Azure のデータセンターとオンプレミスまたはコロケーション環境のどちらかにあるインフラストラクチャの間でプライベート接続を提供する Azure サービス。
Hello Inoue
Yes, your understanding is mostly correct. When you set up your ExpressRoute circuit for maximum resiliency, you'll want to ensure you specify your service key to the provider. This configures the routes accordingly so that both East and West vNET gateways can be associated correctly with your ExpressRoute circuit.
1) You link the ExpressRoute Circuit to the ExpressRoute Gateway.
- Provider side
- The provider provisions the circuit using the Service Key generated when the ExpressRoute circuit is created.
- Azure side
- You create an ExpressRoute connection between the circuit and the ExpressRoute Gateway.
2) Two circuits (two provider contracts)—Tokyo & Osaka—are sufficient for this DR objective. Each ExpressRoute circuit already includes dual physical cross‑connects and redundant BGP sessions for availability; geo‑redundancy comes from having another circuit in a different peering location. A four‑circuit design is only for extra diversity beyond this baseline (e.g., multiple providers per location).
Reference: Designing for disaster recovery with ExpressRoute private peering
Reference: ExpressRoute routing requirements
3) Each circuit is independent: You will have one Tokyo circuit and one Osaka circuit.
Gateway association: Each circuit can be associated with multiple vNET gateways. For example:
Tokyo circuit → East Japan vNET gateway
Osaka circuit → East Japan vNET gateway and West Japan vNET gateway
This way, both circuits can reach East Japan resources, and Osaka can also serve West Japan workloads. NOTE: Within the same geopolitical region, a circuit can be associated with VNets in multiple regions (e.g., Tokyo circuit → Japan East VNet and/or Japan West VNet). Premium SKU is not required for Japan East/West because they are in the same geopolitical region; Premium is needed only when you cross geopolitical boundaries or for Global Reach across geopolitical.
4) For the setup you’re envisioning, you’ll need to configure Global Reach on Azure. This means you’ll set up BGP peering properly, ensuring routes are advertised correctly across your circuits. Your provider's BGP priority settings (like Tokyo Link1, Tokyo Link2, etc.) must align with your Azure configurations to maintain expected routing priorities.
Reference:
About ExpressRoute Global Reach
Important note: If you want traffic to fail over seamlessly, you must ensure that both circuits advertise the same prefixes consistently. Otherwise, routing asymmetry can occur.
Can you please update us if the action plan provided was helpful?
Should there be any follow-up questions or concerns, please let us know and we shall try to address them.
Please do not forget to Accept the answer and up-vote it wherever the information provided helps you, this can be beneficial to other community members. It would be greatly appreciated and helpful to others.