virtual_network_gateways
Creates, updates, deletes, gets or lists a virtual_network_gateways resource.
Overview
| Name | virtual_network_gateways |
| Type | Resource |
| Id | azure.network.virtual_network_gateways |
Fields
The following fields are returned by SELECT queries:
- get_failover_all_test_details
- get_failover_single_test_details
- get_advertised_routes
- get
- list
| Name | Datatype | Description |
|---|---|---|
circuits | array | All circuits in the peering location. |
connections | array | All connections to the circuits in the peering location. |
endTime | string | Time when the test was completed. |
issues | array | A list of all issues with the test. |
peeringLocation | string | Peering location of the test. |
startTime | string | Time when the test was started. |
status | string | The current status of the test. Known values are: "NotStarted", "Starting", "Running", "StartFailed", "Stopping", "Completed", "StopFailed", "Invalid", and "Expired". (NotStarted, Starting, Running, StartFailed, Stopping, Completed, StopFailed, Invalid, Expired) |
testGuid | string | The unique GUID associated with the test. |
testType | string | The type of failover test. Known values are: "SingleSiteFailover", "MultiSiteFailover", and "All". (SingleSiteFailover, MultiSiteFailover, All) |
| Name | Datatype | Description |
|---|---|---|
endTimeUtc | string | Time when the test was completed. |
failoverConnectionDetails | array | List of all the failover connections for this peering location. |
nonRedundantRoutes | array | List of al the routes that were received only from this peering location. |
peeringLocation | string | Peering location of the test. |
redundantRoutes | array | List of routes received from this peering as well as some other peering location. |
startTimeUtc | string | Time when the test was started. |
status | string | The current status of the test. Known values are: "NotStarted", "Starting", "Running", "StartFailed", "Stopping", "Completed", "StopFailed", "Invalid", and "Expired". (NotStarted, Starting, Running, StartFailed, Stopping, Completed, StopFailed, Invalid, Expired) |
wasSimulationSuccessful | boolean | Whether the failover simulation was successful or not. |
| Name | Datatype | Description |
|---|---|---|
asPath | string | The route's AS path sequence. |
localAddress | string | The gateway's local address. |
network | string | The route's network prefix. |
nextHop | string | The route's next hop. |
origin | string | The source this route was learned from. |
sourcePeer | string | The peer this route was learned from. |
weight | integer | The route's weight. |
| Name | Datatype | Description |
|---|---|---|
id | string | Resource ID. |
name | string | Resource name. |
activeActive | boolean | ActiveActive flag. |
adminState | string | Property to indicate if the Express Route Gateway serves traffic when there are multiple Express Route Gateways in the vnet. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
allowRemoteVnetTraffic | boolean | Configure this gateway to accept traffic from other Azure Virtual Networks. This configuration does not support connectivity to Azure Virtual WAN. |
allowVirtualWanTraffic | boolean | Configures this gateway to accept traffic from remote Virtual WAN networks. |
autoScaleConfiguration | object | Autoscale configuration for virutal network gateway. |
bgpSettings | object | Virtual network gateway's BGP speaker settings. |
customRoutes | object | The reference to the address space resource which represents the custom routes address space specified by the customer for virtual network gateway and VpnClient. |
disableIPSecReplayProtection | boolean | disableIPSecReplayProtection flag. |
enableBgp | boolean | Whether BGP is enabled for this virtual network gateway or not. |
enableBgpRouteTranslationForNat | boolean | EnableBgpRouteTranslationForNat flag. |
enableDnsForwarding | boolean | Whether dns forwarding is enabled or not. |
enableHighBandwidthVpnGateway | boolean | To enable Advanced Connectivity feature for VPN gateway. |
enablePrivateIpAddress | boolean | Whether private IP needs to be enabled on this gateway for connections or not. |
etag | string | A unique read-only string that changes whenever the resource is updated. |
extendedLocation | object | The extended location of type local virtual network gateway. |
gatewayDefaultSite | object | Reference to another subresource. |
gatewayType | string | The type of this virtual network gateway. Known values are: "Vpn", "ExpressRoute", and "LocalGateway". (Vpn, ExpressRoute, LocalGateway) |
identity | object | The identity of the virtual network gateway, if configured. |
inboundDnsForwardingEndpoint | string | The IP address allocated by the gateway to which dns requests can be sent. |
ipConfigurations | array | IP configurations for virtual network gateway. |
location | string | Resource location. |
natRules | array | NatRules for virtual network gateway. |
