First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Azure Site-to-Site VPN and ExpressRoute Implementation
Implementation

Azure Site-to-Site VPN and ExpressRoute Implementation

IT Partner connects your office or datacenter to your Azure workloads over a private, encrypted path. For a single site, the Site-to-Site VPN implementation is a fixed $2,450, one-week engagement: VPN gateway on a current zone-redundant SKU, IPsec/IKE policy matched to your firewall, BGP or static routing, coordination with your firewall administrator or vendor, failover validation, and as-built documentation. ExpressRoute — a dedicated private circuit through a connectivity provider — and multi-site VPN topologies are scoped and quoted individually, and this page includes an honest guide to which one you actually need. Two costs are explicitly not ours: your carrier or ISP circuit charges, and Azure's own gateway and bandwidth charges, which Microsoft bills directly — we size and estimate them in the design so neither surprises you.

Timeline 1 weekService owner Roman SotnikMicrosoft AzureAzure VPN GatewayAzure ExpressRoute

What this engagement is

Every hybrid Azure story runs through the same sentence: the workloads moved, and now the office needs to reach them properly. The wrong answer is the one we still find in the wild — management ports exposed to the public internet, or a VPN improvised years ago from defaults that nobody dares touch. The right answer is a designed private path: a Site-to-Site VPN for most organizations, or an ExpressRoute circuit when the requirements genuinely demand one, built once, documented, and validated under failure conditions rather than assumed to work. The fixed-price engagement delivers the Site-to-Site VPN end to end for a single site. We design the address space and routing so nothing overlaps and nothing is left to chance, deploy an Azure VPN gateway on a current zone-redundant SKU — Microsoft has been consolidating gateway SKUs and retiring legacy tiers through 2026, and we deliberately deploy what is current rather than what is on a retirement list — then build the IPsec/IKE tunnel to match your on-premises firewall, configure BGP or static routing to fit your network, and coordinate directly with your firewall administrator or vendor so the two ends are configured by people talking to each other, not guessing at each other. Before handover we validate the part most VPN setups skip: what happens when a tunnel drops, a gateway instance fails over, or the primary path degrades. You receive as-built documentation and a runbook, so the next engineer to touch this understands it in minutes. ExpressRoute is the second half of the page, and we are honest about it: it is a dedicated private circuit into Microsoft's network through a connectivity provider — predictable latency, high bandwidth from 50 Mbps up to 10 Gbps through providers, and traffic that never touches the public internet. It is also a project with a telecom in the middle: circuits carry monthly provider fees and provisioning lead times measured in weeks, which is why ExpressRoute engagements are scoped and quoted rather than sold at a flat price. Most SMB workloads are served excellently by a well-built VPN; ExpressRoute earns its cost when latency-sensitive workloads, sustained data volumes, or compliance requirements say so. The decision guide below is the same one we use on scoping calls — and a common, sensible pattern is both: the VPN ships this week and later becomes the failover path for a circuit that takes six to eight weeks to arrive.

Which one applies to you

The honest decision guide. Most organizations need the left column; the right column earns its cost in specific, nameable circumstances.

Site-to-Site VPN — $2,450 fixedExpressRoute — quoted
How traffic travelsEncrypted IPsec tunnel across your existing internet connection.Dedicated private circuit into Microsoft's network via a connectivity provider — traffic never crosses the public internet.
Best forOffice-to-Azure access, server administration, file and application traffic, branch connectivity — the standard hybrid workload.Latency-sensitive workloads, sustained large data volumes, and compliance postures that mandate private connectivity.
Bandwidth and latencyBounded by your internet uplink, gateway SKU, and firewall throughput; latency varies with the internet path.Committed circuit bandwidth from 50 Mbps to 10 Gbps through providers, with predictable latency.
What it depends onYour existing internet service and a compatible firewall — nothing new to procure.A carrier or connectivity provider contract, a peering location, and provider provisioning.
Time to liveAbout one week, most of it design and validation.Typically weeks, driven by provider circuit delivery — outside anyone's control but the carrier's.
Recurring costs (Microsoft/carrier, not ours)Azure VPN gateway hours and standard bandwidth charges.Monthly circuit fee to the provider plus Azure ExpressRoute and gateway charges.

A frequent right answer is both: the VPN ships now, then stays as the failover path once the ExpressRoute circuit is delivered — Azure supports that coexistence deliberately.

Multi-site VPN topologies (several offices into one Azure footprint) are quoted per design rather than multiplied from the single-site price, because routing design is where the real work lives.

