Intermediate Architecture

Hybrid Connectivity — ExpressRoute, FastConnect and VPN in Practice

Start with the connection, not the circuit

Write down the source, destination, protocols, permitted audience and business operation. Then record peak traffic, acceptable latency, interruption tolerance and operating owners. Those requirements determine whether a connection is suitable; a “production” label alone does not select ExpressRoute or FastConnect.

ApproachWhat to evaluate
Site-to-site VPNTunnel endpoints, encryption, internet or underlying transport, gateway capacity and route convergence
Private connectivityProvider path, circuit and gateway limits, lead time, reachability, encryption and recurring charges
Multiple pathsShared failure points, surviving capacity, routing preference, failover and failback

A VPN can support production when it meets the requirements. A private circuit can still be the wrong fit if its cost, provisioning dependencies or recovery behaviour do not.

Private does not mean application-to-application encryption

ExpressRoute keeps the supported connection off the public internet, but confidentiality still depends on the chosen protection. Application TLS, IPsec and supported MACsec designs protect different parts of the path. MACsec does not by itself promise encryption between the application endpoints. Check the current ExpressRoute FAQ and the selected service configuration.

Specify the endpoints of encryption in the design. “Encrypted network” is incomplete if data is decrypted at a gateway and crosses another unprotected segment.

Understand the provider’s actual connection model

OCI FastConnect has partner, third-party-provider and colocation models. Private and public peering serve different destinations. A cross-connect group aggregates physical links; it should not be described as a guarantee that links span independent locations. Select redundancy at the appropriate devices, sites and carrier paths. Oracle’s FastConnect overview defines those constructs.

Obtain lead times and charges for the actual arrangement. Internet egress allowances should not be used as a shortcut for FastConnect pricing. Include provider services, ports, gateways, processing and the supported data-transfer meters for that route.

Count failure domains, not lines

A pair of logical connections might share your edge router, the building entrance, a duct, carrier equipment or a peering location. Ask which failure each additional path is intended to survive.

Microsoft’s ExpressRoute disaster-recovery guidance considers geographically redundant circuits and customer-side diversity. A single circuit’s built-in redundancy and protection from losing a whole location are different claims.

Use a failure matrix:

Simulated failureEvidence to collect
One edge device unavailableSurviving forwarding path and application result
Primary transport unavailableDetection and convergence times, new and existing sessions
Primary location unavailableAlternate location and its dependencies remain usable
Reduced backup capacityPriority transactions still meet the agreed degraded-service target

Treat failure injection as an approved exercise. A route change can affect workloads outside the one you intended to test.

Measure the end-to-end chain

Circuit speed, gateway capacity, firewall throughput, VM networking and destination-service limits all matter. Test representative transaction sizes, concurrent connections and encryption settings. Observe single-flow behaviour separately from aggregate throughput.

For an illustrative file-transfer workload, record bytes delivered and elapsed time at the application. Compare a quiet period with a busy period and repeat through the backup path. Do not infer the application result from a carrier port counter alone.

Make the fallback operational

An ExpressRoute-to-VPN backup is a supported Azure pattern, but the passive path needs active maintenance. Check the documented VPN backup behaviour, route preferences and actual reachable prefixes.

Record who owns DNS, route advertisements, inspection rules and carrier escalation. Test failback as well as failover; a restored primary connection should not create unexpected asymmetric flows.

Prepare the connectivity brief, agree the recovery target, and include both paths in the cost estimate.

References