Skip to content

Conversation

@MicrosoftAzureAaron
Copy link
Contributor

Clarified requirements for Azure VWAN VPN Gateway packet captures regarding storage account accessibility and endpoint limitations.

Private endpoint and service endpoint work for regular VPN gateway captures but not for Azure VWAN VPN gateway as the CX has no ability to modify the gateway subnet

Clarified requirements for Azure VWAN VPN Gateway packet captures regarding storage account accessibility and endpoint limitations.

Private endpoint and service endpoint work for regular VPN gateway captures but not for Azure VWAN VPN gateway as the CX has no ability to modify the gateway subnet
@prmerger-automator
Copy link
Contributor

@MicrosoftAzureAaron : Thanks for your contribution! The author(s) and reviewer(s) have been notified to review your proposed change.

@learn-build-service-prod
Copy link
Contributor

Learn Build status updates of commit 777c4d2:

✅ Validation status: passed

File Status Preview URL Details
articles/virtual-wan/packet-capture-site-to-site-powershell.md ✅Succeeded

For more details, please refer to the build report.

@v-dirichards v-dirichards requested a review from Copilot November 17, 2025 21:56
@v-dirichards
Copy link
Contributor

@cherylmc Can you review the proposed changes?

Due to the upcoming conference, all merging and publishing is on hold until the morning of November 18th.

Important: When the changes are ready for publication, adding a #sign-off comment is the best way to signal that the PR is ready for the review team to merge.

#label:"aq-pr-triaged"
@MicrosoftDocs/public-repo-pr-review-team

@prmerger-automator prmerger-automator bot added the aq-pr-triaged tracking label for the PR review team label Nov 17, 2025
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the documentation for Azure Virtual WAN VPN Gateway packet captures to clarify storage account accessibility requirements. It explicitly states that public accessibility is required and explains why private endpoints and service endpoints are not supported for VWAN VPN Gateway scenarios.

Key Changes:

  • Added requirement for publicly accessible Azure Storage Account
  • Documented limitation regarding Private Endpoints for Blob Storage
  • Documented limitation regarding Service Endpoints on Gateway subnet

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

* A Virtual WAN and a virtual hub.
* A site-to-site VPN gateway deployed in the virtual hub.
* You can also have connections connecting VPN sites to your site-to-site VPN gateway.
* A publically acessible Azure Storage Account.
Copy link

Copilot AI Nov 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Corrected spelling of 'publically' to 'publicly' and 'acessible' to 'accessible'.

Suggested change
* A publically acessible Azure Storage Account.
* A publicly accessible Azure Storage Account.

Copilot uses AI. Check for mistakes.
Comment on lines +30 to +31
* Private Endpoints for Blob Storage will not work for Azure VWAN VPN Gateway packet captures, as the DNS for the VPN Gateway can not be modified by the customer.
* Serive Endpoints are not a valid connectivity method for Azure VWAN VPN Gateway packet captures as they can not be enabled on the Gateway subnet.
Copy link

Copilot AI Nov 17, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Corrected spelling of 'Serive' to 'Service' and changed 'can not' to 'cannot'.

Suggested change
* Private Endpoints for Blob Storage will not work for Azure VWAN VPN Gateway packet captures, as the DNS for the VPN Gateway can not be modified by the customer.
* Serive Endpoints are not a valid connectivity method for Azure VWAN VPN Gateway packet captures as they can not be enabled on the Gateway subnet.
* Private Endpoints for Blob Storage will not work for Azure VWAN VPN Gateway packet captures, as the DNS for the VPN Gateway cannot be modified by the customer.
* Service Endpoints are not a valid connectivity method for Azure VWAN VPN Gateway packet captures as they cannot be enabled on the Gateway subnet.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants