Hello @Vivek Pathak ,
I understand that you would like to know if traffic between Microsoft Edge Router and Azure is encrypted in a normal Expressroute circuit or not. If not, then how to encrypt it without using IPSec.
By default, traffic over an ExpressRoute connection is not encrypted.
ExpressRoute supports a couple of encryption technologies to ensure confidentiality and integrity of the data traversing between your network and Microsoft's network.
- IPSec VPN over Private peering --> which you don't want to do.
- MACsec for ExpressRoute Direct ports:
https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-howto-macsec
Refer: https://video2.skills-academy.com/en-us/azure/expressroute/expressroute-about-encryption
MACsec with ExpressRoute Direct provides point-to-point encryption between your device and Microsoft device. So, in this case all traffic such as BGP control traffic, Private peering traffic, MS peering traffic - which includes PaaS service traffic as well, gets encrypted using MACsec keys.
MACsec encrypts all traffic on a physical link with a key owned by one entity (for example, customer). Therefore, it's available on ExpressRoute Direct only.
Kindly let us know if the above helps or you need further assistance on this issue.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.