Optional Azure Route Server feature, disabled by default, that passes routes among NVAs and the VPN and ExpressRoute gateways in its VNet, enabling transit between ExpressRoute and site-to-site VPN.
Also called route exchange.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Branch-to-branch in context, with comparison tables and the common traps.
Terms in this definition
- Azure Route Server
Managed service that peers over BGP with network virtual appliances in a VNet and installs the learned routes on the VMs. It works purely in the control plane, so traffic never passes through it.
- VPN
Traffic sent through an encrypted tunnel across a public network, as in a site-to-site connection to a VPN gateway in an Azure GatewaySubnet.
- ExpressRoute
A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
- VNet
A private network belonging to a single subscription and region and covering all of that region's availability zones. A VM can only use a VNet located in the same region.
- S2S
Connects an entire on-premises office or datacentre to an Azure virtual network through an encrypted IPsec/IKE tunnel running between a local VPN device and an Azure VPN gateway.
Related terms
- Active-active VPN gateway
Configuration where tunnels run on both gateway instances, and each instance has a Standard static public IP of its own. Azure Route Server branch-to-branch transit needs this mode plus ASN 65515.
- Connectivity configuration
Virtual Network Manager setting that creates mesh or hub-and-spoke topologies, using peerings or connected groups, over a network group; route exchange between gateways isn't part of it.
- Routing intent
With this Virtual WAN feature, a hub forces private traffic, internet traffic or both through a security solution inside it (Azure Firewall, an NGFW NVA or a SaaS offering). Branch-to-branch and hub-to-hub traffic is then inspected without hand-built route tables.