Azure VPN (basic) P2S won't connect using IKEv2

Adam-2452 20 Reputation points
2026-09-09T20:14:37.6966667+00:00

I have an Azure VPN (Basic SKU) that has been working fine using SSTP for Point-to-site connections. I tried following the steps in migrate your VPN gateway (Option 1) to migrate to IKEv2. However, the new VPN client never connects - it just sits at "Verifying the password" and counts seconds forever (or "Connecting to ..." if I use the powershell client installer). If I re-install the old client, it connects just fine again using SSTP (NOTE: this is with no other change to the Virtual network gateway itself). I've tried disabling the Firewall on my Windows machine and on my router, but no change.

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

Answer accepted by question author
Marco Brouwer 80 Reputation points
2026-09-22T20:42:11.73+00:00

@Adam-2452 @Jose Benjamin Solis Nolasco

I’m seeing the exact same issue on a Basic SKU gateway.

The generated *.vpn.azure.com hostname resolves to a different public IP than the public IP assigned to my VPN Gateway. Wireshark shows repeated IKE_SA_INIT requests to the hostname-resolved IP, but no response at all.

When I test against the actual public IP assigned to the VPN Gateway, I immediately get IKE_SA_INIT and IKE_AUTH responses.

As a workaround, I added a hosts-file entry that maps the original Azure VPN hostname to the actual public IP of the VPN Gateway. This is important because the VPN client still needs to connect using the Azure DNS name rather than directly using the IP address.

With that hosts-file override in place, the P2S IKEv2 VPN connects successfully.

So for now this appears to be a working workaround. It also strongly suggests that the Basic SKU IKEv2 configuration itself is functioning, but the Azure-generated P2S hostname is being mapped to the wrong or non-responsive backend endpoint.

Was this answer helpful?

2 people found this answer helpful.

1 additional answer

Sort by: Oldest
  1. Jose Benjamin Solis Nolasco 12,691 Reputation points Volunteer Moderator
    2026-09-10T15:56:56.44+00:00

    Welcome to Microsoft Q&A!

    Hello @Adam-2452 I hope you are doing well,

    The issue occurs because the Basic SKU has platform limitations and does not support IKEv2 or RADIUS for Point-to-Site connections. On the Basic SKU, Point-to-Site connections are strictly limited to SSTP.

    Because the gateway itself remained on the Basic SKU, it is only listening for SSTP on TCP port 443. The IKEv2 client tries to negotiate over UDP ports 500 and 4500, but the gateway ignores the handshake, leaving the client hanging indefinitely at "Verifying the password."

    1. Deploy a VpnGw1 (or VpnGw1AZ) SKU: Azure does not allow an in-place upgrade from Basic to production SKUs via the dropdown. You must delete the Basic gateway and recreate it as VpnGw1 (or VpnGw1AZ) with a Standard SKU Public IP.

    Enable IKEv2: On the new gateway, go to Point-to-site configuration, set Tunnel type to IKEv2 and SSTP (SSL) (or IKEv2), and click Save.

    Download the updated client: Click Download VPN client, install the new package on your machine, and the IKEv2 connection will establish normally.

    References:

    About Azure Point-to-Site VPN connections - Microsoft Learn

    About gateway SKUs - Microsoft Learn

    Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.