Notes from MS Learn AZ-700 Module 2: Design and Implement Hybrid Networking – Unit 4: Connect Networks with Site-to-Site VPN Connections
Site-to-Site VPN Gateway Connection creates a secure connection to VNet from another VNet or physical network
Diagram from MS Learn

- Info based on diagram
- On-prem network has on prem services such as AD
- Gateway sends encrypted traffic to virtual IP when using public connection
- VNet contains cloud apps and VPN Gateway components
- Azure VPN Gateway provides encrypted tunnel to on-prem
- Virtual Network Gateway
- Local Network Gateway
- Connection
- Gateway Subnet
- Internal load balance handles routing cloud traffic to proper cloud app or resource
- Benefits
- Simplified config and maintenance
- Secure encrypted data/traffic from on-prem and Azure gateways
- Allow for future network requirements