You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/vpn-gateway/gateway-sku-consolidation.md
+23-24Lines changed: 23 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,17 +6,17 @@ author: cherylmc
6
6
ms.service: azure-vpn-gateway
7
7
ms.topic: how-to
8
8
ms.custom: references_regions
9
-
ms.date: 03/31/2025
9
+
ms.date: 02/03/2026
10
10
11
11
ms.author: cherylmc
12
12
13
13
# Customer intent: "As a network administrator, I want to understand the migration process and benefits of VPN Gateway SKUs transitioning to availability zone support, so that I can ensure my organization's VPN solutions are optimized for reliability and cost-efficiency."
14
14
---
15
15
# VPN Gateway SKU consolidation and migration
16
16
17
-
We're simplifying our VPN Gateway SKU portfolio. Due to the lack of redundancy, lower availability, and potential higher costs associated with failover solutions, we're transitioning all non availability zone (AZ) supported SKUs to AZ supported SKUs. This article helps you understand the upcoming changes for VPN Gateway virtual network gateway SKUs. This article expands on the [official announcement.](https://azure.microsoft.com/updates/v2/vpngw1-5-non-az-skus-will-be-retired-on-30-september-2026)
17
+
We're simplifying our VPN Gateway SKU portfolio. Due to the lack of redundancy, lower availability, and potential higher costs associated with failover solutions, we're transitioning all non availability zone (AZ) supported SKUs to AZ supported SKUs. This article helps you understand the upcoming changes for VPN Gateway virtual network gateway SKUs. This article expands on the [official announcement.](https://azure.microsoft.com/updates/v2/vpngw1-5-non-az-skus-will-be-retired-on-30-september-2026).
18
18
19
-
***Effective November 1, 2025**: Creation of new VPN gateways using VpnGw1-5 SKUs (non-AZ) will no longer be possible. This date has been updated from the originally announced January 1, 2025 date
19
+
***Effective November 1, 2025**: Creation of new VPN gateways using VpnGw1-5 SKUs (non-AZ) will no longer be possible. This date has changed from the originally announced January 1, 2025 date.
20
20
***Migration period**: From September 2025 to September 2026, all existing VPN gateways using VpnGw1-5 SKUs (non-AZ SKUs) could be seamlessly migrated to VpnGw1-5 SKUs (AZ).
21
21
22
22
To support this migration, we're reducing the prices on AZ SKUs. For more information about SKUs and pricing, see the [FAQ](#faq) section of this article.
@@ -34,7 +34,9 @@ The following diagram shows current SKUs and the new SKUs they'll automatically
34
34
35
35
### What actions do I need to take?
36
36
37
-
You can [upgrade the gateway SKUs](gateway-sku-upgrade.md) to AZ versions through portal/powershell/CLI after Sep 2025. There's no downtime expected for Non-AZ SKUs migration using Standard IPs. We recommend that you don't change your SKU manually in anticipation of SKU migration unless you want to upgrade to a higher SKU. If your gateway currently uses Legacy Gateway SKUs, see [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
37
+
* We recommend that you don't change your gateway SKU manually in anticipation of SKU migration unless you want to upgrade to a higher gateway SKU.
38
+
* You can [manually upgrade](gateway-sku-upgrade.md) non-AZ gateway SKUs to AZ gateway SKUs using the portal/PowerShell/CLI after Sep 2025. There's no downtime expected to manually upgrade non-AZ SKUs that currently use Standard public IP addresses.
39
+
* If your gateway currently uses Legacy Gateway SKUs, see [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
38
40
39
41
### What is the timeline?
40
42
@@ -61,14 +63,14 @@ Yes. The new pricing timeline is:
61
63
62
64
### Can I deploy VpnGw 1-5 AZ SKUs in all regions?
63
65
64
-
Yes, effective June 2025 you'll be able to deploy AZ SKUs in all regions. If a region doesn't currently support availability zones, you can still create VPN Gateway AZ SKUs, but the deployment will remain regional. When the region supports availability zones, we'll enable zone redundancy for the gateways
66
+
Yes, effective June 2025 you'll be able to deploy AZ SKUs in all regions. If a region doesn't currently support availability zones, you can still create VPN Gateway AZ SKUs, but the deployment will remain regional. When the region supports availability zones, we'll enable zone redundancy for the gateways.
65
67
66
68
### Can I migrate my Gen 1 gateway to Gen 2 gateway?
67
69
68
-
* For gateways using Basic IP, you'll need to migrate your gateway to use Standard IP when the migration tool becomes available. As part of the Basic IP to Standard IP migration, the gateways will be upgraded to Gen2 with no further action needed.
69
-
* For gateways already using Standard IP, we'll migrate them to Gen2 separately before September 30, 2026. This will be done seamlessly during regular updates, with no downtime involved.
70
+
***For gateways using a Basic public IP address**: You'll need to migrate your gateway to use Standard public IP address when the migration tool becomes available. As part of this Basic public IP address to Standard public IP address migration, your gateway will be upgraded to Gen2 with no further action needed.
71
+
***For gateways already using a Standard public IP address**: We'll migrate these gateways to Gen2 separately before September 30, 2026. This is done seamlessly during regular updates, with no downtime involved.
70
72
71
-
### Will there be downtime during migrating my Non-AZ gateways?
73
+
### Will there be downtime during migrating my non-AZ gateways?
72
74
73
75
No. This migration is seamless and there's no expected downtime during migration.
