The Local Network Gateway Isn't a Gateway: Azure Hybrid Networking Terms

October 6, 2026 · Azure Networking, Packet by Packet: NSGs, Route Tables, ASGs and Azure Firewall (part 5)

▶ Watch on YouTube & subscribe to The Stack Underflow

A VPN gateway and a local network gateway. A peering location and an Azure region. Hybrid networking leans on words that are easy to mix up. This primer explains each one, with a memory peg, before the hybrid video uses them. The running example is the hybrid video’s network: app-1 (10.20.4.25) in the virtual network orders-vnet (10.20.0.0/16) sends a packet to a server in the office (10.30.5.10, in 10.30.0.0/16), through a site-to-site VPN or through ExpressRoute.

The one-line version: of GatewaySubnet, the VPN gateway and the local network gateway, only the VPN gateway is a gateway. GatewaySubnet is where Azure’s gateways live, and the local network gateway is Azure’s record of your office.

Last verified against Microsoft Learn and the IETF RFCs: 5 October 2026. Every claim links to its source at the bottom of the page.

One picture: a city and its ways out

Every word gets a memory peg from one picture: your virtual network is a city, and the office is a town it needs to reach. The pegs are an analogy, a teaching aid for roles, not a map of the real topology. Where one breaks, the table says so.

Inside Azure: the gateway components

WordMemory pegWhat it actually is
GatewaySubnetThe intercity terminalThe subnet where Azure puts its virtual network gateways (VPN or ExpressRoute). It must have exactly that name. For non-Basic gateways, /27 is the platform minimum; only the Basic SKU allows /29. If a VPN gateway and an ExpressRoute gateway will coexist, Microsoft’s hybrid design guide recommends planning a /26.
VPN gatewayThe armored-van depotSends traffic between your virtual network and your office through an IPsec/IKE tunnel over the public internet. It sits in GatewaySubnet. New VPN gateways need a Standard public IP, and Microsoft recommends the AZ SKUs for new deployments.
Local network gatewayThe town’s address cardNot a physical gateway in your office. It’s an Azure configuration object, Azure’s record of your site: the public IP address or FQDN of your VPN device, and the address prefixes behind it (here 10.30.0.0/16), or BGP settings instead.
ConnectionThe signed agreementTies the VPN gateway to the local network gateway and holds the tunnel settings. In this setup, a pre-shared key authenticates the site-to-site VPN; certificate authentication also exists.

The trap: three names so far contain “gateway”, but only the VPN gateway is an actual gateway. GatewaySubnet is the space it lives in; the local network gateway is a description.

WordMemory pegWhat it actually is
ExpressRoute gatewayThe private rail stationAlso in GatewaySubnet. It connects your virtual network to an ExpressRoute circuit: private connectivity into Microsoft’s network that doesn’t use the public internet. You reach it through a connectivity provider or, with ExpressRoute Direct, on your own ports at Microsoft’s edge.

Site-to-site VPN: IPsec, IKE and CPE

WordMemory pegWhat it actually is
IPsecThe sealed armored vanGives IP packets confidentiality (encryption keeps their contents from eavesdroppers) and integrity (tampering is detected). The VPN gateway wraps each packet in IPsec before it crosses the public internet. The road is public; the cargo isn’t.
IKEThe key handoverThe Internet Key Exchange authenticates the two peers and negotiates the security associations and key material that IPsec then uses. In a pre-shared-key setup, that key helps the two VPN devices prove who they are. For the route-based setup in the hybrid video, think IKE version 2.
CPE (the office VPN device)The town’s gate guardCustomer premises equipment: the networking equipment on your side (a general networking term, not an Azure one). Here it’s the router or firewall that ends the VPN, unwraps the packet and passes it on to the server. It needs a reachable public IPv4 endpoint, and it can sit behind NAT if it starts the tunnel.

ExpressRoute: peering locations, MSEEs and providers

The private railway is a memory aid too: it doesn’t mean Microsoft runs a dedicated fiber from your office to Azure.

