Validate VPN gateway traffic before committing the Basic public-IP migration

Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Keeping the numerical IP address does not remove the validation and commit stages or the accompanying gateway SKU change.

Potentially affected

Eligible non-Basic-SKU VPN gateways using the documented Basic public-IP migration workflow.

DSE recommendation

Validate actual tunnel traffic and the gateway change before the final migration commit.

Source facts

The guided process preserves the gateway’s numerical IP address while moving it to a Standard public-IP resource. It also changes a non-AZ VPN gateway SKU to its AZ counterpart. Microsoft’s documented workflow excludes the Basic gateway SKU, which requires a different procedure.

Before committing, Microsoft directs operators to validate receiving and transmitting traffic. Abort is the rollback path before commitment. Without the final commit, the old Basic public-IP resource remains pending rather than being deleted. Microsoft Learn.

Applicability

Confirm gateway and public-IP SKUs separately, migration eligibility, subnet capacity and any special legacy-DNS P2S requirements. Do not apply this workflow to a gateway solely because its public IP is Basic.

DSE recommendation

DSE recommends defining traffic acceptance checks and rollback authority before starting. Review the accompanying gateway SKU transition with its owner. Do not treat retention of the IP address as proof that tunnels, routing and required client paths work. Keep the validation decision separate from the action that finalizes the migration.

Verification

During an approved window, compare the gateway’s ingress and egress evidence with the agreed end-to-end connection tests. Resolve failures before committing and use the documented pre-commit abort path if required. After an approved commit, inspect the final resource and gateway state and preserve the receipt with traffic evidence. A resource left pending should remain an open migration item.

Official references

Microsoft Learn: How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway. Source retrieved September 9, 2026.

Primary reference

Review the official source

How to migrate a Basic SKU public IP address to a Standard SKU for VPN Gateway - Azure VPN Gateway | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE