Azure Point-to-Site VPN Gateway Monitoring
An Azure Point-to-Site (P2S) VPN Gateway enables individual remote clients to connect securely to Azure virtual networks over an encrypted tunnel. Hosted in an Azure Virtual WAN hub, it manages client authentication and routing for remote users.
Benefits of Azure Point-to-Site VPN monitoring
Site24x7 monitors P2S VPN Gateways to help you track active client connections, bandwidth consumption, and route distribution—giving you visibility into the health and capacity of your remote access infrastructure.
Setup and configuration
Adding an Azure P2S VPN Gateway monitor while configuring a new Azure monitor:
- Log in to your Site24x7 account.
- Go to Cloud > Azure > Add Azure Monitor .
- During Azure monitor configuration, on the Add Azure Monitor page, select Azure Point-to-Site VPN Gateway from the Service/Resource Types drop-down.
Adding an Azure P2S VPN Gateway monitor to an existing Azure monitor:
- Log in to your Site24x7 account.
- Go to Cloud > Azure , select your Azure monitor, then go to any of the dashboards on the left navigation bar of the page.
-
Click the hamburger
icon
and select Edit
to open the Edit Azure Monitor
page. - Select the relevant Subscriptions and Resource Groups , select Azure Point-to-Site VPN Gateway from the Service/Resource Types drop-down, and click Save .
After successful configuration, go to Cloud > Azure > Azure Monitor > Azure Point-to-Site VPN Gateway to view the discovered gateways.
It will take 15–30 minutes to discover new Azure resources. For immediate discovery, go to the Service View Dashboard of the Azure monitor and click Discover Now button on the top-right corner of the page.
Polling frequency
Site24x7 collects P2S VPN Gateway performance metrics every five minutes and displays the minute-by-minute status. The P2S Bandwidth and P2S Connection Count metrics are also available at one-minute granularity.
Performance metrics
|
Metric |
Description |
Statistic |
Unit |
|
P2S Bandwidth |
The average throughput of all active Point-to-Site (P2S) client connections through this gateway. A sustained high value approaching the gateway's scale unit limit indicates the need for capacity scaling. |
Average |
Bytes/sec |
|
P2S Connection Count |
The total number of active Point-to-Site client connections on this gateway. Use this to track remote user activity and plan gateway capacity based on peak connection demand. |
Total |
Count |
|
User VPN Route Count |
The total number of Point-to-Site User VPN routes currently distributed by this gateway to connected clients. A sudden change may indicate a routing configuration update or a BGP/static route propagation issue. |
Total |
Count |
Configuration attributes
The following attributes are collected when the configuration changes and are displayed in the Metadata tab:
|
Attribute |
Description |
|
Subscription |
The Azure subscription in which this P2S VPN Gateway is deployed. |
|
Resource Group |
The Azure resource group containing this gateway. |
|
Location |
The Azure region where this gateway is deployed. |
|
Name |
The display name of the P2S VPN Gateway resource. |
|
Provisioning State |
The current provisioning state of the gateway (for example, Succeeded , Updating , or Failed ). Alerts can be configured when this value changes. |
|
Virtual Hub |
The Azure Virtual WAN hub this P2S VPN Gateway is associated with. |
|
VPN Server Configuration |
The VPN server configuration resource associated with this gateway, which defines the authentication methods and client address pools. |
|
VPN Server Configuration Location |
The Azure region of the associated VPN server configuration resource. |
|
VPN Gateway Detach Status |
Indicates whether this gateway has been detached from its Virtual WAN hub. An alert is triggered by default when this value changes to Detached . |
|
VPN Gateway Scale Unit |
The scale unit size of this gateway, which determines its maximum throughput and connection capacity. Alerts can be configured when this value changes. |
|
VPN Client Address Prefixes |
The IP address ranges assigned to VPN clients upon connection. These prefixes are used for client-side routing. |
|
Routing Preference Internet |
Indicates whether internet routing preference is enabled for this gateway. Alerts can be configured when this setting changes. |
|
P2S Connection Configurations Count |
The number of P2S connection configurations defined on this gateway. |
|
Custom DNS Servers Count |
The number of custom DNS server entries configured for VPN clients connecting through this gateway. |
Threshold configuration
Global configuration
- In the Site24x7 web client, go to Admin > Configuration Profiles > Threshold and Availability (+) .
- Click Add Threshold Profile and select Azure Point-to-Site VPN Gateway as the Monitor Type .
- Set threshold values for any of the performance metrics listed above. All metrics support anomaly detection.
Monitor-level configuration
- Go to Cloud > Azure > Azure Monitor > Azure Point-to-Site VPN Gateway .
-
Select a resource, click the hamburger
icon
, and select Edit
. - Configure threshold values using the Threshold and Availability option and click Save .
The following configuration change alerts are also available:
- Provisioning State change: Alerts when the gateway provisioning state changes.
- VPN Gateway Detach Status change: Alerts by default when the gateway detach status changes to Detached , indicating the gateway has been disconnected from its Virtual WAN hub.
- VPN Gateway Scale Unit change: Alerts when the gateway capacity scale unit is modified.
- Routing Preference Internet change: Alerts when the internet tunneling preference setting is changed.
IT Automation
Site24x7 IT Automation allows you to define automated remediation actions that trigger on alert events for this monitor—for example, notifying a team channel or invoking a webhook when backup protection stops. How to configure IT Automation for a monitor .
Monitor data
The Summary tab displays performance data organized by time for the metrics listed above, with P2S Connection Count and P2S Bandwidth prominently featured.
To view the summary, go to Cloud > Azure > Azure Monitor > Azure Point-to-Site VPN Gateway > select a resource > click the Summary tab.
A Forecast tab is also available for all metrics, providing predictive trend analysis based on historical data.
Licensing
Each Azure Point-to-Site VPN Gateway monitor consumes one basic monitor license .
