Should I use IP addresses from the Gateway Subnet in an Azure VPN? Should I use IP addresses from the Gateway Subnet in an Azure VPN? azure azure

Should I use IP addresses from the Gateway Subnet in an Azure VPN?


The answer is no. Do not use the gateway subnet.

I eventually found exactly what I required on this Microsoft page. Specifically:

And don't deploy VMs or anything else to the gateway subnet.

and

Can I deploy Virtual Machines or role instances to my gateway subnet?

No.


By default, VPN gateways are deployed as two instances in an active/standby configuration, even if you only see one VPN gateway resource in Azure. When planned maintenance or unplanned disruption affects the active instance, the standby instance automatically assumes responsibility for connections without any user intervention. Connections are interrupted during this failover, but they're typically restored within a few seconds for planned maintenance and within 90 seconds for unplanned disruptions.

The new guidance is now - Use at least a /27 address mask for the gateway subnet.