Skip to content

Commit ae911af

Browse files
authored
Merge pull request #312015 from jad0126/articles-about-gateway-skus
[AQ] edit pass: articles-about-gateway-skus
2 parents e5fc8c9 + 005cb90 commit ae911af

7 files changed

Lines changed: 144 additions & 169 deletions
Lines changed: 40 additions & 59 deletions
Original file line numberDiff line numberDiff line change
@@ -1,121 +1,102 @@
11
---
2-
title: Gateway SKU mappings
2+
title: Gateway SKU Mappings
33
titleSuffix: Azure VPN Gateway
44
description: Learn about the changes for virtual network gateway SKUs for VPN Gateway.
55
author: cherylmc
66
ms.service: azure-vpn-gateway
7-
ms.topic: how-to
7+
ms.topic: concept-article
88
ms.custom: references_regions
99
ms.date: 02/03/2026
1010

1111
ms.author: cherylmc
1212

13-
# Customer intent: "As a network administrator, I want to understand the migration process and benefits of VPN Gateway SKUs transitioning to availability zone support, so that I can ensure my organization's VPN solutions are optimized for reliability and cost-efficiency."
13+
#customer intent: As a network administrator, I want to understand the migration process and benefits of VPN Gateway SKUs transitioning to availability zone support, so that I can ensure my organization's VPN solutions are optimized for reliability and cost-efficiency.
1414
---
1515
# VPN Gateway SKU consolidation and migration
1616

17-
We're simplifying our VPN Gateway SKU portfolio. Due to the lack of redundancy, lower availability, and potential higher costs associated with failover solutions, we're transitioning all non availability zone (AZ) supported SKUs to AZ supported SKUs. This article helps you understand the upcoming changes for VPN Gateway virtual network gateway SKUs. This article expands on the [official announcement.](https://azure.microsoft.com/updates/v2/vpngw1-5-non-az-skus-will-be-retired-on-30-september-2026).
17+
We're simplifying our Azure VPN Gateway SKU portfolio. Due to the lack of redundancy, lower availability, and potential higher costs associated with failover solutions, SKUs that aren't supported by an availability zone are migrating to SKUs that are supported by an availability zone.
1818

19-
* **Effective November 1, 2025**: Creation of new VPN gateways using VpnGw1-5 SKUs (non-AZ) will no longer be possible. This date has changed from the originally announced January 1, 2025 date.
20-
* **Migration period**: From September 2025 to September 2026, all existing VPN gateways using VpnGw1-5 SKUs (non-AZ SKUs) can be manually upgraded to VpnGw1-5 SKUs (AZ).
19+
This article helps you understand the changes for VPN Gateway SKUs. This article expands on the [official announcement](https://azure.microsoft.com/updates/v2/vpngw1-5-non-az-skus-will-be-retired-on-30-september-2026).
2120

22-
To support this migration, we're reducing the prices on AZ SKUs. For more information about SKUs and pricing, see the [FAQ](#faq) section of this article.
21+
* *Effective November 1, 2025*: You can no longer create new VPN gateways (VpnGw1-5 SKUs) that aren't supported by an availability zone.
22+
* *Migration period*: From September 2025 to September 2026, all existing VPN gateways (VpnGw1-5 SKUs) that aren't supported by an availability zone can be manually upgraded to VpnGw1-5 SKUs that are supported.
23+
24+
To support this migration, we're reducing the prices on SKUs supported by availability zones. For more information about SKUs and pricing, see the [FAQs](#faqs) section of this article.
2325

2426
> [!NOTE]
25-
> This article doesn't apply to the following legacy gateway SKUs: Standard or High Performance. For information legacy SKUs, including legacy SKU migration, see [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
27+
> This article doesn't apply to the following legacy gateway SKUs: Standard or High Performance. For more information, see [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
2628
2729
## Mapping old SKUs to new SKUs
2830

29-
The following diagram shows current SKUs and the new SKUs they'll automatically be migrated to.
31+
The following diagram shows current SKUs and the new SKUs that they'll automatically be migrated to.
3032

