Azure VPN Gateway is a service that uses a specific type of virtual network gateway to send encrypted traffic between an Azure virtual network and on-premises locations over the public Internet. 

You must configure cloud connections to monitor this entity. See Configure Azure Cloud Connection.

Cisco Cloud Observability displays Azure entities on the Observe page. Metrics are displayed for specific entity instances in the list and detail views.

This document contains references to third-party documentation. Cisco AppDynamics does not own any rights and assumes no responsibility for the accuracy or completeness of such third-party documentation.

Detail View

To display the detail view for an Azure VPN Gateway instance:

  1. Navigate to the Observe page.
  2. Under Networking & App Delivery, click Azure VPN Gateways.
    The list view now displays.
  3. Click an instance Name to display the detail view.
    The detail view displays metrics, key performance indicators, and properties (attributes) related to the instance you selected.

Metrics and Key Performance Indicators 

Cisco Cloud Observability displays the following metrics and key performance indicators (KPIs) for Azure VPN Gateway. See:

Display NameSource Metric NameDescription
Gateway S2S Bandwidth (Bytes/Sec)AverageBandwidthSite-to-site bandwidth of a gateway in bytes per second.
CPU Utilization (%)ExpressRouteGatewayCpuUtilizationCPU Utilization of the ExpressRoute Gateway.
Bits Received Per SecondExpressRouteGatewayBitsPerSecondTotal Bits received on ExpressRoute Gateway per second.
Packets Received Per SecondExpressRouteGatewayPacketsPerSecondTotal Packets received on ExpressRoute Gateway per second.
Frequency of Routes ChangeExpressRouteGatewayFrequencyOfRoutesChangedFrequency of Routes change in ExpressRoute Gateway.

Express Route Gateway Routes (Count)

vpn_gateway.express_route_gateway.routes

ExpressRouteGatewayCountOfRoutesAdvertisedToPeer

Count of Routes advertised to peer by ExpressRoute Gateway.
ExpressRouteGatewayCountOfRoutesLearnedFromPeerCount Of routes learned from peer by ExpressRoute Gateway.
Number of VMs in the Virtual NetworkExpressRouteGatewayNumberOfVmInVnetNumber of VMs in the Virtual Network.
Gateway P2S Bandwidth (Bytes/Sec)

P2SBandwidth

Point-to-site bandwidth of a gateway in bytes per second.
P2S Connection CountP2SConnectionCountPoint-to-site connection count of a gateway.
VPN Gateway Egress Packets (Count)

TunnelEgressPackets

Outgoing packet count of a tunnel.
VPN Gateway Ingress Packets (Count)

TunnelIngressBytes

Incoming bytes of a tunnel.
Tunnel Traffic (Bytes)

TunnelIngressBytes

Incoming bytes of a tunnel.

TunnelEgressBytesOutgoing bytes of a tunnel.
Tunnel NAT Allocations (Count)TunnelNatAllocationsCount of allocations for a NAT rule on a tunnel.

Properties (Attributes)

Cisco Cloud Observability displays the following properties for Azure VPN Gateway.