provisioningState | string | The provisioning state of the virtual network gateway resource. Known values are: "Failed", "Succeeded", "Canceled", "Creating", "Updating", and "Deleting". (Failed, Succeeded, Canceled, Creating, Updating, Deleting) |
resiliencyModel | string | Property to indicate if the Express Route Gateway has resiliency model of MultiHomed or SingleHomed. Known values are: "SingleHomed" and "MultiHomed". (SingleHomed, MultiHomed) |
resourceGuid | string | The resource GUID property of the virtual network gateway resource. |
sku | object | The reference to the VirtualNetworkGatewaySku resource which represents the SKU selected for Virtual network gateway. |
tags | object | Resource tags. |
type | string | Resource type. |
vNetExtendedLocationResourceId | string | Customer vnet resource id. VirtualNetworkGateway of type local gateway is associated with the customer vnet. |
virtualNetworkGatewayMigrationStatus | object | The reference to the VirtualNetworkGatewayMigrationStatus which represents the status of migration. |
virtualNetworkGatewayPolicyGroups | array | The reference to the VirtualNetworkGatewayPolicyGroup resource which represents the available VirtualNetworkGatewayPolicyGroup for the gateway. |
vpnClientConfiguration | object | The reference to the VpnClientConfiguration resource which represents the P2S VpnClient configurations. |
vpnGatewayGeneration | string | The generation for this VirtualNetworkGateway. Must be None if gatewayType is not VPN. Known values are: "None", "Generation1", and "Generation2". (None, Generation1, Generation2) |
vpnType | string | The type of this virtual network gateway. Known values are: "PolicyBased" and "RouteBased". (PolicyBased, RouteBased) |
| Name | Datatype | Description |
|---|---|---|
id | string | Resource ID. |
name | string | Resource name. |
activeActive | boolean | ActiveActive flag. |
adminState | string | Property to indicate if the Express Route Gateway serves traffic when there are multiple Express Route Gateways in the vnet. Known values are: "Enabled" and "Disabled". (Enabled, Disabled) |
allowRemoteVnetTraffic | boolean | Configure this gateway to accept traffic from other Azure Virtual Networks. This configuration does not support connectivity to Azure Virtual WAN. |
allowVirtualWanTraffic | boolean | Configures this gateway to accept traffic from remote Virtual WAN networks. |
autoScaleConfiguration | object | Autoscale configuration for virutal network gateway. |
bgpSettings | object | Virtual network gateway's BGP speaker settings. |
customRoutes | object | The reference to the address space resource which represents the custom routes address space specified by the customer for virtual network gateway and VpnClient. |
disableIPSecReplayProtection | boolean | disableIPSecReplayProtection flag. |
enableBgp | boolean | Whether BGP is enabled for this virtual network gateway or not. |
enableBgpRouteTranslationForNat | boolean | EnableBgpRouteTranslationForNat flag. |
enableDnsForwarding | boolean | Whether dns forwarding is enabled or not. |
enableHighBandwidthVpnGateway | boolean | To enable Advanced Connectivity feature for VPN gateway. |
enablePrivateIpAddress | boolean | Whether private IP needs to be enabled on this gateway for connections or not. |
etag | string | A unique read-only string that changes whenever the resource is updated. |
extendedLocation | object | The extended location of type local virtual network gateway. |
gatewayDefaultSite | object | Reference to another subresource. |
gatewayType | string | The type of this virtual network gateway. Known values are: "Vpn", "ExpressRoute", and "LocalGateway". (Vpn, ExpressRoute, LocalGateway) |
identity | object | The identity of the virtual network gateway, if configured. |
inboundDnsForwardingEndpoint | string | The IP address allocated by the gateway to which dns requests can be sent. |
ipConfigurations | array | IP configurations for virtual network gateway. |
location | string | Resource location. |
natRules | array | NatRules for virtual network gateway. |
provisioningState | string | The provisioning state of the virtual network gateway resource. Known values are: "Failed", "Succeeded", "Canceled", "Creating", "Updating", and "Deleting". (Failed, Succeeded, Canceled, Creating, Updating, Deleting) |
resiliencyModel | string | Property to indicate if the Express Route Gateway has resiliency model of MultiHomed or SingleHomed. Known values are: "SingleHomed" and "MultiHomed". (SingleHomed, MultiHomed) |
resourceGuid | string | The resource GUID property of the virtual network gateway resource. |
sku | object | The reference to the VirtualNetworkGatewaySku resource which represents the SKU selected for Virtual network gateway. |
tags | object | Resource tags. |
type | string | Resource type. |
vNetExtendedLocationResourceId | string | Customer vnet resource id. VirtualNetworkGateway of type local gateway is associated with the customer vnet. |
virtualNetworkGatewayMigrationStatus | object | The reference to the VirtualNetworkGatewayMigrationStatus which represents the status of migration. |
virtualNetworkGatewayPolicyGroups | array | The reference to the VirtualNetworkGatewayPolicyGroup resource which represents the available VirtualNetworkGatewayPolicyGroup for the gateway. |
vpnClientConfiguration | object | The reference to the VpnClientConfiguration resource which represents the P2S VpnClient configurations. |
vpnGatewayGeneration | string | The generation for this VirtualNetworkGateway. Must be None if gatewayType is not VPN. Known values are: "None", "Generation1", and "Generation2". (None, Generation1, Generation2) |
vpnType | string | The type of this virtual network gateway. Known values are: "PolicyBased" and "RouteBased". (PolicyBased, RouteBased) |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_failover_all_test_details | select | resource_group_name, virtual_network_gateway_name, subscription_id, type, fetchLatest | This operation retrieves the details of all the failover tests performed on the gateway for different peering locations. | |
get_failover_single_test_details | select | resource_group_name, virtual_network_gateway_name, subscription_id, peeringLocation, failoverTestId | This operation retrieves the details of a particular failover test performed on the gateway based on the test Guid. | |
get_advertised_routes | select | resource_group_name, virtual_network_gateway_name, subscription_id, peer | This operation retrieves a list of routes the virtual network gateway is advertising to the specified peer. | |
get | select | resource_group_name, virtual_network_gateway_name, subscription_id | Gets the specified virtual network gateway by resource group. | |
list | select | resource_group_name, subscription_id | Gets all virtual network gateways by resource group. | |
create_or_update | insert | resource_group_name, virtual_network_gateway_name, subscription_id, properties | Creates or updates a virtual network gateway in the specified resource group. | |
update_tags | update | resource_group_name, virtual_network_gateway_name, subscription_id | Updates a virtual network gateway tags. | |
create_or_update | replace | resource_group_name, virtual_network_gateway_name, subscription_id, properties | Creates or updates a virtual network gateway in the specified resource group. | |
delete | delete | resource_group_name, virtual_network_gateway_name, subscription_id | Deletes the specified virtual network gateway. | |
list_connections | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Gets all the connections in a virtual network gateway. | |
list_radius_secrets | exec | resource_group_name, virtual_network_gateway_name, subscription_id | List all Radius servers with respective radius secrets from virtual network gateway VpnClientConfiguration. | |
get_vpn_profile_package_url | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Gets pre-generated VPN profile for P2S client of the virtual network gateway in the specified resource group. The profile needs to be generated first using generateVpnProfile. | |
get_bgp_peer_status | exec | resource_group_name, virtual_network_gateway_name, subscription_id | peer | The GetBgpPeerStatus operation retrieves the status of all BGP peers. |
get_learned_routes | exec | resource_group_name, virtual_network_gateway_name, subscription_id | This operation retrieves a list of routes the virtual network gateway has learned, including routes learned from BGP peers. | |
get_resiliency_information | exec | resource_group_name, virtual_network_gateway_name, subscription_id | attemptRefresh | This operation retrieves the resiliency information for an Express Route Gateway, including the gateway's current resiliency score and recommendations to further improve the score. |
get_routes_information | exec | resource_group_name, virtual_network_gateway_name, subscription_id | attemptRefresh | This operation retrieves the route set information for an Express Route Gateway based on their resiliency. |
get_vpnclient_ipsec_parameters | exec | resource_group_name, virtual_network_gateway_name, subscription_id | The Get VpnclientIpsecParameters operation retrieves information about the vpnclient ipsec policy for P2S client of virtual network gateway in the specified resource group through Network resource provider. | |
get_vpnclient_connection_health | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Get VPN client connection health detail per P2S client connection of the virtual network gateway in the specified resource group. | |
reset | exec | resource_group_name, virtual_network_gateway_name, subscription_id | gatewayVip | Resets the primary of the virtual network gateway in the specified resource group. |
reset_vpn_client_shared_key | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Resets the VPN client shared key of the virtual network gateway in the specified resource group. | |
generatevpnclientpackage | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Generates VPN client package for P2S client of the virtual network gateway in the specified resource group. | |
