Connect on-prem networks to Azure critical workloads via multiple ExpressRoutes peering locations
Impact:HighCategory:High Availability
APRL GUID:4d703025-dafc-f840-a183-5dc440456134
Description:
Connecting each ExpressRoute Gateway to a minimum of two circuits in different peering locations enhances redundancy and reliability by ensuring alternate pathways for data in case one circuit fails.
Click the Azure Resource Graph tab to view the query
//cannot-be-validated-with-arg
Ensure ExpressRoute's physical links connect to distinct network edge devices
Impact:HighCategory:High Availability
APRL GUID:0e19cc41-8274-1342-b0db-0e4146eacef8
Description:
Microsoft or the ExpressRoute provider always ensures physical redundancy in their services. It's essential to maintain this level of physical redundancy (two devices, two links) from the ExpressRoute peering location to your network for optimal performance and reliability.
Click the Azure Resource Graph tab to view the query
//cannot-be-validated-with-arg
Ensure both connections of an ExpressRoute are configured in active-active mode
Impact:HighCategory:High Availability
APRL GUID:f06a2bbe-5839-d447-9f39-fc3d20562d88
Description:
Operating both connections of an ExpressRoute circuit in active-active mode enhances high availability as the Microsoft network will load balance the traffic across the connections on a per-flow basis.
Click the Azure Resource Graph tab to view the query
//cannot-be-validated-with-arg
Activate Bidirectional Forwarding Detection on edge devices for faster failover
Impact:HighCategory:High Availability
APRL GUID:2a5bf650-586d-db4c-a292-d922be7d3e0e
Description:
Enabling BFD over ExpressRoute speeds up link failure detection between MSEE devices and routers configured for ExpressRoute (CE/PE), applicable over both customer and Partner Edge routing devices with managed Layer 3 service.
Click the Azure Resource Graph tab to view the query
//cannot-be-validated-with-arg
Configure monitoring and alerting for ExpressRoute circuits
Impact:HighCategory:Monitoring and Alerting
APRL GUID:9771a435-d031-814e-9827-9b5fdafc0f87
Description:
Use Network Insights for monitoring ExpressRoute circuit availability, QoS, and throughput. Set alerts based on Azure Monitor Baseline Alerts for availability, QoS metrics, and throughput metrics exceeding specific thresholds.
Click the Azure Resource Graph tab to view the query
//under-development
Implement rate-limiting across ExpressRoute Direct Circuits to optimize network flow
Impact:MediumCategory:Scalability
APRL GUID:d40c769d-2f08-4980-8d8f-a386946276e6
Description:
Rate limiting controls traffic volume between on-premises networks and Azure via ExpressRoute Direct, applying to private or Microsoft peering. It distributes port bandwidth, ensures stability, and prevents congestion, with steps outlined for enabling on circuits.