14 — Comparatif des SKU (AZ-700)
Fiche de synthèse : 1 table par service avec LA différence clé entre SKU. Valeurs vérifiées MS Learn (consolidées des fiches 1, 4-11).
1. VPN Gateway (S2S / P2S)
| SKU | Throughput (Gen1 / Gen2) | S2S tunnels | P2S users (OpenVPN/IKEv2) | BGP | AZ | Active-Active |
|---|---|---|---|---|---|---|
| Basic | 100 Mbps | 10 | 128 SSTP only | ❌ | ❌ | ❌ |
| VpnGw1AZ | 650 Mbps (Gen1) | 30 | 250 | ✅ | ✅ | ✅ |
| VpnGw2AZ | 1 / 1.25 Gbps | 30 | 500 | ✅ | ✅ | ✅ |
| VpnGw3AZ | 1.25 / 2.5 Gbps | 30 | 1000 | ✅ | ✅ | ✅ |
| VpnGw4AZ | 5 Gbps (Gen2 only) | 100 | 5000 | ✅ | ✅ | ✅ |
| VpnGw5AZ | 10 Gbps (Gen2 only) | 100 | 10000 | ✅ | ✅ | ✅ |
Diff clé : Basic = dev/test (ni BGP, ni AZ, ni active-active, ni OpenVPN). Tout VpnGwXAZ = prod (BGP + zone-redundant + active-active). VpnGw4AZ/5AZ existent uniquement en Gen2. SSTP plafonné à 128 conn. quel que soit le SKU.
- Policy-based (IKEv1, static) : 1 seul tunnel, pas de BGP/P2S/active-active/coexistence ER. Route-based (IKEv2, dynamic) : tout le reste (99% des cas).
- 🚨 Type policy↔route figé à la création (delete+recreate pour changer). Migration Basic→AZ = delete+recreate.
- Legacy : Standard/HighPerf retirés 30 juin 2026 ; VpnGw1-5 non-AZ création bloquée depuis 1er nov 2025.
2. P2S — Tunnel types × Authentification
| Tunnel | Protocole / Port | Plateformes | Auth supportée |
|---|---|---|---|
| OpenVPN | SSL/TLS · TCP 443 | Win/Mac/Linux/iOS/Android (cross-platform) | Cert · Entra ID · RADIUS |
| IKEv2 | IPsec · UDP 500+4500 | Win/Mac/iOS | Cert · RADIUS (pas Entra) |
| SSTP | TLS · TCP 443 | Windows only | Cert · RADIUS (pas Entra) |
Diff clé : 🚨 Entra ID = OpenVPN uniquement. OpenVPN passe les firewalls (443) et est cross-platform → recommandé par défaut. SSTP en retraite (31 mars 2026 : plus activable ; 31 mars 2027 : connexions suspendues), limite 128 conn.
| Auth | Avantage | Limite |
|---|---|---|
| Azure Certificate | Pas de dépendance externe | Gestion certs lourde, révocation par thumbprint individuel |
| Entra ID | MFA + Conditional Access, révocation centralisée | OpenVPN only |
| RADIUS | Réutilise l'AD on-prem (NPS) | Nécessite serveur RADIUS/NPS |
3. ExpressRoute — Circuit + Gateway
Circuit SKU
| SKU | Portée | VNets max | Global Reach |
|---|---|---|---|
| Local | 1-2 régions dans/près de la metro de peering | — | ❌ |
| Standard | 1 geopolitical area (ex Europe) | 10 | ❌ |
| Premium | Global (toutes régions monde) | jusqu'à 100 | ✅ |
Diff clé : portée géographique + nb VNets. Local = data transfer inclus (coût mini, POC/prod locale). Premium obligatoire pour Global Reach cross-geo + >10 VNets.
ExpressRoute Gateway SKU
| SKU | Débit | VMs max | Routes apprises | FastPath |
|---|---|---|---|---|
| Standard (legacy) | 1 Gbps | 2 000 | 4 000 | ❌ |
| HighPerformance (legacy) | 2 Gbps | 4 500 | 9 500 | ❌ |
| UltraPerformance | 10 Gbps | 11 000 | 9 500 | ✅ |
| ErGw1AZ | 1 Gbps | 2 000 | 4 000 | ❌ |
| ErGw2AZ | 2 Gbps | 4 500 | 9 500 | ❌ |
| ErGw3AZ | 10 Gbps | 11 000 | 9 500 | ✅ |
| ErGwScale | 1 Gbps/SU jusqu'à 40 Gbps (≤40 SU) | 11 000 | 9 500 | ✅ (≥10 SU) |
Diff clé : 🚨 FastPath = UltraPerformance / ErGw3AZ / ErGwScale (≥10 SU) uniquement. SKU AZ = zone-redundant active-active en prod. Ne pas confondre VMs max (11 000) et routes apprises (4 000 ou 9 500).
