Azure Site-to-Site VPN Connection

Copper Contributor

Currently I have a Generation1 Basic SKU virtual network gateway setup for my site-to-site VPN. The on-prem side is currently running DH Group 2 and is asking about upgrading to DH Group 14.


From what I can tell (please correct me if I am wrong) using the Gen1 Basic SKU will not support DH Group 14 so it will require an upgrade.  I also found the only way to upgrade is to remove the entire network settings from Azure then re-build it from scratch. 


I have a few questions about this:


  1. Is there a way to run both networks simultaneously? I know there will be an IP overlap that could cause issues, but I am wondering if perhaps you can set it all up then change the network settings afterwards.
  2. Is there a way (other then manually) to document all the existing settings just in case it does need to be removed and re-built.

Any guidance on getting this setup would be appreciated.


0 Replies