VPN Tunnel up but no Traffic coming through

Chad Miller 100 Reputation points
2026-05-31T15:08:07.6466667+00:00

We have a VPN tunnel between our physical site and our Azure infrastructure. Yesterday it was working just fine and traffic was flowing through. Today the tunnel still show as up and connected but no traffic is coming through. We are currently troubleshooting the physical peer but we want to be sure the azure peer is not the issue. No changes have been made to the azure peer.

I have run Azures VPN troubleshooter and that show everything is healthy. I just want to be positive and eliminate Azure peer as the issue. What would be next steps on the azure side of thing so that we can be confident this isn't an Azure problem.

Azure VPN Gateway
Azure VPN Gateway

An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.


Answer accepted by question author
Ravi Varma Mudduluru 12,625 Reputation points Microsoft External Staff Moderator
2026-06-01T06:53:07.25+00:00

Hello @Chad Miller

Thank you for reaching out to Microsoft Q&A.

I understand your Site-to-Site VPN tunnel shows as Connected in Azure, the built-in troubleshooter reports everything healthy, and no changes were made on the Azure side, yet traffic has stopped flowing.

Since the tunnel is up, the IKE/IPsec negotiation is generally fine. The most likely causes at this point are routing, stale Security Associations (SAs), or traffic not hitting the tunnel correctly. Here are the recommended next steps on the Azure side to help rule it out confidently:

Quick Checks:

  1. Go to your Virtual Network Gateway > Connections, select the affected connection, and note the Data In and Data Out values. Try generating traffic from both sides and see if the counters increase.
  2. Review the Effective Routes on an Azure VM in the target subnet to confirm traffic to your on-premises address space is pointing to the Virtual Network Gateway.

Recommended Actions:

  • Reset the VPN Connection: In the Azure portal, go to the Connection resource and click Reset. This clears the current IPsec SAs without restarting the entire gateway. Coordinate with your on-premises team to reset their side at the same time.
  • If that doesn’t help, Reset the VPN Gateway itself (brief downtime). This often resolves stale tunnel issues.
  • Enable/review Diagnostic Logs if not already done: Enable TunnelDiagnosticLog, IKEDiagnosticLog, and RouteDiagnosticLog. Then query them in Log Analytics to check for any recent disconnects, errors, or route-related events around the time the traffic stopped.

These steps usually help us confirm whether the issue is on the Azure side or not.

Microsoft Documentation:

If the answer is helpful, please click "Accept Answer". If you have extra questions about this answer, please click "Comment".

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Oldest
  1. Chad Miller 100 Reputation points
    2026-06-04T13:46:03.88+00:00

    Since the tunnel is up, the IKE/IPsec negotiation is generally fine. The most likely causes at this point are routing, stale Security Associations (SAs), or traffic not hitting the tunnel correctly. Here are the recommended next steps on the Azure side to help rule it out confidently:

    Quick Checks:

    1. Go to your Virtual Network Gateway > Connections, select the affected connection, and note the Data In and Data Out values. Try generating traffic from both sides and see if the counters increase.
    2. Review the Effective Routes on an Azure VM in the target subnet to confirm traffic to your on-premises address space is pointing to the Virtual Network Gateway.

    Recommended Actions:

    • Reset the VPN Connection: In the Azure portal, go to the Connection resource and click Reset. This clears the current IPsec SAs without restarting the entire gateway. Coordinate with your on-premises team to reset their side at the same time.
    • If that doesn’t help, Reset the VPN Gateway itself (brief downtime). This often resolves stale tunnel issues.
    • Enable/review Diagnostic Logs if not already done: Enable TunnelDiagnosticLog, IKEDiagnosticLog, and RouteDiagnosticLog. Then query them in Log Analytics to check for any recent disconnects, errors, or route-related events around the time the traffic stopped.

    These steps usually help us confirm whether the issue is on the Azure side or not.

    Microsoft Documentation:

    If the answer is helpful, please click "upvote". If you have extra questions about this answer, please click "Comment".Since the tunnel is up, the IKE/IPsec negotiation is generally fine. The most likely causes at this point are routing, stale Security Associations (SAs), or traffic not hitting the tunnel correctly. Here are the recommended next steps on the Azure side to help rule it out confidently:

    Quick Checks:

    1. Go to your Virtual Network Gateway > Connections, select the affected connection, and note the Data In and Data Out values. Try generating traffic from both sides and see if the counters increase.
    2. Review the Effective Routes on an Azure VM in the target subnet to confirm traffic to your on-premises address space is pointing to the Virtual Network Gateway.

    Recommended Actions:

    • Reset the VPN Connection: In the Azure portal, go to the Connection resource and click Reset. This clears the current IPsec SAs without restarting the entire gateway. Coordinate with your on-premises team to reset their side at the same time.
    • If that doesn’t help, Reset the VPN Gateway itself (brief downtime). This often resolves stale tunnel issues.
    • Enable/review Diagnostic Logs if not already done: Enable TunnelDiagnosticLog, IKEDiagnosticLog, and RouteDiagnosticLog. Then query them in Log Analytics to check for any recent disconnects, errors, or route-related events around the time the traffic stopped.

    These steps usually help us confirm whether the issue is on the Azure side or not.

    Microsoft Documentation:

    If the answer is helpful, please click "upvote". If you have extra questions about this answer, please click "Comment".

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.