vNet Virtual Network Gateway - Basic SKU no longer works with VPN Point-to-site Self-Signed Certificates

Neil McAlister 291 Reputation points
2023-10-13T09:35:29.1466667+00:00

Back in August 2023 I had a template of infrastructure code that provisioned a Virtual Network Gateway with the Basic SKU in the UK South region - and set it up with a self-signed certificate - as per instructions - and it worked perfectly. https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-certificates-point-to-site

Yesterday, October 12th 2023 I returned to this template to spin up another new service and while the resource/service provisions successfully - the VPN Client won't connect. The error on the Windows machines GUI is displayed as follows...

Root certificate which is not trusted by the trust provider. (0x800b0109)

The log file displays the following error...

[cmdial32] 08:15:58 21 On-Error Event ErrorCode = -2146762487 ErrorSource = RAS

I've no idea what error code -2146762487 means

I took the same template configuration and spun up the same thing with a SKU of VpnGw1 (Generation1) and it works with no issues

My question is therefore - what has broken the Basic SKU version of Virtual Network Gateway since August 2023 to October 2023? As this was working OK previously, many times.

Can it be fixed? I don't think Basic SKU is working now for new resource provisions - maybe UK South or maybe worldwide?

Please note: I've tried everything around this initial GUI error of 0x800b0109 - it's not that - I've moved certs around into different stores, done a Windows repair etc. etc. thank you but it's something to do with the SKU's

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,718 questions
Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,719 questions
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 49,326 Reputation points Microsoft Employee
    2023-10-18T09:28:08.4533333+00:00

    @Neil McAlister

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you are experiencing P2S Certificate issues while deploying a Basic SKU VPN Gateway using a Terraform template.

    To troubleshoot,

    • I enquired if you were able to reproduce the error for second time? (using Basic SKU itself)
      • You confirmed yes
    • If so, can you please upload the cert Data from Portal once the VPN gateway is deployed and see if that works?

    Meanwhile, you confirmed the issue is no longer reproducible

    The error code -2146762487 (0x800b0109) is issues by the OS. This, as the error states, generally means there is a trust issue with the certificate(s) used.

    I also checked this behavior internally but could not find any similar reported incident, or support cases wrt Basic SKU.

    I further suggested we file a support ticket to isolate the issue, should it ever resurface.

    Thanks,

    Kapil


    Please Accept an answer if correct.

    Original posters help the community find answers faster by identifying the correct answer.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.