> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getcollate.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Collate to your Azure network over Site-to-Site VPN

> Establish an encrypted Site-to-Site VPN between your Azure virtual network and your Collate environment so Collate can reach data sources in Azure without the public internet.

# Connect Collate to your Azure network over Site-to-Site VPN

Collate SaaS runs in AWS. This guide connects your Azure virtual network to it over an encrypted IPSec Site-to-Site VPN, so Collate can reach data sources that live in your Azure network, such as a database with no public access. Traffic is encrypted end to end and runs over two tunnels for high availability.

<Note>
  **Note**: Site-to-Site VPN is available for Collate SaaS instances. Contact your Collate representative to have a VPN provisioned before you begin. Collate exchanges tunnel details with you as part of setup.
</Note>

## How It Works

Collate provisions a VPN gateway on its AWS side and shares the tunnel details with you. On the Azure side you create a VPN gateway, then a local network gateway and a connection for each of Collate's two tunnels, following the standard [Azure Site-to-Site VPN](https://learn.microsoft.com/azure/vpn-gateway/tutorial-site-to-site-portal) model:

* Collate provisions the VPN on its side and sends you the two tunnel outside IPs, the inside /30s, and the pre-shared keys.
* You create an Azure VPN gateway and share its public IPs back with Collate.
* You create a local network gateway and a connection for each of Collate's two tunnels.
* Once both connections report Connected, Collate reaches your data sources over the tunnels using their private IPs.

## When to Use This

Site-to-Site VPN is one of a few ways to let Collate read from private data sources. Consider the alternatives too:

* The [Hybrid Runner](/ai-2-0/how-to-guides/deployment/hybrid-runner) runs ingestion inside your own environment, so credentials and data never leave it. This is usually the simplest option and needs no VPN.
* Site-to-Site VPN is a good fit when you'd rather Collate connect directly to your data sources over an encrypted link than run ingestion yourself.

## Before You Begin

Setup starts by contacting Collate support to provision the VPN. You then exchange the following.

**Collate provides you with**:

| Item | Notes |
| - | - |
| Tunnel outside IPs | Two, one per tunnel, your local network gateways point at these |
| Tunnel inside IPv4 CIDRs | A `/30` from the `169.254.0.0/16` range, one per tunnel |
| Collate's private network CIDR | The IPv4 range of your servers inside the Collate VPC, used as the local network gateway address space |
| Pre-shared key (PSK) | One per tunnel, for the connection |

**You provide Collate with**:

| Item | Why it's needed |
| - | - |
| The IPv4 CIDR ranges routed through the tunnel | The Azure networks Collate needs to reach, such as your database subnets |
| Your Azure VPN gateway public IPs | Both of them, so Collate points its side at your gateway |

### Azure Prerequisites

Before you create the VPN gateway, confirm your Azure network meets these requirements:

* A virtual network with a dedicated gateway subnet (a `/27` is recommended).
* A route table on your workload subnets with **Propagate gateway routes** enabled.

## Step 1: Create the Azure VPN Gateway

The VPN gateway is the Azure resource that terminates the tunnels. It deploys into the gateway subnet and takes several minutes to provision.

1. In the [Azure portal](https://portal.azure.com/), create a **Virtual network gateway**.
2. For **Gateway type**, choose **VPN**, and for **VPN type**, choose **Route-based**.
3. Place it in the virtual network and gateway subnet from the prerequisites.
4. Enable **Active-active mode** so the gateway has two public IPs, one per tunnel, for high availability.
5. Create the gateway, then share both **public IP addresses** with Collate.

## Step 2: Create the Local Network Gateway for Tunnel 1

The local network gateway describes Collate's end of the tunnel to Azure.

1. Create a **Local network gateway**.
2. For **IP address**, enter Collate's tunnel 1 outside IP.
3. For **Address space**, enter Collate's private network CIDR.
4. Create the local network gateway.

## Step 3: Create the Connection for Tunnel 1

1. On the VPN gateway, create a **Connection**.
2. For **Connection type**, choose **Site-to-site (IPsec)**.
3. For the local network gateway, select the one from Step 2.
4. For **Shared key (PSK)**, enter Collate's tunnel 1 pre-shared key.
5. Create the connection and wait for its status to read **Connected**.

## Step 4: Add Tunnel 2 for High Availability

Repeat the pattern for Collate's second tunnel so the link survives one tunnel going down.

1. Create a second **Local network gateway** with Collate's tunnel 2 outside IP and the same address space.
2. Create a second **Connection** on the VPN gateway using that local network gateway and Collate's tunnel 2 pre-shared key.
3. Wait for the second connection to read **Connected**.

## Troubleshooting

<Accordion title="Tunnel Is UP but There's No Connectivity to My Databases">
  The tunnel is healthy but traffic isn't reaching the data source. Check two things: the network security group on the data source allows inbound traffic from Collate's private network CIDR on the right port, and your route table has a route to Collate's network via the gateway with **Propagate gateway routes** enabled.
</Accordion>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.