generate_vpn_profile | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Generates VPN profile for P2S client of the virtual network gateway in the specified resource group. Used for IKEV2 and radius based authentication. | |
supported_vpn_devices | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Gets a xml format representation for supported vpn devices. | |
set_vpnclient_ipsec_parameters | exec | resource_group_name, virtual_network_gateway_name, subscription_id, saLifeTimeSeconds, saDataSizeKilobytes, ipsecEncryption, ipsecIntegrity, ikeEncryption, ikeIntegrity, dhGroup, pfsGroup | The Set VpnclientIpsecParameters operation sets the vpnclient ipsec policy for P2S client of virtual network gateway in the specified resource group through Network resource provider. | |
start_packet_capture | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Starts packet capture on virtual network gateway in the specified resource group. | |
stop_packet_capture | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Stops packet capture on virtual network gateway in the specified resource group. | |
start_express_route_site_failover_simulation | exec | resource_group_name, virtual_network_gateway_name, subscription_id, peeringLocation | This operation starts failover simulation on the gateway for the specified peering location. | |
stop_express_route_site_failover_simulation | exec | resource_group_name, virtual_network_gateway_name, subscription_id | This operation stops failover simulation on the gateway for the specified peering location. | |
disconnect_virtual_network_gateway_vpn_connections | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Disconnect vpn connections of virtual network gateway in the specified resource group. | |
invoke_prepare_migration | exec | resource_group_name, virtual_network_gateway_name, subscription_id, migrationType | Trigger prepare migration for the virtual network gateway. | |
invoke_execute_migration | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Trigger execute migration for the virtual network gateway. | |
invoke_commit_migration | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Trigger commit migration for the virtual network gateway. | |
invoke_abort_migration | exec | resource_group_name, virtual_network_gateway_name, subscription_id | Trigger abort migration for the virtual network gateway. | |
vpn_device_configuration_script | exec | resource_group_name, virtual_network_gateway_connection_name, subscription_id | Gets a xml format representation for vpn device configuration script. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
failoverTestId | string | The unique Guid value which identifies the test. Required. |
fetchLatest | boolean | Fetch only the latest tests for each peering location. Required. |
peer | string | The IP address of the peer. Required. |
peeringLocation | string | Peering location of the test. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
subscription_id | string | |
type | string | The type of failover test. Required. |
virtual_network_gateway_connection_name | string | The name of the virtual network gateway connection. Required. |
virtual_network_gateway_name | string | The name of the virtual network gateway. Required. |
attemptRefresh | boolean | Attempt to recalculate the Route Sets Information for the gateway. Default value is None. |
gatewayVip | string | Virtual network gateway vip address supplied to the begin reset of the active-active feature enabled gateway. Default value is None. |
peer | string | The IP address of the peer to retrieve the status of. Default value is None. |
SELECT examples
- get_failover_all_test_details
- get_failover_single_test_details
- get_advertised_routes
- get
- list
This operation retrieves the details of all the failover tests performed on the gateway for different peering locations.
SELECT
circuits,
connections,
endTime,
issues,
peeringLocation,
startTime,
status,
testGuid,
testType
FROM azure.network.virtual_network_gateways
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND type = '{{ type }}' -- required
AND fetchLatest = '{{ fetchLatest }}' -- required
;
This operation retrieves the details of a particular failover test performed on the gateway based on the test Guid.
SELECT
endTimeUtc,
failoverConnectionDetails,
nonRedundantRoutes,
peeringLocation,
redundantRoutes,
startTimeUtc,
status,
wasSimulationSuccessful
FROM azure.network.virtual_network_gateways
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND peeringLocation = '{{ peeringLocation }}' -- required
AND failoverTestId = '{{ failoverTestId }}' -- required
;
This operation retrieves a list of routes the virtual network gateway is advertising to the specified peer.
SELECT
asPath,
localAddress,
network,
nextHop,
origin,
sourcePeer,
weight
FROM azure.network.virtual_network_gateways
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND peer = '{{ peer }}' -- required
;
Gets the specified virtual network gateway by resource group.
