An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
The fact that simply saving the Local Network Gateway fixes it is the biggest clue. That save forces the gateway to reprogram routes and tear down and rebuild every IPsec security association. So whatever breaks is stateful and gets reset, it isn't the config itself.
Why only one subnet breaks: most on-prem firewalls build a separate child SA per subnet pair (traffic selector). If one of those SAs goes stale after a rekey, only that subnet loses traffic while the others keep flowing through their own healthy SAs. The "fixes itself without changes" part fits too, it recovers at the next rekey cycle.
To confirm and fix it:
- Compare traffic selectors on both sides. Azure route-based gateways expect any-to-any (0.0.0.0/0). If the on-prem device is policy-based or defines per-subnet selectors, enable UsePolicyBasedTrafficSelectors on the connection with a custom IPsec/IKE policy that matches on-prem exactly, or switch the on-prem side to route-based (VTI) with 0.0.0.0/0 selectors. This mismatch is the most common cause of exactly this pattern.
- Align the SA lifetimes and PFS settings on both ends. Azure defaults are 28,800 seconds for IKE and 27,000 seconds for IPsec. A mismatch often breaks just one child SA at rekey time.
- Check for overlap on 172.19.0.0/16. Look at the effective routes on an Azure VM NIC in the affected path and make sure no VNet, peered VNet, UDR or BGP route also covers part of 172.19.x.x. A more specific route elsewhere would explain why adding 172.19.20.0/22 changes behavior.
- Next time it drops, before touching anything, run VPN troubleshoot in Network Watcher on the connection and turn on gateway diagnostics to Log Analytics (IKEDiagnosticLog, TunnelDiagnosticLog, RouteDiagnosticLog). The IKE log will show which SA failed and why.
- If your VpnGw1AZ is active-active, make sure on-prem has tunnels to both gateway instances. Otherwise Azure can return traffic through the instance with no tunnel.
If this helped, please click Accept Answer so others with intermittent S2S drops can find it.
References: https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps https://learn.microsoft.com/en-us/azure/vpn-gateway/troubleshoot-vpn-with-azure-diagnostics