24 | staging, dev, sandbox | DevOps Engineers, Lead App Developers, Lead ETL Engineers, Lead AI Engineers |
dev_sandbox | 172.16.4.0/23 | dev, sandbox | App Developers, ETL Engineers, AI Engineers; also the default pool |
The pools sit outside the organization range, in reserved.client_vpn_pools of the address plan. A route table on GatewaySubnet sends each spoke prefix and the runner network to the Azure Firewall, so VPN traffic crosses the same stateful policy in both directions. VPN clients resolve private endpoint names through the DNS Private Resolver, whose address the hub hands out as its DNS server. The network path is only half the control: what an auditor can do once connected is still decided by Azure RBAC. The Conditional Access policy set includes an optional 8-hour sign-in frequency for the VPN, enable_vpn_sign_in_frequency_policy.
Terms you will see
| Term | Meaning |
|---|---|
| Point-to-site | A VPN from one client device to the virtual network. |
| Client address pool | The range VPN clients get addresses from; one per access profile here. |
| Access profile | A named set of reachable stages: all, plat_all, lower, dev_sandbox. |
| Policy group | The gateway setting that assigns Entra group members to an address pool. |
| Azure VPN Client | Microsoft's client app that signs in with Entra ID. |
Where to read more
- Azure Enterprise Baseline overview for remote access to the private network.
- Conditional Access for the sign-in policies that cover the VPN.
- Least privilege for why each group reaches only its stages.