A dedicated private link between on-premises networks and Azure, using Microsoft peering or private peering.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains ExpressRoute in context, with comparison tables and the common traps.
Terms in this definition
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
- Azure Private Link
Azure capability placing PaaS services such as Azure Storage behind a private endpoint in your VNet. Traffic stays on the Microsoft backbone with no public IP involved, though VNet and DNS configuration are required.
- Microsoft peering
Routing domain on ExpressRoute that reaches public endpoints of Azure PaaS and Microsoft 365 using public IP prefixes you own. Circuits created since August 2017 advertise nothing until you attach a route filter.
- Private peering
The ExpressRoute routing domain for reaching Azure VNets from on-premises networks over private addressing. Unless IPsec or MACsec is layered on, the traffic travels unencrypted.
Related terms
- Allow gateway transit
Peering option set on the hub, which owns the gateway, so that peered VNets can share its ExpressRoute or VPN gateway. The spoke sets Use remote gateways to match; on a VNet lacking a gateway the option has no effect.
- AS Path (hub routing preference)
Routing preference for a Virtual WAN hub under which the shortest BGP AS path wins regardless of where the route came from. When local routes tie, ExpressRoute is chosen over site-to-site VPN.
- Azure public peering
Older ExpressRoute peering for reaching Azure's public endpoints; it is deprecated for new circuits, with Microsoft peering in its place.
- BareMetal Infrastructure
Azure offering of dedicated physical servers, SAP HANA Large Instances being one example, linked to your network over ExpressRoute.
- BFD
Protocol that spots a failed ExpressRoute link in less than a second. Microsoft's MSEE routers already have it on for new peerings, so you enable it on your own edge routers and tie it to the BGP session.
- BGP
Dynamic routing protocol used with both ExpressRoute and VPN connections. On ExpressRoute private peering it is the only way to exchange routes, including a 0.0.0.0/0 default route for forced tunnelling.
- Branch-to-branch
Optional Azure Route Server feature, disabled by default, that passes routes among NVAs and the VPN and ExpressRoute gateways in its VNet, enabling transit between ExpressRoute and site-to-site VPN.
- Connectivity provider
Telecoms partner that, given the circuit's service key, provisions ExpressRoute at a peering location; with ExpressRoute Direct you connect without one.