Skip to content

Commit bc0411c

Browse files
authored
Update terminology for routing devices in VPN documentation
Selective traffic encryption
1 parent 4985e68 commit bc0411c

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

articles/vpn-gateway/site-to-site-high-bandwidth-tunnel.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,7 @@ To ensure predictable routing, advertise different on-premises IP network prefix
9797

9898
**Option 2 – Route precedence using more specific network prefixes**
9999

100-
Advertise more specific (longer subnet masks) on‑premises IP network prefixes over the IPsec tunnels than the on-premises prefixes you advertise over the ExpressRoute circuit. Because Azure and on‑premises routers both select routes based on longest prefix match (LPM), these more specific prefixes learned through the IPsec tunnel will take precedence over the less specific prefixes learned through ExpressRoute. This ensures that traffic destined for those networks follows the encrypted IPsec path rather than the unencrypted ExpressRoute path.
100+
Advertise more specific (longer subnet masks) on‑premises IP network prefixes over the IPsec tunnels than the on-premises prefixes you advertise over the ExpressRoute circuit. Because Azure and on‑premises devices both select routes based on longest prefix match (LPM), these more specific prefixes learned through the IPsec tunnel will take precedence over the less specific prefixes learned through ExpressRoute. This ensures that traffic destined for those networks follows the encrypted IPsec path rather than the unencrypted ExpressRoute path.
101101

102102
These considerations apply regardless of whether static or dynamic routing is used for the IPsec tunnels.
103103

0 commit comments

Comments
 (0)