The Local Network Gateway Isn't a Gateway: Azure Hybrid Networking Terms
▶ Watch on YouTube & subscribe to The Stack Underflow
A VPN gateway and a local network gateway. A peering location and an Azure region. Hybrid networking leans on words that are easy to mix up. This primer explains each one, with a memory peg, before the hybrid video uses them. The running example is the hybrid video’s network: app-1 (10.20.4.25) in the virtual network orders-vnet (10.20.0.0/16) sends a packet to a server in the office (10.30.5.10, in 10.30.0.0/16), through a site-to-site VPN or through ExpressRoute.
The one-line version: of GatewaySubnet, the VPN gateway and the local network gateway, only the VPN gateway is a gateway. GatewaySubnet is where Azure’s gateways live, and the local network gateway is Azure’s record of your office.
Last verified against Microsoft Learn and the IETF RFCs: 5 October 2026. Every claim links to its source at the bottom of the page.
One picture: a city and its ways out
Every word gets a memory peg from one picture: your virtual network is a city, and the office is a town it needs to reach. The pegs are an analogy, a teaching aid for roles, not a map of the real topology. Where one breaks, the table says so.
Inside Azure: the gateway components
| Word | Memory peg | What it actually is |
|---|---|---|
| GatewaySubnet | The intercity terminal | The subnet where Azure puts its virtual network gateways (VPN or ExpressRoute). It must have exactly that name. For non-Basic gateways, /27 is the platform minimum; only the Basic SKU allows /29. If a VPN gateway and an ExpressRoute gateway will coexist, Microsoft’s hybrid design guide recommends planning a /26. |
| VPN gateway | The armored-van depot | Sends traffic between your virtual network and your office through an IPsec/IKE tunnel over the public internet. It sits in GatewaySubnet. New VPN gateways need a Standard public IP, and Microsoft recommends the AZ SKUs for new deployments. |
| Local network gateway | The town’s address card | Not a physical gateway in your office. It’s an Azure configuration object, Azure’s record of your site: the public IP address or FQDN of your VPN device, and the address prefixes behind it (here 10.30.0.0/16), or BGP settings instead. |
| Connection | The signed agreement | Ties the VPN gateway to the local network gateway and holds the tunnel settings. In this setup, a pre-shared key authenticates the site-to-site VPN; certificate authentication also exists. |
The trap: three names so far contain “gateway”, but only the VPN gateway is an actual gateway. GatewaySubnet is the space it lives in; the local network gateway is a description.
| Word | Memory peg | What it actually is |
|---|---|---|
| ExpressRoute gateway | The private rail station | Also in GatewaySubnet. It connects your virtual network to an ExpressRoute circuit: private connectivity into Microsoft’s network that doesn’t use the public internet. You reach it through a connectivity provider or, with ExpressRoute Direct, on your own ports at Microsoft’s edge. |
Site-to-site VPN: IPsec, IKE and CPE
| Word | Memory peg | What it actually is |
|---|---|---|
| IPsec | The sealed armored van | Gives IP packets confidentiality (encryption keeps their contents from eavesdroppers) and integrity (tampering is detected). The VPN gateway wraps each packet in IPsec before it crosses the public internet. The road is public; the cargo isn’t. |
| IKE | The key handover | The Internet Key Exchange authenticates the two peers and negotiates the security associations and key material that IPsec then uses. In a pre-shared-key setup, that key helps the two VPN devices prove who they are. For the route-based setup in the hybrid video, think IKE version 2. |
| CPE (the office VPN device) | The town’s gate guard | Customer premises equipment: the networking equipment on your side (a general networking term, not an Azure one). Here it’s the router or firewall that ends the VPN, unwraps the packet and passes it on to the server. It needs a reachable public IPv4 endpoint, and it can sit behind NAT if it starts the tunnel. |
ExpressRoute: peering locations, MSEEs and providers
The private railway is a memory aid too: it doesn’t mean Microsoft runs a dedicated fiber from your office to Azure.
| Word | Memory peg | What it actually is |
|---|---|---|
| Peering location | The interchange station | The facility where your network, or your connectivity provider’s, connects to Microsoft’s edge, for example Amsterdam. A circuit is mapped to one. It is not an Azure region: from Amsterdam you reach regions such as North and West Europe. For maximum resiliency, Microsoft recommends two circuits in two peering locations. |
| MSEE | Two open platforms | Microsoft Enterprise Edge router. Each ExpressRoute circuit has two redundant connections to two MSEEs, and Microsoft runs both active-active, so different flows can use either. If one fails, the circuit stays up. Where the peg breaks: the second path’s spare capacity isn’t guaranteed, so don’t size a design on it as permanent extra bandwidth. |
| Circuit and connectivity provider | Your reserved service | The ExpressRoute circuit is a logical connection with a fixed bandwidth. In the provider model, your connectivity provider gets you to the peering location, and circuits run from 50 Mbps to 10 Gbps. With ExpressRoute Direct, circuits sit on your own port pair at Microsoft’s edge. Private means it avoids the public internet; it doesn’t mean encrypted: ExpressRoute isn’t encrypted by default. |
| MPLS, IPVPN | The provider’s private rail network | MPLS forwards packets by label inside a provider’s network, and many carriers use it to build private layer-3 services such as BGP/MPLS IP VPNs. With ExpressRoute’s any-to-any (IPVPN) model, such a provider WAN can bring in Microsoft’s cloud, so Azure acts like another site on it. MPLS gives routing and isolation, not IPsec encryption. And MPLS is not ExpressRoute. |
ExpressRoute has four connectivity models: provider Ethernet (point-to-point), MPLS/IPVPN (any-to-any), colocation, and ExpressRoute Direct. MPLS is one option, not part of every ExpressRoute path.
