Azure VPN Gateway Calculator
Check a VPN Gateway SKU against your throughput and tunnel needs, then cost the gateway and its egress data.
Inputs
Other SKUs are scaled from this rate; zone-redundant AZ SKUs cost more.
Monthly Cost
$534.62
SKU Throughput
1,000Mbps
Throughput Utilisation
60.0%
Spare Tunnels
12tunnels
Gateway Charge
$360.62
Outbound Data Charge
$174.00
Capacity Verdict
Fits with comfortable headroom
Step by step
Values used
Gateway SKU = VpnGw2 — 1 Gbps, 30 tunnels; VpnGw1 reference rate = 0.1900 USD/hour; Aggregate throughput required = 600 Mbps; IPsec tunnels required = 18 tunnels; Outbound data through the tunnels = 2,000 GB/month; Outbound data price per GB = 0.0870 USD; Billed hours per month = 730 hours
Azure VPN Gateway
Each SKU has a fixed aggregate throughput and tunnel count; monthly = SKU hourly rate × 730 + outbound GB × egress price, with utilisation = required Mbps ÷ SKU throughput.
Monthly Cost
= 534.62
SKU Throughput
= 1,000 Mbps
Throughput Utilisation
= 60.0
Spare Tunnels
= 12 tunnels
Gateway Charge
= 360.62
Outbound Data Charge
= 174.00
How it works
VPN Gateway throughput is an aggregate across every tunnel on the gateway, so ten branches sharing a VpnGw1 share its 650 Mbps rather than each getting it. Tunnel limits step from 10 on Basic to 30 on VpnGw1–3 and 100 on VpnGw4–5, and changing SKU family requires recreating the gateway. A gateway that is one SKU too small shows up as unexplained packet loss during backup windows rather than a clean error, and outbound data through the tunnel is billed at normal internet egress rates — confirm the SKU prices and egress bands for your region in the Azure pricing calculator.
Formula
Azure VPN Gateway
Each SKU has a fixed aggregate throughput and tunnel count; monthly = SKU hourly rate × 730 + outbound GB × egress price, with utilisation = required Mbps ÷ SKU throughput.
- aggregate throughput
- Total across all tunnels on the gateway, not per tunnel
- tunnel count
- Maximum simultaneous site-to-site IPsec tunnels the SKU terminates
- reference rate
- VpnGw1 hourly price from which the other SKUs are scaled
Frequently Asked Questions
How is Azure VPN Gateway calculated?
Each SKU has a fixed aggregate throughput and tunnel count; monthly = SKU hourly rate × 730 + outbound GB × egress price, with utilisation = required Mbps ÷ SKU throughput. VPN Gateway throughput is an aggregate across every tunnel on the gateway, so ten branches sharing a VpnGw1 share its 650 Mbps rather than each getting it. Tunnel limits step from 10 on Basic to 30 on VpnGw1–3 and 100 on VpnGw4–5, and changing SKU family requires recreating the gateway.
Why does Azure VPN Gateway matter?
A gateway that is one SKU too small shows up as unexplained packet loss during backup windows rather than a clean error, and outbound data through the tunnel is billed at normal internet egress rates — confirm the SKU prices and egress bands for your region in the Azure pricing calculator.
What values do I need to enter?
This calculator takes 7 inputs: Gateway SKU, VpnGw1 reference rate, Aggregate throughput required, IPsec tunnels required, Outbound data through the tunnels, Outbound data price per GB, Billed hours per month. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
You might also need
- Azure Network Cost CalculatorCommonly used together
- Azure ExpressRoute CalculatorCommonly used together
- Azure Firewall CalculatorCommonly used together
- Azure Kubernetes Service (AKS) CalculatorAlso in Microsoft Azure
- Azure Availability Zone PlannerAlso in Microsoft Azure
- Azure Blob Storage CalculatorAlso in Microsoft Azure