SELECT
id,
name,
activeActive,
adminState,
allowRemoteVnetTraffic,
allowVirtualWanTraffic,
autoScaleConfiguration,
bgpSettings,
customRoutes,
disableIPSecReplayProtection,
enableBgp,
enableBgpRouteTranslationForNat,
enableDnsForwarding,
enableHighBandwidthVpnGateway,
enablePrivateIpAddress,
etag,
extendedLocation,
gatewayDefaultSite,
gatewayType,
identity,
inboundDnsForwardingEndpoint,
ipConfigurations,
location,
natRules,
provisioningState,
resiliencyModel,
resourceGuid,
sku,
tags,
type,
vNetExtendedLocationResourceId,
virtualNetworkGatewayMigrationStatus,
virtualNetworkGatewayPolicyGroups,
vpnClientConfiguration,
vpnGatewayGeneration,
vpnType
FROM azure.network.virtual_network_gateways
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets all virtual network gateways by resource group.
SELECT
id,
name,
activeActive,
adminState,
allowRemoteVnetTraffic,
allowVirtualWanTraffic,
autoScaleConfiguration,
bgpSettings,
customRoutes,
disableIPSecReplayProtection,
enableBgp,
enableBgpRouteTranslationForNat,
enableDnsForwarding,
enableHighBandwidthVpnGateway,
enablePrivateIpAddress,
etag,
extendedLocation,
gatewayDefaultSite,
gatewayType,
identity,
inboundDnsForwardingEndpoint,
ipConfigurations,
location,
natRules,
provisioningState,
resiliencyModel,
resourceGuid,
sku,
tags,
type,
vNetExtendedLocationResourceId,
virtualNetworkGatewayMigrationStatus,
virtualNetworkGatewayPolicyGroups,
vpnClientConfiguration,
vpnGatewayGeneration,
vpnType
FROM azure.network.virtual_network_gateways
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
INSERT examples
- create_or_update
- Manifest
Creates or updates a virtual network gateway in the specified resource group.
INSERT INTO azure.network.virtual_network_gateways (
id,
location,
tags,
properties,
extendedLocation,
identity,
resource_group_name,
virtual_network_gateway_name,
subscription_id
)
SELECT
'{{ id }}',
'{{ location }}',
'{{ tags }}',
'{{ properties }}' /* required */,
'{{ extendedLocation }}',
'{{ identity }}',
'{{ resource_group_name }}',
'{{ virtual_network_gateway_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
etag,
extendedLocation,
identity,
location,
properties,
tags,
type
;
# Description fields are for documentation purposes
- name: virtual_network_gateways
props:
- name: resource_group_name
value: "{{ resource_group_name }}"
description: Required parameter for the virtual_network_gateways resource.
- name: virtual_network_gateway_name
value: "{{ virtual_network_gateway_name }}"
description: Required parameter for the virtual_network_gateways resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the virtual_network_gateways resource.
- name: id
value: "{{ id }}"
description: |
Resource ID.
- name: location
value: "{{ location }}"
description: |
Resource location.
- name: tags
value: "{{ tags }}"
description: |
Resource tags.
- name: properties
description: |
Properties of the virtual network gateway. Required.
