|
| 1 | +- description: Connect ExpressRoute gateway with circuits from diverse peering locations |
| 2 | + aprlGuid: d37db635-157f-584d-9bce-4f6fc8c65ce5 |
| 3 | + recommendationTypeId: 8d61a7d4-5405-4f43-81e3-8c6239b844a6 |
| 4 | + recommendationControl: HighAvailability |
| 5 | + recommendationImpact: High |
| 6 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 7 | + recommendationMetadataState: Active |
| 8 | + longDescription: | |
| 9 | + For improved reliability, each ExpressRoute gateway should connect to at least two circuits, with each circuit sourced from a different peering location. This setup ensures diverse connectivity paths, enhancing resilience and minimizing service disruption risks. |
| 10 | + potentialBenefits: Enhanced resilience through diverse connectivity paths |
| 11 | + pgVerified: true |
| 12 | + automationAvailable: true |
| 13 | + tags: [] |
| 14 | + learnMoreLink: |
| 15 | + - name: Designing for disaster recovery with ExpressRoute private peering |
| 16 | + url: "https://learn.microsoft.com/azure/expressroute/designing-for-disaster-recovery-with-expressroute-privatepeering" |
| 17 | + |
| 18 | +- description: Use Zone-redundant ExpressRoute gateway SKUs |
| 19 | + aprlGuid: bbe668b7-eb5c-c746-8b82-70afdedf0cae |
| 20 | + recommendationTypeId: c9af1ef6-55bc-48af-bfe4-2c80490159f8 |
| 21 | + recommendationControl: HighAvailability |
| 22 | + recommendationImpact: High |
| 23 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 24 | + recommendationMetadataState: Active |
| 25 | + longDescription: | |
| 26 | + Azure ExpressRoute gateway offers variable SLAs based on deployment in single or multiple availability zones. To deploy virtual network gateways across zones automatically, use zone-redundant gateways for accessing critical, scalable services with increased resilience. |
| 27 | + potentialBenefits: Enhanced SLA and resilience |
| 28 | + pgVerified: true |
| 29 | + automationAvailable: true |
| 30 | + tags: [] |
| 31 | + learnMoreLink: |
| 32 | + - name: About ExpressRoute virtual network gateways - Zone-redundant gateway SKUs |
| 33 | + url: "https://learn.microsoft.com/azure/expressroute/expressroute-about-virtual-network-gateways#zrgw" |
| 34 | + |
| 35 | +- description: Monitor health for ExpressRoute gateway |
| 36 | + aprlGuid: 1c34faa8-8b99-974c-adbf-71922eae943c |
| 37 | + recommendationTypeId: null |
| 38 | + recommendationControl: MonitoringAndAlerting |
| 39 | + recommendationImpact: High |
| 40 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 41 | + recommendationMetadataState: Active |
| 42 | + longDescription: | |
| 43 | + Use Network Insights for monitoring ExpressRoute Gateway's health, including availability, performance, and scalability. |
| 44 | + potentialBenefits: Enhanced monitoring and alerting |
| 45 | + pgVerified: true |
| 46 | + automationAvailable: false |
| 47 | + tags: [] |
| 48 | + learnMoreLink: |
| 49 | + - name: ExpressRoute monitoring, metrics, and alerts | ExpressRoute gateways |
| 50 | + url: "https://learn.microsoft.com/azure/expressroute/expressroute-monitoring-metrics-alerts#expressroute-gateways" |
| 51 | + |
| 52 | +- description: Avoid using ExpressRoute circuits for VNet to VNet communication |
| 53 | + aprlGuid: 194c14ac-0d7a-5a48-ae32-75fa450ee564 |
| 54 | + recommendationTypeId: null |
| 55 | + recommendationControl: HighAvailability |
| 56 | + recommendationImpact: Medium |
| 57 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 58 | + recommendationMetadataState: Active |
| 59 | + longDescription: | |
| 60 | + While multiple VNets can connect via the same ExpressRoute gateway, Microsoft recommends using alternatives like VNet peering, Azure Firewall, NVA, Azure Route Server, site-to-site VPN, virtual WAN, or SD-WAN for VNet-to-VNet communication to optimize network performance and management. |
| 61 | + potentialBenefits: Enhanced VNet integration efficiency |
| 62 | + pgVerified: true |
| 63 | + automationAvailable: false |
| 64 | + tags: [] |
| 65 | + learnMoreLink: |
| 66 | + - name: About ExpressRoute virtual network gateways - VNet-to-VNet connectivity |