Success criteria

01A connectivity design is documented and approved before deployment: address spaces, routing approach (BGP or static), gateway SKU, and failover behavior.
02The Azure VPN gateway is deployed on a current zone-redundant SKU with the local network gateway and connection configured to the design.
03The IPsec/IKE tunnel establishes and stays established, with the policy explicitly configured to match the on-premises device rather than left to defaults.
04Routing works in both directions: on-premises subnets reach the agreed Azure ranges and vice versa, verified by test plan rather than assumption.
05Failover behavior is validated: tunnel re-establishment after interruption and gateway resilience behavior are tested and the observed results documented.
06The on-premises firewall configuration is completed in coordination with the client's firewall administrator or vendor, with both ends' settings recorded.
07Baseline connectivity metrics — latency and throughput between site and Azure — are measured and recorded at handover.
08The client receives as-built documentation and an operational runbook covering health checks, pre-shared key rotation, and what to do when the tunnel drops.
09For ExpressRoute engagements: circuit requirements, provider options, peering design, and a written quote are delivered before any commitment is made.

What you receive

Connectivity design document: address plan, routing approach, gateway SKU selection with rationale, DNS considerations, and failure-mode behavior.
Azure VPN gateway deployment on a current zone-redundant SKU, with public IP, virtual network gateway, local network gateway, and connection resources built to the design.
IPsec/IKE policy configuration matched to your on-premises firewall's capabilities, with pre-shared key generation and a documented rotation procedure.
BGP configuration (where your device supports it) or static route configuration, including route propagation into the relevant Azure subnets.
A working session with your firewall administrator or vendor to configure the on-premises end — we bring the exact parameters, not a generic PDF.
Failover and resilience validation: tunnel interruption and re-establishment testing, with observed behavior documented.
Connectivity test plan execution: bidirectional reachability, name resolution checks against the design, and a recorded latency/throughput baseline.
Azure cost estimate for the gateway and expected bandwidth charges, stated per Microsoft's current price list so the recurring cost is a decision, not a discovery.
As-built documentation and operational runbook: topology diagram, both ends' configuration parameters, health checks, and first-response steps for tunnel failure.
For ExpressRoute scope (quoted separately): requirements analysis, circuit sizing and peering-location recommendation, provider coordination through circuit provisioning, private peering and gateway configuration, and validation — including VPN-as-failover design where wanted.

How the work unfolds

1. Scoping and design (days 1-2)

Inventory the two ends: on-premises firewall make, model, and firmware; internet service; address spaces; and what in Azure needs reaching. Produce the design — routing approach, gateway SKU, IPsec parameters, failover expectations — and agree it with your team. Overlapping address space is caught here, while it is a design item rather than an outage.

2. Azure-side deployment (days 2-3)

Deploy the virtual network gateway (zone-redundant SKU), public IP, local network gateway, and connection resources. Gateway provisioning takes Azure a while on its own — we sequence around it rather than letting it stall the week.

3. On-premises coordination and tunnel bring-up (days 3-4)

Working session with your firewall administrator or vendor: apply the matched IPsec/IKE parameters on the on-premises end, establish the tunnel, and bring up BGP or static routing. Both ends' final settings are recorded as configured.

4. Validation (day 4)

Execute the test plan: bidirectional reachability across the agreed ranges, name resolution behavior, latency and throughput baseline, and failover testing — deliberately interrupt and re-establish the tunnel and document what users would experience.

5. Documentation and handover (day 5)

Deliver the as-built documentation, runbook, and Azure cost estimate; walk your team through health checks and the pre-shared key rotation procedure; and close out with any observations for the future — including whether ExpressRoute is worth a quote, or explicitly is not.

Prerequisites

An Azure subscription with permissions to deploy networking resources, and an existing virtual network (or agreement that we create one to the design).
A route-based-capable VPN device or firewall on-premises with IKEv2 support preferred — compatibility is confirmed against Microsoft's validated-device guidance during scoping, and unusual devices are flagged before work begins.
A static public IP address on the on-premises internet connection for the VPN endpoint.
Access to the person or vendor who administers the on-premises firewall, available for the coordination session — we configure Azure directly, and their end with them.
Address space information for both ends; overlapping ranges are resolved in design (NAT or re-addressing) before deployment, as a stated change if re-addressing is needed.
For BGP routing: confirmation that the on-premises device supports it and the ASN to use; otherwise static routing is designed explicitly.
For ExpressRoute scope: a chosen or shortlisted connectivity provider and peering location, and acknowledgment that circuit contracting and monthly fees sit between you and the provider.
Awareness that Azure gateway and bandwidth charges are billed by Microsoft to your subscription — estimated in the design, but not part of our fee.

