Azure ExpressRoute: Circuits, Private Peering and BGP - 夜莺博客

Azure ExpressRoute: Circuits, Private Peering and BGP

ExpressRoute replaces internet transit to Azure with a private, provider-delivered circuit, but it still relies on BGP for every prefix exchange. Teams that treat it as a cable usually end up with asymmetric routing or a silent failover because the second BGP session was never verified. This guide covers circuit creation, the two peering types, and the verification steps that prove both sessions carry routes independently.

Circuits and service keys

An ExpressRoute circuit is a logical connection identified by a GUID called the service key (s-key) and a bandwidth you select at order time. The s-key is shared with your connectivity provider to provision the physical cross-connect; it is an identifier, not a secret.

az network express-route create \
  --name er-prod-hk \
  --resource-group rg-network \
  --bandwidth 1000 \
  --peering-location HongKong \
  --provider "PCCW" \
  --sku-family MeteredData --sku-tier Standard

az network express-route show --name er-prod-hk -g rg-network \
  --query "{serviceKey: serviceKey, status: circuitProvisioningState, sp: serviceProviderProvisioningState}"

The circuit is not usable until serviceProviderProvisioningState reaches Provisioned. Configuration can be prepared in advance, but BGP will not come up before then.

Two peering types

Peering Reaches Addressing
Azure private VNet resources on private IPs (VMs, internal load balancers) Any RFC1918 or valid WAN range you own
Microsoft Microsoft 365, Azure public PaaS endpoints Public prefixes you or the provider own, registered in an RIR/IRR

Private peering is where infrastructure traffic belongs; Microsoft peering is only needed for PaaS/M365 access over the private path.

Configuring private peering

az network express-route peering create \
  --circuit-name er-prod-hk --resource-group rg-network \
  --peering-type AzurePrivatePeering \
  --peer-asn 65001 \
  --primary-peer-subnet 172.16.1.0/30 \
  --secondary-peer-subnet 172.16.2.0/30 \
  --vlan-id 100

az network express-route peering show \
  --circuit-name er-prod-hk -g rg-network -n AzurePrivatePeering

BGP peering IPs are provider-side addresses inside those two /30s. The redundancy lives in the subnet pair: primary and secondary sessions terminate on separate Microsoft routers and separate provider edge devices.

On your edge router

! Cisco IOS-XE example: primary session only, MD5 optional
router bgp 65001
 neighbor 172.16.1.1 remote-as 12076
 neighbor 172.16.1.1 password <md5-key>
 address-family ipv4 unicast
  neighbor 172.16.1.1 activate
  network 10.10.0.0 mask 255.255.0.0
 exit-address-family

# verify sessions and learned prefixes
show bgp ipv4 unicast summary
show bgp ipv4 unicast neighbors 172.16.1.1 advertised-routes

Microsoft uses ASN 12076 for ExpressRoute. Advertising more than a handful of prefixes? Aggregate: the default private peering limit is 4,000 IPv4 prefixes (10,000 with ExpressRoute Premium), and the smallest subnet you should publish is a /29. Route limits are enforced by dropping the session, which is a very visible outage for a routing mistake.

Failover that actually fails over

# test one session at a time, watching the VNet effective routes
az network nic show-effective-route-table -g rg-app --name vm-web-nic -o table
az network vnet-gateway list-learned-routes -g rg-network -n vng-er
az network vnet-gateway list-advertised-routes -g rg-network -n vng-er --peer 172.16.1.1

With the primary shut down, the effective route table for a workload NIC must still list the on-premises prefixes through the gateway. If the prefixes disappear instead of moving to the secondary session, the on-premises advertisements are asymmetric: one router is advertising to only one Microsoft peer.

Design notes

  • Connect private peering to your core, not to a DMZ hop that adds a second routing domain.
  • Use a VNet gateway plus a gateway subnet sized to the SKU (ErGw3AZ and above for zone-redundant, higher throughput scenarios).
  • Plan an ExpressRoute plus VPN coexistence pattern if the circuit is business-critical; a provider maintenance window is not a maintenance window for the business.

Related reading: AWS Transit Gateway attachments and route tables, BGP best-external and add-path advertisement, and Azure AD Connect will not start.

原文链接:https://learn.microsoft.com/en-us/azure/expressroute/expressroute-howto-routing-arm