3133
:::image type="content" source="./media/gateway-sku-consolidation/sku-mapping.png" alt-text="Diagram of gateway SKU mapping." lightbox="./media/gateway-sku-consolidation/sku-mapping-expand.png":::
3234

33-
## FAQ
35+
## FAQs
3436

3537
### What actions do I need to take?
3638

37-
* We recommend that you [manually upgrade](gateway-sku-upgrade.md) non-AZ gateway SKUs to AZ gateway SKUs using the portal/PowerShell/CLI after Sep 2025. There's no downtime expected to manually upgrade non-AZ SKUs that currently use Standard public IP addresses. If you are still using Basic IP Address, please upgrade to Standard IP address.
38-
* If your gateway currently uses Legacy Gateway SKUs, see [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
39-
40-
### What is the timeline?
41-
42-
Migration experience will be available after August 2025.
43-
44-
### Can I create new gateways using the older SKUs?
45-
46-
No. You can't create a new gateway using VpnGw1-5 SKUs (non-AZ SKUs) after January 2025.
39+
* We recommend that you [manually upgrade](gateway-sku-upgrade.md) gateway SKUs that aren't supported by availability zones to those that are. You can use the Azure portal, PowerShell, or the Azure CLI. There's no downtime expected to manually upgrade SKUs that currently use Standard public IP addresses. If you're still using a Basic IP address, upgrade to a Standard IP address.
40+
* If your gateway currently uses legacy SKUs, see [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
4741

4842
### How long will my existing gateway SKUs be supported?
4943

50-
The existing gateway SKUs are supported until they're migrated to AZ SKUs. The targeted deprecation for non-AZ SKUs is September 16, 2026. There will be no impact to existing AZ SKUs.
44+
The existing gateway SKUs are supported until they're migrated to the new SKUs. The old SKUs are currently scheduled for deprecation on September 16, 2026. There will be no impact to existing SKUs that are supported by availability zones.
5145

5246
### Will there be any pricing differences for my gateways after migration?
5347

54-
Yes. On January 1, 2025 you can see the new [Pricing](https://azure.microsoft.com/pricing/details/vpn-gateway). Until that date, the pricing changes won't show on the pricing page.
48+
Yes. For more information, see the new [pricing](https://azure.microsoft.com/pricing/details/vpn-gateway).
5549

56-
### When does new AZ pricing take effect?
57-
58-
Yes. The new pricing timeline is:
50+
### When does new pricing take effect?
5951

6052
* If your existing gateway uses a VpnGw1-5 SKU, new pricing starts after your gateway is migrated.
61-
* If your existing gateway uses a VpnGw1AZ-5AZ SKU, new pricing starts January 1, 2025.
53+
* If your existing gateway uses a VpnGw1AZ-5AZ SKU, new pricing is already in effect.
6254

63-
### Can I deploy VpnGw 1-5 AZ SKUs in all regions?
55+
### Can I deploy availability zone SKUs in all regions?
6456

65-
Yes, effective June 2025 you'll be able to deploy AZ SKUs in all regions. If a region doesn't currently support availability zones, you can still create VPN Gateway AZ SKUs, but the deployment will remain regional. When the region supports availability zones, we'll enable zone redundancy for the gateways.
57+
Yes. If a region doesn't currently support availability zones, you can still create VPN Gateway SKUs supported by availability zones, but the deployment will remain regional. When the region supports availability zones, we'll enable zone redundancy for the gateways.
6658

67-
### Can I migrate my Gen 1 gateway to Gen 2 gateway?
59+
### Can I migrate my gateway from one generation to another?
6860

69-
* **For gateways using a Basic public IP address**: You'll need to migrate your gateway to use Standard public IP address when the migration tool becomes available. As part of this Basic public IP address to Standard public IP address migration, your gateway will be upgraded to Gen2 with no further action needed.
70-
* **For gateways already using a Standard public IP address**: We'll migrate these gateways to Gen2 separately before September 30, 2026. This is done seamlessly during regular updates, with no downtime involved.
61+
* *For gateways that use a Basic public IP address*: You'll need to migrate your gateway to use a Standard public IP address when the migration tool becomes available. As part of this IP address migration, your gateway is upgraded to the next generation (called *Generation 2*). You don't need to take any further action.
62+
* *For gateways that already use a Standard public IP address*: We'll migrate these gateways to the next generation separately before September 30, 2026. This migration happens seamlessly during regular updates, with no downtime involved.
7163

72-
### Will there be downtime during migrating my non-AZ gateways?
64+
### Will there be downtime during migration?
7365

74-
No. This migration is seamless and there's no expected downtime during migration.
66+
No. This migration is seamless, and there's no expected downtime during migration.
7567

7668
### Will there be any performance impact on my gateways with this migration?
7769

78-
Yes. AZ SKUs get the benefits of Zone redundancy for VPN gateways in [Azure regions with availability zones](/azure/reliability/availability-zones-region-support). If the region doesn't support zone redundancy, the gateway is regional until the region it's deployed to supports zone redundancy.
70+
Yes. SKUs get the benefits of zone redundancy for VPN gateways in [Azure regions with availability zones](/azure/reliability/availability-zones-region-support). If the region doesn't support zone redundancy, the gateway is regional until the region where it's deployed supports zone redundancy.
7971

8072
### Is the VPN Gateway Basic SKU retiring?
8173

82-
No, the VPN Gateway Basic SKU isn't retiring. You can create a VPN gateway using the Basic gateway SKU via [PowerShell](create-gateway-basic-sku-powershell.md) or CLI.
83-
84-
### Can I create a new Basic SKU VPN gateway using a Basic SKU public IP address after March 31, 2025?
85-
86-
You can create a VPN gateway using a gateway Basic SKU and a Basic public IP address SKU until June 2025. After that date, you'll use a Standard SKU public IP address when you create Basic SKU VPN gateway.
74+
No, the VPN Gateway Basic SKU isn't retiring. You can create a gateway with this SKU by using [PowerShell](create-gateway-basic-sku-powershell.md) or the Azure CLI.
8775

88-
### When will my Standard or HighPerformance gateway be migrated?
76+
### Can I create a new Basic SKU VPN gateway by using a Basic SKU public IP address?
8977

90-
Standard and HighPerformance gateways will be migrated to AZ gateways in CY26. For more information, see this [announcement](https://azure.microsoft.com/updates/standard-and-highperformance-vpn-gateway-skus-will-be-retired-on-30-september-2025/) and [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
78+
No. Use a Standard SKU public IP address when you create a Basic SKU VPN gateway.
9179

92-
### I have an existing VPN gateway using a non-Availability Zone (non-AZ) SKU (VpnGw1–VpnGw5). What changes after this rollout?
80+
### When will my legacy gateway be migrated?
9381

94-
After the "block non-AZ SKU" feature flag rolls out, existing VPN gateways using non-AZ SKUs will no longer allow configuration changes. If you attempt any management or configuration operation on a non-AZ gateway, you'll receive a ValidationException. This is expected behavior after the rollout.
82+
See [this announcement](https://azure.microsoft.com/updates/standard-and-highperformance-vpn-gateway-skus-will-be-retired-on-30-september-2025/) and [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
9583

96-
### Why am I seeing a ValidationException error message?
84+
### I have an existing VPN gateway not supported by an availability zone. What changes after this rollout?
9785

98-
**Example error message:** "Microsoft.WindowsAzure.Networking.Nrp.Frontend.Common.ValidationException: VpnGw1-5 non-AZ SKUs are no longer supported for VPN gateways. Only VpnGw1-5AZ SKUs can be created going forward"
99-
100-
The exception indicates that configuration changes on non-AZ VPN Gateway SKUs are no longer supported. To proceed, the gateway must first be migrated to an equivalent Availability Zone–enabled (AZ) SKU.
86+
Existing VPN gateways not supported by an availability zone will no longer allow configuration changes. If you attempt any management or configuration operation, you'll get an error message. This is expected behavior after the rollout.
10187

