Deploying Virtual Gateways in Microsoft Azure

Virtual Gateways (VGWs) simplify branch network deployments for organizations intending to migrate their infrastructure to cloud providers such as Microsoft Azure.

Integrating EdgeConnect SD-Branch with a private cloud infrastructure hosted in Microsoft Azure allows you to set up a secure connection between the HPE Aruba Networking Branch Gateways and the Virtual Network (VNET) environments in Microsoft Azure.

HPE Aruba Networking Branch Gateway supports standard IPsec tunnels, and establishes direct communication with the Azure VPN Virtual Private Network. VPN enables secure access to a corporate network when located remotely. It enables a computer to send and receive data across shared or public networks as if it were directly connected to the private network, while benefiting from the functionality, security, and management policies of the private network. This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two. Gateway.

Classic Central supports deploying and managing VGWs hosted on the Microsoft Azure VNETs using one of the following methods:

  • Orchestrated mode—In the orchestrated mode, Classic Central allows administrators to deploy Virtual Gateways using the orchestrator application in Classic Central. The Virtual Gateway orchestrator in Classic Central imports VNETs from a Microsoft Azure account, deploys, connects, and allows you to manage Virtual Gateways from Classic Central. For step-by-step instructions on deploying Virtual Gateways in the managed mode, see Deploying Virtual Gateway in Microsoft Azure (Orchestrated Mode).
  • Manual mode—In the manual mode, Virtual Gateways must be manually deployed and launched from the cloud provider console. Classic Central allows you to generate user data for such deployments and manage Virtual Gateways from Classic Central. For step-by-step instructions on deploying Virtual Gateway in manual mode, see Deploying Virtual Gateway in Microsoft Azure (Manual Mode).

Starting with AOS 10.5.0.0, downgrading to AOS 10.4.x is not supported.

Virtual Gateway Sizing

HPE Aruba Networking Virtual Gateway requires the use of a supported Azure instance with a minimum of 500 Mbps of throughput. This table lists out the supported Azure instances for each HPE Aruba Networking Model:

Model(SKU Name)

Throughput

Supported Azure Instance

vCPU

Disk Size (GB)

Tunnels

VGW-500MB

500 Mbps

Standard_DS3_v2

4

16

512

Standard_F8s_v2

8

32

Standard_F16s_v2

16

64

VGW-2GB

2 Gbps Gigabits per second.

Standard_F8s_v2

8

32

4096

Standard_F16s_v2

16

64

VGW-4GB

4 Gbps

Standard_F16s_v2

16

64

8192

If a higher number of tunnels are required, contact your HPE Aruba Networking Sales Specialist.

Deployment Procedure

See the following topics for step-by-step instructions on how to deploy an HPE Aruba Networking Virtual Gateway in Microsoft Azure VNet:

Additional References

For a detailed description of SD-WAN Software-Defined Wide Area Network. SD-WAN is an application for applying SDN technology to WAN connections that connect enterprise networks across disparate geographical locations. integration with Microsoft Azure and Virtual Gateway deployment in Microsoft Azure, see the SD-WAN Integration with Microsoft Azure Public Cloud Technical Note.