ExpressRoute Connection


The presented resiliency recommendations in this guidance include ExpressRoute Connection and associated resources and settings.

Summary of Recommendations

Recommendations Details

ERCON-1 - For Connections using ExpressRoute Direct circuits and UltraPerformance or ErGw3AZ ExpressRoute Gateways, enable FastPath to improve data path performance between your on-premises network and your virtual network

Category: System Efficiency

Impact: Medium

Recommendation/Guidance

ExpressRoute virtual network gateway is designed to exchange network routes and route network traffic. FastPath is designed to improve the data path performance between your on-premises network and your virtual network. When enabled, FastPath sends network traffic directly to virtual machines in the virtual network, bypassing the gateway. Bypassing the gateway enhances resiliency by reducing its utilization of the gateway.

Resources

Resource Graph Query

// under-development



ERCON-2 - Configure an Azure Resource Lock on connections to prevent accidental deletion

Category: Availability

Impact: High

Recommendation/Guidance

Configure an Azure Resource lock for Gateway Connection resources to prevent accidental deletion. Accidental deletion of a Gateway Connection resource may result in unexpected loss of connectivity between your on-premises network and Azure workloads. As an administrator, you can lock an Azure subscription, resource group, or resource to protect them from accidental user deletions and modifications. The lock overrides any user permission.

Resources

Resource Graph Query

// under-development