You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/route-server/troubleshoot-route-server.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -57,13 +57,13 @@ When you deploy a Route Server to a virtual network, we need to update the contr
57
57
58
58
### Why does my on-premises network connected to Azure VPN gateway not receive the default route advertised by the Route Server?
59
59
60
-
Although Azure VPN gateway can receive the default route from its BGP peers including the Route Server, it [doesn't advertise the default route](../vpn-gateway/vpn-gateway-vpn-faq.md#what-address-prefixes-will-azure-vpn-gateways-advertise-to-me) to other peers.
60
+
Although Azure VPN gateway can receive the default route from its BGP peers including the Route Server, it [doesn't advertise the default route](../vpn-gateway/vpn-gateway-vpn-faq.md#what-address-prefixes-do-azure-vpn-gateways-advertise-to-me) to other peers.
61
61
62
62
### Why does my NVA not receive routes from the Route Server even though the BGP peering is up?
63
63
64
64
The ASN that the Route Server uses is 65515. Make sure you configure a different ASN for your NVA so that an *eBGP* session can be established between your NVA and Route Server so route propagation can happen automatically. Make sure you enable "multi-hop" in your BGP configuration because your NVA and the Route Server are in different subnets in the virtual network.
65
65
66
-
### The BGP peering between my NVA and Route Server is up. I can see routes exchanged correctly between them. Why aren’t the NVA routes in the effective routing table of my VM?
66
+
### The BGP peering between my NVA and Route Server is up. I can see routes exchanged correctly between them. Why aren't the NVA routes in the effective routing table of my VM?
67
67
68
68
* If your VM is in the same virtual network as your NVA and Route Server:
Depending on the VPN device that you have, you may be able to download a VPN device configuration script. For more information, see [Download VPN device configuration scripts](../articles/vpn-gateway/vpn-gateway-download-vpndevicescript.md).
13
+
Depending on the VPN device that you have, you might be able to download a VPN device configuration script. For more information, see [Download VPN device configuration scripts](../articles/vpn-gateway/vpn-gateway-download-vpndevicescript.md).
15
14
16
-
**See the following links for additional configuration information:**
15
+
The following links provide more configuration information:
17
16
18
-
- For information about compatible VPN devices, see [VPN Devices](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md).
17
+
- For information about compatible VPN devices, see [About VPN devices](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md).
19
18
20
-
- Before configuring your VPN device, check for any [Known device compatibility issues](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#known) for the VPN device that you want to use.
19
+
- Before you configure your VPN device, check for any [known device compatibility issues](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#known).
21
20
22
-
- For links to device configuration settings, see [Validated VPN Devices](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#devicetable). The device configuration links are provided on a best-effort basis. It's always best to check with your device manufacturer for the latest configuration information. The list shows the versions we have tested. If your OS is not on that list, it is still possible that the version is compatible. Check with your device manufacturer to verify that OS version for your VPN device is compatible.
21
+
- For links to device configuration settings, see [Validated VPN devices](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#devicetable). We provide the device configuration links on a best-effort basis, but it's always best to check with your device manufacturer for the latest configuration information.
23
22
24
-
- For an overview of VPN device configuration, see [VPN device configuration overview](../articles/vpn-gateway/vpn-gateway-3rdparty-device-config-overview.md).
23
+
The list shows the versions that we tested. If the OS version for your VPN device isn't on the list, it still might be compatible. Check with your device manufacturer.
24
+
25
+
- For basic information about VPN device configuration, see [Overview of partner VPN device configurations](../articles/vpn-gateway/vpn-gateway-3rdparty-device-config-overview.md).
25
26
26
27
- For information about editing device configuration samples, see [Editing samples](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#editing).
27
28
28
29
- For cryptographic requirements, see [About cryptographic requirements and Azure VPN gateways](../articles/vpn-gateway/vpn-gateway-about-compliance-crypto.md).
29
30
30
-
- For information about IPsec/IKE parameters, see [About VPN devices and IPsec/IKE parameters for Site-to-Site VPN gateway connections](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#ipsec). This link shows information about IKE version, Diffie-Hellman Group, Authentication method, encryption and hashing algorithms, SA lifetime, PFS, and DPD, in addition to other parameter information that you need to complete your configuration.
31
+
- For information about parameters that you need to complete your configuration, see [Default IPsec/IKE parameters](../articles/vpn-gateway/vpn-gateway-about-vpn-devices.md#ipsec). The information includes IKE version, Diffie-Hellman (DH) group, authentication method, encryption and hashing algorithms, security association (SA) lifetime, perfect forward secrecy (PFS), and Dead Peer Detection (DPD).
31
32
32
-
- For IPsec/IKE policy configuration steps, see [Configure IPsec/IKE policy for S2S VPN or VNet-to-VNet connections](../articles/vpn-gateway/vpn-gateway-ipsecikepolicy-rm-powershell.md).
