Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Azure Virtual Network encryption is a feature of Azure Virtual Networks. Virtual network encryption allows you to seamlessly encrypt and decrypt traffic between Azure Virtual Machines by creating a DTLS tunnel.
Virtual network encryption enables you to encrypt traffic between Virtual Machines and Virtual Machines Scale Sets within the same virtual network. Virtual network encryption encrypts traffic between regionally and globally peered virtual networks. For more information about virtual network peering, see Virtual network peering.
Virtual network encryption enhances existing encryption in transit capabilities in Azure. For more information about encryption in Azure, see Azure encryption overview.
Requirements
Virtual network encryption has the following requirements:
Virtual network encryption supports the following virtual machine instance sizes:
The D/E series entries in the following list are a baseline, not an exhaustive list. Virtual network encryption supports all v5 and newer generations of D-series and E-series.
For all other families, encryption supports the specific series listed in the following table. The product team adds new sizes as they're validated. This support includes the compute-optimized (F-series), storage-optimized (L-series), memory-optimized (M-series), and GPU-accelerated compute sizes.
Type VM Series VM SKU General purpose workloads D-series V4
D-series V5
D-series V6Dv4 and Dsv4-series
Ddv4 and Ddsv4-series
Dav4 and Dasv4-series
Dv5 and Dsv5-series
Ddv5 and Ddsv5-series
Dlsv5 and Dldsv5-series
Dasv5 and Dadsv5-series
Dasv6 and Dadsv6-series
Dalsv6 and Daldsv6-series
Dsv6-series
Dplsv6 and Dpldsv6-series
Dpsv6 and Dpdsv6-seriesMemory intensive workloads E-series V4
E-series V5
E-series V6
M-series V2
M-series V3Ev4 and Esv4-series
Edv4 and Edsv4-series
Eav4 and Easv4-series
Ev5 and Esv5-series
Edv5 and Edsv5-series
Easv5 and Eadsv5-series
Easv6 and Eadsv6-series
Epsv6 and Epdsv6-series
Mv2-series
Msv2 and Mdsv2 Medium Memory series
Msv3 and Mdsv3 Medium Memory seriesStorage intensive workloads L-series V3 LSv3-series Compute optimized F-series V6 Falsv6-series
Famsv6-series
Fasv6-seriesGPU - accelerated compute NC-H100 series V5
ND-GB200 series V6
ND-GB300 series V6NC-H100 v5-series
ND-GB200 v6-series
ND-GB300 v6-series
Accelerated Networking must be enabled on the network interface of the virtual machine. For more information about Accelerated Networking, see What is Accelerated Networking?
Encryption is only applied to traffic between virtual machines in a virtual network. Traffic is encrypted from a private IP address to a private IP address.
Traffic to unsupported Virtual Machines is unencrypted. Use Virtual Network Flow Logs to confirm flow encryption between virtual machines. For more information, see Virtual network flow logs.
The start/stop of existing virtual machines is required after enabling encryption in a virtual network.
Availability
Azure Virtual Network encryption is generally available in all Azure public regions and is currently in public preview in Azure Government and Microsoft Azure operated by 21Vianet.
Limitations
Azure Virtual Network encryption has the following limitations:
- AllowUnencrypted is the only supported enforcement at general availability.
- DropUnencrypted enforcement will be supported in the future.
- Don't enable Virtual Network encryption if the VM SKU doesn't support Accelerated Networking or Virtual Network encryption.
- Don't enable Virtual Network encryption in virtual networks that use Azure confidential computing VM SKUs. If you want to use Azure confidential computing VMs in virtual networks where Virtual Network encryption is enabled, then:
- Enable Accelerated Networking on the VM's NIC if it's supported.
- If Accelerated Networking isn't supported, change the VM SKU to one that supports Accelerated Networking or Virtual Network encryption.
Scenarios list
Supported - traffic connectivity is preserved when encryption is enabled. Encrypted - traffic is encrypted on the datapath.
Note
A scenario can be "Supported=Yes" and still be "Encrypted=No".
| Scenario | Supported | Encrypted |
|---|---|---|
| Virtual machines in the same virtual network (including virtual machine scale sets and their internal load balancer) | Yes | Yes - on traffic between virtual machines from these SKUs. |
| Virtual network peering | Yes | Yes - on traffic between virtual machines across regional peering. |
| Global virtual network peering | Yes | Yes - on traffic between virtual machines across global peering. |
| Azure ExpressRoute Gateways | Yes | No. - Traffic to and from Azure ExpressRoute Gateways isn't encrypted. |
| Azure Private Link service Azure Private Endpoint |
Yes | No. - Traffic to and from Private Link Service/Private Endpoint isn't encrypted. |
| Azure Application Gateway | Yes | No |
| Azure Firewall Premium | Yes | Yes |
| Azure Firewall Standard | Yes | No - Operates on VM SKUs that don't support virtual network encryption. |
| Internal Load Balancer + Supported VM SKUs for backend pool | Yes | Yes. - All virtual machines behind the load balancer must be on supported VM SKUs |
| Internal Load Balancer + Mixed SKUs for backend pool | No | N/A |
| Internal Load Balancer + backend pool with network interface secondary IPv4 configurations | No | N/A. - The backend pool of an internal load balancer must not include any network interface secondary IPv4 configurations to prevent connection failures to the load balancer. |
| Azure DNS Private Resolver | No | N/A |
| PaaS | Yes | The virtual machine where the PaaS is hosted dictates if virtual network encryption is supported. - Yes - supported VM SKUs. - No - unsupported VM SKUs. - The virtual machine must meet the above listed requirements. |
| Azure Kubernetes Service (AKS) | Yes | - Supported on AKS using Azure CNI (regular or overlay mode), Kubenet, or BYOCNI: node and pod traffic is encrypted. - Partially supported on AKS using Azure CNI Dynamic Pod IP Assignment (podSubnetId specified): node traffic is encrypted, but pod traffic isn't encrypted. - Traffic to the AKS managed control plane egresses from the virtual network and thus isn't in scope for virtual network encryption. However, this traffic is always encrypted via TLS. |
Note
Other services that currently don't support virtual network encryption are included in our future roadmap.