10288
### What action is required to resolve this error?
10389

104-
You must migrate your VPN gateway from a non-AZ SKU to the corresponding AZ SKU before making any other changes.
105-
For example:
106-
107-
VpnGw1 → VpnGw1AZ
108-
VpnGw2 → VpnGw2AZ
90+
You must migrate your VPN gateway from a SKU not supported by an availability zone to one that is supported.
10991

110-
### Will migrating to an AZ SKU cause downtime?
92+
### Will migrating cause downtime?
11193

112-
* Same SKU family migration (for example, VpnGw1 → VpnGw1AZ) is nondisruptive and is a metadata-only change.
113-
* Cross-family migration (for example, VpnGw1 → VpnGw3AZ) is disruptive, consistent with existing VPN Gateway resize behavior.
94+
No, not if you're migrating from a SKU that's unsupported by an availability zone to one that is supported in the same SKU family. If you're upgrading in addition to migrating, you might experience downtime consistent with existing VPN Gateway resize behavior. This is called *cross-family migration*.
11495

115-
### Do AZ SKUs automatically become zone-redundant?
96+
### Are SKUs that are supported by availability zones automatically zone redundant?
11697

117-
AZ SKUs are AZ-capable. They become zone-redundant only in regions that support Availability Zones, as described in [this section](gateway-sku-consolidation.md#will-there-be-any-performance-impact-on-my-gateways-with-this-migration) of the article.
98+
These SKUs become zone redundant only in regions that support availability zones, as described in [this section](gateway-sku-consolidation.md#will-there-be-any-performance-impact-on-my-gateways-with-this-migration) of the article.
11899

119-
## Next steps
100+
## Related content
120101

121-
For more information about SKUs, see [About gateway SKUs](about-gateway-skus.md).
102+
* For more information about SKUs, see [About gateway SKUs](about-gateway-skus.md).

articles/vpn-gateway/gateway-sku-upgrade.md

Lines changed: 30 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -13,52 +13,60 @@ ms.author: cherylmc
1313
---
1414
# Upgrade a VPN Gateway SKU
1515

16-
This article helps you upgrade a VPN Gateway virtual network gateway SKU. Upgrading a gateway SKU is a relatively fast process with minimal downtime (approximately 45 minutes). You can upgrade a SKU easily in the Azure portal, or by using PowerShell or Azure CLI. When you upgrade a SKU, the public IP address assigned to your gateway SKU doesn't change and you don't need to reconfigure your VPN device or your P2S clients.
16+
This article helps you upgrade an Azure VPN Gateway virtual network gateway SKU. Upgrading a gateway SKU is a relatively fast process with minimal downtime (approximately 45 minutes). You can upgrade a SKU in the Azure portal, or by using PowerShell or the Azure CLI.
17+
18+
When you upgrade a SKU, the public IP address assigned to your gateway SKU doesn't change. You don't need to reconfigure your VPN device or your point-to-site (P2S) clients.
1719

1820
## Considerations
1921

20-
There are many things to consider when upgrading to a new gateway SKU. The following table helps you understand the required method to move from one SKU to another. Notice that not all gateway SKUs are eligible to be upgraded directly. Some SKUs require you to delete the existing gateway and create a new one.
22+
There are many things to consider when you upgrade to a new gateway SKU. The following table helps you understand the required method to move from one SKU to another. Notice that not all gateway SKUs are eligible to be upgraded directly. Some SKUs require you to delete the existing gateway and create a new one.
2123

22-
| Starting SKU | Target SKU | Eligible for SKU upgrade| Delete/Recreate only |
23-
| --- | --- |--- | --- |
24-
| Basic SKU | Any other SKU | No | Yes |
25-
| Generation 1 SKU | Generation 1 AZ SKU | Yes| No |
24+
| Starting SKU | Target SKU | Eligible for SKU upgrade | Delete/re-create only |
25+
| --- | --- | --- | --- |
26+
| Basic SKU | Any other SKU | No | Yes |
27+
| Generation 1 SKU | Generation 1 AZ SKU | Yes | No |
2628
| Generation 1 SKU | Generation 2 AZ SKU | No | Yes |
2729
| Generation 2 SKU | Generation 2 AZ SKU | Yes | No |
28-
| Generation 2 SKU | Generation 1 AZ SKU | No |Yes |
30+
| Generation 2 SKU | Generation 1 AZ SKU | No | Yes |
2931

