How to Migration Onprem VMware to Azure VMware Solution using Site to Site VPN

Paul 0 Reputation points
2025-06-23T15:01:48.6833333+00:00

Could you please advise on the best approach to migrating on-premises VMware workloads to Azure VMware Solution (AVS) using a Site-to-Site VPN connection via HCX? Is an Azure Firewall necessary for this process? Furthermore, I've found limited Visio diagrams on AVS illustrating this architecture in the Azure Architecture Center.

Azure VMware Solution
{count} votes

1 answer

Sort by: Most helpful
  1. Vamsi Ram Annepu 915 Reputation points Microsoft External Staff Moderator
    2025-06-23T19:19:00.77+00:00

    Hi Paul,
    As you're looking to migrate your on-premises VMware workloads to Azure VMware Solution using a Site-to-Site VPN connection through HCX. Here are some steps and considerations.

    1. Deployment Preparation:
      • Ensure you have your Azure subscription and a resource group ready.
      • Plan your network setup: You need a dedicated Azure Virtual Network with a virtual network gateway for the Site-to-Site connection.
    2. Site-to-Site VPN Setup:
      • Establish a Site-to-Site VPN connection between your on-premises environment and Azure using a Virtual Network Gateway. Ensure that the necessary ports are open:
      • TCP/443 for HCX
      • UDP ports 500 and 4500 for the IPsec VPN.
    3. HCX Deployment:
      • Deploy VMware HCX in your Azure VMware Solution environment. You will create a site pairing between your on-premises HCX Connector and the HCX Cloud Manager running in Azure.
    4. Network Segments:
      • Use NSX-T Data Center to define network segments for various tasks like vMotion and ensure your CIDR range doesn’t overlap with the IP addresses in your on-premises environment.
    5. Migration Tools:
      • You can choose from different migration methodologies, such as live migration, cold migration, or bulk migration, based on your performance needs and downtime tolerance.

    For the Visio diagrams on Azure VMware Solution architecture, you might find limited resources directly in the Azure Architecture Center. However, refer to the documentation provided to design your architecture effectively during migration.

    For more information you can refer the below document
    https://free.blessedness.top/en-us/azure/vpn-gateway/tutorial-site-to-site-portal
    https://free.blessedness.top/en-us/azure/migrate/?view=migrate-classic
    https://free.blessedness.top/en-us/azure/expressroute/expressroute-introduction
    https://free.blessedness.top/en-us/azure/migrate/tutorial-migrate-vmware?view=migrate-classic

    Feel free to reach out if you have any further queries.

    If you found the information useful, please click "Upvote" on the post to let us know.

    Thank You.

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.