> Source: [sk101275](https://support.checkpoint.com/results/sk/sk101275)

# sk101275 - How to setup Site-to-Site VPN between Microsoft Azure and an on premises Check Point Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk101275 |
| Date Created | 2014-06-14 |
| Last Modified | 2026-06-10 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| Platform | Azure |

## Solution

This article deals with setting up a VPN tunnel between Microsoft Azure and an on-premises Check Point Security Gateway. If you are interested in setting up a VPN tunnel between a **Check Point Security Gateway in Azure** and an on-premises Check Point Security Gateway, refer to [sk109360 - Check Point Reference Architecture for Azure](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109360).

For a detailed walk through on setting up a Site-to-Site VPN, refer to [sk53980 - How to set up a Site-to-Site VPN with a 3rd-party remote gateway](http://supportcontent.checkpoint.com/solutions?id=sk53980).

The setting on the tables below contain the combinations of algorithms and parameters Azure VPN gateways use in default configuration (Default policies). For route-based VPN gateways created using the Azure Resource Management deployment model, you can specify a custom policy on each individual connection. Refer to [Configure IPsec/IKE policy](https://learn.microsoft.com/en-gb/azure/vpn-gateway/vpn-gateway-ipsecikepolicy-rm-powershell) for detailed instructions.   

For more information on IPsec/IKE parameters for Site-to-Site VPN Gateway connections, refer to [Microsoft Azure Documentation](https://learn.microsoft.com/en-us/azure/vpn-gateway/ipsec-ike-policy-howto).

**Notes:**

* While establishing a VPN with Microsoft Azure VPN Gateway, Check Point recommends configuring the VPN using Domain Based VPN
* Refer to <https://docs.microsoft.com/en-gb/azure/vpn-gateway/vpn-gateway-about-vpn-devices>
* For information about TCP MSS clamping, also refer to <https://docs.microsoft.com/en-gb/azure/vpn-gateway/vpn-gateway-about-vpn-devices>
* You can do VPN with Azure using some SMB appliances (R77.20.87 jumbo hotfix and newer 1500 Branch Office Appliances).
* For a discussion of this topic on Checkmates, click [here](https://community.checkpoint.com/t5/Security-Gateways/Azure-Site-to-Site-VPn-fail/td-p/16102).

**IKE Phase 1 setup**

|---------------------------------------------------|------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Property                                          | Static routing (PolicyBased) VPN gateway | Dynamic routing (RouteBased) VPN gateway                                                                                                                                              |
| IKE Version                                       | IKEv1                                    | IKEv2                                                                                                                                                                                 |
| Diffie-Hellman Group                              | Group 15 (3072 bit)                      | Group 15 (3072 bit)                                                                                                                                                                   |
| Authentication Method                             | Pre-Shared Key                           | Pre-Shared Key                                                                                                                                                                        |
| Encryption Algorithms                             | AES256 AES128 3DES                       | AES256 AES128 3DES                                                                                                                                                                    |
| Data Integrity Algorithm                          | SHA256                                   | SHA256                                                                                                                                                                                |
| Phase 1 Security Association (SA) Lifetime (Time) | 28,800 seconds (480 minutes)             | 28,800 seconds (480 minutes) Refer to [About VPN devices for Site-to-Site VPN Gateway connections](https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices) |

**IKE Phase 2 setup**

|---------------------------------------------------------------------------|------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Property                                                                  | Static routing (PolicyBased) VPN gateway | Dynamic routing (RouteBased) VPN gateway                                                                                                                                                                                                                                                                                                                 |
| IKE Version                                                               | IKEv1                                    | IKEv2                                                                                                                                                                                                                                                                                                                                                    |
| Data Integrity Algorithm                                                  | SHA256                                   | SHA256                                                                                                                                                                                                                                                                                                                                                   |
| Phase 2 Security Association (SA) Lifetime (Time)                         | 3,600 seconds (60 minutes)               | 27,000 seconds (450 minutes)                                                                                                                                                                                                                                                                                                                             |
| IPsec SA Encryption \& Authentication Offers (in the order of preference) | ESP-AES256 ESP-AES128 ESP-3DES           | Refer to [Dynamic Routing Gateway](https://azure.microsoft.com/en-gb/documentation/articles/vpn-gateway-about-vpn-devices/) [IPsec Security Association](https://azure.microsoft.com/en-gb/documentation/articles/vpn-gateway-about-vpn-devices/) [(SA) Offers](https://azure.microsoft.com/en-gb/documentation/articles/vpn-gateway-about-vpn-devices/) |
| Perfect Forward Secrecy (PFS)                                             | No                                       | No                                                                                                                                                                                                                                                                                                                                                       |
| Dead Peer Detection                                                       | Not supported                            | Supported                                                                                                                                                                                                                                                                                                                                                |

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk101275/VPN202410301819051.png)

**Notes:**

* To configure Phase 2 properties for IKEv1 and IKEv2 in Check Point SmartConsole: go to *IPSec VPN* tab - double-click on the relevant VPN Community - go to the *Encryption* page - in the section *Encryption Suite* , select *Custom* - click on *Custom Encryption...* button - configure the relevant properties - click on *OK* to apply the settings - install the policy.  

* When setting up a Site-to-Site VPN with Azure, you will need to see if Azure is offering subnet-to-subnet or gateway-to-gateway VPN:

  * If Azure is using ***subnet-to-subnet*** , then Check Point side must be configured in the following way in Check Point SmartConsole: go to *IPSec VPN* tab - double-click on the relevant VPN Community - go to the *Tunnel Management* page - in the section *VPN Tunnel Sharing* , select ***One VPN tunnel per subnet pair*** - click on *OK* to apply the settings - install the policy.  

  * If Azure is using ***gateway-to-gateway*** , then Check Point side must be configured in the following way in Check Point SmartConsole: go to *IPSec VPN* tab - double-click on the relevant VPN Community - go to the 'Tunnel Management' page - in the section *VPN Tunnel Sharing* , select ***One VPN tunnel per Gateway pair*** - click on *OK* to apply the settings - install the policy.  

  * The ***subnet-to-subnet*** is what Azure calls "policy-based VPN" and ***gateway-to-gateway*** is what Azure calls "route-based VPN". This should help customers identify what they have on Azure against what they need to configure on the Check Point device.  

  * Also, when using ***subnet-to-subnet,***users can define one or more address prefixes to use in their virtual network, and then carve out multiple subnets within each prefix. Azure VPN in policy-based configuration will use the prefix pairs for the Traffic Selectors for the SA negotiation, not subnet ranges.

  <br />

  <br />

* Selecting ***Set Permanent Tunnels*** on the Tunnel Management page is supported.  

  You can configure permanent tunnels using two primary methods: **DPD (Dead Peer Detection)** or **Tunnel Test** .  

  Tunnel Test is a Check Point proprietary mechanism and is supported only when the Azure Gateway is a Check Point device. In such cases, you can use this method.  

  In all other scenarios, you must configure DPD.  

* Make sure the Networks in the respective encryption domains correspond to the settings configured at the Azure side (you may use the setting ***subnet_for_range_and_peer*** to make sure the subnets are negotiated as required - for details, refer to "*Scenario 1* " in [sk108600 - VPN Site-to-Site with 3rd party](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600#Scenario 1)).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
