An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
Hello @Chad Miller
Thank you for reaching out to Microsoft Q&A.
I understand your Site-to-Site VPN tunnel shows as Connected in Azure, the built-in troubleshooter reports everything healthy, and no changes were made on the Azure side, yet traffic has stopped flowing.
Since the tunnel is up, the IKE/IPsec negotiation is generally fine. The most likely causes at this point are routing, stale Security Associations (SAs), or traffic not hitting the tunnel correctly. Here are the recommended next steps on the Azure side to help rule it out confidently:
Quick Checks:
- Go to your Virtual Network Gateway > Connections, select the affected connection, and note the Data In and Data Out values. Try generating traffic from both sides and see if the counters increase.
- Review the Effective Routes on an Azure VM in the target subnet to confirm traffic to your on-premises address space is pointing to the Virtual Network Gateway.
Recommended Actions:
- Reset the VPN Connection: In the Azure portal, go to the Connection resource and click Reset. This clears the current IPsec SAs without restarting the entire gateway. Coordinate with your on-premises team to reset their side at the same time.
- If that doesn’t help, Reset the VPN Gateway itself (brief downtime). This often resolves stale tunnel issues.
- Enable/review Diagnostic Logs if not already done: Enable TunnelDiagnosticLog, IKEDiagnosticLog, and RouteDiagnosticLog. Then query them in Log Analytics to check for any recent disconnects, errors, or route-related events around the time the traffic stopped.
These steps usually help us confirm whether the issue is on the Azure side or not.
Microsoft Documentation:
- Reset a VPN gateway or a connection
- Troubleshoot an Azure S2S VPN connection
- Troubleshoot Azure VPN Gateway using diagnostic logs
If the answer is helpful, please click "Accept Answer". If you have extra questions about this answer, please click "Comment".