azure-docs icon indicating copy to clipboard operation
azure-docs copied to clipboard

Can I move a VPN Gateway between subscriptions?

Open jonwbstr opened this issue 3 years ago • 4 comments

The supported resources page says "yes" to both publicipaddresses and virtualnetworkgateways. No asterisks or exceptions.

This page has a note that says,

Any resource, including a VPN Gateway, that is associated with a public IP Standard SKU address must be disassociated from the public IP address before moving across subscriptions.

So standard SKU addresses can only be moved if they are disassociated? Which article is right about moving publicipaddresses. Yes but only if they are disassociated, or "yes"

And, virtualnetworkgateways can be moved, but only if we disassociate the public IP address? According to this article changing or removing the public IP address is not supported.

Change or remove public IP address VPN gateway doesn't support changing the public IP address after creation.

Is there is some way to disassociate the public IP from the vpn gateway, move the resources and re-associate the public IP?

Please point me to an article that describes how to move a VPN gateway between subscriptions. Thanks!

p.s. assuming non-standard sku's do allow a vpn gateway to move, maybe we need to change the public IP address sku to enable support for moving between subscriptions?


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

jonwbstr avatar Oct 14 '22 14:10 jonwbstr

#94730 says as of June 2022 standard SKUs are support moving between subscriptions

jonwbstr avatar Oct 14 '22 14:10 jonwbstr

@jonwbstr Thanks for your feedback! We will investigate and update as appropriate.

Naveenommi-MSFT avatar Oct 14 '22 16:10 Naveenommi-MSFT

Confirmed, VPN moved to another subscription without any issues using a standard Public IP. That was easy!

jonwbstr avatar Oct 14 '22 23:10 jonwbstr

@jonwbstr was it definitely a standard SKU public IP you successfully moved with the VPN gateway? what VPN SKU did you move?

I have checked using the Azure portal to move a VPN gateway SKU of "VpnGW2" which uses the standard Public IP and I get the following error "Move for resource type publicIPAddresses is not supported"

as you mention docs say to disassociate public IP before move but you cant on a VPN gateway.

jimbob21787 avatar Oct 17 '22 16:10 jimbob21787

Tagging @tfitzmac for visibility, review and document enhancement consideration as appropriate to avoid any confusion.

KrishnaG-MSFT avatar Oct 19 '22 14:10 KrishnaG-MSFT

@brianlehr - can you assist us with this issue? I don't see a way through the portal to disassociate a public IP address from a VPN Gateway. Is there an article we can link to?

tfitzmac avatar Oct 28 '22 23:10 tfitzmac

I'll take the skew I move tomorrow, you can't disassociate IP address from VPN According to a different article

On Fri, Oct 28, 2022, 7:01 PM Tom FitzMacken @.***> wrote:

@brianlehr https://github.com/brianlehr - can you assist us with this issue? I don't see a way through the portal to disassociate a public IP address from a VPN Gateway. Is there an article we can link to?

— Reply to this email directly, view it on GitHub https://github.com/MicrosoftDocs/azure-docs/issues/99969#issuecomment-1295610953, or unsubscribe https://github.com/notifications/unsubscribe-auth/ADXTPAEO6JGPDBNR35SFP3LWFRLKZANCNFSM6AAAAAARFJKAXA . You are receiving this because you were mentioned.Message ID: @.***>

jonwbstr avatar Oct 28 '22 23:10 jonwbstr

Sorry for the confusion around this documentation. I have added a couple of notes to the supported resource type table that link to the networking guidance. Within that article, I clarified that resources associated with a public IP standard SKU can't be moved, but that VMs can be disassociated from the public IP.

tfitzmac avatar Oct 28 '22 23:10 tfitzmac

The update should get published on Monday. #please-close

tfitzmac avatar Oct 28 '22 23:10 tfitzmac

@tfitzmac that is not correct, I moved a VPN gateway containing a standard IP attached to VPN gateway SKU: VpnGw1.

I also moved several machines with Public IPs assigned standard IPs, without disassociating the IP address

jonwbstr avatar Nov 01 '22 21:11 jonwbstr

Moving IPs between regions is still hard, but moving resources using standard IPs between subscriptions in the same region has gotten easier

jonwbstr avatar Nov 01 '22 21:11 jonwbstr

@tfitzmac This is still very confusing.

https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/move-limitations/networking-move-limitations#dependent-resources

Any resource, including a VPN Gateway, that is associated with a public IP Standard SKU address can't be moved across subscriptions. For virtual machines, you can disassociate the public IP address before moving across subscriptions.

  • States VPN Gateways can't be moved

When moving a resource, you must also move its dependent resources (for example - public IP addresses, virtual network gateways, all associated connection resources). Local network gateways can be in a different resource group.

  • Implies VPN Gateways can be moved (a virtual network gateway is a VPN Gateway)

VPN Gateways

You cannot move VPN Gateways across subscriptions if they are of Basic SKU. Basic SKU is only meant for test environment usage and doesn't support resource move operation.

  • States Basic VPN Gateways can't be moved, but others can

I also noticed in comments that @jonwbstr noted that he tested moving a VPN Gateway and it worked. Is it supported or is it not?

drew010 avatar Feb 16 '23 03:02 drew010

I am facing similar issues while moving my VPN with GW1 SKU between subscription. The document, https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/move-limitations/networking-move-limitations, seem to contradict themselves:

"When moving a resource, you must also move its dependent networking resources. However, any resource that is associated with a Standard SKU public IP address can't be moved across subscriptions. For example, you can't move a VPN Gateway that is associated with a Standard SKU public IP address to a new subscription."

"You can't move VPN Gateways across resource groups or subscriptions if they are of Basic SKU. Basic SKU is only meant for test environment usage and doesn't support resource move operation. A virtual network gateway must always be in the same resource group as its virtual network, they can't be moved separately"

When creating a VpnGw1 SKU VPN, public IP is by default a standard SKU public IP and we cannot change it. How do we move without having to delete and create the VPN again in the new subscription.

Bigfoot2049 avatar Jul 07 '23 10:07 Bigfoot2049

Did you try?

On Fri, Jul 7, 2023, 6:39 AM Bigfoot2049 @.***> wrote:

I am facing similar issues while moving my VPN with GW1 SKU between subscription. The document, https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/move-limitations/networking-move-limitations, seem to contradict themselves:

"When moving a resource, you must also move its dependent networking resources. However, any resource that is associated with a Standard SKU public IP address can't be moved across subscriptions. For example, you can't move a VPN Gateway that is associated with a Standard SKU public IP address to a new subscription."

"You can't move VPN Gateways across resource groups or subscriptions if they are of Basic SKU. Basic SKU is only meant for test environment usage and doesn't support resource move operation. A virtual network gateway must always be in the same resource group as its virtual network, they can't be moved separately"

When creating a VpnGw1 SKU VPN, public IP is by default a standard SKU public IP and we can change it. How do we move without having to delete and create the VPN again in the new subscription.

— Reply to this email directly, view it on GitHub https://github.com/MicrosoftDocs/azure-docs/issues/99969#issuecomment-1625216373, or unsubscribe https://github.com/notifications/unsubscribe-auth/ADXTPAHB32WUSDAWFUHNJQLXO7ROXANCNFSM6AAAAAARFJKAXA . You are receiving this because you were mentioned.Message ID: @.***>

jonwbstr avatar Jul 07 '23 11:07 jonwbstr