| 67 | + url: "https://learn.microsoft.com/azure/expressroute/expressroute-about-virtual-network-gateways#vnet-to-vnet-connectivity" |
| 68 | + |
| 69 | +- description: Configure customer-controlled ExpressRoute gateway maintenance |
| 70 | + aprlGuid: 3e115044-a3aa-433e-be01-ce17d67e50da |
| 71 | + recommendationTypeId: null |
| 72 | + recommendationControl: HighAvailability |
| 73 | + recommendationImpact: Medium |
| 74 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 75 | + recommendationMetadataState: Active |
| 76 | + longDescription: | |
| 77 | + ExpressRoute gateways are updated for improved functionality, reliability, performance, and security. Customer-controlled maintenance configuration and scheduling minimize update impact and align with your maintenance windows. |
| 78 | + potentialBenefits: Minimizes update impact |
| 79 | + pgVerified: true |
| 80 | + automationAvailable: true |
| 81 | + tags: [] |
| 82 | + learnMoreLink: |
| 83 | + - name: Configure customer-controlled maintenance for your virtual network gateway - ExpressRoute | Microsoft Learn |
| 84 | + url: "https://learn.microsoft.com/azure/expressroute/customer-controlled-gateway-maintenance#azure-portal-steps" |
| 85 | + |
| 86 | +- description: Configure customer-controlled VPN gateway maintenance |
| 87 | + aprlGuid: f8c2e6d9-4b3a-45d6-b9e2-8e7f3a1c2d04 |
| 88 | + recommendationTypeId: null |
| 89 | + recommendationControl: HighAvailability |
| 90 | + recommendationImpact: Medium |
| 91 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 92 | + recommendationMetadataState: Active |
| 93 | + longDescription: | |
| 94 | + VPN gateways are updated for improved functionality, reliability, performance, and security. Customer-controlled maintenance configuration and scheduling minimize update impact and align with your maintenance windows. |
| 95 | + potentialBenefits: Minimizes update impact |
| 96 | + pgVerified: false |
| 97 | + automationAvailable: true |
| 98 | + tags: [] |
| 99 | + learnMoreLink: |
| 100 | + - name: Configure customer-controlled gateway maintenance for VPN Gateway |
| 101 | + url: "https://learn.microsoft.com/azure/vpn-gateway/customer-controlled-gateway-maintenance" |
| 102 | + |
| 103 | +- description: Choose a Zone-redundant VPN gateway |
| 104 | + aprlGuid: 5b1933a6-90e4-f642-a01f-e58594e5aab2 |
| 105 | + recommendationTypeId: null |
| 106 | + recommendationControl: HighAvailability |
| 107 | + recommendationImpact: High |
| 108 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 109 | + recommendationMetadataState: Active |
| 110 | + longDescription: | |
| 111 | + Deploying zone-redundant virtual network gateways across availability zones ensures zone-resiliency, improving access to mission-critical, scalable services on Azure. Mission Critical workloads should use dual ExpressRoutes instead of VPN. |
| 112 | + potentialBenefits: Enhanced reliability and scalability |
| 113 | + pgVerified: true |
| 114 | + automationAvailable: true |
| 115 | + tags: [] |
| 116 | + learnMoreLink: |
| 117 | + - name: Zone redundant Virtual network gateway in availability zone |
| 118 | + url: "https://learn.microsoft.com/azure/vpn-gateway/about-zone-redundant-vnet-gateways" |
| 119 | + |
| 120 | +- description: Enable Active-Active VPN Gateways for redundancy |
| 121 | + aprlGuid: 281a2713-c0e0-3c48-b596-19f590c46671 |
| 122 | + recommendationTypeId: c249dc0e-9a17-423e-838a-d72719e8c5dd |
| 123 | + recommendationControl: HighAvailability |
| 124 | + recommendationImpact: Medium |
| 125 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 126 | + recommendationMetadataState: Active |
| 127 | + longDescription: | |
| 128 | + The active-active mode is available for all SKUs except Basic, allowing for two Gateway IP configurations and two public IP addresses, enhancing redundancy and traffic handling. Mission Critical workloads should use dual ExpressRoutes instead of VPN. |
| 129 | + potentialBenefits: Enhanced reliability and network capacity |
| 130 | + pgVerified: true |
| 131 | + automationAvailable: true |
| 132 | + tags: [] |
| 133 | + learnMoreLink: |
| 134 | + - name: Active-active VPN gateway |
| 135 | + url: "https://learn.microsoft.com/azure/vpn-gateway/active-active-portal#gateway" |
