惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024
Comparing Ways to Connect to Microsoft Azure
2022-09-12 · via Megaport Blog

By Paul McGuinness, Head of Solutions Europe

There are several methods of connecting to the popular Cloud Service Provider, but which one is right for your business?

Curious about Microsoft Azure and the best ways to connect? Azure is a hybrid Cloud Service Provider (CSP) with customized, scalable, cloud-based packages. These encompass Software as a Service (SaaS), based on subscription-based software licensing and delivery, Platform as a Service (PaaS), allowing companies to develop, deploy, manage, and update applications, and Infrastructure as a Service (IaaS), providing high-level application programming interfaces (APIs).

Whether you’re part of a multinational corporation or a small startup, you can choose among Azure service plans to meet your needs. Enterprises use these services for artificial intelligence (AI)-based number crunching and analytics, virtual desktop networking, integration with the internet of things (IoT), storage/retrieval, and more.

There are a lot of services to reach in Microsoft Azure but how do you communicate with these services from outside the cloud?

An overview of Azure connections

ExpressRoute and ExpressRoute Direct bypass the public internet, making it attractive to financial corporations and governments, among others. VPN Connections are also a popular way to connect to Microsoft Cloud by facilitating encrypted traffic over the public internet.

Azure Virtual WAN (wide area network) uses hub-and-spoke architecture to connect to Microsoft’s global network, automating branch connectivity and optimizes routing on a vast scale.

There are a lot of scenarios for connectivity where multiple methods may be used together, and it’s worth noting that ExpressRoute and VPN Gateway are two options to reach Azure Virtual WAN.

What is Microsoft ExpressRoute?

ExpressRoute links enterprises to Microsoft data centers through private connections like:

  1. cloud exchange colocation,
  2. any-to-any IP VPNs (usually MPLS), or
  3. point-to-point Ethernet networks.

Connections are secured by on-premises networks or colocation facilities using a third-party connectivity provider’s virtual cross-connection software.

connection diagram

You can use the same ExpressRoute to privately pass your data into your Virtual Networks via Private Peering and access Microsoft public services via Microsoft Peering. All ExpressRoutes come with a primary and secondary connection, however it’s up to the user if they wish to use both connections. The data rate provisioned on the ExpressRoute will allow you the full data rate capability on both the primary and secondary interfaces. Note that you will need to have both enabled to receive the Microsoft ExpressRoute SLA.

connection diagram

What are the benefits of ExpressRoute?

Dedicated data that bypasses the public internet travels with higher bandwidth and reliability, and lower and more consistent latency. Security is enhanced greatly through this private connection because of the private nature of ExpressRoute and your data not touching the internet. Some enterprises also report cost savings due to significantly lower egress data costs versus the internet.

Specifically, ExpressRoute offers these features as outlined by Microsoft:

  • Layer 3 connectivity between on-premises and Microsoft Cloud through a connectivity provider
  • Connectivity to Microsoft cloud services across all regions in the geopolitical region or to all global regions with the ExpressRoute premium add-on.
  • Dynamic routing between your network and Microsoft via BGP
  • Built-in ExpressRoute redundancy in every peering location for higher reliability
  • ExpressRoute Connection uptime SLA
  • Scalable data rates from 50 Mbps to 10 Gbps.

Onboarding with ExpressRoute

Enterprises peer with Microsoft through an ExpressRoute carrier partner. Order an ExpressRoute circuit, and your connectivity provider extends your network to an ExpressRoute location or peering location. ExpressRoute locations are colocation facilities that host Microsoft Enterprise Edge devices.

There is also an option to encrypt your data over a private ExpressRoute. Using an encrypted ExpressRoute private connection, your data accesses Azure VNets with, as Microsoft explains, “confidentiality, anti-replay, authenticity, and integrity.” The data travels on a site-to-site IPsec/IKE VPN tunnel to and from your networks and Azure VNets, which cross-connect to the Microsoft network. The protocol is direct over a virtual local area network (VLAN) or MPLS.

If enterprises do not wish to use an ExpressRoute partner, they can connect by choosing a regional carrier and connecting via a physical Ethernet connection. Data goes through the supported exchange provider to peer with Microsoft via ExpressRoute Direct.

What is Microsoft ExpressRoute Direct?

With ExpressRoute Direct, Microsoft Cloud customers can connect at global peering locations distributed around the world to reach Microsoft’s global network directly. Connectivity interfaces are either 10 Gbps or 100 Gbps, with various circuit SKU options available up to the interface data rate. This typically means ordering two cross connects from your rack directly to Microsoft’s ExpressRoute Direct interfaces. See Microsoft ExpressRoute Direct for more information.

diagram

Image courtesy of Microsoft. Source

What are the benefits of ExpressRoute Direct?

As with Azure ExpressRoute, using ExpressRoute Direct reduces lag, increases bandwidth, and ensures low latency, giving clients dual 100 Gbps or 10 Gbps connectivity. In addition, enterprise IT teams have Active/Active connectivity at scale, allowing them to manage peering traffic as needed.

Heavily regulated industries, such as banking, government, and retail, sometimes require dedicated and isolated connectivity; ExpressRoute Direct (and Azure ExpressRoute in general) provides the necessary physical isolation. Clients that generate huge amounts of data, such as large retailers, government agencies, and global manufacturers, use ExpressRoute Direct to manage their massive database and storage needs.

It’s worth looking at costs before going down the ExpressRoute Direct path, as it can get expensive – the current cost of a 100Gbps ER Direct Port Pair is over $50,000 per month.

