Connecting Multiple ExpressRoute Circuit into Single ExpressRoute Gateway or Using Single ExpressRoute Circuit & gateway for 2 On-prem Data Centers

Karthik Rajendiran 0 Reputation points
2024-09-30T12:34:49.6533333+00:00

Dear Team,

We have requirement to connect to an Vendor cloud from the On-prem through Azure using the ExpressRoute, Azure Firewall &VPN Gateway. Below is the flow we planned,

User's image

We have 2 different Data centers in On-prem to connect to Vendor Cloud using Azure ExpressRoute. Our Plan is to Setup 2 different ExpressRoute Circuit (Same Virtual Network, but different Peering Locations) in Azure, one circuit for 1 on-prem data center. But we would like to know below possibilities,

  1. If we can attach the Single ExpressRoute Gateway to both these ExpressRoute Circuit to Forward Traffic into Azure Firewall?
  2. Or Can we create One ExpressRoute Circuit and connect from 2 Different Data Centers to receive traffic and then forward to Azure Firewall?
  3. Or Any other possible options available to achieve this?

Basically, I need connection to be established from 2 On-prem Data Centers (Active-Active) either using 2 ExpressRoute Circuit (1 for each Data Center) & 1 ExpressRoute Gateway (Common for both ExpressRoute Circuit) OR 1 ExpressRoute Circuit (Common for both On-prem Data Center) & 1 ExpressRoute Gateway.

Please advise the best & supported possibilities to implement this.

Azure ExpressRoute
Azure ExpressRoute
An Azure service that provides private connections between Azure datacenters and infrastructure, either on premises or in a colocation environment.
385 questions
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 47,206 Reputation points Microsoft Employee
    2024-10-01T05:27:58.83+00:00

    @Karthik Rajendiran ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    May I ask if DC1 and DC2 are in the same region or in same geopolitical area?

    • I believe it should be in region(s) in the same geopolitical area, but please confirm
    • As long as they are in the same geopolitical area, and you are planning to use the same Service Provider (assuming they support in case of different regions in the same geopolitical area) , you can use a single ExpressRoute Circuit.
    • Make sure the SKU of the circuit is Standard
    • If your requirement is only one region , you can also consider ExpressRoute Local

    You can find a detailed comparison of SKUs here :

    • User's image

    Even if you were to use 2 different Circuits (for redundancy across Service Providers)

    • This set up would work
    • Note that The maximum number of ExpressRoute circuits from the same peering location that can connect to the same virtual network is 4 for all gateways SKU
    • Refer : Gateway SKU Comparison
    • If you are connecting 2 Circuits to this gateway (From same peering location), you can connect 2 more Circuits to this gateway from the same peering location.

    The only advantage I can think of having two circuits over one is redundancy (across Service Providers).

    Please let us know if we can be of any further assistance here.

    Thanks,

    Kapil


    Please Accept an answer if correct.

    Original posters help the community find answers faster by identifying the correct answer.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.