Routing: BGP
| Word | Memory peg | What it actually is |
|---|---|---|
| BGP | The timetable exchange | The Border Gateway Protocol: how networks tell each other which address prefixes they can reach. Over ExpressRoute, your routers and the MSEEs exchange routes with BGP. A VPN can use BGP too, or the local network gateway’s prefixes. |
By default, routes learned by a virtual network gateway show up in every subnet’s effective routes with source “Virtual network gateway”. A subnet’s route table can turn that propagation off. Gateways and rails are useless until each side knows which destinations the other can reach.
The whole map
- Inside Azure: GatewaySubnet with its two gateways, the local network gateway and the connection.
- On the public road: the IPsec tunnel to the office’s CPE.
- On the ExpressRoute path: the MSEEs at the peering location, and your connectivity model: a provider Ethernet service, an MPLS IPVPN, colocation, or ExpressRoute Direct.
- Everywhere: BGP, telling both sides the routes.
Pause & Prove
1. The pinned question
Three of the names in this setup contain the word “gateway”: GatewaySubnet, the VPN gateway and the local network gateway. Which of them is an actual gateway, and what are the other two?
- GatewaySubnet. Not a gateway: it’s the subnet, the space where Azure’s virtual network gateways live.
- The VPN gateway. ✓ The only actual gateway: it sends your traffic to the office through an encrypted tunnel.
- The local network gateway. The tempting one. It isn’t a device at all: it’s Azure’s record of your site, with your VPN device’s address and the prefixes behind it.
2. The Community poll
Inside a provider’s network, what does MPLS give you?
- Encryption, like IPsec. The tempting one. MPLS doesn’t encrypt: BGP/MPLS IP VPNs “do not by themselves encrypt the data for privacy” (RFC 4364). Encryption is IPsec’s job.
- Routing and isolation. ✓ MPLS forwards packets by label inside the provider’s network, and carriers use it to build private layer-3 services.
- The ExpressRoute circuit itself. MPLS isn’t ExpressRoute. With the any-to-any (IPVPN) model, a provider’s MPLS network can bring in Microsoft’s cloud, but that’s one of four connectivity models, and the circuit is a logical connection mapped to a provider and a peering location.
- Public internet access. MPLS IP VPNs are private layer-3 services built inside the provider’s network, and ExpressRoute connections don’t go over the public internet.
3. Peg drill
Say the peg for each before reading on: GatewaySubnet, IPsec, IKE, local network gateway, MSEE, BGP.
Answers: GatewaySubnet is the intercity terminal. IPsec is the sealed armored van, and IKE is the key handover before the trip. The local network gateway is the town’s address card. The MSEEs are two open platforms at the interchange. BGP is the timetable exchange. MPLS may be part of a provider’s path, but it isn’t ExpressRoute.
Before / after this video
- Before: Azure CIDR & Subnets: Why You Can Use Only 251 of 256 IPs in a /24, where the same packet to
10.30.5.10is dropped by the10.0.0.0/8→ None route. - After: Why Your Azure VM Can’t Reach On-Premises: VPN vs ExpressRoute, Packet by Packet, the deep dive that uses every word on this page. It sends one packet from
app-1to the office four times: with no gateway, through the VPN, through ExpressRoute, and when ExpressRoute becomes unavailable and the VPN takes over as the backup.
Sources
Read on 4 October 2026, and on 5 October 2026 where noted:
- About VPN Gateway configuration settings: GatewaySubnet name,
/29only for Basic and/27or larger otherwise; the local network gateway describes your site (device address, prefixes or BGP settings) - Hybrid connectivity design guide:
/26suggested when VPN and ExpressRoute gateways coexist - What is Azure VPN Gateway?: site-to-site IPsec/IKE tunnel over the public internet; VPN gateway, Standard public IP, local network gateway and connection
- About gateway SKUs and gateway SKU consolidation: AZ SKUs recommended for new gateways
- Site-to-site certificate authentication (read 5 October): certificate authentication exists alongside the pre-shared key
- VPN Gateway FAQ: the on-premises device needs a public IPv4 address; NAT traversal works if the device starts the tunnel; IKEv2 on route-based gateways
- ExpressRoute connectivity models: not over the public internet; the four models; “IPVPN providers (typically MPLS VPN) offer any-to-any connectivity”
- ExpressRoute overview: two connections to two MSEEs, the secondary’s capacity isn’t guaranteed, two circuits in two peering locations for maximum resiliency, provider bandwidths; Amsterdam → North and West Europe (read 5 October)
- ExpressRoute circuits and peering (read 5 October): a circuit is a logical connection with a fixed bandwidth, mapped to a provider and a peering location
- About ExpressRoute Direct (read 5 October): circuits on your own port pair
- Designing for high availability with ExpressRoute (read 5 October): active-active, per-flow load balancing
- ExpressRoute encryption: not encrypted by default
- ExpressRoute routing requirements: BGP between your routers and the MSEEs
- Virtual network traffic routing: gateway-learned routes with source “Virtual network gateway”; propagation can be turned off on a route table
- IETF: RFC 4301 (IPsec), RFC 7296 (IKEv2), RFC 4271 (BGP), RFC 3031 (MPLS) and RFC 4364 (BGP/MPLS IP VPNs; section 1.6 read 5 October)
SKUs and limits change, so check the current pages.
Change notes
- 6 Oct 2026: first published.
Not affiliated with or endorsed by Microsoft. Azure is a trademark of Microsoft Corporation. Found a mistake? Tell us in the video’s comments and we’ll correct this page.
Found this useful? The deep version lives on YouTube — new breakdowns of how AI dev tools actually work, weekly.
Subscribe on YouTube →Prefer email? Get the free newsletter: one failure, traced step by step, about once a week.