Who does what

IT Partner

  • Produce the connectivity design and get it approved before deploying anything.
  • Deploy and configure all Azure-side resources: gateway, public IP, local network gateway, connection, and routing.
  • Provide exact, device-appropriate IPsec/IKE parameters and work the coordination session with your firewall administrator or vendor.
  • Validate connectivity, routing, and failover behavior against the test plan and record the results.
  • Deliver as-built documentation, the runbook, and the Azure recurring-cost estimate.
  • For ExpressRoute engagements: scope requirements, recommend circuit and peering design, coordinate with the provider through provisioning, and configure the Azure side.

Your team

  • Provide Azure subscription access and network information for both ends.
  • Make the firewall administrator or vendor available for the coordination session and own any vendor support contracts.
  • Own the internet service and, for ExpressRoute, the provider relationship, circuit contract, and carrier charges.
  • Approve the design, the change window for bring-up, and any re-addressing decisions.
  • Operate the connection after handover using the runbook, including pre-shared key rotation on the documented schedule.
  • Pay Azure consumption charges billed by Microsoft to your subscription.

What's not included

Carrier and ISP services: circuit contracting, internet service upgrades, ExpressRoute circuit monthly fees, and provider SLAs — those contracts are between you and the carrier, and we coordinate rather than intermediate.
Azure consumption charges — gateway hours, bandwidth egress, and ExpressRoute resources are billed by Microsoft; the design includes the estimate so the number is known before you commit.
SD-WAN rollouts, Azure Virtual WAN hub design, and branch-networking transformation programs — different projects; when your site count points that way, we say so in the scoping call instead of stretching this engagement around it.
On-premises firewall procurement, replacement, licensing, or general firewall administration beyond the VPN configuration itself.
Point-to-site (individual user) VPN rollouts and remote-access redesign — related but separately scoped work.
Multi-site topologies under the fixed price — connecting several offices is quoted per design, because routing architecture is the actual work.
Disaster-recovery replication design — Azure Site Recovery implementation is its own engagement, though the connectivity built here is exactly what its replication and failback traffic rides.
Ongoing monitoring and operations of the connection after handover — available through Azure Resource Monitoring and Maintenance.
Building the Azure workload environment itself — that is the Azure IaaS Proof of Concept or a full Azure Landing Zone, into which this connectivity slots cleanly.

Limitations & technical notes

!The fixed $2,450 price covers one site to one Azure virtual network gateway: a single tunnel configuration to a single on-premises device pair, with BGP or static routing. Multi-site, forced-tunneling designs, and coexistence architectures are quoted individually.
!VPN throughput is bounded by real things: your internet uplink, the gateway SKU, IPsec overhead, and your firewall's encryption capacity. The design states the expected envelope, and the validation baseline records what was actually measured — we do not quote theoretical maximums as promises.
!Availability of the tunnel path depends on Microsoft's platform SLAs and your internet service; we design for resilience and validate failover behavior, but the underlying service levels belong to Microsoft and your carrier.
!ExpressRoute timelines are honest by construction: provider circuit delivery typically takes weeks and is outside our control and Microsoft's. We sequence the work around it — and the VPN can carry you in the meantime.
!Overlapping address space between your network and Azure is a design problem with real solutions (NAT rules or re-addressing), but re-addressing is its own change with its own blast radius — flagged in design, never smuggled into a VPN deployment.
!Microsoft's gateway SKU consolidation retired legacy SKUs during 2026; environments carrying an old gateway may need a migration path, which we identify in scoping if it applies to you.
!Old or non-route-based VPN devices can limit the design to weaker parameters or block BGP; scoping flags this and, where the honest answer is a firewall upgrade first, we say that instead of shipping a fragile tunnel.

Frequently asked questions

Do we need ExpressRoute, or is a Site-to-Site VPN enough?

For most SMB and mid-market workloads — office-to-Azure access, administration, file and application traffic — a properly designed VPN is enough, and it is a fixed $2,450 delivered in a week. ExpressRoute earns its monthly circuit cost in specific circumstances: latency-sensitive workloads, sustained heavy data movement, or compliance requirements that mandate traffic never touching the public internet. The comparison table on this page is the same logic we use on scoping calls, and if you do not need ExpressRoute we will tell you exactly that.

