Is it possible to downgrade the SKU on-the-fly for the Azure VPN Gateway after deployment anytime?

Rajesh Swarnkar 931 Reputation points
2025-12-04T08:35:08.3933333+00:00

Hi, Is it possible to downgrade the SKU on-the-fly for the Azure VPN Gateway after deployment anytime? E.g. from VpnGw4AZ to VpnGw2AZ or VpnGw2?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
0 comments No comments
{count} votes

Answer recommended by moderator
  1. Q&A Assist
    2025-12-04T08:35:18.2966667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    No, it is not possible to downgrade the SKU on-the-fly for the Azure VPN Gateway after deployment. You can only upgrade your gateway to a gateway SKU within the same SKU family, and downgrading requires deleting the existing gateway and creating a new one. This process incurs downtime and changes the public IP address assigned to your gateway SKU, even if you specify the same public IP address object used previously.


    References:

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Thanmayi Godithi 2,455 Reputation points Microsoft External Staff Moderator
    2025-12-12T04:02:19.2966667+00:00

    Hey @Rajesh Swarnkar,

    It sounds like you're looking to downgrade the SKU of your Azure VPN Gateway after deployment. Unfortunately, downgrading a VPN Gateway SKU isn't as straightforward as upgrading. Here's what you need to know:

    1. Downgrades Not Allowed On-the-Fly: You cannot downgrade the SKU from, for example, VpnGw4AZ to VpnGw2AZ or VpnGw2 without performing a deletion and creation of the gateway. The Azure infrastructure does not support on-the-fly downgrades.
    2. Process:
      • Delete the existing VPN Gateway: Before creating a new one, you need to remove any existing connections to the current gateway.
      • Create a new VPN Gateway: After deletion, you can create a new VPN gateway with the desired SKU.
      • Public IP Change: Keep in mind that this process will change the public IP address assigned to your new gateway, and you'll have to reconfigure your VPN settings accordingly.

    This process does incur downtime, so you'll want to plan for that during a maintenance window. Here’s a brief overview of the steps you’ll take:

    1. Remove connections to the virtual network gateway.
    2. Delete the old VPN gateway.
    3. Create the new VPN gateway with the desired SKU.
    4. Update any configurations for your VPN devices and clients as needed.

    For more detailed instructions on upgrading and downgrading VPN Gateway SKUs, check out the following resources:

    Hope this helps you with your Azure VPN setup! If you have any more questions or need clarification, feel free to ask.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.