惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024 Top 5 Cloud and Networking Announcements From Cisco Live 2024
Improve Your Microsoft ExpressRoute Resilience with Megaport
2025-11-04 · via Megaport Blog

By Paul McGuinness, Head of Solutions Europe

Improve ExpressRoute reliability with these deployment models and strategies for stronger cloud resilience, powered by Megaport.

Every year, businesses become even more reliant on their network for the success of their entire operations. For the 350,000+ companies using Microsoft Azure, building resilient, reliable network connectivity to this service is essential.

Microsoft’s private Azure ExpressRoute offers private, low-latency connections to Azure, and when paired with Megaport’s scalable, flexible infrastructure, it becomes even more robust. ExpressRoute has become one of the top global cloud interconnects used by Megaport customers, with Azure adoption accelerating faster than any other cloud provider in the Megaport ecosystem.

Let’s explore how to architect high-resilience ExpressRoute environments using Megaport.

Microsoft Azure connectivity options

Before exploring this topic further, it’s important to understand all the ways organizations can connect to Microsoft Azure. The connectivity method chosen will depend on your organization’s performance, security, and resilience needs.

The public internet offers the simplest and most cost-effective option, suitable for general workloads but with variable latency and reliability. For secure tunneling over the internet, site-to-site VPNs extend on-premises networks into Azure for branch or backup connectivity, while point-to-site VPNs provide individual users and small teams encrypted access.

For enterprises requiring predictable performance and stronger SLAs, ExpressRoute delivers private, dedicated connectivity via a network provider, making it ideal for mission-critical and compliance-driven workloads.

Azure Virtual WAN integrates VPN, SD-WAN, and ExpressRoute into a Microsoft-managed global networking service, ideal for large, distributed enterprises looking to deploy connectivity and optimize traffic routing worldwide.

Together, these options offer network teams a spectrum of connectivity paths, from flexible internet-based access to enterprise-grade, globally resilient private networking.

What is Microsoft ExpressRoute and why is it so widely used by enterprises?

Microsoft ExpressRoute is a dedicated, private connection between your on-premises infrastructure and Microsoft cloud services like Azure, Microsoft 365, and Dynamics 365.

Unlike typical internet-based connectivity, ExpressRoute typically runs over a partner’s network to deliver lower latency, higher reliability, and tighter security. Organizations use ExpressRoute to bypass the public internet, achieving more predictable performance and compliance for workloads including business-critical applications and large-scale data migrations.

ExpressRoute is available in two models: ExpressRoute (partner) and ExpressRoute Direct.

You can use ExpressRoute Direct to connect directly to the Microsoft global backbone through 100 Gbps or 10 Gbps peering sites worldwide. Setting up circuits with ExpressRoute Direct can be challenging and expensive, making the partner model more popular. But where ExpressRoute Direct excels is in delivering high-capacity connectivity designed for large-scale workloads.

Connecting to ExpressRoute through a partner like is so popular because it provides enterprises with a simpler, faster, and more flexible way to access private connectivity without having to build and manage their own physical infrastructure to Microsoft’s edge.

Partners already have established interconnections with Microsoft’s global network at multiple peering locations, which means organizations can provision ExpressRoute circuits quickly (often on-demand) and scale bandwidth as needed.

Enterprises connecting to ExpressRoute via a partner also enjoy benefits like:

  • reduced upfront costs
  • the simplicity of going through a single carrier
  • the ability to easily integrate Azure connectivity into existing data centers, branch offices, or hybrid WANs
  • improved agility alongside the same reliability and performance benefits of private cloud connectivity

ExpressRoute Gateways for zone resilience

While this blog explores ExpressRoute interconnect resilience levels, regions and availability zones are also vital to your application design.

To maximize resilience, Microsoft recommends deploying ExpressRoute Virtual Network Gateways as zone-redundant across availability zones within a region. These zones are physically separate, with independent power, cooling, and networking, protecting connectivity from zone-level failures.

Zone-redundant gateways improve your Azure network’s scalability, availability, and reliability for mission-critical workloads, ensuring that equipment failures or disasters in a single data center don’t disrupt your access to Azure services.

Understanding ExpressRoute resilience levels

When planning connectivity to Microsoft Azure, it’s important to understand the different levels of ExpressRoute resilience (referred to by Azure as “resiliency”) and how to select the right option for your workload requirements.

