Azure Site-to-Site VPN and ExpressRoute Implementation
IT Partner connects your office or datacenter to your Azure workloads over a private, encrypted path. For a single site, the Site-to-Site VPN implementation is a fixed $2,450, one-week engagement: VPN gateway on a current zone-redundant SKU, IPsec/IKE policy matched to your firewall, BGP or static routing, coordination with your firewall administrator or vendor, failover validation, and as-built documentation. ExpressRoute — a dedicated private circuit through a connectivity provider — and multi-site VPN topologies are scoped and quoted individually, and this page includes an honest guide to which one you actually need. Two costs are explicitly not ours: your carrier or ISP circuit charges, and Azure's own gateway and bandwidth charges, which Microsoft bills directly — we size and estimate them in the design so neither surprises you.
What this engagement is
Every hybrid Azure story runs through the same sentence: the workloads moved, and now the office needs to reach them properly. The wrong answer is the one we still find in the wild — management ports exposed to the public internet, or a VPN improvised years ago from defaults that nobody dares touch. The right answer is a designed private path: a Site-to-Site VPN for most organizations, or an ExpressRoute circuit when the requirements genuinely demand one, built once, documented, and validated under failure conditions rather than assumed to work. The fixed-price engagement delivers the Site-to-Site VPN end to end for a single site. We design the address space and routing so nothing overlaps and nothing is left to chance, deploy an Azure VPN gateway on a current zone-redundant SKU — Microsoft has been consolidating gateway SKUs and retiring legacy tiers through 2026, and we deliberately deploy what is current rather than what is on a retirement list — then build the IPsec/IKE tunnel to match your on-premises firewall, configure BGP or static routing to fit your network, and coordinate directly with your firewall administrator or vendor so the two ends are configured by people talking to each other, not guessing at each other. Before handover we validate the part most VPN setups skip: what happens when a tunnel drops, a gateway instance fails over, or the primary path degrades. You receive as-built documentation and a runbook, so the next engineer to touch this understands it in minutes. ExpressRoute is the second half of the page, and we are honest about it: it is a dedicated private circuit into Microsoft's network through a connectivity provider — predictable latency, high bandwidth from 50 Mbps up to 10 Gbps through providers, and traffic that never touches the public internet. It is also a project with a telecom in the middle: circuits carry monthly provider fees and provisioning lead times measured in weeks, which is why ExpressRoute engagements are scoped and quoted rather than sold at a flat price. Most SMB workloads are served excellently by a well-built VPN; ExpressRoute earns its cost when latency-sensitive workloads, sustained data volumes, or compliance requirements say so. The decision guide below is the same one we use on scoping calls — and a common, sensible pattern is both: the VPN ships this week and later becomes the failover path for a circuit that takes six to eight weeks to arrive.
Which one applies to you
The honest decision guide. Most organizations need the left column; the right column earns its cost in specific, nameable circumstances.
| Site-to-Site VPN — $2,450 fixed | ExpressRoute — quoted | |
|---|---|---|
| How traffic travels | Encrypted IPsec tunnel across your existing internet connection. | Dedicated private circuit into Microsoft's network via a connectivity provider — traffic never crosses the public internet. |
| Best for | Office-to-Azure access, server administration, file and application traffic, branch connectivity — the standard hybrid workload. | Latency-sensitive workloads, sustained large data volumes, and compliance postures that mandate private connectivity. |
| Bandwidth and latency | Bounded by your internet uplink, gateway SKU, and firewall throughput; latency varies with the internet path. | Committed circuit bandwidth from 50 Mbps to 10 Gbps through providers, with predictable latency. |
| What it depends on | Your existing internet service and a compatible firewall — nothing new to procure. | A carrier or connectivity provider contract, a peering location, and provider provisioning. |
| Time to live | About one week, most of it design and validation. | Typically weeks, driven by provider circuit delivery — outside anyone's control but the carrier's. |
| Recurring costs (Microsoft/carrier, not ours) | Azure VPN gateway hours and standard bandwidth charges. | Monthly circuit fee to the provider plus Azure ExpressRoute and gateway charges. |
A frequent right answer is both: the VPN ships now, then stays as the failover path once the ExpressRoute circuit is delivered — Azure supports that coexistence deliberately.
Multi-site VPN topologies (several offices into one Azure footprint) are quoted per design rather than multiplied from the single-site price, because routing design is where the real work lives.
Success criteria
What you receive
How the work unfolds
Inventory the two ends: on-premises firewall make, model, and firmware; internet service; address spaces; and what in Azure needs reaching. Produce the design — routing approach, gateway SKU, IPsec parameters, failover expectations — and agree it with your team. Overlapping address space is caught here, while it is a design item rather than an outage.
Deploy the virtual network gateway (zone-redundant SKU), public IP, local network gateway, and connection resources. Gateway provisioning takes Azure a while on its own — we sequence around it rather than letting it stall the week.
Working session with your firewall administrator or vendor: apply the matched IPsec/IKE parameters on the on-premises end, establish the tunnel, and bring up BGP or static routing. Both ends' final settings are recorded as configured.
Execute the test plan: bidirectional reachability across the agreed ranges, name resolution behavior, latency and throughput baseline, and failover testing — deliberately interrupt and re-establish the tunnel and document what users would experience.
Deliver the as-built documentation, runbook, and Azure cost estimate; walk your team through health checks and the pre-shared key rotation procedure; and close out with any observations for the future — including whether ExpressRoute is worth a quote, or explicitly is not.
Prerequisites
Who does what
IT Partner
- Produce the connectivity design and get it approved before deploying anything.
- Deploy and configure all Azure-side resources: gateway, public IP, local network gateway, connection, and routing.
