ExpressRoute and VPN

David Ramirez Rodriguez 21 Reputation points
2021-06-14T17:02:32.177+00:00

Hello everyone, I need help with the following scenario:

We are implementing a hub and spoke vnet model, and I have the following requirements:

  1. Enable ExpressRoute between the local datacenter and the hub vnet.
  2. Enable security for the data in transit.
  3. Enable Backup connectivity in case the ExpressRoute is not available.

So far I know I can enable a site to site VPN over ExpressRoute, and I know I can enable a VPN over Internet as a backup for the ExpressRoute, but i´m not sure if I can enable both at the same time. Can this scenario be implemented?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,435 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
342 questions
0 comments No comments
{count} votes

Accepted answer
  1. SaiKishor-MSFT 17,216 Reputation points
    2021-06-14T20:20:36.213+00:00

    @David Ramirez Rodriguez Thank you for reaching out to Microsoft Q&A.

    I understand that you are having questions regarding setting up S2S VPN over ER and S2S VPN over Internet both from the same on-premise as primary/backup solutions.

    This is defintely possible to setup but you need BGP enabled on both the tunnels and you need to advertise the same networks on both of them. Please note that the S2S VPN over ER will always be preferred as it will have lower number of hops. Hope this helps.

    Please let us know if you have any further questions and we will be glad to assist you further. Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful