An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
@Adam-2452 @Jose Benjamin Solis Nolasco
I’m seeing the exact same issue on a Basic SKU gateway.
The generated *.vpn.azure.com hostname resolves to a different public IP than the public IP assigned to my VPN Gateway. Wireshark shows repeated IKE_SA_INIT requests to the hostname-resolved IP, but no response at all.
When I test against the actual public IP assigned to the VPN Gateway, I immediately get IKE_SA_INIT and IKE_AUTH responses.
As a workaround, I added a hosts-file entry that maps the original Azure VPN hostname to the actual public IP of the VPN Gateway. This is important because the VPN client still needs to connect using the Azure DNS name rather than directly using the IP address.
With that hosts-file override in place, the P2S IKEv2 VPN connects successfully.
So for now this appears to be a working workaround. It also strongly suggests that the Basic SKU IKEv2 configuration itself is functioning, but the Azure-generated P2S hostname is being mapped to the wrong or non-responsive backend endpoint.