# Use Door and Azure VPN Gateway to Connect Your Devices to an Azure Virtual Network

Securely connect to Azure Virtual Network using Microsoft VPN Gateway.

## Introduction

**[Soracom Door](https://docs.soracom.io/en/services/door)** (“Door”) allows you to establish VPN connections between sites and Soracom. This guide will show how you can use Soracom Door to make a VPN connection from [**Microsoft Azure**](https://azure.microsoft.com/) (“Azure”).

![Door VPN Architecture Overview](https://docs.soracom.io/_astro/step0-1.BSWmMeLR_nnvRf.webp)

### Prerequisites

- A Soracom account
- A Soracom IoT SIM
- A device that can connect to the internet using the Soracom IoT SIM, such as a Raspberry Pi and USB modem
- An Azure account

## Step 1: Create a Virtual Network, a VPN Gateway, and a Virtual Machine on Azure

In this guide, you will use Soracom Door to connect securely to your own private network. To demonstrate this connection, you must first create your own network, gateway, and virtual machine on Azure.

### Create an Azure Virtual Network

You must first create an Azure Virtual Network (VNet), which will house your Azure Virtual Machine (VM).

> [!NOTE]
>
> If you want to use an existing VNet, its CIDR needs to be within the following:
>
> - 10.0.0.0/8 (For VPGs created in Japan coverage, the address space 10.21.0.0/16 is unavailable)
> - 172.16.0.0/12
> - 192.168.0.0/16

1. Sign in to the **[Microsoft Azure Portal](https://portal.azure.com/#home)**.

2. Click on **More services** to browse all Azure services.

   ![Azure Portal More Services Button](https://docs.soracom.io/_astro/step1-1.CQ8Ys47s_ZKeQuD.webp)

3. Click on **Virtual networks**.

   ![Virtual Networks Service Option](https://docs.soracom.io/_astro/step1-2.e2VZdG8a_iVK1N.webp)

4. Click **Create**.

   ![Create Virtual Network Button](https://docs.soracom.io/_astro/step1-3.B0rhscez_15AGjp.webp)

5. Give the VNet a name and configure it with a resource group if you have one; if not, create one.

   ![Virtual Network Basic Configuration](https://docs.soracom.io/_astro/step1-4-1.V1Q0i1nA_2tlqMv.webp)

6. Configure the VNet with a region of your choosing (in this example, we are using _Japan East_), then click **Next: IP Addresses**.

   ![Virtual Network Region Selection](https://docs.soracom.io/_astro/step1-4-2.CcxxuuAn_1l0s9v.webp)

7. **IPv4 address space**: Specify the address space you would like to use (e.g., 10.0.0.0/16).

   ![IPv4 Address Space Configuration](https://docs.soracom.io/_astro/step1-5.C-oCwOLq_ZJhwNx.webp)

8. Click on **default** right under subnet name and configure the subnet's **Name** and **Starting address** (e.g., 10.0.0.0/24).

   ![Subnet Configuration](https://docs.soracom.io/_astro/step1-6-1.Df4BFn1z_Z1nM9Ga.webp)

9. Click **Save**, then click **Review + create**.

   ![Save and Review Configuration](https://docs.soracom.io/_astro/step1-6-2.D8rxggPH_Z1ISv65.webp)

10. Click **Create**.

    ![Create Virtual Network Button](https://docs.soracom.io/_astro/step1-7.BceLkH2i_Z27uGhh.webp)

> [!CAUTION]
>
> You have successfully created an Azure VNet!

### Create an Azure VPN Gateway

Next, you will set up an Azure VPN Gateway for the VNet you just created.

1. Go back to the homepage of your **[Microsoft Azure Portal](https://portal.azure.com/#home)**.

2. Browse and click **Virtual network gateways**.

   ![Virtual Network Gateways Service](https://docs.soracom.io/_astro/step1-8.Dr-Ew27i_Z1y20CK.webp)

3. Click **Create**.

   ![Create VPN Gateway Button](https://docs.soracom.io/_astro/step1-9.DD28LtGn_Z1XBK92.webp)

