Site-to-Site VPN over Internet AND ExpressRoute

Ben 6 Reputation points
2024-01-14T13:27:04.15+00:00

Hello,

I'm trying to determine whether or not the following is possible: diagram

We have an existing Site-to-Site VPN from DC1 to Azure over the Internet and are in the process of provisioning our ExpressRoute connectivity from DC2 to Azure.

Can I create a highly available VPN configuration with a second tunnel going over the MPLS and ExpressRoute from DC1 to Azure via DC2?

Regards,

Ben

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,554 questions
Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
381 questions
{count} votes

1 answer

Sort by: Most helpful
  1. GitaraniSharma-MSFT 49,651 Reputation points Microsoft Employee
    2024-01-18T11:09:39.3+00:00

    Hello @Ben ,

    I understand that you would like to create a site-to-site VPN configuration with a second tunnel going over the MPLS and ExpressRoute from DC1 to Azure via DC2.

    Meaning the VPN connection should be DC1 <--S2S--> DC2 <--S2S--> Azure

    DC1 <--S2S--> DC2 --> This configuration has to be done on your end, so cannot comment much on this setup.

    DC2 <--S2S--> Azure --> Using the existing VPN gateway, you can connect DC2 site (via another local network gateway) with Azure using BGP.

    NOTE: BGP should also be enabled for the existing Site-to-Site VPN from DC1 to Azure.

    Once BGP is enabled, you can use AS path prepend to prefer direct path over the indirect path.

    Azure VPN gateway honors AS Path prepending to help make routing decisions when BGP is enabled. A shorter AS Path is preferred in BGP path selection.

    Refer: https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-vpn-faq#does-azure-vpn-gateway-honor-as-path-prepending-to-influence-routing-decisions-between-multiple-connections-to-my-on-premises-sites

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please don’t forget to "Accept the answer" wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.