惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024
Q and A for Q-in-Q part 2
2016-09-20 · via Megaport Blog

By Henry Wagner, Chief Marketing Officer

The basics around double-stacked VLAN tagging, otherwise known as Q-in-Q, or by it’s formal IEEE definition, 802.1ad. Part two.

Following our last post where we discussed the concept of stacked VLAN tags (Q-in-Q), in this second part we will focus specifically on Microsoft Azure and the ExpressRoute product offering that brings direct connectivity into the Azure public cloud environment.

If you are looking to implement Microsoft ExpressRoute for Azure and are considering Megaport as your connectivity solution provider, this post will give you some real world examples of customer implementations from small scale development/testing to high availability production workloads.

Q: How do I go about provisioning an ExpressRoute connection via Megaport?

The following diagram shows the overall process, summarised into a few easy steps:

ExpressRoute connection via Megaport

Q: How do I request/generate a Microsoft Azure ExpressRoute Key (Service Key)?

The most recent developments here have been in requesting the Service Key via the Azure Resource Manager (ARM) portal. We have produced a video that details the steps required to request the Service Key here.

If you are wanting to use PowerShell to script or automate some of the functions this can also be achieved by following the Azure documentation at https://azure.microsoft.com/en-us/documentation/articles/expressroute-howto-circuit-arm/, or our video on the setup process for PowerShell (Classic).

Thanks to some recent changes it’s possible to have both ASM (classic) and ARM VNets connected to a single ER circuit – see the steps in the guide https://azure.microsoft.com/en-us/documentation/articles/expressroute-howto-move-arm/ under the ‘Enable an ExpressRoute circuit for both deployment models’ section.

Q: Can I use a single ExpressRoute circuit with multiple subscriptions?

Yes, you can leverage a single ExpressRoute circuit delivered via Megaport with up to 10 subscriptions. Check out https://azure.microsoft.com/en-us/documentation/articles/expressroute-howto-linkvnet-arm/ for more information on how to share ER circuits effectively.

Q: Can I use a single ExpressRoute circuit with multiple VNets?

The default limit of VNets for an ExpressRoute circuit that is created as a ‘Standard’ type is 10, however if you are using the Premium SKU option this will depend on the requested circuit size (min 20, see https://azure.microsoft.com/en-us/documentation/articles/azure-subscription-service-limits/#networking-limits). However thanks to some recent changes, known as VNet peering, you are able to connect two or more Virtual Networks in the same region through the Azure backbone network. Once peered, the two Virtual Networks will appear like a single Virtual Network for all connectivity purposes. See https://azure.microsoft.com/en-us/documentation/articles/virtual-networks-create-vnetpeering-arm-portal/ for more information on this confirguration. This is very useful feature since it can help to bypass the default VNet limit placed on ExpressRoute circuits without needing to upgrade to Premium.

Q: How does Microsoft Azure ExpressRoute work with Megaport’s VXC services?

Azure connections via Megaport are delivered via a Q-in-Q VLAN to either of the Microsoft Primary or Secondary routers in a given Azure region. Within the single outer tag (S-tag) defined via the Megaport portal there are up to three inner tags (C-tags) that are defined on the Azure portal, these are Azure Private, Azure Public and Microsoft Peering which carries Office 365 traffic. The availability of this third peering type is dependent upon prior approval via Microsoft – see https://support.office.com/en-us/article/Azure-ExpressRoute-for-Office-365-6d2534a2-c19c-4a99-be5e-33a0cee5d3bd for details.

Megaport provides point-to-point Layer 2 connectivity between a customer and Megaport (an Ethernet interface/port provided by Megaport). Layer 3 BGP sessions are established between Azure and Megaport customers directly.

ExpressRoute connection via Megaport

Q: Does “A END VLAN” belong to my end or Microsoft end?

The “A END” VLAN which you need to specify in the Megaportal belongs to your end, not the Microsoft end – this is the “B END” VLAN and is only of relevance between Megaport and Microsoft at the traffic source location (primary/secondary router). This “A END” VLAN ID is represented by the “Outer Tag” in the above diagram.

Q: Should I use the same VLAN ID for the Inner VLAN Tags?

It is generally best practice to use different VLAN IDs for the Inner (or Customer) Tags. Inner VLAN Tags are requested either via Azure Resource Manager Portal, or via PowerShell once ExpressRoute request has been provisioned.