4. Configure the gateway with the following and click **Review + create**.

   | Setting | Configuration |
   | - | - |
   | Resource Group | Same Resource Group from when you created your VNet |
   | Name | Enter any recognizable name |
   | Region | Same region that you used for your VNet |
   | Gateway Type | VPN |
   | VPN Type | Route-based |
   | SKU | VpnGw1 |
   | Generation | Generation1 |
   | Virtual network | Select the VNet you just created |
   | Gateway subnet address range | Enter a subnet range that's within the range you specified for your VNet (e.g., 10.0.1.0/24) |
   | Public IP Address Type | Standard |
   | Public IP address | Create new |
   | Public IP address name | Enter any recognizable name for your new IP address |
   | Assignment | Static |
   | Enable active mode | Disabled |
   | Configure BGP | Disabled |

   ![VPN Gateway Configuration Settings - Part 1](https://docs.soracom.io/_astro/step1-10.BpcxSbbL_1R7dXS.webp)

   Scroll down

   ![VPN Gateway Configuration Settings - Part 2](https://docs.soracom.io/_astro/step1-11.BnvowxW__1fDXRX.webp)

5. Click **Create**.

   ![Create VPN Gateway Final Step](https://docs.soracom.io/_astro/step1-12.Dp6Ikmj0_Z1YHWJT.webp)

> [!CAUTION]
>
> You have successfully created an Azure VPN Gateway!

### Creating an Azure Virtual Machine

You will now create an Azure VM within your newly created VNet. In this guide, connecting your device to this VM securely with VPN is the end goal.

1. Go back to the homepage of your **[Microsoft Azure Portal](https://portal.azure.com/#home)**.

2. Browse and click **Virtual machines**.

   ![Virtual Machines Service Selection](https://docs.soracom.io/_astro/step1-13.Cu1D5VK7_Z26Hl5v.webp)

3. Click **Create** then click **Azure virtual machine**.

   ![Create Azure Virtual Machine Menu](https://docs.soracom.io/_astro/step1-14.RpfhNdYq_1hXwdj.webp)

4. Fill out all the configurations as listed below, then click **Next: Disks**.

   | Setting | Configuration |
   | - | - |
   | Resource Group | Same Resource Group from when you created your VNet |
   | Virtual machine name | Enter any recognizable name |
   | Region | Same region that you used for your VNet |
   | Size | Standard\_B1s |
   | Authentication Type | SSH public key |
   | SSH public key source | Generate new key pair If you already have a key pair that you'd like to use here, select Use existing key stored in Azure |
   | Key pair name | If you selected Generate new key pair, name it however you like. |
   | Public inbound ports | None |

   > [!NOTE]
   >
   > Leave unmentioned settings as is.

   ![Virtual Machine Basic Configuration](https://docs.soracom.io/_astro/step1-15.dsdBEVDK_1UwmMM.webp)

   Scroll down

   ![Virtual Machine Authentication Settings](https://docs.soracom.io/_astro/step1-16.BhcCKTls_Z1obe7w.webp)

5. Click **Next: Networking**.

   ![Next to Networking Step](https://docs.soracom.io/_astro/step1-17.DLgHVL90_VaqAz.webp)

6. **Virtual network** and **Subnet**: Select the VNet you made and the subnet you specified earlier.

   ![Virtual Machine Network Configuration](https://docs.soracom.io/_astro/step1-18.1c7W77LK_Z1DKRsH.webp)

7. Scroll down and click the checkbox for **Delete public IP and NIC when VM is deleted**, then click **Review + create**.

   ![Delete Public Resources Configuration](https://docs.soracom.io/_astro/step1-19.Cb6TASTs_Oky8m.webp)

8. Click **Create**.

   ![Create Virtual Machine Final Review](https://docs.soracom.io/_astro/step1-20.DRhGqNuD_1muFNW.webp)

   A pop-up will appear asking you about whether or not to download a key pair.

9. Click **Download private key and create resource**.

   ![Download Private Key Dialog](https://docs.soracom.io/_astro/step1-21.CL9OQ9-0_1Tf4nN.webp)

> [!NOTE]
>
> Make sure you keep this key pair where you can find it later.

> [!CAUTION]
>
> You have successfully created a Virtual Machine on Azure.

## Step 2: Create a VPG

Now that you have created all the necessary Azure components, to link them to Soracom, you must create a Type-F [Virtual Private Gateway](https://docs.soracom.io/en/services/vpg) (VPG). Soracom's VPG option lets you create and manage your own dedicated gateway on the Soracom platform.

> [!WARNING]
>
> If you are using a Type-F2 VPG, follow the **[VPG Type-F2 Configuration](https://docs.soracom.io/en/services/vpg/type-f2)** guide to create your VPG, then return to Step 3 of this guide. You will need your VPG's Device Subnet IP address range (visible on the VPG settings page) for Step 4.

