The Azure virtual network uses a virtual network gateway for its side of the VPN
tunnel to Prisma Access. This gateway uses a subnet called GatewaySubnet. The
GatewaySubnet contains IP addresses used for virtual network gateway resources
and services and is part of the virtual network IP address range that you
specify when you configure your virtual network on Azure.
Each Azure VPN gateway incorporates high availability by having two instances per
gateway in an active-standby configuration. If an active instance goes down for
planned maintenance or an unplanned outage, the instance automatically fails
over to the standby instance and resumes the site-to-site VPN connections. For a
planned maintenance, Azure restores the connectivity in approximately 10 to 15
seconds. For an unplanned outage, Azure restores the connectivity in
approximately 1 minute to 90 seconds.
Create the virtual network and virtual network gateway using the following
task.