For example, you may use VLAN 2000 (“Outer tag”) as the Megaport VLAN and then have 20/30/40 setup for public/private/Microsoft VLANs on the Azure portal. Each frame is tagged to you twice with “Inner tag” and “Outer tag”, i.e., Q-in-Q, and your network equipment needs to break out “Inner tags” to remove the 2000 tag (“Outer tag”).

It is possible to request Megaport to remove the outer tag by selecting “Untag this VLAN” when creating the first VXC upon your port, however this will then limit the port to be used only for this single VXC so is not recommended for a long term solution as it is more difficult to then add other services against your port (such as secondary Azure VXC, private VXCs, IX connection or similar).

Q: Do I need to set Primary and Secondary circuits to user ExpressRoute?

Technically speaking, you do not need to set the secondary circuit. It is important to note that within the Azure portal you will be required to set IP addressing for both primary and secondary router presentations and this must be matched to the circuit termination that you select when entering your Service Key on the Megaportal. Microsoft does require both the primary and secondary circuits connected with a live BGP session to both to be covered by the ExpressRoute SLA (see https://azure.microsoft.com/en-us/support/legal/sla/expressroute/v1_0/).

Q: How can I set up BGP peering configuration from my router to an ExpressRoute router?

Microsoft provides some sample configuration guidance for Cisco and Juniper routers. Please visit the following site https://azure.microsoft.com/en-us/documentation/articles/expressroute-config-samples-routing/.

Q: I want to set up Azure public peering. Where can I obtain publicly routable IP addresses and an Autonomous System Number (ASN)?

If your network is located in APAC region, contact Asia Pacific Network Information Centre (APNIC) – https://www.apnic.net/get-ip and APNIC Helpdesk: https://www.apnic.net/get-ip/helpdesk.

If your network is located in North America region, contact American Registry for Internet Numbers (ARIN) – https://www.arin.net/resources/request.html.

If your network is located in European region, contact RIPE Network Coordination Centre (RIPE NCC) – https://www.ripe.net/manage-ips-and-asns/ipv4/request-an-ipv4-22-from-the-last-8 and https://www.ripe.net/manage-ips-and-asns/as-numbers.

Q: How would I configure a fully diverse ExpressRoute circuit using Megaport VXCs?

Below is an example of a fully diverse ExpressRoute configuration using all three peering types presented across two physical Megaports:

ExpressRoute connection via Megaport

For the configuration of the above scenario, see below (please note, configuration samples are presented as a guide only and can not take into account factors that are specific to your network):

Cisco 3850 Switch Stack – IOS XE

vlan 45
name Megaport_Azure-Pri
vlan 55
name Megaport_Azure-Sec
!
interface TenGigabitEthernet1/0/24
Description Megaport Primary
switchport mode trunk
no cdp enable
!
interface TenGigabitEthernet2/0/24
description Megaport Secondary
switchport mode trunk
no cdp enable
!
interface Port-channel101
switchport access vlan 45
switchport trunk native vlan 45
switchport trunk allowed vlan 45
switchport mode dot1q-tunnel
!
interface Port-channel102
switchport access vlan 55
switchport trunk native vlan 55
switchport trunk allowed vlan 55
switchport mode dot1q-tunnel
!

Cisco Nexus 9000 – Aggregation Switch #1

vlan 100
name AzurePri-Link1
vlan 101
name AzurePub-Link1
vlan 102
name MSFT-Link1
!
interface port-channel101
switchport mode trunk
switchport trunk native vlan 45 
!
interface Vlan100
no shutdown
vrf member AzurePriv01 ip address 10.x.x.x/30
!
interface Vlan101
no shutdown
vrf member AzurePublic01 ip address y.y.y.v/30
!
interface Vlan102
no shutdown
vrf member MSFT01 ip address y.y.y.w/30
!
interface port-channel1
switchport mode trunk
switchport trunk allowed vlan {lower-upper}
!

Nexus 9000 – Aggregation Switch #2

vlan 100
name AzurePri-Link2
vlan 101
name AzurePub-Link2
vlan 102
name MSFT-Link2
!
interface port-channel102
switchport mode trunk
switchport trunk native vlan 55 
!
interface Vlan100
no shutdown
vrf member AzurePriv02 ip address 10.x.x.y/30
!
interface Vlan101
no shutdown
vrf member AzurePublic02 ip address y.y.y.x/30
!
interface Vlan102
no shutdown
vrf member MSFT02 ip address y.y.y.y/30
!
interface port-channel1
switchport mode trunk
switchport trunk allowed vlan {lower-upper}
!