Display NameProperty NameDescription
Nameazure.nameThe Resource Name of the Azure Resource.
Resource Groupazure.resource.groupThe resource group of the Azure Resource.
Resource IDazure.resource.idThe fully qualified ID of the Azure Resource.
Active-Activeazure.vpn_gateway.active_activeIndicates whether active-active mode is enabled for the virtual network gateway.
Allow Remote Vnet Trafficazure.vpn_gateway.allow_remote_vnet_trafficSpecifies whether to allow remote Vnet traffic to pass through the gateway.
Allow Virtual WAN Trafficazure.vpn_gateway.allow_virtual_wan_trafficSpecifies whether the virtual network gateway allows Virtual WAN traffic to flow through the gateway.
Minimum Scale Units for Auto Scalingazure.vpn_gateway.auto_scale_configuration.min_scale_unitsSpecifies the minimum number of virtual network gateways to be deployed when autoscaling is enabled.
BGP ASNazure.vpn_gateway.bgp_settings.asnThe BGP Autonomous System Number (ASN) associated with this virtual network gateway.
BGP Peering Addressazure.vpn_gateway.bgp_settings.bgp_peering_addressThe IP address for the BGP peering interface on the virtual network gateway.
BGP Peer Weightazure.vpn_gateway.bgp_settings.peer_weightSpecifies the weight for the BGP peer. The higher the weight, the more preferred the peer is.
Custom Routes Address Prefixesazure.vpn_gateway.custom_routes.address_prefixesA list of address prefixes for custom routes in the virtual network gateway.
Disable IPSec Replay Protectionazure.vpn_gateway.disable_ip_sec_replay_protectionA boolean value indicating whether IPSec replay protection is disabled for the virtual network gateway.
Enable BGPazure.vpn_gateway.enable_bgpSpecifies whether BGP (Border Gateway Protocol) is enabled for this virtual network gateway. Default is false.
Enable BGP Route Translation for NATazure.vpn_gateway.enable_bgp_route_translation_for_natEnables BGP route translation for Network Address Translation (NAT) on this virtual network gateway. Default is false.
Enable DNS Forwardingazure.vpn_gateway.enable_dns_forwardingSpecifies whether DNS forwarding is enabled on the virtual network gateway.
Enable Private IP Addressazure.vpn_gateway.enable_private_ip_addressIndicates whether private IP address is enabled for the virtual network gateway.
Gateway Default Site IDazure.vpn_gateway.gateway_default_site.idThe ID of the default site for the virtual network gateway.
Gateway Typeazure.vpn_gateway.gateway_typeSpecifies the type of this virtual network gateway. Possible values are 'Vpn' and 'ExpressRoute'.
Migrate to CSESazure.vpn_gateway.is_migrate_to_csesSpecifies whether the virtual network gateway is in the process of being migrated to the Cloud Services Environment (CSES) or not.
Migration Phaseazure.vpn_gateway.migration_phaseThe phase of the migration process for the virtual network gateway.
Packet Capture Diagnostic Stateazure.vpn_gateway.packet_capture_diagnostic_stateIndicates whether packet capture diagnostic is enabled or disabled for this virtual network gateway.
Provisioning Stateazure.vpn_gateway.provisioning_stateThe provisioning state of the virtual network gateway resource.
Resource GUIDazure.vpn_gateway.resource_guidSpecifies the unique identifier for this virtual network gateway resource.
SKU Capacityazure.vpn_gateway.sku.capacityThe capacity of the virtual network gateway SKU.
SKU Nameazure.vpn_gateway.sku.nameThe name of the SKU (stock keeping unit) for the virtual network gateway.
SKU Tierazure.vpn_gateway.sku.tierSpecifies the SKU tier of the virtual network gateway.
Tunnel Inbound Authentication Root Certificatesazure.vpn_gateway.tunnel_inbound_auth_root_certificatesA list of base-64 encoded strings that represent the root certificates of the authentication certificate authorities used for tunnel inbound authentication.
Tunnel Outbound Authentication Certificate Pathazure.vpn_gateway.tunnel_outbound_auth_certificate_pathSpecifies the path of the certificate used for tunnel outbound authentication.
Virtual Network Extended Location Resource IDazure.vpn_gateway.vnet_extended_location_resource_idThe resource ID of the virtual network extended location associated with the virtual network gateway.
Azure Active Directory Audienceazure.vpn_gateway.vpn_client_configuration.aad_audienceThe Azure Active Directory audience(s) for the virtual network gateway VPN client configuration.
AAD Issuerazure.vpn_gateway.vpn_client_configuration.aad_issuerThe issuer of the Azure Active Directory used for authentication of Point-to-Site VPN clients.
VPN Client Configuration - AAD Tenantazure.vpn_gateway.vpn_client_configuration.aad_tenantThe issuer of the Azure Active Directory used for authentication of Point-to-Site VPN clients.
VPN Client Radius Server Addressazure.vpn_gateway.vpn_client_configuration.radius_server_addressThe address of the RADIUS server for VPN clients connecting to the virtual network gateway.
VPN Client Configuration - RADIUS Server Secretazure.vpn_gateway.vpn_client_configuration.radius_server_secretThe secret used to authenticate against the RADIUS server for VPN client authentication.
VPN Client Configuration Authentication Typesazure.vpn_gateway.vpn_client_configuration.vpn_authentication_typesThe authentication types used by the VPN clients connecting to the virtual network gateway.
VPN Client Configuration Address Prefixesazure.vpn_gateway.vpn_client_configuration.vpn_client_address_pool.address_prefixesThe address prefixes for the VPN client address pool associated with the virtual network gateway.
Allocated IP Addresses for VPN Client Connection Healthazure.vpn_gateway.vpn_client_configuration.vpn_client_connection_health.allocated_ip_addressesA list of IP addresses allocated for VPN client connections that are currently connected to the virtual network gateway.
Total Egress Bytes Transferredazure.vpn_gateway.vpn_client_configuration.vpn_client_connection_health.total_egress_bytes_transferredThe total number of bytes transferred out of the virtual network gateway for VPN client connections.
VPN Client Connection Health - Total Ingress Bytes Transferredazure.vpn_gateway.vpn_client_configuration.vpn_client_connection_health.total_ingress_bytes_transferredSpecifies the total number of ingress bytes transferred for the VPN client connection health.
VPN Client Configuration - VPN Client Connections Countazure.vpn_gateway.vpn_client_configuration.vpn_client_connection_health.vpn_client_connections_countSpecifies the number of VPN client connections allowed for the virtual network gateway.
VPN Client Protocolsazure.vpn_gateway.vpn_client_configuration.vpn_client_protocolsSpecifies the VPN client protocols that are allowed for the virtual network gateway.
VPN Gateway Generationazure.vpn_gateway.vpn_gateway_generationSpecifies the type of VPN connection that the virtual network gateway supports. Valid values are 'RouteBased' and 'PolicyBased'.
VPN Typeazure.vpn_gateway.vpn_typeSpecifies the type of VPN connection that the virtual network gateway supports. Valid values are 'RouteBased' and 'PolicyBased'.
Account IDcloud.account.idThe cloud account ID the resource is assigned to.
Platformcloud.platformThe cloud platform in use.
Regioncloud.regionThe location of the Azure Function resource.

Retention and Purge Time-To-Live (TTL)

For all cloud and infrastructure entities, the retention TTL is 180 minutes (3 hours) and the purge TTL is 525,600 minutes (365 days). 

Microsoft Azure, the Microsoft Azure logo, Azure, and any other Microsoft Azure Marks used in these materials are trademarks of Microsoft Corporation or its affiliates in the United States and/or other countries.