You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Terraform配置Azure点到站点VPN时遇BgpPeeringAddress修改错误

配置Azure点到站点VPN时遇到VirtualNetworkGatewayBgpPeeringAddressCannotBeModified错误

错误信息

│ Error: Creating/Updating Virtual Network Gateway: (Name "vpng-connectivity-shared-centralus-001" / Resource Group "rg-connectivity-shared-centralus-001"): network.VirtualNetworkGatewaysClient#CreateOrUpdate: Failure sending request: StatusCode=400 -- Original Error: Code="VirtualNetworkGatewayBgpPeeringAddressCannotBeModified" Message="The BgpPeeringAddress for the virtual network gateway /subscriptions/xxxx/resourceGroups/rg-connectivity-shared-centralus-001/providers/Microsoft.Network/virtualNetworkGateways/vpng-connectivity-shared-centralus-001 cannot be modified" Details=[]
│ 
│   with module.create_connectivity_hub_subscription.azurerm_virtual_network_gateway.connectivity-hub-vnet-gateway,
│   on ../../Azure_Terraform_Modules/connectivity_subscription/connectivity_subscription.tf line 558, in resource "azurerm_virtual_network_gateway" "connectivity-hub-vnet-gateway":
│  558: resource "azurerm_virtual_network_gateway" "connectivity-hub-vnet-gateway" {
│ 
╵
##[error]Bash exited with code '1'.

配置代码

resource "azurerm_virtual_network_gateway" "connectivity-hub-vnet-gateway" {
  name                = "vpng-${var.subscription_type}-shared-${var.location}-001"
  location            = var.location
  resource_group_name = module.create_rg.rg_name

  type     = "Vpn"
  vpn_type = "RouteBased"

  active_active = false
  enable_bgp    = false
  sku           = "VpnGw1"

  ip_configuration {
    name                          = "vnetGatewayConfig"
    public_ip_address_id          = azurerm_public_ip.connectivity-hub-vpn-gateway1-pip.id
    private_ip_address_allocation = "Dynamic"
    subnet_id                     = module.create_gateway_subnet.subnet_id
  }

  vpn_client_configuration {
    address_space = ["172.16.0.0/16"]
    root_certificate {
      name = "ROOTCERT"
      public_cert_data = <<EOF
      MIIC3zCCAcegAwIBAgIQJdWvUysG/oxPlBZu2cCi1DANBgkqhkiG9w0BAQsFADAS
      EOF 
    }
  }

  depends_on = [azurerm_public_ip.connectivity-hub-vpn-gateway1-pip, module.create_gateway_subnet]
  tags       = var.tags
}

解决方法

原因分析

该错误的核心原因是:目标虚拟网络网关已在Azure中存在,且之前的配置启用过BGP。Azure不允许直接修改已存在网关的BGP对等地址相关属性,尤其是从启用BGP切换到禁用BGP的场景。

可行方案

  • 方案1:删除现有网关后重新部署(推荐)

    1. 通过Azure门户或Azure CLI删除已存在的虚拟网络网关vpng-connectivity-shared-centralus-001
    2. 清理Terraform状态,执行以下命令移除状态中对应的网关记录:
      terraform state rm module.create_connectivity_hub_subscription.azurerm_virtual_network_gateway.connectivity-hub-vnet-gateway
      
    3. 重新执行terraform apply部署新的网关
  • 方案2:保留BGP配置(仅适用于业务允许的场景)
    如果业务可以接受启用BGP,将配置中的enable_bgp改为true,并补充BGP设置块(示例如下),避免修改已有的BGP相关属性:

    bgp_settings {
      asn               = 65515
      bgp_peering_address = "10.0.0.127"
    }
    

    注意:BGP对等地址需要在网关子网的Cidr范围内。

注意事项

  • 删除网关会导致依赖该网关的所有VPN连接中断,操作前需确认业务维护窗口
  • 确保Terraform状态与实际Azure资源状态一致,避免后续部署出现资源冲突

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 00:15:45