ExpressRoute Peering Locations and Azure regions

When you create an ExpressRoute, you must choose an ExpressRoute peering location and a home region. The peering location is the actual on-ramp location of the Partner NNI with Microsoft. The region, in most cases, does not have to be the same as the Peering Location.

You’ll also need to choose the SKU type of Local, Standard, or Premium. With an ExpressRoute Local circuit SKU, you can connect to resources in Azure regions in the same metro as the peering site. The Standard SKU allows you to connect to all Azure regions in the geopolitical area of the ExpressRoute. If you need to connect to regions outside the geopolitical region of the ExpressRoute, then you’ll need to configure an ExpressRoute Premium SKU circuit. The Premium SKU will allow you to access resources globally across all Azure regions – see example diagram below from Microsoft FAQs.

You can have up to 10 virtual networks connected on a standard ExpressRoute circuit, and up to 100 on a premium ExpressRoute circuit.

diagram

Image courtesy of Microsoft. Source

What is VPN Gateway?

If you don’t want to use ExpressRoute or ExpressRoute Direct, you could choose Azure VPN Gateway. This is a Virtual Network Gateway type that sends encrypted data from on-premises devices over the public internet to the Azure virtual network. The data is encrypted in a private tunnel, as shown in the lower part of the diagram. As with the encryption options offered with ExpressRoute, Azure VPN Gateway gives IT staff control over who has access to data and other assets.

What are the benefits of Azure VPN?

VPN GWs are typically used to connect to Azure with one of two types of VPN – either Site to Site or Point to Site. Each type comes with different features regarding throughput, routing, resilience, use cases, and pricing, which should be considered to select the one that suits your needs.

VPN Gateways are very popular due to their speed of deployment, seamless accessibility from anywhere, encrypted traffic, and ease of use.

Other features include:

  • Users can access the VPN gateway remotely—site to site or point to site—with their devices (laptops, tablets, phones, IoT etc.)
  • Enterprises pay based on the VPN Gateway sizing and the amount of Egress Data sent
  • Bandwidth is up to 10 Gpbs
  • Gateways are easy to set up
  • Scalability and resiliency.

What is Azure Virtual WAN?

Azure offers a single interface through Azure Virtual WAN, meaning networking, security, and routing occur through hub-and-spoke architecture. Setup and configuration are also automated and updated behind the scenes. ExpressRoute and VPN connectivity are two methods you can combine with Virtual WAN to give you access from outside Microsoft Azure.

diagram

Image courtesy of Microsoft. Source

What are the benefits of Azure Virtual WAN?

Clients can diversify ways to connect to cloud destinations and services through Virtual WAN’s hub-and-spoke architecture. Microsoft outlines these benefits:

  • Branch connectivity (via connectivity automation from Virtual WAN Partner devices such as SD-WAN or VPN CPE)
  • Site-to-site VPN connectivity
  • Remote user VPN connectivity (point-to-site)
  • Private connectivity (ExpressRoute)
  • Intracloud connectivity (transitive connectivity for virtual networks)
  • VPN ExpressRoute interconnectivity
  • Routing, Azure Firewall, and encryption for private connectivity.

Which Azure connectivity option is best for you?

Healthcare, financial services, government agencies, retail firms, and manufacturers all rely on Azure services, depending on their needs. Azure offers hybrid cloud, AI, IoT, and mixed reality to quickly scale, improve security, and instantly update software. Governments use Azure to meet compliance standards and lower costs through faster connections, and industries operating globally can unite their workforce and analyze data on a vast scale.

Communicating with Azure cloud services can be fine-tuned among private and public connections. Users can connect their on-premises equipment privately via Microsoft connectivity partners, or connect across the internet via VPNs. Your security needs and data flow, whether you’re part of an industry or public institution, will affect which connection is best.

Choosing ExpressRoute or ExpressRoute Direct

ExpressRoute manages data up to 10 Gbps, with Direct adding a tenfold bump to 100 Gps. For government entities and corporations that need high speeds, low latency, and high reliability, both ExpressRoute products should be considered. ExpressRoute and ExpressRoute Direct provide access to all Azure services and tend to be more expensive than VPN due to the private highway that you’re accessing. There are use cases for high data rate users where the lower egress fees will allow ExpressRoute to pay for itself.

Choosing VPN Gateway

IT managers should consider VPN Gateway for hybrid applications where the traffic between on-premises hardware and the cloud is likely to be light. It is not, however, recommended for high data transfers. At the cost of slightly extended latency, enterprises will receive Azure’s flexibility and access all of Azure’s services. It is also not for organizations with compliance or restrictions on passing their data across the internet. Small organizations appreciate VPN, especially those prototyping and developing products.

Choosing Azure Virtual WAN

For clients needing a higher level of options, and that have a global reach, Virtual WAN might be the answer. It can link a multinational corporation’s branch offices, IoT devices (point of sale or otherwise), and virtual desktops. Data connections can be expanded, reduced, or rerouted seamlessly through partners, OpenVPN clients, and ExpressRoute interfaces.

Moving forward with Azure

No matter which plan you choose, Azure is adaptable. The range of options may seem daunting, but if you triage your crucial levels of data protection, speed, and reliability against your budget, you can start with a solution and modify it later.

Megaport’s Network as a Service (NaaS) solutions enable fast, flexible, and secure connectivity to Azure and other top cloud providers, data center operators, systems integrators, and managed service providers.

Our global Software Defined Network (SDN) helps businesses rapidly and securely connect their networks to services through our easy-to-use portal or open API, reducing operating costs and increasing speed to market compared to traditional networking solutions. To learn more, chat to one of our Solutions Architects.