An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
Good question. I couldn't find Microsoft docs that call this an architectural guarantee in so many words, but the docs do treat primary and secondary as circuit-level paths, not per-peering ones. The ARP table doc says each circuit has two paths, primary and secondary, and the routing doc puts the first /30 of every peering on the primary link. So your primary-to-primary assumption lines up with how Microsoft describes it.
To check it on your own circuit and get it in writing:
- Pull the ARP table for the primary path on both peerings with
Get-AzExpressRouteCircuitARPTable -PeeringType AzurePrivatePeering -DevicePath Primary, then run it again with-PeeringType MicrosoftPeering. - Compare the Microsoft-side MAC address in both results. If they match, that's a good sign both primary sessions sit on the same MSEE.
- If you need this as a design guarantee, open a support request on the circuit and ask the ExpressRoute team to confirm it in writing.
Is this for failover planning, like making sure a single MSEE failure only ever takes down the primary sessions together?
If this resolved your question, please consider accepting it as the answer. If you still need more detail, let me know and I'll be happy to keep helping.
Reference: