How can we migrate a ExpressRoute Gateway from Basic SKU Public IP to Standard SKU Public IP if the mirgration fails due to a too small gateway network?

Ulrich Haake 20 Reputation points
2025-09-29T11:50:53.3566667+00:00

Gateway SKU Migration

  1. Validation: OK
  2. Preparation: FAILS
    { "code": "GatewaySubnetTooSmallForVMSSGatewaySku", "message": "To deploy a zone-redundant/zonal gateway, the GatewaySubnet must be /27 or larger. Current subnet ... ... /GatewaySubnet referenced by gateway /subscriptions/... /Microsoft.Network/virtualNetworkGateways/ ... has size 10.x.x.x**/28**.", "details": [] }

The size of the network should be /27 ... how can we change this or bypass the error?

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
{count} votes

Answer accepted by question author
  1. Praveen Bandaru 9,250 Reputation points Microsoft External Staff Moderator
    2025-09-30T13:32:05.92+00:00

    Hello Ulrich Haake
    Thank you for your response. I believe there may have been a misunderstanding regarding my previous comment.

    1.Delete the current GatewaySubnet 10.x.x.x/28. 2.Create a new GatewaySubnet 10.x.x.x/27 (same subscritpion, same ressource group, same virtual network).

    You cannot delete the Gateway Subnet directly. Azure prevents deletion of the Gateway Subnet if a gateway is still using it.

    You need to delete the Virtual Network Gateway (ExpressRoute Gateway) before you can remove the Gateway Subnet.

    This means you will need to delete your existing VPN gateway and create a new Virtual Network Gateway (ExpressRoute Gateway). If you delete the Gateway subnet, you can create a new gateway subnet and then set up a new VPN gateway.

    The new subnet is automatically "attached" to the ExpressRoute Gateway (and whatever) and we can proceed with migration?

    No, that's not possible. You'll need to deploy a new ExpressRoute gateway, as resizing a subnet directly isn't supported. To proceed, you'll have to delete and recreate the VPN Gateway (ExpressRoute gateway) and Gateway Subnet as well, which is the only available method. Please note that this process will cause downtime, so make sure to schedule it outside of business hours.

    Check the below document for Upcoming projected changes:

    https://v4.hkg1.meaqua.org/en-us/azure/vpn-gateway/whats-new#upcoming-projected-changes


    Hope the above answer helps! Please let us know do you have any further queries.

    Please do not forget to "accept answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.