Skip to main content
When implementing a dedicated connection into the public cloud through ExpressRoute to Microsoft Azure or Direct Connect to Amazon Web Services, the security of the transport path is part of a security risk assessment to minimize the risk of any potential man-in-the-middle attack. Azure and AWS have published details on how to use VPN services through their respective dedicated cloud connectivity options: This topic describes several scenarios using dedicated cloud connectivity, including:
  • Scenario 1: IPsec VPN — Azure ER Microsoft Peering or AWS DX Public VIF
  • Scenario 2: IPsec VPN via Megaport Cloud Router (MCR) — Azure ER Microsoft Peering or AWS DX Public VIF
  • Scenario 3: IPsec VPN — Azure ER Private Peering or AWS DX Private VIF with in Azure or AWS
  • Scenario 4: IPsec VPN — Multicloud with Network Virtual Appliance (NVA) in Azure and AWS
IPsec VPN — Azure ER Microsoft Peering or AWS DX Public VIFPrerequisites
  • Owned public IP addresses that can be assigned to use Microsoft Peering and Public VIF. Note: If public IP addresses are not owned, use MCR (Scenario 2).
  • Owned network appliance capable of IPsec.
Megaport Technology RequiredConsiderations
  • Azure and AWS use industry standard protocol IPsec AES128 or AES256 for encryption: using other protocols for security or performance is not easily customizable.
  • Azure and AWS IPsec VPN can be configured with Active-Active HA configuration.
  • The maximum throughput available to AWS Virtual Private Gateway is 1.25 Gbps. The maximum throughput of Azure VPNs depends on the VPN Gateway SKU.

Helpful references

Last modified on August 28, 2026