使用Terraform配置Azure点到站点VPN时遇BgpPeeringAddress修改错误
配置Azure点到站点VPN时遇到VirtualNetworkGatewayBgpPeeringAddressCannotBeModified错误
错误信息
│ Error: Creating/Updating Virtual Network Gateway: (Name "vpng-connectivity-shared-centralus-001" / Resource Group "rg-connectivity-shared-centralus-001"): network.VirtualNetworkGatewaysClient#CreateOrUpdate: Failure sending request: StatusCode=400 -- Original Error: Code="VirtualNetworkGatewayBgpPeeringAddressCannotBeModified" Message="The BgpPeeringAddress for the virtual network gateway /subscriptions/xxxx/resourceGroups/rg-connectivity-shared-centralus-001/providers/Microsoft.Network/virtualNetworkGateways/vpng-connectivity-shared-centralus-001 cannot be modified" Details=[] │ │ with module.create_connectivity_hub_subscription.azurerm_virtual_network_gateway.connectivity-hub-vnet-gateway, │ on ../../Azure_Terraform_Modules/connectivity_subscription/connectivity_subscription.tf line 558, in resource "azurerm_virtual_network_gateway" "connectivity-hub-vnet-gateway": │ 558: resource "azurerm_virtual_network_gateway" "connectivity-hub-vnet-gateway" { │ ╵ ##[error]Bash exited with code '1'.
配置代码
resource "azurerm_virtual_network_gateway" "connectivity-hub-vnet-gateway" { name = "vpng-${var.subscription_type}-shared-${var.location}-001" location = var.location resource_group_name = module.create_rg.rg_name type = "Vpn" vpn_type = "RouteBased" active_active = false enable_bgp = false sku = "VpnGw1" ip_configuration { name = "vnetGatewayConfig" public_ip_address_id = azurerm_public_ip.connectivity-hub-vpn-gateway1-pip.id private_ip_address_allocation = "Dynamic" subnet_id = module.create_gateway_subnet.subnet_id } vpn_client_configuration { address_space = ["172.16.0.0/16"] root_certificate { name = "ROOTCERT" public_cert_data = <<EOF MIIC3zCCAcegAwIBAgIQJdWvUysG/oxPlBZu2cCi1DANBgkqhkiG9w0BAQsFADAS EOF } } depends_on = [azurerm_public_ip.connectivity-hub-vpn-gateway1-pip, module.create_gateway_subnet] tags = var.tags }
解决方法
原因分析
该错误的核心原因是:目标虚拟网络网关已在Azure中存在,且之前的配置启用过BGP。Azure不允许直接修改已存在网关的BGP对等地址相关属性,尤其是从启用BGP切换到禁用BGP的场景。
可行方案
方案1:删除现有网关后重新部署(推荐)
- 通过Azure门户或Azure CLI删除已存在的虚拟网络网关
vpng-connectivity-shared-centralus-001 - 清理Terraform状态,执行以下命令移除状态中对应的网关记录:
terraform state rm module.create_connectivity_hub_subscription.azurerm_virtual_network_gateway.connectivity-hub-vnet-gateway - 重新执行
terraform apply部署新的网关
- 通过Azure门户或Azure CLI删除已存在的虚拟网络网关
方案2:保留BGP配置(仅适用于业务允许的场景)
如果业务可以接受启用BGP,将配置中的enable_bgp改为true,并补充BGP设置块(示例如下),避免修改已有的BGP相关属性:bgp_settings { asn = 65515 bgp_peering_address = "10.0.0.127" }注意:BGP对等地址需要在网关子网的Cidr范围内。
注意事项
- 删除网关会导致依赖该网关的所有VPN连接中断,操作前需确认业务维护窗口
- 确保Terraform状态与实际Azure资源状态一致,避免后续部署出现资源冲突
内容的提问来源于stack exchange,提问作者One Developer
相关产品推荐
相关产品推荐

