VPN Custom IPSec Policy

Last updated: 03/05/2021

This custom IPSec Policy allows more granular configuration of the IKE Parameters. This allows you to deploy a site-to-site VPN Policy to support specific settings on your VPN Endpoit Device.

This Azure Resource Manager (ARM) template was created by a member of the community and not by Microsoft. Each ARM template is licensed to you under a licence agreement by its owner, not Microsoft. Microsoft is not responsible for ARM templates provided and licensed by community members and does not screen for security, compatibility or performance. Community ARM templates are not supported under any Microsoft support programme or service, and are made available AS IS without warranty of any kind.

Parameters

Parameter Name Description
location Resource Location
vpnGateway_Name Name of existing Virtual Network Gateway to deploy the connection to
localGateway_Name Name of existing Local Network Gateway to deploy the connection to
vpnName Name of the VPN connection between Azure and On-Premises (ex: AzureUKS-to-LDN)
vpnProtocol Protocol utilised by the VPN Connection (IKEv1, IKEv2)
saLifeTimeSeconds Security Association Lifetime (Seconds)
saDataSizeKilobytes Security Association Data Size (KB)
ipsecEncryption IPSec Encryption
ipsecIntegrity IPSec Integrity
ikeEncryption IKE Encryption
ikeIntegrity IKE Integrity
dhGroup Diffie-Hellman Group
pfsGroup Perfect Forward Secrecy Group
sharedKey Pre-Shared Key
policyBasedTrafficSelectors Enable this if the OnPremises VPN endpoint needs to be configured as a Policy-Based VPN

Use the template

PowerShell

New-AzResourceGroup -Name <resource-group-name> -Location <resource-group-location> #use this command when you need to create a new resource group for your deployment
New-AzResourceGroupDeployment -ResourceGroupName <resource-group-name> -TemplateUri https://raw.githubusercontent.com/Azure/azure-quickstart-templates/master/quickstarts/microsoft.network/vpn-custom-ipsec-policy/azuredeploy.json
Installing and configuring Azure PowerShell

Command line

az group create --name <resource-group-name> --location <resource-group-location> #use this command when you need to create a new resource group for your deployment
az group deployment create --resource-group <my-resource-group> --template-uri https://raw.githubusercontent.com/Azure/azure-quickstart-templates/master/quickstarts/microsoft.network/vpn-custom-ipsec-policy/azuredeploy.json
Installing and configuring the Azure cross-platform command-line interface