value:
autoScaleConfiguration:
bounds:
min: {{ min }}
max: {{ max }}
ipConfigurations:
- id: "{{ id }}"
properties:
privateIPAllocationMethod: "{{ privateIPAllocationMethod }}"
subnet:
id: "{{ id }}"
publicIPAddress:
id: "{{ id }}"
privateIPAddress: "{{ privateIPAddress }}"
provisioningState: "{{ provisioningState }}"
name: "{{ name }}"
etag: "{{ etag }}"
gatewayType: "{{ gatewayType }}"
vpnType: "{{ vpnType }}"
vpnGatewayGeneration: "{{ vpnGatewayGeneration }}"
enableBgp: {{ enableBgp }}
enablePrivateIpAddress: {{ enablePrivateIpAddress }}
virtualNetworkGatewayMigrationStatus:
state: "{{ state }}"
phase: "{{ phase }}"
errorMessage: "{{ errorMessage }}"
activeActive: {{ activeActive }}
enableHighBandwidthVpnGateway: {{ enableHighBandwidthVpnGateway }}
disableIPSecReplayProtection: {{ disableIPSecReplayProtection }}
gatewayDefaultSite:
id: "{{ id }}"
sku:
name: "{{ name }}"
tier: "{{ tier }}"
capacity: {{ capacity }}
vpnClientConfiguration:
vpnClientAddressPool:
addressPrefixes:
- "{{ addressPrefixes }}"
ipamPoolPrefixAllocations:
- pool:
id: "{{ id }}"
numberOfIpAddresses: "{{ numberOfIpAddresses }}"
allocatedAddressPrefixes: "{{ allocatedAddressPrefixes }}"
vpnClientRootCertificates:
- id: "{{ id }}"
properties:
publicCertData: "{{ publicCertData }}"
provisioningState: "{{ provisioningState }}"
name: "{{ name }}"
etag: "{{ etag }}"
vpnClientRevokedCertificates:
- id: "{{ id }}"
properties:
thumbprint: "{{ thumbprint }}"
provisioningState: "{{ provisioningState }}"
name: "{{ name }}"
etag: "{{ etag }}"
vpnClientProtocols:
- "{{ vpnClientProtocols }}"
vpnAuthenticationTypes:
- "{{ vpnAuthenticationTypes }}"
vpnClientIpsecPolicies:
- saLifeTimeSeconds: {{ saLifeTimeSeconds }}
saDataSizeKilobytes: {{ saDataSizeKilobytes }}
ipsecEncryption: "{{ ipsecEncryption }}"
ipsecIntegrity: "{{ ipsecIntegrity }}"
ikeEncryption: "{{ ikeEncryption }}"
ikeIntegrity: "{{ ikeIntegrity }}"
dhGroup: "{{ dhGroup }}"
pfsGroup: "{{ pfsGroup }}"
radiusServerAddress: "{{ radiusServerAddress }}"
radiusServerSecret: "{{ radiusServerSecret }}"
radiusServers:
- radiusServerAddress: "{{ radiusServerAddress }}"
radiusServerScore: {{ radiusServerScore }}
radiusServerSecret: "{{ radiusServerSecret }}"
aadTenant: "{{ aadTenant }}"
aadAudience: "{{ aadAudience }}"
aadIssuer: "{{ aadIssuer }}"
vngClientConnectionConfigurations:
- id: "{{ id }}"
properties:
vpnClientAddressPool:
addressPrefixes: "{{ addressPrefixes }}"
ipamPoolPrefixAllocations: "{{ ipamPoolPrefixAllocations }}"
virtualNetworkGatewayPolicyGroups:
- id: "{{ id }}"
provisioningState: "{{ provisioningState }}"
name: "{{ name }}"
etag: "{{ etag }}"
virtualNetworkGatewayPolicyGroups:
- id: "{{ id }}"
properties:
isDefault: {{ isDefault }}
priority: {{ priority }}
policyMembers:
- name: "{{ name }}"
attributeType: "{{ attributeType }}"
attributeValue: "{{ attributeValue }}"
vngClientConnectionConfigurations:
- id: "{{ id }}"
provisioningState: "{{ provisioningState }}"
name: "{{ name }}"
etag: "{{ etag }}"
bgpSettings:
asn: {{ asn }}
bgpPeeringAddress: "{{ bgpPeeringAddress }}"
peerWeight: {{ peerWeight }}
bgpPeeringAddresses:
- ipconfigurationId: "{{ ipconfigurationId }}"
defaultBgpIpAddresses: "{{ defaultBgpIpAddresses }}"
customBgpIpAddresses: "{{ customBgpIpAddresses }}"
tunnelIpAddresses: "{{ tunnelIpAddresses }}"
customRoutes:
addressPrefixes:
- "{{ addressPrefixes }}"
ipamPoolPrefixAllocations:
- pool:
id: "{{ id }}"
numberOfIpAddresses: "{{ numberOfIpAddresses }}"
allocatedAddressPrefixes: "{{ allocatedAddressPrefixes }}"
resourceGuid: "{{ resourceGuid }}"
provisioningState: "{{ provisioningState }}"
enableDnsForwarding: {{ enableDnsForwarding }}
inboundDnsForwardingEndpoint: "{{ inboundDnsForwardingEndpoint }}"
vNetExtendedLocationResourceId: "{{ vNetExtendedLocationResourceId }}"
natRules:
- id: "{{ id }}"
name: "{{ name }}"
type: "{{ type }}"
properties:
provisioningState: "{{ provisioningState }}"
type: "{{ type }}"
mode: "{{ mode }}"
internalMappings:
- addressSpace: "{{ addressSpace }}"
portRange: "{{ portRange }}"
externalMappings:
- addressSpace: "{{ addressSpace }}"
portRange: "{{ portRange }}"
ipConfigurationId: "{{ ipConfigurationId }}"
etag: "{{ etag }}"
enableBgpRouteTranslationForNat: {{ enableBgpRouteTranslationForNat }}
allowVirtualWanTraffic: {{ allowVirtualWanTraffic }}
allowRemoteVnetTraffic: {{ allowRemoteVnetTraffic }}
adminState: "{{ adminState }}"
resiliencyModel: "{{ resiliencyModel }}"
- name: extendedLocation
description: |
The extended location of type local virtual network gateway.
