⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 170 of 186 in AWS & Cloud Architecture
Staff Cloud Architect Azure & Cloud Cloud Architecture & Hybrid Networking Enterprise Networking

Q: Your enterprise connects its on-premises data centers to Azure via a 10 Gbps ExpressRoute circuit. To satisfy compliance and ensure business continuity during fiber cuts, you must deploy a Site-to-Site VPN as an automated backup. How do you configure ExpressRoute and VPN Gateway coexistence to prevent asymmetric routing and ensure seamless failover?

Designing a fault-tolerant hybrid cloud topology where an active ExpressRoute circuit automatically fails over to an encrypted Site-to-Site VPN with BGP route manipulation and AS-Path prepending.

#Azure #ExpressRoute #VPN Gateway #BGP #Hybrid Cloud #Disaster Recovery
🎙️ Candidate Opening & Architectural Context
"When a terrestrial fiber cut took down our primary ExpressRoute provider circuit, our on-premises data center lost connectivity to Azure for 4 hours. We architected ExpressRoute and VPN Gateway coexistence with dynamic BGP route steering."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Provision Coexisting ExpressRoute and VPN Gateways in GatewaySubnet

Deploy both gateways inside the designated GatewaySubnet:

  • GatewaySubnet Sizing: Allocated a minimum /26 or /27 GatewaySubnet in the Hub VNet to accommodate both gateway instances.
  • Deploy Gateways: Provisioned ExpressRoute Gateway (az network express-route-gateway create) and Route-Based VPN Gateway (az network vpn-gateway create) in the same VNet.
Pro Tip: Both ExpressRoute and VPN gateways can peacefully coexist within the same GatewaySubnet if the subnet is at least /27 in size.
2️⃣

Configure Dynamic BGP Peering and Route Advertisements

Establish BGP sessions over both paths to exchange on-premises and Azure routes dynamically:

  • BGP ASN Assignment: Configured Azure Gateway ASN (e.g., 65515) and on-premises core router ASN (e.g., 65001).
  • Equal Route Advertising: Advertised identical on-premises CIDR ranges (e.g., 10.0.0.0/16) across both the ExpressRoute BGP session and the IPsec VPN BGP session.
Pro Tip: By default, Azure route selection algorithm always prefers ExpressRoute paths over VPN paths when receiving identical prefix lengths.
3️⃣

Prevent Asymmetric Routing with AS-Path Prepending & Local Preference

Ensure return traffic from on-premises to Azure follows the identical physical path:

  • BGP Local Preference: On the on-premises core router, configured BGP Local Preference to 200 for ExpressRoute routes and 100 for VPN routes.
  • AS-Path Prepending: Prepended the on-premises ASN three times (set as-path prepend 65001 65001 65001) on BGP updates sent over the backup IPsec VPN tunnel.
Pro Tip: Without AS-Path prepending and local preference tuning, packets may flow out via ExpressRoute and return via VPN, causing stateful firewalls to drop connections.
4️⃣

Simulate Circuit Failure & Measure BGP Convergence Time

Validate automated switchover and switchback without administrative intervention:

  • Simulate Failure: Administratively shut down the on-premises ExpressRoute BGP peering interface.
  • Convergence Telemetry: Traffic seamlessly switched to the encrypted IPsec VPN tunnel within 3.2 seconds with zero dropped TCP connections.
  • Failback Verification: Upon re-enabling the circuit, BGP restored ExpressRoute as the preferred path automatically.
Pro Tip: Tuning BGP Keepalive to 10s and Hold Time to 30s accelerates fast failover detection during physical line interruptions.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"ExpressRoute and VPN Gateway coexistence provides enterprise high availability. Azure inherently prefers ExpressRoute; aligning on-premises routing via AS-Path prepending and BGP Local Preference prevents asymmetric routing drops."
⚡ 60-Second Elevator Pitch Talking Points
  • Provision both ExpressRoute and VPN Gateways within a /27 or larger GatewaySubnet.
  • Establish dynamic BGP peering advertising identical network prefixes over both paths.
  • Configure on-premises AS-Path prepending and Local Preference to ensure symmetric routing.
  • Validate automated 3-second failover and seamless recovery during circuit outage simulations.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →