Skip to main content

VPN Gateway

Azure VPN Gateway connects networks and individual clients to an Azure virtual network over an encrypted tunnel. The Azure Enterprise Baseline can add a point-to-site gateway to the hub with one switch, off by default, so engineers reach private endpoints with their Microsoft Entra identity and only the stages their groups allow.

What it does​

A virtual network gateway of type VPN lives in the hub's GatewaySubnet. Point-to-site (P2S) connections come from individual clients: each client receives an address from a client address pool and reaches the virtual network, and its peers that allow gateway transit, through the tunnel. With Microsoft Entra ID authentication over OpenVPN, the user signs in with the Azure VPN Client, so multifactor authentication and Conditional Access apply to the connection. Policy groups assign users to different address pools by group membership, and client connection configurations tie each pool to its policy groups.

How BuiltForProd uses it​

The switch and the access matrix are in network.hcl:

Azure/acme-azure-platform-baseline/environments/core/network/eastus2/network.hcl (lines 39-51)
# ─── Point-to-site VPN ───────────────────────────────────────────────────────────────────────────
# VpnGw1AZ gateway with Entra ID authentication: ~$0.361/hour (~$263/month) plus P2S connection-hours. Read by
# client-vpn (gateway), firewall-policy (vpn-access rules) and vnet-peering (use_remote_gateways).
enable_client_vpn = false # @optional: true creates the gateway, the firewall rules and flips the spoke peerings to use the hub gateway

# Access profiles: pool name -> "all" (every plat VNet plus the core supernets) or the list of reachable stages.
# The pool CIDRs are reserved.client_vpn_pools in vnet_map.yaml (same keys).
vpn_access_profiles = { # @optional: what each address pool may reach
all = "all"
plat_all = ["plat-prod", "plat-staging", "plat-dev", "plat-sandbox"]
lower = ["plat-staging", "plat-dev", "plat-sandbox"]
dev_sandbox = ["plat-dev", "plat-sandbox"]
}

When enable_client_vpn = true, three units change together:

  1. client-vpn creates acme-eus2-network-vpngw, a zone-redundant VpnGw1AZ gateway with a zone-redundant public IP, OpenVPN only and Entra ID authentication against the tenant. The comments list about $0.361 an hour (about $263 a month) plus P2S connection-hours; VpnGw2AZ or larger is the option for more than 250 concurrent connections. It creates one policy group and one client connection configuration per pool, whose members are the Entra groups mapped to it, and sends gateway, tunnel, route, IKE and P2S logs to the audit workspace.
  2. firewall-policy adds the vpn-access rule collection group: one rule per pool, from the pool's range to the stages its groups may reach and to the resolver's inbound address.
  3. vnet-peering switches every spoke side of the peering to use the hub's gateway.
PoolRangeReachesGroups (from vpn_group_access)
all172.16.0.0/23every plat network and the core rangesPlatform Leads, Platform Engineers, Lead Security Auditors, Security Auditors
plat_all172.16.2.0/24the four plat stagesDevOps Leads
lower172.16.3.0/24staging, dev, sandboxDevOps Engineers, Lead App Developers, Lead ETL Engineers, Lead AI Engineers
dev_sandbox172.16.4.0/23dev, sandboxApp Developers, ETL Engineers, AI Engineers; also the default pool

The pools sit outside the organization range, in reserved.client_vpn_pools of the address plan. A route table on GatewaySubnet sends each spoke prefix and the runner network to the Azure Firewall, so VPN traffic crosses the same stateful policy in both directions. VPN clients resolve private endpoint names through the DNS Private Resolver, whose address the hub hands out as its DNS server. The network path is only half the control: what an auditor can do once connected is still decided by Azure RBAC. The Conditional Access policy set includes an optional 8-hour sign-in frequency for the VPN, enable_vpn_sign_in_frequency_policy.

Terms you will see​

TermMeaning
Point-to-siteA VPN from one client device to the virtual network.
Client address poolThe range VPN clients get addresses from; one per access profile here.
Access profileA named set of reachable stages: all, plat_all, lower, dev_sandbox.
Policy groupThe gateway setting that assigns Entra group members to an address pool.
Azure VPN ClientMicrosoft's client app that signs in with Entra ID.

Where to read more​