value:
name: "{{ name }}"
type: "{{ type }}"
- name: identity
description: |
The identity of the virtual network gateway, if configured.
value:
principalId: "{{ principalId }}"
tenantId: "{{ tenantId }}"
type: "{{ type }}"
userAssignedIdentities: "{{ userAssignedIdentities }}"
UPDATE examples
- update_tags
Updates a virtual network gateway tags.
UPDATE azure.network.virtual_network_gateways
SET
tags = '{{ tags }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
etag,
extendedLocation,
identity,
location,
properties,
tags,
type;
REPLACE examples
- create_or_update
Creates or updates a virtual network gateway in the specified resource group.
REPLACE azure.network.virtual_network_gateways
SET
id = '{{ id }}',
location = '{{ location }}',
tags = '{{ tags }}',
properties = '{{ properties }}',
extendedLocation = '{{ extendedLocation }}',
identity = '{{ identity }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND properties = '{{ properties }}' --required
RETURNING
id,
name,
etag,
extendedLocation,
identity,
location,
properties,
tags,
type;
DELETE examples
- delete
Deletes the specified virtual network gateway.
DELETE FROM azure.network.virtual_network_gateways
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND virtual_network_gateway_name = '{{ virtual_network_gateway_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
Lifecycle Methods
- list_connections
- list_radius_secrets
- get_vpn_profile_package_url
- get_bgp_peer_status
- get_learned_routes
- get_resiliency_information
- get_routes_information
- get_vpnclient_ipsec_parameters
- get_vpnclient_connection_health
- reset
- reset_vpn_client_shared_key
- generatevpnclientpackage
- generate_vpn_profile
- supported_vpn_devices
- set_vpnclient_ipsec_parameters
- start_packet_capture
- stop_packet_capture
- start_express_route_site_failover_simulation
- stop_express_route_site_failover_simulation
- disconnect_virtual_network_gateway_vpn_connections
- invoke_prepare_migration
- invoke_execute_migration
- invoke_commit_migration
- invoke_abort_migration
- vpn_device_configuration_script
Gets all the connections in a virtual network gateway.
EXEC azure.network.virtual_network_gateways.list_connections
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
List all Radius servers with respective radius secrets from virtual network gateway VpnClientConfiguration.
EXEC azure.network.virtual_network_gateways.list_radius_secrets
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Gets pre-generated VPN profile for P2S client of the virtual network gateway in the specified resource group. The profile needs to be generated first using generateVpnProfile.
EXEC azure.network.virtual_network_gateways.get_vpn_profile_package_url
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
The GetBgpPeerStatus operation retrieves the status of all BGP peers.
EXEC azure.network.virtual_network_gateways.get_bgp_peer_status
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required,
@peer='{{ peer }}'
;
This operation retrieves a list of routes the virtual network gateway has learned, including routes learned from BGP peers.
EXEC azure.network.virtual_network_gateways.get_learned_routes
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
This operation retrieves the resiliency information for an Express Route Gateway, including the gateway's current resiliency score and recommendations to further improve the score.
EXEC azure.network.virtual_network_gateways.get_resiliency_information
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required,
@attemptRefresh={{ attemptRefresh }}
;
This operation retrieves the route set information for an Express Route Gateway based on their resiliency.
EXEC azure.network.virtual_network_gateways.get_routes_information
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required,
@attemptRefresh={{ attemptRefresh }}
;
The Get VpnclientIpsecParameters operation retrieves information about the vpnclient ipsec policy for P2S client of virtual network gateway in the specified resource group through Network resource provider.
