Virtual Network Gateway no longer receiving ingress traffic

Cody Durand 40 Reputation points
2026-09-29T14:14:37.8933333+00:00

We have a Virtual Network Gateway configured to connect our on-premise network to our Azure virtual network over an IKEv2 tunnel. This tunnel has been configured and working for years. As of a few days ago, we are no longer able to send traffic over the VPN tunnel into the Azure virtual network.

The tunnel shows as active/connected on both ends, and I do see that Azure reflects that traffic is flowing from Azure into our local network, just not the other way.

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Cody Durand 40 Reputation points
    2026-09-30T14:27:55.51+00:00

    I did want to provide an update on my question. Oddly enough, the issue resolved itself over night. We had exhausted our troubleshooting steps during the day and none of the attempted fixes had resolved the issue. However, at the start of the next day traffic was flowing successfully. It is unknown if the IP sku issue I mentioned in a previous reply was the underlying issue and it simply took a bit of time for the migration to take effect, or if there was a very specific outage that was occurring that impacted my organization that we were unaware of. Either way, the issue has been resolved so I will mark this as closed.

    Was this answer helpful?

    0 comments No comments

  2. Salamat Shah 750 Reputation points MVP
    2026-09-29T17:24:47.31+00:00

    Since the VPN tunnel is Connected but traffic works only Azure → on-premises, this most likely indicates an asymmetric routing, traffic-selector, firewall, or IPsec policy issue rather than tunnel establishment. Azure recommends checking VPN diagnostic/IKE logs for these scenarios.

    Recommendation:

    Since the VPN tunnel is Connected but traffic works only Azure → on-premises, this most likely indicates an asymmetric routing, traffic-selector, firewall, or IPsec policy issue rather than tunnel establishment. Azure recommends checking VPN diagnostic/IKE logs for these scenarios.

    https://learn.microsoft.com/en-us/troubleshoot/azure/vpn-gateway/vpn-gateway-troubleshoot

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.