30-
For gateway SKU throughput and connection limits, see [About gateway SKUs](about-gateway-skus.md#benchmark).
32+
In the preceding table, *AZ* stands for *availability zone*, and means that the SKU offers support for availability zones. For gateway SKU throughput and connection limits, see [About gateway SKUs](about-gateway-skus.md#benchmark).
3133

3234
## Limitations and restrictions
3335

3436
* You can't upgrade a Basic SKU to a new SKU. You must delete the gateway, and then create a new one.
3537
* You can't downgrade a SKU without deleting the gateway and creating a new one.
36-
* Legacy gateway SKUs (Standard and High Performance) can't be upgraded to the new SKU families. You must delete the gateway and create a new one. For more information about working with legacy gateway SKUS, see [VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md)
38+
* Legacy gateway SKUs (Standard and High Performance) can't be upgraded to the new SKU families. You must delete the gateway and create a new one. For more information about working with legacy gateway SKUs, see [VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
3739

38-
## Upgrade a gateway SKU using the Azure portal
40+
## Upgrade a gateway SKU by using the Azure portal
3941

40-
Upgrading a gateway SKU takes about 45 minutes to complete.
42+
This upgrade takes about 45 minutes to complete. If you're switching to a SKU that supports availability zones within the same tier (for example, from VpnGw1 to VpnGw1AZ), there's no downtime.
4143

4244
1. Go to the **Configuration** page for your virtual network gateway.
43-
1. On the right side of the page, click the dropdown arrow to show a list of available SKUs. The options listed are based on the starting SKU and SKU Generation. Select the SKU from the dropdown.
44-
1. **Save** your changes to begin the SKU upgrade.
45-
* If you are switching to an AZ SKU within the same tier (e.g., VpnGw1 → VpnGw1AZ), there will be no downtime.
46-
* The upgrade process typically takes about 45 minutes to complete for all other scenarios (e.g., VpnGw1 → VpnGw2AZ).
45+
46+
1. On the right side of the page, select the dropdown arrow to show a list of available SKUs. The options listed are based on the starting SKU and SKU generation. Select the SKU that you want from the list.
47+
48+
1. To save your changes and begin the upgrade, select **Save**.
4749

4850
## Workflow for SKUs that can't be upgraded
4951

50-
For SKUs that can't be directly upgraded (Basic and legacy gateway SKUs), you must delete the existing gateway and create a new one. This process incurs downtime. The public IP address assigned to your gateway SKU changes. You must also reconfigure your VPN device and P2S clients.
52+
Basic SKUs and legacy gateway SKUs can't be directly upgraded. You must delete the existing gateway and create a new one. This process incurs downtime. The public IP address assigned to your gateway SKU changes. You must also reconfigure your VPN device and P2S clients.
5153

52-
The high level workflow is:
54+
The high-level workflow is:
5355

5456
1. Remove any connections to the virtual network gateway.
57+
5558
1. Delete the old VPN gateway.
59+
5660
1. Create the new VPN gateway.
61+
5762
1. Update your on-premises VPN devices with the new VPN gateway IP address (for site-to-site connections).
58-
1. Update the gateway IP address value for any VNet-to-VNet local network gateways that connect to this gateway.
59-
1. Download new client VPN configuration packages for point-to-site clients connecting to the virtual network through this VPN gateway.
60-
1. Recreate the connections to the virtual network gateway.
6163

62-
## Next steps
64+
1. Update the gateway IP address value for any network-to-network local network gateways that connect to this gateway.
65+
66+
1. Download new client VPN configuration packages for point-to-site clients that connect to the virtual network through this VPN gateway.
67+
68+
1. Re-create the connections to the virtual network gateway.
69+
70+
## Related content
6371

64-
For more information about gateway SKUs, see [About gateway SKUs](about-gateway-skus.md).
72+
* For more information about gateway SKUs, see [About gateway SKUs](about-gateway-skus.md).

0 commit comments

Comments
 (0)