Site-to-Site VPN vs dedicated interconnect
hybrid connectivity tradeoffs.
VPN is quick, cheap, encrypted over public internet with variable latency; Direct Connect or ExpressRoute is a private dedicated link with consistent low latency, high bandwidth, longer lead time and…
What's really being asked
The interviewer wants a clear comparison of hybrid connectivity along the dimensions that actually drive the decision: latency consistency, bandwidth, cost, security, and time to provision.
The full answer
A Site-to-Site VPN establishes an encrypted IPsec tunnel between your on-premises gateway and a cloud VPN gateway over the public internet. It is inexpensive, can be provisioned in hours, and encrypts data in transit, but because it rides the public internet it has variable latency, jitter, and throughput capped by both the internet path and tunnel limits. A dedicated interconnect, such as AWS Direct Connect or Azure ExpressRoute, is a private circuit provisioned through a partner that bypasses the public internet entirely. It delivers consistent low latency, high and predictable bandwidth up to many gigabits, and stronger SLAs, which matters for large data transfers, latency-sensitive workloads, and compliance that disfavors public transit. The tradeoffs are higher recurring cost and a lead time of weeks because physical cross-connects must be installed. A common production pattern uses the dedicated link as primary and a VPN as an encrypted, cheaper failover. Note that ExpressRoute and Direct Connect are not encrypted by default at the circuit level, so you may layer encryption on top for sensitive data.
The mistakes people make
Claiming the dedicated link is always better and ignoring its cost and weeks-long provisioning. Assuming Direct Connect or ExpressRoute is automatically encrypted. Treating VPN throughput and latency as equivalent to a private circuit.
What usually comes next
How do you achieve redundancy on a dedicated link? How is encryption added over ExpressRoute? What bandwidth justifies the cost crossover?
A concrete example
A nightly 10 TB analytics sync to the cloud saturates and stalls over a VPN, so the team provisions a 10 Gbps Direct Connect for predictable throughput and keeps the existing VPN as an encrypted failover path.
Interview question
A workload needs predictable single-digit-millisecond latency and steady multi-gigabit throughput to the cloud. Which is the strongest choice and its main cost?
- a.Dedicated interconnect, with higher recurring cost and weeks of lead timeCorrect
- b.Site-to-Site VPN, with the cost being weeks of provisioning lead time
- c.Dedicated interconnect, which is free and provisions instantly
- d.Site-to-Site VPN, because the public internet guarantees consistent latency
Why? this is the answer
A dedicated interconnect bypasses the public internet for consistent low latency and high bandwidth, but costs more and takes weeks to install. VPNs inherit variable internet latency, so they cannot guarantee it.
Just read this? Test yourself on what you have been reading.
Read the original → azure.microsoft.com
- #hybrid-cloud
- #networking
- #vpn
- #direct-connect
- #expressroute
You just looked this up. Could you explain it out loud?
That is the part interviews actually test. Tezvyn takes questions like this one and gives you what the interviewer is really checking, the answer that lands, and the mistake that ends the conversation, in the four minutes before your next meeting.
The iPhone app is on the way
We are building it. Until it lands, nothing here is held back from you: every interview card, your saved cards, streaks and the job board all work in Safari, plus hundreds of free practice quizzes of thirty questions each. Sign in and it all carries over to the app the day it arrives.
Want it as an icon? Tap Share at the bottom of Safari, then Add to Home Screen. It opens full screen and the cards you have read stay available offline.
We are hiring for this. Every open role lists the topics its interview covers, so you can prepare for the real thing rather than guessing.
See open roles