> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Migrating to Azure VPN Load Balancer Standard SKU

> Follow these steps to migrate from the Basic Azure VPN Load Balancer SKU to the Standard Azure VPN Load Balancer SKU.

Follow these steps to migrate from the Basic Azure VPN Load Balancer SKU to the Standard Azure VPN Load Balancer SKU. Azure is [deprecating the Basic Load Balancer](https://learn.microsoft.com/en-us/answers/questions/1033471/retirement-announcement-basic-load-balancer-will-b) in September 2025.

<Note>
  Aviatrix recommends migrating when you need to replace your VPN gateway. VPN gateways are automatically updated after you perform the procedure in this document.

  You must <a href={"/docs/enterprise/" + "10.1" + "/guides/maintenance/gateway-image-upgrade"}>perform a gateway image upgrade</a> to update your Spoke and Transit gateways to the Standard SKU. You may need to open a ticket with [Aviatrix Support](https://support.aviatrix.com/) to perform your gateway upgrade.
</Note>

1. In your Azure portal, search for "Load balancer" or "public IP addresses" and identify the Azure VPN Basic Load Balancers that need to be migrated.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=17bd9212816dd78875cb1e9980baf81c" alt="Azure Load Balancer search results showing Basic SKU" width="1697" height="450" data-path="images/guides/uservpn/migrate-lb-sku.png" />

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku2.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=7fb71fcc9e7759c61a29631df7ea173c" alt="Azure public IP addresses showing Basic SKU" width="1376" height="268" data-path="images/guides/uservpn/migrate-lb-sku2.png" />

2. In Aviatrix CoPilot, under Cloud Fabric > Use VPN > Users, identify the VPN users connected to the existing load balancer.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku3.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=049360c5efa02de5140dc066174c2d03" alt="CoPilot VPN Users page showing connected users" width="1697" height="396" data-path="images/guides/uservpn/migrate-lb-sku3.png" />

<Note>
  You can also check and detach the VPN users in the Aviatrix Controller under OpenVPN > Users. Remember that the Aviatrix Controller is being deprecated in 2025.
</Note>

3. Detach the VPN users from the associated VPN gateway.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku4.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=0a18b14ec5e416cc73846378852071ca" alt="Detaching VPN users from the VPN gateway" width="1707" height="413" data-path="images/guides/uservpn/migrate-lb-sku4.png" />

4. On the Cloud Fabric > UserVPN > VPN Gateways tab, delete the VPN gateway.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku4a.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=160458559e1ebc3e90d294dcc67718f9" alt="Deleting the VPN gateway" width="1697" height="386" data-path="images/guides/uservpn/migrate-lb-sku4a.png" />

   After all VPN users are detached from the associated VPN gateway, and the VPN gateway itself is deleted, this automatically deletes the Load Balancer from the Azure portal.

5. In Aviatrix CoPilot, under Cloud Fabric > UserVPN > VPN Gateways, recreate the VPN gateway. This automatically creates a new Load Balancer in the Azure portal with a standard SKU.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku4b.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=de6567afe255b4db329fac33f1e270dd" alt="Recreating the VPN gateway" width="1499" height="507" data-path="images/guides/uservpn/migrate-lb-sku4b.png" />

6. On the Cloud Fabric > UserVPN > VPN Users tab, reattach the VPN users to the recreated VPN gateway.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku5.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=4ed41fda177cea881188ed08180ee6c1" alt="Reattaching VPN users to the recreated VPN gateway" width="2258" height="642" data-path="images/guides/uservpn/migrate-lb-sku5.png" />

7. Reissue the certificate for the VPN users.

   <img src="https://mintcdn.com/aviatrix-14b37c43/MwMAaVUDwCmP6YfF/images/guides/uservpn/migrate-lb-sku6.png?fit=max&auto=format&n=MwMAaVUDwCmP6YfF&q=85&s=d8fc4ecb5468a856880ca22fa29c409c" alt="Reissuing VPN user certificates" width="1686" height="429" data-path="images/guides/uservpn/migrate-lb-sku6.png" />

8. For each VPN user, verify the VPN connectivity by trying to connect to the VPN Client.