4. Virtual WAN
| SKU | Features |
|---|---|
| Basic | S2S VPN only — pas de hub-to-hub, pas d'ER, pas de P2S, pas de NVA, pas de Routing Intent |
| Standard | Tout : S2S + P2S + ER + hub-to-hub + Secured Hub (Azure Firewall) + NVA + Routing Intent + custom routing |
Diff clé : Basic = S2S only sans transitivité. Standard obligatoire pour tout enterprise. 🚨 Upgrade Basic→Standard irréversible ; downgrade impossible.
5. Azure Firewall
| SKU | Débit | Threat Intel | IDPS | TLS inspection | Web Categories | Use case |
|---|---|---|---|---|---|---|
| Basic | ~250 Mbps | Alert only | ❌ | ❌ | ❌ | TPE / lab (2 instances fixes, pas d'autoscale) |
| Standard | ≤30 Gbps | Alert / Alert+Deny | ❌ | ❌ | ✅ (sur FQDN) | Prod normale (90% des cas) |
| Premium | ≤100 Gbps | Alert+Deny | ✅ | ✅ | ✅ (sur URL complète) | Compliance gov/fintech/santé |
Diff clé : 🚨 IDPS + TLS inspection = Premium uniquement. Basic A bien le Threat Intel mais mode Alert seulement (pas Alert+Deny). Web Categories en Standard ET Premium (Standard = FQDN, Premium = URL full-path). URL filtering full-path = Premium-only.
6. Application Gateway
| SKU | Statut 2026 | Autoscale | AZ | WAF | Note |
|---|---|---|---|---|---|
| 🚨 RETIRÉ 28 avril 2026 | ❌ | ❌ | v1 | Migrer vers v2 | |
| Standard_v2 | Recommandé | ✅ | ✅ | ❌ | Header/URL rewrite, static VIP, provisioning rapide |
| WAF_v2 | Recommandé sécu | ✅ | ✅ | ✅ (CRS + custom + Bot Manager) | Standard_v2 + WAF |
Diff clé : v1 retiré → tout en v2. WAF_v2 = seul à porter le WAF (L7 régional). Scale : Manual (charge prévisible) vs Autoscale (pics, recommandé prod). Subnet dédié /24 recommandé.
7. WAF (Web Application Firewall)
| WAF Front Door | WAF App Gateway | |
|---|---|---|
| Scope | Global (edge anycast) | Régional (1 région) |
| Attaché à | Front Door Std ou Premium | App Gateway WAF_v2 |
| Managed rules | DRS 2.2 / 2.1 (Premium only) ; Standard = custom rules only | CRS 3.2 / 3.1 / 3.0 + DRS |
| Bot protection | Bot Manager (Premium) | — |
| Granularité | Endpoint / route | Listener / path (plus fin) |
| Body inspection | 128 KB | 2 MB |
Diff clé : 🚨 WAF Front Door Standard = custom rules only ; managed DRS + Bot Manager = Premium. App Gateway = CRS (OWASP) avec granularité par listener/path. 1 WAF policy = 1 type de service (jamais réutilisable entre FD et AGW → defense-in-depth = 2 policies).
| Mode | Effet |
|---|---|
| Detection | Log seulement → phase de tuning (1-2 semaines) |
| Prevention | Bloque → prod |
🚨 Toujours démarrer en Detection, basculer en Prevention après tuning.
8. Front Door
| Tier | Statut | LB global + CDN + SSL | Managed WAF (DRS) | Bot Manager | Private Link to origin |
|---|---|---|---|---|---|
| Standard | Actif | ✅ + custom WAF rules | ❌ | ❌ | ❌ |
| Premium | Actif | ✅ | ✅ (DRS) | ✅ | ✅ |
| 🚨 Retraite 31 mars 2027 | — | — | — | — |
Diff clé : 🚨 Managed DRS + Bot Manager + Private Link to origin = Premium. Standard = custom WAF rules seulement. Classic à migrer avant 31 mars 2027.