1. Sign in to the **[User Console](https://console.soracom.io/?coverage_type=g)**. From the **☰ Menu**, open the **VPG** screen.

2. Click the **+ Create VPG** button.

3. Enter a name to identify the VPG, then select **Type-F**.

   ![Create VPG](https://docs.soracom.io/_astro/step2-3.D-FW-lHX_1HxUvp.webp)

   > [!NOTE]
   >
   > Once created, the **Internet Gateway**, **Rendezvous Point**, and **CIDR Range** settings cannot be changed.

4. Select a rendezvous point.

   For more information, refer to the [Rendezvous point documentation](https://docs.soracom.io/en/services/air/rendezvous-points).

   > [!WARNING]
   >
   > The rendezvous point you choose here can differ based on what your IoT SIM's subscription is and the region your device is located in.

   ![VPG Rendezvous Point Selection](https://docs.soracom.io/_astro/step2-4.r-nu3tQr_RbbPJ.webp)

5. Click **Create**.

   > [!CAUTION]
   >
   > You have successfully created a Type-F VPG.

   Now you will need to get the VPG's IP address in preparation for the next steps.

6. Click on your newly created VPG.

   ![Select Created VPG](https://docs.soracom.io/_astro/step2-6.jDx1bcS-_Z1ldOdz.webp)

7. Copy down the **VPG IP ADDRESS RANGE** for use later.

   ![VPG IP Address Range Information](https://docs.soracom.io/_astro/step2-7.9Lv7BSbr_1wLC0X.webp)

## Step 3: Apply to Use Soracom Door

Next, to apply for access to Soracom Door, [**submit a support ticket**](https://docs.soracom.io/en/services/account/support) and select `I want to apply for a Soracom Door connection` from the **Which category best describes your inquiry?** dropdown menu.

Provide the following information required by the form:

| Field | Information to Enter |
| - | - |
| Company Name and Address | Provide your company's name and address |
| Door Use Case | Describe your use case and why it requires a VPN connection |
| VPG ID for Door Connection | Provide the ID of the VPG created in Step 2 |
| The Router or Cloud Provider You Are Using | Enter `Azure VPN Gateway` |
| Your Router or Cloud Instance's Global IP Address | Enter the IP address that was configured for the Azure VPN Gateway created in Step 1 |
| Routing Type | Select `Static` |
| IP Address Range | Enter the IP address range of your Azure Virtual Network that was created in Step 1 |

> [!WARNING]
>
> Applications are approved on a conditional basis. In some cases, we may not be able to approve access to Soracom Door due to technical limitations or unsuitable use cases.

## Step 4: Configure Azure VPN Gateway

Now that you can use Soracom Door, you must create two local network gateways for the Soracom VPG endpoints, then add two IPsec connections to your VPN Gateway.

A couple of days after completing Step 3, you should receive an email from Soracom. Open it to see more details about your VPN connection.

### Retrieve Your VPG's IP Address and Pre-Shared Key

1. Open the email you received from Soracom regarding Soracom Door.

2. Open the attached file and use **Cmd F** or **Ctrl F** to find **Outside IP Addresses** (there should be two locations).

3. Copy the two addresses that follow **Virtual Private Gateway :** and save them somewhere.

   Both of these addresses should look like the following

   ```
   Outside IP Addresses:
   - Customer Gateway        : XX.XX.XX.XX
   - Virtual Private Gateway : XX.XX.XX.XX <- save this address
   ```

4. Use **Cmd F** or **Ctrl F** again to find the two locations with **Pre-Shared Key**.

5. Copy the two Pre-Shared Keys and save them somewhere.

   It should look like the following

   ```
   - IKE version              : IKEv2
   - Authentication Method    : Pre-Shared Key
   - Pre-Shared Key           : xxxxxxxxxxxxxxxxxxxxx <- save this key
   - Authentication Algorithm : sha1
   ...
   ```

> [!NOTE]
>
> Make sure you know which Pre-Shared Key corresponds to which IP Address. The first IP will correspond to the first Pre-Shared Key and the second IP will correspond to the second Pre-Shared Key. Your memo should look something like the following:
>
> - First Connection
> - - Outside IP: XX.XX.XX.XX
>   - Pre-Shared Key: xxxxxxxxxxxxx
>   Second Connection
>   - Outside IP: XX.XX.XX.XX
>   - Pre-Shared Key: xxxxxxxxxxxxx

### Create Local Network Gateways

Now you will create a local network gateway for each connection.