WordMemory pegWhat it actually is
Peering locationThe interchange stationThe facility where your network, or your connectivity provider’s, connects to Microsoft’s edge, for example Amsterdam. A circuit is mapped to one. It is not an Azure region: from Amsterdam you reach regions such as North and West Europe. For maximum resiliency, Microsoft recommends two circuits in two peering locations.
MSEETwo open platformsMicrosoft Enterprise Edge router. Each ExpressRoute circuit has two redundant connections to two MSEEs, and Microsoft runs both active-active, so different flows can use either. If one fails, the circuit stays up. Where the peg breaks: the second path’s spare capacity isn’t guaranteed, so don’t size a design on it as permanent extra bandwidth.
Circuit and connectivity providerYour reserved serviceThe ExpressRoute circuit is a logical connection with a fixed bandwidth. In the provider model, your connectivity provider gets you to the peering location, and circuits run from 50 Mbps to 10 Gbps. With ExpressRoute Direct, circuits sit on your own port pair at Microsoft’s edge. Private means it avoids the public internet; it doesn’t mean encrypted: ExpressRoute isn’t encrypted by default.
MPLS, IPVPNThe provider’s private rail networkMPLS forwards packets by label inside a provider’s network, and many carriers use it to build private layer-3 services such as BGP/MPLS IP VPNs. With ExpressRoute’s any-to-any (IPVPN) model, such a provider WAN can bring in Microsoft’s cloud, so Azure acts like another site on it. MPLS gives routing and isolation, not IPsec encryption. And MPLS is not ExpressRoute.

ExpressRoute has four connectivity models: provider Ethernet (point-to-point), MPLS/IPVPN (any-to-any), colocation, and ExpressRoute Direct. MPLS is one option, not part of every ExpressRoute path.

Routing: BGP

WordMemory pegWhat it actually is
BGPThe timetable exchangeThe Border Gateway Protocol: how networks tell each other which address prefixes they can reach. Over ExpressRoute, your routers and the MSEEs exchange routes with BGP. A VPN can use BGP too, or the local network gateway’s prefixes.

By default, routes learned by a virtual network gateway show up in every subnet’s effective routes with source “Virtual network gateway”. A subnet’s route table can turn that propagation off. Gateways and rails are useless until each side knows which destinations the other can reach.

The whole map

  • Inside Azure: GatewaySubnet with its two gateways, the local network gateway and the connection.
  • On the public road: the IPsec tunnel to the office’s CPE.
  • On the ExpressRoute path: the MSEEs at the peering location, and your connectivity model: a provider Ethernet service, an MPLS IPVPN, colocation, or ExpressRoute Direct.
  • Everywhere: BGP, telling both sides the routes.

Pause & Prove

1. The pinned question

Three of the names in this setup contain the word “gateway”: GatewaySubnet, the VPN gateway and the local network gateway. Which of them is an actual gateway, and what are the other two?

  • GatewaySubnet. Not a gateway: it’s the subnet, the space where Azure’s virtual network gateways live.
  • The VPN gateway. ✓ The only actual gateway: it sends your traffic to the office through an encrypted tunnel.
  • The local network gateway. The tempting one. It isn’t a device at all: it’s Azure’s record of your site, with your VPN device’s address and the prefixes behind it.

2. The Community poll

Inside a provider’s network, what does MPLS give you?

  • Encryption, like IPsec. The tempting one. MPLS doesn’t encrypt: BGP/MPLS IP VPNs “do not by themselves encrypt the data for privacy” (RFC 4364). Encryption is IPsec’s job.
  • Routing and isolation. ✓ MPLS forwards packets by label inside the provider’s network, and carriers use it to build private layer-3 services.
  • The ExpressRoute circuit itself. MPLS isn’t ExpressRoute. With the any-to-any (IPVPN) model, a provider’s MPLS network can bring in Microsoft’s cloud, but that’s one of four connectivity models, and the circuit is a logical connection mapped to a provider and a peering location.
  • Public internet access. MPLS IP VPNs are private layer-3 services built inside the provider’s network, and ExpressRoute connections don’t go over the public internet.

3. Peg drill

Say the peg for each before reading on: GatewaySubnet, IPsec, IKE, local network gateway, MSEE, BGP.

Answers: GatewaySubnet is the intercity terminal. IPsec is the sealed armored van, and IKE is the key handover before the trip. The local network gateway is the town’s address card. The MSEEs are two open platforms at the interchange. BGP is the timetable exchange. MPLS may be part of a provider’s path, but it isn’t ExpressRoute.

Before / after this video

Sources

Read on 4 October 2026, and on 5 October 2026 where noted:

SKUs and limits change, so check the current pages.

Change notes

  • 6 Oct 2026: first published.

Not affiliated with or endorsed by Microsoft. Azure is a trademark of Microsoft Corporation. Found a mistake? Tell us in the video’s comments and we’ll correct this page.

Found this useful? The deep version lives on YouTube — new breakdowns of how AI dev tools actually work, weekly.

Subscribe on YouTube →

Prefer email? Get the free newsletter: one failure, traced step by step, about once a week.