9. Load Balancer
| Basic (retiré) | Standard | Cross-region (Global) | |
|---|---|---|---|
| Statut 2026 | 🚨 RETIRÉ 30 sept 2025 | Actif | Tier Global du Standard |
| AZ | ❌ | ✅ | N/A (anycast global) |
| SLA | ❌ | 99.99% | hérité régional |
| Outbound | Open (NSG requis) | Bloqué par défaut (outbound rule ou NAT GW) | — |
| HA Ports | ❌ | ✅ (Internal only) | — |
| Backend pool | VM en Avail. Set / VMSS (300) | VM/VMSS même VNet (1000) | LB régionaux (pas des VMs) |
Diff clé : Basic retiré → tout en Standard. Cross-region = L4 global, IP anycast statique, failover instant (proxy, pas DNS), préserve l'IP client. 🚨 Cross-region incompatible avec un Gateway LB attaché. Public (IP publique) vs Internal/ILB (IP privée, tier app→DB, SQL AG listener). HA Ports = Standard + Internal uniquement (pas Public).
10. Public IP
| SKU | Statut 2026 | Allocation | Inbound par défaut | Zones |
|---|---|---|---|---|
| Basic | 🚨 RETIRÉ 30 sept 2025 | Dynamic / Static | Ouvert | ❌ |
| Standard | Actif | Static obligatoire | Bloqué (sauf NSG) | Zone-redundant / Zonal / No-zone |
Diff clé : Standard = Static forcé (Dynamic n'existait qu'en Basic). Le SKU de la Public IP doit matcher celui du LB / VPN GW / NAT GW associé.
11. NAT Gateway
| SKU | Zone | HA |
|---|---|---|
| Standard | Zonal (zone précise ou no-zone) | SPOF zonal : si la zone tombe, SNAT perdu |
| StandardV2 | Zone-redundant | Réparti sur toutes les AZ, survit à une panne de zone |
Diff clé : V1 Standard = zonale (SPOF) ; StandardV2 = zone-redundant. NAT GW gagne toujours en outbound vs Public IP de VM. 🚨 Ne s'attache pas à un subnet avec des ressources Basic SKU.
12. Bastion
| SKU | Instances | Features clés |
|---|---|---|
| Developer | Partagé MS | Gratuit, 1 connexion, dev/test only |
| Basic | 2 fixes | RDP/SSH via portail, pas de host scaling |
| Standard | 2-50 (host scaling) | + native client, shareable links, IP-based, custom ports, file transfer |
| Premium | 2-50 | + session recording, private-only deployment |
Diff clé : host scaling (>40 sessions RDP) à partir de Standard. Session recording = Premium. 🚨 Upgrade Basic→Standard IRRÉVERSIBLE → choisir Standard d'emblée si scaling/features prévus. ~20 RDP / ~40 SSH par instance.
13. DDoS Protection
| IP Protection | Network Protection | |
|---|---|---|
| Portée | Par IP publique (granulaire) | Toutes les IP publiques protégées du tenant |
| Use case | Quelques IP à protéger, coût à l'IP | Couverture large, WAF mitigation cost protection, rapid response |
Diff clé : IP Protection = facturation/protection par IP ; Network Protection = plan couvrant l'ensemble des Public IP (+ features avancées : cost protection, support DDoS Rapid Response).
⚠️ Pièges SKU (récap exam)
- Matching SKU obligatoire : Public IP Standard ↔ Load Balancer Standard ↔ NAT Gateway Standard. Un mismatch (ex VM avec Public IP Basic) bloque l'attachement → upgrader ou retirer la Public IP.
- NAT GW ⊕ Basic SKU : NAT Gateway (Standard/V2) refuse un subnet contenant des ressources Basic (Public IP Basic, Basic LB).
- Upgrades irréversibles : Bastion Basic→Standard ; vWAN Basic→Standard ; VPN Gateway type policy↔route (delete+recreate). Migration VPN Basic→AZ = delete+recreate (coupure).
- FastPath = UltraPerformance / ErGw3AZ / ErGwScale ≥10 SU seulement (jamais sur Standard/HighPerf/ErGw1AZ/ErGw2AZ).
- Entra ID auth P2S = OpenVPN only (jamais IKEv2 ni SSTP).
- IDPS + TLS inspection = Azure Firewall Premium only ; Threat Intel Alert+Deny dès Standard (Basic = Alert seulement).
- Managed WAF (DRS/Bot Manager) + Private Link origin = Front Door Premium (Standard = custom rules only).
- HA Ports = Standard + Internal LB only (le "Public LB + HA Ports" est un distracteur faux).
- Cross-region LB ⊕ Gateway LB : incompatibles.
- Retraits 2026-2027 : Public IP Basic & LB Basic (30 sept 2025), VPN Standard/HighPerf (30 juin 2026), App Gateway v1 (28 avril 2026), SSTP P2S (31 mars 2026 activation / 31 mars 2027 connexions), Front Door Classic (31 mars 2027).