Azure VPN Gateway vs ExpressRoute: choosing hybrid connectivity

Both connect your on-premises network to Azure, but one runs encrypted over the internet and the other runs privately through a provider. How each works, the SKU changes, encryption, failover, Virtual WAN and three exam traps.

By Tony Rough

  • AZ-900
  • AZ-700
  • AZ-104
  • AZ-305
  • networking
  • hybrid connectivity
  • exam traps

Your datacentre needs to talk to your Azure virtual networks. Azure gives you two main ways to do it: Azure VPN Gateway or ExpressRoute. The difference is the path your traffic takes.

The one-sentence difference

VPN Gateway: encrypted, over the internet

It’s the cheaper, quicker option: Learn puts gateway provisioning at about 45 minutes.

ExpressRoute: private, through a provider

An ExpressRoute circuit connects you to Microsoft at a peering location, with two connections to two Microsoft edge routers for built-in redundancy and BGP for routing. A circuit has two peerings:

Getting a circuit takes weeks to months, because the provider has to provision physical infrastructure.

Encryption options

Because ExpressRoute isn’t encrypted by default, Learn lists two add-ons:

Global Reach and FastPath

Bandwidth and SLA

VPN Gateway ExpressRoute
Path Public internet, IPsec Private, via provider
Encrypted by default Yes No
Bandwidth Up to 10 Gbps aggregate (VpnGw5AZ); one tunnel is much lower Provider circuits 50 Mbps to 10 Gbps; Direct ports of 10, 100 or 400 Gbps
Latency Variable (internet) Low and predictable
SLA 99.95% for every SKU except Basic Depends on design: single site, Metro or multiple peering locations
Set-up time Hours to days Weeks to months

For maximum ExpressRoute resiliency, Microsoft recommends two circuits in two peering locations.

Gateway SKUs, as Learn states them now

VPN as a backup for ExpressRoute

The two can coexist in one virtual network, so a site-to-site VPN can act as a secure failover path for ExpressRoute, or connect branch sites that have no circuit. The rules:

Many sites? Consider Virtual WAN

Virtual WAN puts S2S VPN, P2S, ExpressRoute and SD-WAN partner devices into Microsoft-managed hubs, with transit between VPN and ExpressRoute sites. Learn’s SKU page says that if you need more than 100 site-to-site tunnels, use Virtual WAN instead of VPN Gateway. A Basic virtual WAN does site-to-site VPN only; ExpressRoute needs Standard.

Three exam traps

  1. “Private” doesn’t mean “encrypted”. ExpressRoute traffic isn’t encrypted by default. MACsec needs ExpressRoute Direct; on a provider circuit, the answer is IPsec over private peering.
  2. VPN failover covers private peering only. There’s no VPN-based failover for services reached over Microsoft peering, and the backup VPN gateway can’t be Basic.
  3. Global Reach joins your sites, not your VNets, and it isn’t transitive. Linking circuit A to B and B to C doesn’t connect A to C; you link each pair yourself, and the two circuits must be at different peering locations.

Pick it in five seconds

You need… Choose
Encrypted link on a budget, up and running today Site-to-site VPN
Individual remote users into a VNet Point-to-site VPN
Private, predictable, high-bandwidth, no internet path ExpressRoute (private peering)
Microsoft 365 or PaaS over ExpressRoute Microsoft peering
Encryption on ExpressRoute MACsec (Direct) or IPsec over private peering
Two on-premises sites linked through Microsoft’s network Global Reach
A cheap safety net if the circuit fails Coexisting site-to-site VPN
Dozens of branches, or more than 100 tunnels Virtual WAN

Go deeper

Hybrid connectivity is covered in the AZ-700 study guide, the AZ-104 study guide the AZ-305 study guide and, for the basics, the AZ-900 study guide, with the traps called out like these. Facts checked against Microsoft Learn on 8 October 2026.

The books in this post

Never miss a free Kindle weekend

An email when an Ultra Transcenders book is free on Kindle, and when a new book comes out. Sign up and you also get the free exam-day checklist: booking, ID, the online check-in and what to expect on the day.

We'll email you to confirm first. A few emails a month at most, no spam, unsubscribe any time. The list is run by Kit; see the privacy notice.

More from the blog

All posts