Unifi VPN to Azure, what are you using in Azure (vnetgw, NVA, etc)?

I’m curious, what are you using as the VPN endpoint in Azure?

I’m using a Virtual Network Gateway, I think the SKU is v2 (need it for certain features), and it costs $500/month. I’m looking for more cost-effective options, obviously.

I know of a peer company that is all Meraki, and they are about to deploy a Meraki Virtual Firewall as the VPN endpoint, at considerably lower cost.

I am a mixture of Meraki and Palo Alto, looking into the option of a PAN virtual firewall in Azure. I’m considering Ubiquity in 12-24 months in a network refresh cycle (eliminating Meraki for sure, but likely removing both Meraki and PAN), but my connection to Azure is the main thing I need to figure out (now and the future).

I know I could run a VM in Azure with OpnSense, but I have eliminated this option. This is a corporate environment, with a small IT shop and limited networking/firewall skills. It is already a challenge to have 2 different firewalls (Meraki and PAN).

Anyway, thanks for any response (including an Azure VM with OpnSense)!

This might be worth a read.

Thank you, but this is exactly what I currently have, and what I am trying to replace.

My fault. I misunderstood what you were after. You can look at pfsense. It is in then official marketplace.

Thank you, but this is basically the same as the OpnSense solution that I have eliminated. I know it is possible, but it has 2 problems:

  1. It is not much of a cost savings, perhaps 50%
  2. It is yet another firewall platform that I don’t want to train my people on (at least not right now).

Here’s the thing, you don’t want to use cloud native VPN tech, but also you can’t use a VM because you don’t want to use a firewall other than Unifi.

This means you don’t have anymore options, those are the choices for cloud connectivity unless you consider full SASE or something but that is going to add complexity that is beyond just having another firewall.

What you should do, IMO, is ask yourself this:

  1. How much does it matter that you have 2 different firewalls? If it’s just for a VPN setup it should not be that complex
  2. If it’s a big deal, maybe don’t consider Unifi for your firewalls and go with something more proper enterprise throughout and get Netgate units or something along those lines.

Unifi is nice, but they still lack a ton, and aren’t the most stable, so IMO a corporate environment that needs more than just basic internet and VLANs for cameras, should use something else. Which, judging by the fact that you need a VPN to Azure at all, tells me your setup is more complex than what I just described.

Thanks for the response. At the end of the day, you are right that Unifi is just not ready for an org that is still as small as mine.

I also looked deeper into PAN and Meraki Virtual firewalls. When my quote for Meraki was pretty close to the cost of my VNetGW, I asked more questions. Turns out the peer company was using the “small” size virtual firewall, hence the low cost. I need the “large” size for my daily backup and DR requirements.

The smallest PAN virtual firewall was roughly the same spec and cost as the “large” Meraki.

For now, I am going to stick with the VNetGW, there just isn’t enough cost savings to make the change.

I have a couple of projects in the works that should drastically reduce my backup and DR needs. In a couple of years, the environment might be basic internet and a VLAN for a handful of server VMs (plus that pesky connection to Azure for a BI app).

I’ll put it a different way. The peer company just spent x dollars on Meraki gear. I built a unfi cart with equivalent or better (higher speed, or POE, etc.) and it was 1/3 the cost of Meraki.

I’m just about simple enough that Unifi fits, and I would probably use a VNetGW (maybe smaller SKU) when I need to do a network refresh.

Yeah agreed with you on all points here, this makes the most sense.

Unifi certainly has come a LONG way in the firewall department, especially recently, but the stability is still a big issue for any place that needs high uptime IMO.