- Provide exact, device-appropriate IPsec/IKE parameters and work the coordination session with your firewall administrator or vendor.
- Validate connectivity, routing, and failover behavior against the test plan and record the results.
- Deliver as-built documentation, the runbook, and the Azure recurring-cost estimate.
- For ExpressRoute engagements: scope requirements, recommend circuit and peering design, coordinate with the provider through provisioning, and configure the Azure side.
Your team
- Provide Azure subscription access and network information for both ends.
- Make the firewall administrator or vendor available for the coordination session and own any vendor support contracts.
- Own the internet service and, for ExpressRoute, the provider relationship, circuit contract, and carrier charges.
- Approve the design, the change window for bring-up, and any re-addressing decisions.
- Operate the connection after handover using the runbook, including pre-shared key rotation on the documented schedule.
- Pay Azure consumption charges billed by Microsoft to your subscription.
What's not included
Limitations & technical notes
Frequently asked questions
Do we need ExpressRoute, or is a Site-to-Site VPN enough?
For most SMB and mid-market workloads — office-to-Azure access, administration, file and application traffic — a properly designed VPN is enough, and it is a fixed $2,450 delivered in a week. ExpressRoute earns its monthly circuit cost in specific circumstances: latency-sensitive workloads, sustained heavy data movement, or compliance requirements that mandate traffic never touching the public internet. The comparison table on this page is the same logic we use on scoping calls, and if you do not need ExpressRoute we will tell you exactly that.
What exactly does the $2,450 fixed price include?
The complete single-site Site-to-Site VPN: design document, Azure VPN gateway on a current zone-redundant SKU, local network gateway and connection configuration, IPsec/IKE policy matched to your firewall, BGP or static routing, a working session with your firewall administrator to configure the on-premises end, failover validation, a latency/throughput baseline, and as-built documentation with a runbook. Excluded and stated plainly: carrier charges, Azure's own gateway and bandwidth charges, multi-site topologies, and ExpressRoute — the latter two are quoted.
We have three offices — does the price just triple?
No, and we will not pretend it works that way. Multi-site connectivity is a routing design problem: how sites reach Azure and each other, whether BGP propagates routes or static tables are maintained, and at some site count whether Azure Virtual WAN is the more honest architecture. We quote multi-site work from the actual topology — often it is less than three times the single-site price, sometimes the right answer is a different design entirely.
How long does ExpressRoute really take to stand up?
The Azure-side work is measured in days; the circuit is measured in weeks. Provisioning runs through your connectivity provider — contract, physical or logical circuit delivery, then provider-side configuration — and that lead time belongs to the carrier, not to us or Microsoft. The pattern we recommend when timing matters: deploy the Site-to-Site VPN now, run production over it, and cut over to ExpressRoute when the circuit is delivered, keeping the VPN as the failover path afterward.
Will you work directly with our firewall vendor?
Yes — that coordination is a deliverable, not a favor. We bring exact parameters to a working session with your firewall administrator or vendor: IKE version, encryption and integrity algorithms, DH groups, lifetimes, and traffic selectors, matched to what your device supports. Both ends get configured by people in the same conversation, and both ends' final settings land in the as-built documentation.
What VPN devices and firewalls are supported?
Any device capable of route-based IPsec — which covers current firewalls from the mainstream vendors — with IKEv2 preferred. Microsoft publishes validated-device guidance and we confirm your specific model and firmware during scoping. Where a device is old, policy-based-only, or lacks BGP support, we say so up front: sometimes the design adapts, and sometimes the honest recommendation is to fix the firewall first.
Should we use BGP or static routing?
BGP where your device supports it: routes propagate automatically, failover converges without human intervention, and adding networks later does not mean editing route tables on both ends. Static routing is perfectly serviceable for a stable single-site topology and remains fully supported in the design — the decision is made explicitly during design, based on your device and how much your network changes, not by default.
What does the VPN cost to run each month after you leave?
Our fee is one-time. Ongoing costs are Microsoft's meters on your subscription: VPN gateway hours for the SKU we deploy, plus standard bandwidth charges for traffic leaving Azure. The design includes an estimate against Microsoft's current price list for your expected usage — we deliberately do not print gateway prices on this page because Microsoft revises them, but you will have the number in writing before you approve the design.
How do you make the connection resilient?
Layers, chosen deliberately in design. The gateway itself deploys on a zone-redundant SKU, so Microsoft's platform survives zone-level failures. The tunnel is validated for re-establishment after interruption — we test it rather than assume it. Beyond that, options scale with your needs: redundant tunnels to a second on-premises device, active-active gateway configurations, and ultimately ExpressRoute with VPN failover. The design states which layers you are getting and which you declined, so resilience is a documented decision.
Can this be done without downtime to our existing network?
The Azure-side build touches nothing on-premises, so it is invisible to users. The on-premises change is the firewall configuration session — new tunnel configuration on an existing device, which on modern firewalls does not interrupt other traffic. If we are replacing an existing improvised VPN, cutover is sequenced in a maintenance window with the old path kept as rollback until the new one is validated.
Does this cover remote workers connecting from home?
No — that is point-to-site VPN or, increasingly, no VPN at all: identity-based access through Entra and Conditional Access often serves remote workers better than network tunnels. This engagement connects networks to networks. If remote-user access is part of your picture, raise it on the scoping call and we will point at the right pattern honestly, including when it is not a VPN.
What happens after handover if the tunnel goes down at 2 a.m.?
The runbook is written for exactly that moment: health checks to run, the usual causes in order of likelihood, and what to restart or re-key on each end. Operating the connection is yours after handover by design — no forced retainer. If you want someone watching it instead, our Azure Resource Monitoring and Maintenance service covers the connection as part of the monitored estate, as a separate, explicit engagement.