Welcome to Microsoft Q&A and thank you for your questions!
To establish a reliable and scalable VPN Gateway connection between Azure, AWS, and potentially GCP, you're right to consider allocating a /27 subnet for the VPN Gateway itself, as that’s the minimum recommended size. However, given that you'll be using the gateway not only for console access but also for AI services (like Azure GenU and AWS Bedrock
Connections & Tunnels: Each site-to-site VPN (e.g., AWS now, GCP later) uses gateway IPs for tunnels. Active-active HA adds more (2 instances). /27 works for 1-2 basic connections, but 3+ or HA pushes toward /26 (64 IPs).
AI/Traffic Load: Bedrock/GenU access means potential high throughput—focus on VpnGw2+ SKUs for bandwidth, but subnet needs room for gateway services.
Future-Proofing: MS recommends /26+ for complex setups (e.g., ExpressRoute coexist needs even larger). No NSGs/UDRs on GatewaySubnet.
Steps to Implement
Create VNet > Add GatewaySubnet (/26, e.g., 10.1.255.0/26)—name must be exact.
Deploy VPN Gateway (VpnGw2AZ+ for zones/HA) on it—takes ~45 mins.
Add connections: Local Network Gateway for AWS/GCP public IPs/ranges, then Site-to-Site (IPsec). Match shared keys.
Test: Portal > Gateway > Connections (aim for "Connected"). Monitor limits. https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-limits
Key Sizing Factors
Connections & Tunnels: Each site-to-site VPN (e.g., AWS now, GCP later) uses gateway IPs for tunnels. Active-active HA adds more (2 instances). /27 works for 1-2 basic connections, but 3+ or HA pushes toward /26 (64 IPs).
AI/Traffic Load: Bedrock/GenU access means potential high throughput—focus on VpnGw2+ SKUs for bandwidth, but subnet needs room for gateway services.
Futureproofing: MS recommends /26+ for complex setups (e.g., ExpressRoute coexist needs even larger). No NSGs/UDRs on GatewaySubnet.
We hope the above answers will be of great help to you in resolving the issue. If not, please contact us for any explanation.
If the provided information answer your query, do click "Upvote" and "Accept Answer", it will help others who might be facing similar challenges.
Thanks
Jose Premnath