1. Sign in to the **[Microsoft Azure Portal](https://portal.azure.com/#home)**.

2. Browse and click **Local network gateways**.

   ![Local Network Gateways Service](https://docs.soracom.io/_astro/step4-1.BWATCIoK_HEyq9.webp)

3. Click **Create**.

   ![Create Local Network Gateway Button](https://docs.soracom.io/_astro/step4-2.tEKG1Wmn_2gRuXT.webp)

4. Enter the same resource group as Step 1, select the same region as in Step 1, and name the local gateway however you'd like.

   ![Local Network Gateway Basic Configuration](https://docs.soracom.io/_astro/step4-3.BDNp3tQa_g0r9v.webp)

5. **IP address**: Enter the VPG's Outside IP for the first connection.

   ![VPG Outside IP Address Configuration](https://docs.soracom.io/_astro/step4-4.CbpwauoW_Z2te4sE.webp)

6. **Address Space(s)**: Enter the Soracom-side address range that Azure should route through this connection. The value depends on your VPG type, as shown in the following table.

   | VPG type | Value to enter |
   | - | - |
   | Type-E / Type-F / Type-G | **VPG IP address range** |
   | Type-F2 | **Device subnet IP address range** |

   ![Address Space(s) configuration](https://docs.soracom.io/_astro/step4-5.CFDq_jtd_1XA3Th.webp)

   > [!NOTE]
   >
   > The range you specify here must not overlap with your Azure virtual network or subnet.

7. Click **Review + create**.

   ![Review Local Network Gateway](https://docs.soracom.io/_astro/step4-6.Bkzye5w-_Z21eYWg.webp)

8. Click **Create**.

   ![Create Local Network Gateway Final Step](https://docs.soracom.io/_astro/step4-7.D_w15HBY_1YAUzR.webp)

9. Repeat steps 3-8 to create one more local network gateway, but now replace the IP address with the second VPG outside IP address.

> [!CAUTION]
>
> You've successfully made local network gateways for your connections!

### Add Connections

1. Sign in to the **[Microsoft Azure Portal](https://portal.azure.com/#home)**.

2. Browse and click **Virtual network gateways** as you did in Step 1.

3. Click on the Virtual network gateway that you created in Step 1.

   ![Select Virtual Network Gateway](https://docs.soracom.io/_astro/step4-8.Bzw4CFG8_LLxeL.webp)

4. Click **Connections**.

   ![Virtual Network Gateway Connections Menu](https://docs.soracom.io/_astro/step4-9.CDAI6tBC_Z15xUMT.webp)

5. Click **Add**.

   ![Add Connection Button](https://docs.soracom.io/_astro/step4-10.CjNFdYzY_CgVy4.webp)

6. Select the same resource group you have been using from before.

   ![Connection Resource Group Selection](https://docs.soracom.io/_astro/step4-11.BdzXGt5Y_1yhAGK.webp)

7. **Connection type**: Select **Site-to-site (IPsec)**.

   ![Site-to-Site IPsec Connection Type](https://docs.soracom.io/_astro/step4-12.eH2CQBgw_2kpw4m.webp)

8. Assign the same region you have been using and give the connection a recognizable name, then click **Next: Settings**.

   ![Connection Name and Region Configuration](https://docs.soracom.io/_astro/step4-13.BMENQsOM_Z9G74b.webp)

9. Select the Virtual network gateway from Step 1 and the first Local network gateway that you created just now.

   ![Gateway Selection for Connection](https://docs.soracom.io/_astro/step4-14.HjJMK3hF_oMtjd.webp)

10. **Shared key (PSK)**: Enter the Pre-Shared Key of the first connection.

    ![Pre-Shared Key Configuration](https://docs.soracom.io/_astro/step4-15.DkJNQ9Z2_ZCd7Qk.webp)

11. **IKE Protocol**: Click **IKEv2**, then click **Review + create**.

    ![IKEv2 Protocol Selection](https://docs.soracom.io/_astro/step4-16.B8UV3uNf_Z24V3jC.webp)

12. Click **Create**.

    ![Create Connection Final Step](https://docs.soracom.io/_astro/step4-17.BgtliELa_Z63yDd.webp)

13. Repeat these steps to add another connection, this time for the second local network gateway and the second Pre-Shared Key.

    > [!CAUTION]
    >
    > Your two connections should show **Connected** as you can see below.