74
76
@@ -78,45 +80,42 @@ Yes. AZ SKUs get the benefits of Zone redundancy for VPN gateways in [Azure regi
78
80
79
81
### Is the VPN Gateway Basic SKU retiring?
80
82
81
-
No, the VPN Gateway Basic SKU isn't retiring. You can create a VPN gateway using the Basic gateway SKU via [PowerShell](create-gateway-basic-sku-powershell.md) or CLI. Currently, the VPN Gateway Basic SKU supports only the Basic SKU public IP address resource (which is on a path to retirement). We're working on adding support for the Standard SKU public IP address resource to the VPN Gateway Basic SKU.
83
+
No, the VPN Gateway Basic SKU isn't retiring. You can create a VPN gateway using the Basic gateway SKU via [PowerShell](create-gateway-basic-sku-powershell.md) or CLI.
82
84
83
-
### Can I create a VPN Gateway Basic SKU gateway with a Basic SKU public IP address after March 31, 2025?
85
+
### Can I create a new Basic SKU VPN gateway using a Basic SKU public IP address after March 31, 2025?
84
86
85
-
Yes, you can create a VPN gateway using a gateway Basic SKU and a Basic public IP address SKU until June 2025.
87
+
You can create a VPN gateway using a gateway Basic SKU and a Basic public IP address SKU until June 2025. After that date, you'll use a Standard SKU public IP address when you create Basic SKU VPN gateway.
86
88
87
-
### When will I be able to create a VPN Gateway Basic SKU with a Standard SKU public IP address?
89
+
### When will my Standard or HighPerformance gateway be migrated?
88
90
89
-
Using the Standard SKU public IP address parameter with a VPN Gateway Basic SKU is rolling out and is projected to be completed in April 2025.
91
+
Standard and HighPerformance gateways will be migrated to AZ gateways in CY26. For more information, see this [announcement](https://azure.microsoft.com/updates/standard-and-highperformance-vpn-gateway-skus-will-be-retired-on-30-september-2025/) and [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
90
92
91
-
### When will my Standard and HighPerformance gateway be migrated?
93
+
### I have an existing VPN gateway using a non-Availability Zone (non-AZ) SKU (VpnGw1–VpnGw5). What changes after this rollout?
92
94
93
-
Standard and HighPerformance gateway will be migrated to AZ gateways in CY26. For more information, see this [announcement](https://azure.microsoft.com/updates/standard-and-highperformance-vpn-gateway-skus-will-be-retired-on-30-september-2025/) and [Working with VPN Gateway legacy SKUs](vpn-gateway-about-skus-legacy.md).
95
+
After the "block non-AZ SKU" feature flag rolls out, existing VPN gateways using non-AZ SKUs will no longer allow configuration changes. If you attempt any management or configuration operation on a non-AZ gateway, you'll receive a ValidationException. This is expected behavior after the rollout.
94
96
95
-
### What happens to existing non-AZ VPN Gateways after the “block non-AZ SKU” rollout starting in February'26?
96
-
### I have an existing VPN Gateway using a non-Availability Zone (non-AZ) SKU (VpnGw1–VpnGw5). What changes after this rollout?
97
+
### Why am I seeing a ValidationException error message?
97
98
98
-
After the “block non-AZ SKU” feature flag rolls out, existing VPN Gateways using non-AZ SKUs will no longer allow configuration changes. If you attempt any management or configuration operation on a non-AZ gateway, you will receive a ValidationException. This is expected behavior after the rollout.
99
-
100
-
### Why am I seeing a ValidationException? example error message: Microsoft.WindowsAzure.Networking.Nrp.Frontend.Common.ValidationException: VpnGw1-5 non-AZ SKUs are no longer supported for VPN gateways. Only VpnGw1-5AZ SKUs can be created going forward
99
+
**Example error message:** "Microsoft.WindowsAzure.Networking.Nrp.Frontend.Common.ValidationException: VpnGw1-5 non-AZ SKUs are no longer supported for VPN gateways. Only VpnGw1-5AZ SKUs can be created going forward"
101
100
102
101
The exception indicates that configuration changes on non-AZ VPN Gateway SKUs are no longer supported. To proceed, the gateway must first be migrated to an equivalent Availability Zone–enabled (AZ) SKU.
103
102
104
103
### What action is required to resolve this error?
105
104
106
-
You must migrate your VPN Gateway from a non-AZ SKU to the corresponding AZ SKU before making any other changes.
105
+
You must migrate your VPN gateway from a non-AZ SKU to the corresponding AZ SKU before making any other changes.
107
106
For example:
108
107
109
108
VpnGw1 → VpnGw1AZ
110
109
VpnGw2 → VpnGw2AZ
111
110
112
111
### Will migrating to an AZ SKU cause downtime?
113
112
114
-
Same SKU family migration (for example, VpnGw1 → VpnGw1AZ) is non-disruptive and is a metadata-only change.
115
-
Cross-family migration (for example, VpnGw1 → VpnGw3AZ) is disruptive, consistent with existing VPN Gateway resize behavior.
113
+
*Same SKU family migration (for example, VpnGw1 → VpnGw1AZ) is nondisruptive and is a metadata-only change.
114
+
*Cross-family migration (for example, VpnGw1 → VpnGw3AZ) is disruptive, consistent with existing VPN Gateway resize behavior.
116
115
117
116
### Do AZ SKUs automatically become zone-redundant?
118
117
119
-
AZ SKUs are AZ-capable. They become zone-redundant only in regions that support Availability Zones, as described in the [existing documentation](gateway-sku-consolidation.md#will-there-be-any-performance-impact-on-my-gateways-with-this-migration)
118
+
AZ SKUs are AZ-capable. They become zone-redundant only in regions that support Availability Zones, as described in [this section](gateway-sku-consolidation.md#will-there-be-any-performance-impact-on-my-gateways-with-this-migration) of the article.
0 commit comments