> For the complete documentation index, see [llms.txt](https://docs.monogoto.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.monogoto.io/advanced-console/platform/vpn-setup-examples/vpn-setup-with-azure.md).

# VPN Setup with Azure

1\.      Login to the Monogoto portal and go to ***Network.***

2\.      Edit your **vpneu.mono** network (EU zone) or **"vpnus.mono"** network (US zone).

![](/files/QyoXNHhLethqFPeSysvp)

3\.      Go to **Routes** and copy Gateway IP.

![](/files/jKgDfRzfinCup6QEcN3k)

4\.      Login to your Azure account and create a new **Virtual Network Gateway**.

![](/files/a1taMBI7RzKpRbnaJeLU)

5\.       In the window that opens, please do the following changes:&#x20;

* Name the **Virtual Network Gateway** as you see fit.
* Choose the **Region** your **Virtual Network** resides in.
* Select **VPN, Route-based, VpnGw1, Generation1** and select your **Virtual Network**.
* Allocate a subnet address range for your **Virtual Network Gateway** on your **Virtual Network**.

![](/files/1vaHJ8ji9CtlwtGmboRD)

6\.      For **Public IP address**, select **reate new**”and give it an appropriate name.

Leave other options as default and click **Next** if you wish to tag your **Virtual Network Gateway** or **Review + create** to skip tagging. Note that **Virtual Network Gateway** can take a while to deploy.

![](/files/rWPLRz7lrV5uLuyJ7R5o)

7\.      Create a new **Local network gateway.**

![](/files/33YNoQ4KPwGhV0S4Ckns)

8\.      Choose the appropriate **Resource group** & **Region**, name the **Local network gateway** to your liking, and for **IP address** enter the **Monogoto Gateway IP** we copied earlier.

![](/files/yVbWnj50sp6QxIoH8KTG)

9\.      In a new tab, go to the **Monogoto Network** we used earlier, and copy the CIDR range under **Ip Address / Mask** in **Address Pools.**

![](/files/m6Al5XXl7x1e4vFaJYyX)

10\.      Go back to the **Create local network gateway** tab and paste the **CIDR range** we copied in the **Address space** field, then click **Review + Create** and finally **reate**”

![](/files/CZe6AnwrqOYNK6btzpA5)

11\.      Next, go to the **Virtual network gateway** we created earlier and copy the **Public IP address.**

![](/files/X2xh7eTNz0tyWbXvF52s)

12\.      Go back to the **Monogoto Network** page, and under **VPN** click **Add new.**

![](/files/pWVqkhBnfOhG3cJCb8os)

13\.      Name the VPN connection as you’d like.&#x20;

* Paste the **Virtual network gateway**’s public IP address we copied earlier in the **Destination IP Address** field.
* In **Destination Network**, paste the **Azure Virtual Network** address range you would like to be able to access the VPN.

![](/files/gseqLNRnebmYRZUBrqTC)

14\.      Click **Save & Close** and then **Apply Settings**”

15\.      Once the VPN is created, click the **download configuration** button and copy the **Pre-Shared Key** from the downloaded file.

![](/files/yi8qVUz2lvVbka7Bouav)

![](/files/OroDrc9gA3agqP5uVrIE)

16\.      On Azure, go to the **Virtual Network Gateway** we created earlier and click on **Connections**, then click **Add.**

![](/files/yQrIi5zYLZXSXYPAfcUO)

![](/files/GOvClZ7yUsNA2HLQiviv)

17\.      Name your connection as you’d like.&#x20;

* Under **Connection type** select **Site-to-site (IPsec)**.
* Click **Local network gateway** and select the Local network gateway we created earlier.
* Paste the **Pre-Shared Key** you copied from the downloaded configuration file.

**Important!** Monogoto's platform negotiates IKEv1 Main Mode on all VPN connections, regardless of whether you're using policy-based or route-based VPN. Select **IKEv1** here — selecting IKEv2 will cause the tunnel to fail silently (Phase 1 negotiation will time out with no response).

![](/files/KHWKCe0dbX0bAtZY1Luy)

18\.      (**OPTIONAL**) If you prefer to use policy-based connections, click **configuration** in the connection we just created, change **IPsec / IKE policy** to **Custom** and make sure the settings are identical to the following screenshot:

![](/files/xPT5UqGl2CwIKryDVcTb)

19\.       Create/change any firewall rules you need to allow traffic between your Virtual Network and the Monogoto Address Pool.

20\.      That’s it, your VPN connection should be up and connected.
