Hybrid Connectivity — ExpressRoute, FastConnect and VPN in Practice
Start with the connection, not the circuit
Write down the source, destination, protocols, permitted audience and business operation. Then record peak traffic, acceptable latency, interruption tolerance and operating owners. Those requirements determine whether a connection is suitable; a “production” label alone does not select ExpressRoute or FastConnect.
| Approach | What to evaluate |
|---|---|
| Site-to-site VPN | Tunnel endpoints, encryption, internet or underlying transport, gateway capacity and route convergence |
| Private connectivity | Provider path, circuit and gateway limits, lead time, reachability, encryption and recurring charges |
| Multiple paths | Shared failure points, surviving capacity, routing preference, failover and failback |
A VPN can support production when it meets the requirements. A private circuit can still be the wrong fit if its cost, provisioning dependencies or recovery behaviour do not.
Private does not mean application-to-application encryption
ExpressRoute keeps the supported connection off the public internet, but confidentiality still depends on the chosen protection. Application TLS, IPsec and supported MACsec designs protect different parts of the path. MACsec does not by itself promise encryption between the application endpoints. Check the current ExpressRoute FAQ and the selected service configuration.
Specify the endpoints of encryption in the design. “Encrypted network” is incomplete if data is decrypted at a gateway and crosses another unprotected segment.
Understand the provider’s actual connection model
OCI FastConnect has partner, third-party-provider and colocation models. Private and public peering serve different destinations. A cross-connect group aggregates physical links; it should not be described as a guarantee that links span independent locations. Select redundancy at the appropriate devices, sites and carrier paths. Oracle’s FastConnect overview defines those constructs.
Obtain lead times and charges for the actual arrangement. Internet egress allowances should not be used as a shortcut for FastConnect pricing. Include provider services, ports, gateways, processing and the supported data-transfer meters for that route.
Count failure domains, not lines
A pair of logical connections might share your edge router, the building entrance, a duct, carrier equipment or a peering location. Ask which failure each additional path is intended to survive.
Microsoft’s ExpressRoute disaster-recovery guidance considers geographically redundant circuits and customer-side diversity. A single circuit’s built-in redundancy and protection from losing a whole location are different claims.
Use a failure matrix:
| Simulated failure | Evidence to collect |
|---|---|
| One edge device unavailable | Surviving forwarding path and application result |
| Primary transport unavailable | Detection and convergence times, new and existing sessions |
| Primary location unavailable | Alternate location and its dependencies remain usable |
| Reduced backup capacity | Priority transactions still meet the agreed degraded-service target |
Treat failure injection as an approved exercise. A route change can affect workloads outside the one you intended to test.
Measure the end-to-end chain
Circuit speed, gateway capacity, firewall throughput, VM networking and destination-service limits all matter. Test representative transaction sizes, concurrent connections and encryption settings. Observe single-flow behaviour separately from aggregate throughput.
For an illustrative file-transfer workload, record bytes delivered and elapsed time at the application. Compare a quiet period with a busy period and repeat through the backup path. Do not infer the application result from a carrier port counter alone.
Make the fallback operational
An ExpressRoute-to-VPN backup is a supported Azure pattern, but the passive path needs active maintenance. Check the documented VPN backup behaviour, route preferences and actual reachable prefixes.
Record who owns DNS, route advertisements, inspection rules and carrier escalation. Test failback as well as failover; a restored primary connection should not create unexpected asymmetric flows.
Prepare the connectivity brief, agree the recovery target, and include both paths in the cost estimate.