They have a standard ExpressRoute circuit (not Direct) and still need network-layer encryption from the yard to the VNet. Which approach meets that need?
Select an answer to reveal the explanation.
Short Explanation
No Direct ports? You can’t lean on MACsec. Ride an IPsec VPN over ExpressRoute private peering—VPN gateway or Virtual WAN—so Layer 3 gets real encryption.
Full Explanation
On a standard (non-Direct) ExpressRoute circuit, network-layer encryption is commonly achieved by running a site-to-site IPsec VPN over ExpressRoute private peering with a VPN gateway or Azure Virtual WAN. FastPath does not add encryption by itself. MACsec applies to ExpressRoute Direct physical ports, not typical provider-managed circuits. Bastion and JIT secure administrative access paths; they do not encrypt all ExpressRoute workloads.