33
+
- For IPsec/IKE policy configuration steps, see [Configure custom IPsec/IKE connection policies for S2S VPN and VNet-to-VNet](../articles/vpn-gateway/vpn-gateway-ipsecikepolicy-rm-powershell.md).
33
34
34
-
- To connect multiple policy-based VPN devices, see [Connect Azure VPN gateways to multiple on-premises policy-based VPN devices using PowerShell](../articles/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps.md).
35
+
- To connect multiple policy-based VPN devices, see [Connect a VPN gateway to multiple on-premises policy-based VPN devices](../articles/vpn-gateway/vpn-gateway-connect-multiple-policybased-rm-ps.md).
If you're having trouble connecting to a virtual machine over your VPN connection, check the following items:
13
13
14
14
* Verify that your VPN connection is successful.
15
15
* Verify that you're connecting to the private IP address for the VM.
16
-
* If you can connect to the VM using the private IP address, but not the computer name, verify that you have configured DNS properly. For more information about how name resolution works for VMs, see [Name Resolution for VMs](../articles/virtual-network/virtual-networks-name-resolution-for-vms-and-role-instances.md).
16
+
* If you can connect to the VM by using the private IP address but not the computer name, verify that you configured DNS properly. For more information about how name resolution works for VMs, see [Name resolution for resources in Azure virtual networks](../articles/virtual-network/virtual-networks-name-resolution-for-vms-and-role-instances.md).
17
17
18
-
When you connect over Point-to-Site, check the following additional items:
18
+
When you connect over point-to-site, check the following additional items:
19
19
20
-
* Use 'ipconfig' to check the IPv4 address assigned to the Ethernet adapter on the computer from which you're connecting. If the IP address is within the address range of the virtual network that you're connecting to, or within the address range of your VPNClientAddressPool, this is referred to as an overlapping address space. When your address space overlaps in this way, the network traffic doesn't reach Azure, it stays on the local network.
21
-
* Verify that the VPN client configuration package was generated after the DNS server IP addresses were specified for the virtual network. If you updated the DNS server IP addresses, generate and install a new VPN client configuration package.
20
+
* Use `ipconfig` to check the IPv4 address assigned to the Ethernet adapter on the computer from which you're connecting. If the IP address is within the address range of the virtual network that you're connecting to, or within the address range of your VPN client address pool, it's an overlapping address space. When your address space overlaps in this way, the network traffic doesn't reach Azure. It stays on the local network.
21
+
* Verify that the VPN client configuration package was generated after you specified the DNS server IP addresses for the virtual network. If you updated the DNS server IP addresses, generate and install a new VPN client configuration package.
22
22
23
-
For more information about troubleshooting an RDP connection, see [Troubleshoot Remote Desktop connections to a VM](/troubleshoot/azure/virtual-machines/troubleshoot-rdp-connection).
23
+
For more information about troubleshooting an RDP connection, see [Troubleshoot Remote Desktop connections to a VM](/troubleshoot/azure/virtual-machines/troubleshoot-rdp-connection).
Copy file name to clipboardExpand all lines: includes/vpn-gateway-customer-controlled-gateway-maintenance-faq.md
+24-24Lines changed: 24 additions & 24 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,57 +9,57 @@ ms.topic: include
9
9
10
10
---
11
11
12
-
### Which services are included in the Maintenance Configuration scope of Network Gateways?
12
+
### Which services are included in maintenance configuration for the Network Gateways scope?
13
13
14
-
The Network Gateways scope includes gateway resources in Networking services. There are four types of resources in the Network Gateways scope:
14
+
The Network Gateways scope includes gateway resources in networking services. There are four types of resources in the Network Gateways scope:
15
15
16
-
* Virtual network gateway in the ExpressRoute service.
17
-
* Virtual network gateway in the VPN Gateway service.
18
-
* VPN gateway (Site-to-Site) in the Virtual WAN service.
19
-
* ExpressRoute gateway in the Virtual WAN service.
16
+
* Virtual network gateway in the ExpressRoute service
17
+
* Virtual network gateway in the VPN Gateway service
18
+
* VPN gateway (site-to-site) in the Azure Virtual WAN service
19
+
* ExpressRoute gateway in the Virtual WAN service
20
20
21
-
### Which maintenance is supported or not supported by customer-controlled maintenance?
21
+
### Which maintenance does customer-controlled maintenance support?
22
22
23
-
Azure services go through periodic maintenance updates to improve functionality, reliability, performance, and security. Once you configure a maintenance window for your resources, Guest OS and Service maintenance are performed during that window. Host updates, beyond the host updates (TOR, Power etc.) and critical security updates, aren't covered by the customer-controlled maintenance.
23
+
Azure services go through periodic maintenance updates to improve functionality, reliability, performance, and security. After you configure a maintenance window for your resources, guest OS maintenance and service maintenance are performed during that window. Customer-controlled maintenance doesn't cover host updates (beyond the host updates for Power, for example) and critical security updates.
24
24
25
25
### Can I get advanced notification of the maintenance?
26
26
27
-
At this time, advanced notification can't be enabled for the maintenance of Network Gateway resources.
27
+
At this time, you can't get advanced notification for the maintenance of Network Gateway REST API resources.
28
28
29
29
### Can I configure a maintenance window shorter than five hours?
30
30
31
-
At this time, you need to configure a minimum of a fivehour window in your preferred time zone.
31
+
At this time, you need to configure a minimum of a five-hour window in your preferred time zone.
32
32
33
-
### Can I configure a maintenance window other than Daily schedule?
33
+
### Can I configure a maintenance window other than a daily schedule?
34
34
35
35
At this time, you need to configure a daily maintenance window.
36
36
37
-
### Are there cases where I can’t control certain updates?
37
+
### Are there cases where I can't control certain updates?
38
38
39
-
Customer-controlled maintenance supports Guest OS and Service updates. These updates account for most of the maintenance items that cause concern for the customers. Some other types of updates, including Host updates, are outside of the scope of customer-controlled maintenance.
39
+
Customer-controlled maintenance supports guest OS and service updates. These updates account for most of the maintenance items that cause concern for customers. Some other types of updates, including host updates, are outside the scope of customer-controlled maintenance.
40
40
41
-
Additionally, if there's a high-severity security issue that might endanger our customers, Azure might need to override customer control of the maintenance window and push the change. These are rare occurrences that would only be used in extreme cases.
41
+
If a high-severity security issue might endanger customers, Azure might need to override customer control of the maintenance window and push a change. These changes are rare occurrences that we use only in extreme cases.
42
42
43
-
### Do Maintenance Configuration resources need to be in the same region as the gateway resource?
43
+
### Do maintenance configuration resources need to be in the same region as the gateway resource?
44
44
45
-
Yes
45
+
Yes.
46
46
47
-
### Which gateway SKUs can be configured to use customer-controlled maintenance?
47
+
### Which gateway SKUs can I configure to use customer-controlled maintenance?
48
48
49
-
All gateway SKUs (except the Basic SKU for VPN Gateway) can be configured to use customer-controlled maintenance.
49
+
All the Azure VPN Gateway SKUs (except the Basic SKU) can be configured to use customer-controlled maintenance.
50
50
51
-
### How long does it take for maintenance configuration policy to become effective after it gets assigned to the gateway resource?
51
+
### How long does it take for a maintenance configuration policy to become effective after it's assigned to the gateway resource?
52
52
53
53
It might take up to 24 hours for Network Gateways to follow the maintenance schedule after the maintenance policy is associated with the gateway resource.
54
54
55
-
### Are there any limitations on using customer-controlled maintenance based on the Basic SKU Public IP address?
55
+
### Are there any limitations on using customer-controlled maintenance based on the Basic SKU public IP address?
56
56
57
-
Yes. Gateway resources that use a Basic SKU Public IP address will only be able to have service updates following the customer-controlled maintenance schedule. For these gateways, Guest OS maintenance does NOT follow the customer-controlled maintenance schedule due to infrastructure limitations.
57
+
Yes. Customer-controlled maintenance doesn't work for resources that use Basic SKU public IP addresses, except in the case of service updates. For these gateways, guest OS maintenance does *not* follow the customer-controlled maintenance schedule because of infrastructure limitations.
58
58
59
59
### How should I plan maintenance windows when using VPN and ExpressRoute in a coexistence scenario?
60
60
61
-
When working with VPN and ExpressRoute in a coexistence scenario or whenever you have resources acting as backups, we recommend setting up separate maintenance windows. This approach ensures that maintenance doesn't affect your backup resources at the same time.
61
+
When you work with VPN and ExpressRoute in a coexistence scenario or whenever you have resources that act as backups, we recommend setting up separate maintenance windows. This approach ensures that maintenance doesn't affect your backup resources at the same time.
62
62
63
-
### I've scheduled a maintenance window for a future date for one of my resources. Will maintenance activities be paused on this resource until then?
63
+
### I scheduled a maintenance window for a future date for one of my resources. Are maintenance activities paused on this resource until then?
64
64
65
-
No, maintenance activities won't be paused on your resource during the period before the scheduled maintenance window. For the days not covered in your maintenance schedule, maintenance continues as usual on the resource.
65
+
No, maintenance activities aren't paused on your resource during the period before the scheduled maintenance window. For the days not covered in your maintenance schedule, maintenance continues as usual on the resource.
0 commit comments