Standard resiliency

Standard resiliency is the most basic option and provides a single circuit with dual connections to Microsoft edge devices in the same location. This setup offers some redundancy through active-active routing, but it remains vulnerable to failures at the Microsoft peering site.

A common question I hear from customers is why it’s considered a single circuit when there are two physical links. The answer is that in ExpressRoute standard resiliency, you are provisioned with one logical circuit, and that circuit includes two physical connections (primary and secondary) to Microsoft Enterprise Edge (MSEE) routers in the same site. Microsoft treats these links as components of a single circuit rather than separate circuits.

Up until early 2024 this was the only available method for ExpressRoute deployment, so customers would use multiple circuits in different peering locations to prevent dependence on a single location. ExpressRoute Metro was introduced to solve this problem and give users more connectivity design options (more on this below).

With Megaport, standard resiliency can be achieved by deploying two Virtual Cross Connects (VXCs) to dual MSEEs from one or two Megaport Ports deployed in either the same Megaport enabled data center or in separate Megaport enabled data centers.

As per Microsoft’s guidance, the standard model does not protect against location-wide outages.

ExpressRoute standard resiliency
ExpressRoute standard resiliency

High resiliency (ExpressRoute Metro)

For organizations seeking stronger fault tolerance, high resiliency (ExpressRoute Metro) offers greater protection by establishing dual-homed links into two separate peering sites within the same metro area. This design safeguards against the loss of a single edge location so traffic can continue flowing even in the event of a localized outage.

With Megaport, this is typically delivered by connecting VXCs from one or more Ports into MSEEs across different data centers for flexibility and added assurance against site-level failures.

Microsoft is constantly deploying ExpressRoute Metro in more locations; you can view the current deployment list here. For your critical workloads, we highly recommend you consider high resiliency at a minimum.

ExpressRoute high resiliency
ExpressRoute high resiliency

Maximum resiliency

Enterprises after the highest possible availability should explore maximum resiliency, which is designed for mission-critical workloads where downtime is not an option. This model deploys four separate circuits across two peering sites, eliminating any single point of failure.

Megaport supports this approach by enabling enterprises to deploy four Ports with VXCs spread across MSEEs in dual metro locations. This architecture is ideal for businesses requiring ultra-high uptime, such as those in finance, healthcare, or global-scale digital services.

ExpressRoute maximum resiliency
ExpressRoute maximum resiliency

ExpressRoute SLAs

So, what does all of this mean in regards to SLAs for Microsoft ExpressRoute?

As you may have guessed, Microsoft ExpressRoute service levels and service credits available to you depend on the level of resiliency deployed.

Service credits for a multi-circuit or site architecture are only applicable if simultaneous outages on both circuits and/or sites lead to a complete loss of connectivity to the connected gateway.

To meet SLA requirements, customers must establish a BGP peer (Layer 3) on each MSEE router. Both peers are active, giving customers control over routing.

Customers often ask me if it’s possible to connect via a single provisioned peer, and the answer is yes; the single peer will be fully functional, however it will not be covered by the Azure ExpressRoute SLA.

The Microsoft SLA, on the other hand, extends from the Azure edge/peer location’s MSEE router across the Microsoft network. Customers can choose to terminate both connections/peers on a single device or split them across two devices. As long as both peers are established with each MSEE, the Microsoft SLA applies.

Here are the current service credits based on uptime percentage for each configuration:

At least two dedicated circuits in a 2+ site configuration to an ER gateway

Maximum

Uptime percentage

Service credit

< 99.95%

10%

< 99.9%

25%

Dedicated circuit in a metro site configuration to an ER gateway

High

Uptime percentage

Service credit

< 99.9%

10%

< 99%

25%

Dedicated circuit in a single site configuration to an ER gateway

Standard

Uptime percentage

Service credit

< 99.0%

10%

< 95%

25%

Get started

Choosing the right ExpressRoute resiliency level is crucial for maintaining continuous operations and for meeting your specific business requirements.

Whether you opt for standard, high, or maximum resiliency, Megaport provides the flexible, on-demand connectivity needed to optimize your ExpressRoute environment. By leveraging Megaport’s global network, you can design a highly available, secure, and scalable connection to Microsoft Azure, ensuring your critical applications and data remain accessible even in the face of unforeseen disruptions.

To discuss your design, reach out to your Megaport Solutions Architect or book a free demo call. We’ll help you simplify the complex details around the different Microsoft ExpressRoute peerings, VLAN options, and more.