What exactly does the $2,450 fixed price include?

The complete single-site Site-to-Site VPN: design document, Azure VPN gateway on a current zone-redundant SKU, local network gateway and connection configuration, IPsec/IKE policy matched to your firewall, BGP or static routing, a working session with your firewall administrator to configure the on-premises end, failover validation, a latency/throughput baseline, and as-built documentation with a runbook. Excluded and stated plainly: carrier charges, Azure's own gateway and bandwidth charges, multi-site topologies, and ExpressRoute — the latter two are quoted.

We have three offices — does the price just triple?

No, and we will not pretend it works that way. Multi-site connectivity is a routing design problem: how sites reach Azure and each other, whether BGP propagates routes or static tables are maintained, and at some site count whether Azure Virtual WAN is the more honest architecture. We quote multi-site work from the actual topology — often it is less than three times the single-site price, sometimes the right answer is a different design entirely.

How long does ExpressRoute really take to stand up?

The Azure-side work is measured in days; the circuit is measured in weeks. Provisioning runs through your connectivity provider — contract, physical or logical circuit delivery, then provider-side configuration — and that lead time belongs to the carrier, not to us or Microsoft. The pattern we recommend when timing matters: deploy the Site-to-Site VPN now, run production over it, and cut over to ExpressRoute when the circuit is delivered, keeping the VPN as the failover path afterward.

Will you work directly with our firewall vendor?

Yes — that coordination is a deliverable, not a favor. We bring exact parameters to a working session with your firewall administrator or vendor: IKE version, encryption and integrity algorithms, DH groups, lifetimes, and traffic selectors, matched to what your device supports. Both ends get configured by people in the same conversation, and both ends' final settings land in the as-built documentation.

What VPN devices and firewalls are supported?

Any device capable of route-based IPsec — which covers current firewalls from the mainstream vendors — with IKEv2 preferred. Microsoft publishes validated-device guidance and we confirm your specific model and firmware during scoping. Where a device is old, policy-based-only, or lacks BGP support, we say so up front: sometimes the design adapts, and sometimes the honest recommendation is to fix the firewall first.

Should we use BGP or static routing?

BGP where your device supports it: routes propagate automatically, failover converges without human intervention, and adding networks later does not mean editing route tables on both ends. Static routing is perfectly serviceable for a stable single-site topology and remains fully supported in the design — the decision is made explicitly during design, based on your device and how much your network changes, not by default.

What does the VPN cost to run each month after you leave?

Our fee is one-time. Ongoing costs are Microsoft's meters on your subscription: VPN gateway hours for the SKU we deploy, plus standard bandwidth charges for traffic leaving Azure. The design includes an estimate against Microsoft's current price list for your expected usage — we deliberately do not print gateway prices on this page because Microsoft revises them, but you will have the number in writing before you approve the design.

How do you make the connection resilient?

Layers, chosen deliberately in design. The gateway itself deploys on a zone-redundant SKU, so Microsoft's platform survives zone-level failures. The tunnel is validated for re-establishment after interruption — we test it rather than assume it. Beyond that, options scale with your needs: redundant tunnels to a second on-premises device, active-active gateway configurations, and ultimately ExpressRoute with VPN failover. The design states which layers you are getting and which you declined, so resilience is a documented decision.

Can this be done without downtime to our existing network?

The Azure-side build touches nothing on-premises, so it is invisible to users. The on-premises change is the firewall configuration session — new tunnel configuration on an existing device, which on modern firewalls does not interrupt other traffic. If we are replacing an existing improvised VPN, cutover is sequenced in a maintenance window with the old path kept as rollback until the new one is validated.

Does this cover remote workers connecting from home?

No — that is point-to-site VPN or, increasingly, no VPN at all: identity-based access through Entra and Conditional Access often serves remote workers better than network tunnels. This engagement connects networks to networks. If remote-user access is part of your picture, raise it on the scoping call and we will point at the right pattern honestly, including when it is not a VPN.

What happens after handover if the tunnel goes down at 2 a.m.?

The runbook is written for exactly that moment: health checks to run, the usual causes in order of likelihood, and what to restart or re-key on each end. Operating the connection is yours after handover by design — no forced retainer. If you want someone watching it instead, our Azure Resource Monitoring and Maintenance service covers the connection as part of the monitored estate, as a separate, explicit engagement.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$2,450 per project
1 week
Book a connectivity scoping call