An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Welcome to Microsoft Q&A
Hello @Mathew K Varghese , Thank you for the details.
A few common causes for VpnGw1 → VpnGw1AZ validation failures are:
- The gateway is deployed in a region that does not support Availability Zone VPN Gateway SKUs.
- The associated GatewaySubnet does not meet the minimum sizing requirements.
- The Public IP configuration is not compatible with the target AZ SKU.
- There is an existing gateway configuration or dependency that is not supported with zone-redundant gateways.
Since the portal only shows "Deployment validation failed", I would recommend checking Portal → Resource Group → Deployments and opening the failed deployment operation. In many cases, the detailed validation error contains the exact resource and property causing the failure.
References
- VPN Gateway SKUs and AZ support: https://learn.microsoft.com/azure/vpn-gateway/about-gateway-skus
- Migrate to Availability Zone VPN Gateway SKUs: https://learn.microsoft.com/azure/vpn-gateway/gateway-sku-upgrade
- GatewaySubnet requirements: https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-about-vpn-gateway-settings
- https://learn.microsoft.com/en-us/answers/questions/5938338/upgrading-vpn-gateway-sku-to-vpngw1az-fails-with-d (Here is a interesting case )
- https://learn.microsoft.com/en-us/answers/questions/5985100/how-to-upgrade-vpn-gateway-non-az-skus-to-an-vpn-g?page=1&orderby=Helpful&translated=false#answers (Similar case)
If my answer helped you resolve your issue, please consider marking it as the correct answer. This helps others in the community find solutions more easily.