Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
Also called Border Gateway Protocol.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-5002V0-17.25AZ-900ALZ
Each book explains BGP in context, with comparison tables and the common traps.
Terms in this definition
- Geographic
A Traffic Manager routing method that picks the endpoint according to where the user is located geographically.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- Private peering
The ExpressRoute routing domain for reaching Azure VNets from on-premises networks over private addressing. Unless IPsec or MACsec is layered on, the traffic travels unencrypted.
- Default route
The 0.0.0.0/0 route matching any destination. Advertised by on-premises routers through BGP on ExpressRoute private peering (Microsoft peering won't do), it sends internet traffic from connected VNets back on-premises.
- Forced tunnelling
Routing Azure's internet-bound traffic through an on-premises device or NVA rather than letting it break out directly. ExpressRoute achieves this when 0.0.0.0/0 is advertised over BGP, and site-to-site VPN uses BGP or a default site; Azure Firewall needs a management NIC (
AzureFirewallManagementSubnetand a management public IP) for it.
Related terms
- AS path
BGP attribute recording each ASN a route has passed through. Routes with shorter paths usually win, so adding extra ASNs makes one look less attractive.
- AS Path (hub routing preference)
Routing preference for a Virtual WAN hub under which the shortest BGP AS path wins regardless of where the route came from. When local routes tie, ExpressRoute is chosen over site-to-site VPN.
- AS-path prepending
Making a BGP route less attractive by repeating ASNs to lengthen its AS path, steering traffic towards a different site or path.
- ASN
Short for autonomous system number, which identifies a BGP routing domain. Azure VPN gateways use 65515 by default, a reserved value on-premises peers must avoid; Defender EASM also discovers ASNs as an internet asset type.
- Azure Route Server
Managed service that peers over BGP with network virtual appliances in a VNet and installs the learned routes on the VMs. It works purely in the control plane, so traffic never passes through it.
- BFD
Protocol that spots a failed ExpressRoute link in less than a second. Microsoft's MSEE routers already have it on for new peerings, so you enable it on your own edge routers and tie it to the BGP session.
- BGP peer IP
IP address from which each router runs its BGP session. Azure allocates one to a VPN gateway when BGP is switched on, and you record the internal address of your on-premises router in the local network gateway.
- BGP peering with the virtual hub
Virtual WAN capability where a network virtual appliance in a spoke connected directly to the hub runs a BGP session with the hub's router; the spoke's VNet connection must be associated with
defaultRouteTable.