| 136 | + |
| 137 | +- description: Deploy active-active VPN concentrators on your premises |
| 138 | + aprlGuid: af11fc4c-c06c-4f4c-b98d-6eee6d5c4c70 |
| 139 | + recommendationTypeId: null |
| 140 | + recommendationControl: DisasterRecovery |
| 141 | + recommendationImpact: High |
| 142 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 143 | + recommendationMetadataState: Active |
| 144 | + longDescription: | |
| 145 | + Deploying active-active VPN concentrators and Azure VPN Gateways maximizes resilience and availability using a fully-meshed topology with four IPSec tunnels. Mission Critical workloads should use dual ExpressRoutes instead of VPN. |
| 146 | + potentialBenefits: Maximizes resilience and availability |
| 147 | + pgVerified: true |
| 148 | + automationAvailable: false |
| 149 | + tags: [] |
| 150 | + learnMoreLink: |
| 151 | + - name: Dual-redundancy active-active VPN gateways for both Azure and on-premises networks |
| 152 | + url: "https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-highlyavailable#dual-redundancy-active-active-vpn-gateways-for-both-azure-and-on-premises-networks" |
| 153 | + |
| 154 | +- description: Monitor VPN gateway connections and health |
| 155 | + aprlGuid: 9eab120e-f6d3-ee49-ba0d-766562ce7df1 |
| 156 | + recommendationTypeId: null |
| 157 | + recommendationControl: MonitoringAndAlerting |
| 158 | + recommendationImpact: High |
| 159 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 160 | + recommendationMetadataState: Active |
| 161 | + longDescription: | |
| 162 | + Set up monitoring and alerts for Virtual Network Gateway health to utilize a variety of metrics for ensuring operational efficiency and prompt response to any disruptions. Mission Critical workloads should use dual ExpressRoutes instead of VPN. |
| 163 | + potentialBenefits: Improved uptime and issue awareness |
| 164 | + pgVerified: true |
| 165 | + automationAvailable: false |
| 166 | + tags: [] |
| 167 | + learnMoreLink: |
| 168 | + - name: VPN gateway data reference |
| 169 | + url: "https://learn.microsoft.com/azure/vpn-gateway/monitor-vpn-gateway-reference" |
| 170 | + |
| 171 | +- description: Enable VPN gateway service health |
| 172 | + aprlGuid: 9186dae0-7ddc-8f4b-bea5-55538cea4893 |
| 173 | + recommendationTypeId: null |
| 174 | + recommendationControl: MonitoringAndAlerting |
| 175 | + recommendationImpact: High |
| 176 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 177 | + recommendationMetadataState: Active |
| 178 | + longDescription: | |
| 179 | + VPN gateway leverages service health to inform users about both planned and unplanned maintenance, ensuring they are notified about modifications to their VPN connectivity. Mission Critical workloads should use dual ExpressRoutes instead of VPN. |
| 180 | + potentialBenefits: Improves VPN maintenance alerts |
| 181 | + pgVerified: true |
| 182 | + automationAvailable: false |
| 183 | + tags: [] |
| 184 | + learnMoreLink: |
| 185 | + - name: Monitor VPN gateway |
| 186 | + url: "https://learn.microsoft.com/azure/vpn-gateway/monitor-vpn-gateway-reference#metrics" |
| 187 | + |
| 188 | +- description: Deploy VPN gateways with zone-redundant Public IPs |
| 189 | + aprlGuid: 4bae5a28-5cf4-40d9-bcf1-623d28f6d917 |
| 190 | + recommendationTypeId: null |
| 191 | + recommendationControl: HighAvailability |
| 192 | + recommendationImpact: High |
| 193 | + recommendationResourceType: Microsoft.Network/virtualNetworkGateways |
| 194 | + recommendationMetadataState: Active |
| 195 | + longDescription: | |
| 196 | + For zone-redundant VPN gateways, always use zone-redundant Standard SKU public IPs to avoid deploying all instances in one zone. This ensures the gateway's reliability. Mission Critical workloads should use dual ExpressRoutes instead of VPN. |
| 197 | + potentialBenefits: Enhanced reliability and disaster recovery |
| 198 | + pgVerified: true |
| 199 | + automationAvailable: true |
| 200 | + tags: [] |
| 201 | + learnMoreLink: |
| 202 | + - name: About zone-redundant virtual network gateway in Azure availability zones |
| 203 | + url: "https://learn.microsoft.com/azure/vpn-gateway/about-zone-redundant-vnet-gateways" |
0 commit comments