    ![Connected Status Confirmation](https://docs.soracom.io/_astro/step4-18.DX8YcfyW_2ev63a.webp)

## Step 5: Attach Your IoT SIM Group to Your VPG

Now that you've finished setting up your network gateways, you must attach your device's IoT SIM to the VPG you created.

1. Sign in to your account on the **[Soracom Console](https://console.soracom.io/)**.

2. Click the top left menu bar and click **Groups**.

   ![Soracom Console Groups Menu](https://docs.soracom.io/_astro/step5-1.CZTxudkr_Z2u1gba.webp)

3. Click the SIM group you would like to use.

   ![Select SIM Group](https://docs.soracom.io/_astro/step5-2.BedWp5LS_9ae8F.webp)

> [!WARNING]
>
> Attaching your IoT SIM to your VPG is done at the group level. For more information on Groups and how to add your SIM plans to a group, check the Groups section in the [User-Console Guide](https://docs.soracom.io/en/guides/user-console).

4. Click **SORACOM Air for Cellular**.

   ![SORACOM Air for Cellular Settings](https://docs.soracom.io/_astro/step5-3.DpQUKrQf_Z18bThD.webp)

5. Scroll down and turn on the **VPG** setting, select the VPG you previously created, then click **Save**.

   ![VPG Setting Configuration](https://docs.soracom.io/_astro/step5-4.DNf1wrC9_msewU.webp)

6. Restart all IoT SIM sessions belonging to your group, or simply restart your IoT devices.

> [!NOTE]
>
> Even if you have the right VPG attached to your SIM group in the Soracom console, you must restart the session or the device housing your IoT SIM to apply these changes.

## Step 6: Connect Your Device with a Private Network

Connect your devices that use the Type-F VPG to the VM that you created in Step 1.

1. Sign in to the **[Microsoft Azure Portal](https://portal.azure.com/#home)**.

2. Browse and click **Virtual machines** as you did in Step 1.

3. Click on the Virtual machine that you created earlier.

   ![Select Created Virtual Machine](https://docs.soracom.io/_astro/step6-1.DEhiaABD_Z1Ip4iA.webp)

4. Under **Properties**, copy down the **Private IP address**.

   ![Virtual Machine Private IP Address](https://docs.soracom.io/_astro/step6-2.6MKT5MSL_VqTdV.webp)

5. Run the following command from a device that uses the IoT SIM that is registered in the group that you created earlier.

   ```bash
   ping 10.0.0.XXX -c 4
   ```

   The output should look like the following

   ```
   64 bytes from 10.0.0.XXX : icmp_seq=1 ttl=63 time=22.2 ms
   64 bytes from 10.0.0.XXX : icmp_seq=2 ttl=63 time=16.9 ms
   64 bytes from 10.0.0.XXX : icmp_seq=3 ttl=63 time=18.3 ms
   64 bytes from 10.0.0.XXX : icmp_seq=4 ttl=63 time=18.1 ms
   ```

   A response like this confirms that you are successfully connected to the private network.

## Reference: Stop Using Soracom Door and VPN

To stop using Soracom Door and your VPN, you must delete the VPN connection and terminate your VPG.

1. Sign in to your account on the **[Soracom Console](https://console.soracom.io/)**.

2. Click on the top left menu, then click **VPG**.

   ![Soracom Console VPG Menu for Termination](https://docs.soracom.io/_astro/step2-1.BqC4aAxE_Z2c54wi.webp)

3. Click the VPG corresponding to the connection you want to terminate.

4. Copy and save the **VPG ID**.

   ![VPG ID for Termination](https://docs.soracom.io/_astro/reference-1.BI-nWKdV_ZcDc55.webp)

5. Click **CLOSED NETWORK**.

6. Scroll down to **VPN Connection (SORACOM Door)** and save the **VPN ID**.

   ![VPN ID for Door Connection](https://docs.soracom.io/_astro/reference-2.CIqlGxSN_ZEpF6H.webp)

7. [Contact Soracom Support](https://support.soracom.io/hc/en-us/requests/new?ticket_form_id=37517451420313) with the following information:

   - Indicate that you are looking to terminate your VPN connection using Door.
   - Your VPG ID
   - Your VPN ID

   The Soracom Support team will reach out to you regarding the termination of your VPN connection.

8. Once your VPN connection has been terminated, you can safely remove your IoT SIM group from the VPG and terminate your VPG.