EXEC azure.network.virtual_network_gateways.get_vpnclient_ipsec_parameters
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Get VPN client connection health detail per P2S client connection of the virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.get_vpnclient_connection_health
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Resets the primary of the virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.reset
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required,
@gatewayVip='{{ gatewayVip }}'
;
Resets the VPN client shared key of the virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.reset_vpn_client_shared_key
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Generates VPN client package for P2S client of the virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.generatevpnclientpackage
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"processorArchitecture": "{{ processorArchitecture }}",
"authenticationMethod": "{{ authenticationMethod }}",
"radiusServerAuthCertificate": "{{ radiusServerAuthCertificate }}",
"clientRootCertificates": "{{ clientRootCertificates }}"
}'
;
Generates VPN profile for P2S client of the virtual network gateway in the specified resource group. Used for IKEV2 and radius based authentication.
EXEC azure.network.virtual_network_gateways.generate_vpn_profile
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"processorArchitecture": "{{ processorArchitecture }}",
"authenticationMethod": "{{ authenticationMethod }}",
"radiusServerAuthCertificate": "{{ radiusServerAuthCertificate }}",
"clientRootCertificates": "{{ clientRootCertificates }}"
}'
;
Gets a xml format representation for supported vpn devices.
EXEC azure.network.virtual_network_gateways.supported_vpn_devices
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
The Set VpnclientIpsecParameters operation sets the vpnclient ipsec policy for P2S client of virtual network gateway in the specified resource group through Network resource provider.
EXEC azure.network.virtual_network_gateways.set_vpnclient_ipsec_parameters
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"saLifeTimeSeconds": {{ saLifeTimeSeconds }},
"saDataSizeKilobytes": {{ saDataSizeKilobytes }},
"ipsecEncryption": "{{ ipsecEncryption }}",
"ipsecIntegrity": "{{ ipsecIntegrity }}",
"ikeEncryption": "{{ ikeEncryption }}",
"ikeIntegrity": "{{ ikeIntegrity }}",
"dhGroup": "{{ dhGroup }}",
"pfsGroup": "{{ pfsGroup }}"
}'
;
Starts packet capture on virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.start_packet_capture
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"filterData": "{{ filterData }}"
}'
;
Stops packet capture on virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.stop_packet_capture
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"sasUrl": "{{ sasUrl }}"
}'
;
This operation starts failover simulation on the gateway for the specified peering location.
EXEC azure.network.virtual_network_gateways.start_express_route_site_failover_simulation
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required,
@peeringLocation='{{ peeringLocation }}' --required
;
This operation stops failover simulation on the gateway for the specified peering location.
EXEC azure.network.virtual_network_gateways.stop_express_route_site_failover_simulation
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"peeringLocation": "{{ peeringLocation }}",
"wasSimulationSuccessful": {{ wasSimulationSuccessful }},
"details": "{{ details }}"
}'
;
Disconnect vpn connections of virtual network gateway in the specified resource group.
EXEC azure.network.virtual_network_gateways.disconnect_virtual_network_gateway_vpn_connections
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"vpnConnectionIds": "{{ vpnConnectionIds }}"
}'
;
Trigger prepare migration for the virtual network gateway.
EXEC azure.network.virtual_network_gateways.invoke_prepare_migration
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"migrationType": "{{ migrationType }}",
"resourceUrl": "{{ resourceUrl }}"
}'
;
Trigger execute migration for the virtual network gateway.
EXEC azure.network.virtual_network_gateways.invoke_execute_migration
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Trigger commit migration for the virtual network gateway.
EXEC azure.network.virtual_network_gateways.invoke_commit_migration
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Trigger abort migration for the virtual network gateway.
EXEC azure.network.virtual_network_gateways.invoke_abort_migration
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_name='{{ virtual_network_gateway_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;
Gets a xml format representation for vpn device configuration script.
EXEC azure.network.virtual_network_gateways.vpn_device_configuration_script
@resource_group_name='{{ resource_group_name }}' --required,
@virtual_network_gateway_connection_name='{{ virtual_network_gateway_connection_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
@@json=
'{
"vendor": "{{ vendor }}",
"deviceFamily": "{{ deviceFamily }}",
"firmwareVersion": "{{ firmwareVersion }}"
}'
;