Network Design & Resilience

AWS Direct Connect, Azure ExpressRoute and Google Interconnect vs the Public Internet

A private line into your cloud provider sounds like an enterprise luxury. Sometimes it is. Sometimes it pays for itself in data-transfer charges alone.

A private cloud on-ramp such as AWS Direct Connect, Azure ExpressRoute or Google Cloud Interconnect connects your network to the cloud provider's network without crossing the public internet. It gives more predictable performance and often a lower rate for data leaving the cloud, but it adds port and circuit costs and needs a physical path to a facility where the cloud provider connects. Plenty of businesses are well served by a good internet circuit and an encrypted VPN, and the honest answer for them is to stay there.

Product names, speeds, locations and pricing for all three providers change regularly, so treat the details below as a general guide and check the provider's current documentation before you design anything.

How most businesses reach the cloud today

Most offices reach their cloud environment over their ordinary internet circuit. Staff use cloud applications directly, and servers in the office talk to servers in the cloud over an encrypted IPsec tunnel to the provider's VPN gateway. This works, it is quick to set up, and it costs little beyond the circuit you already have.

The limits show up as the cloud becomes more central. Internet paths change and congest, so latency between the office and the cloud varies. VPN throughput per tunnel is capped. And the cloud provider usually charges for data leaving its network, which becomes a line item worth watching once you move large volumes.

What a private on-ramp is

Each of the big three sells a way to connect directly into its network at specific facilities, usually colocation data centers and carrier hotels:

  • AWS Direct Connect offers dedicated connections on physical ports in a handful of standard speeds at Direct Connect locations, and hosted connections in smaller increments through AWS partners.
  • Azure ExpressRoute is usually bought through a connectivity provider at a range of circuit sizes, with ExpressRoute Direct for organisations that want very large ports of their own.
  • Google Cloud Interconnect comes as Dedicated Interconnect, a physical connection at a Google facility, or Partner Interconnect, where a service provider supplies the connection in smaller sizes.

The common pattern is the same across all three. Either you place your own equipment in a facility where the provider is present and order a physical port, or you buy a smaller virtual connection through a partner that already has big ports into the provider.

The physical path, end to end

A private on-ramp does not start at your office. The cloud provider's port is in a data center, so the full path usually looks like this:

  1. Your office or data center, where your router sits.
  2. A carrier circuit from your building to the on-ramp facility, typically an Ethernet transport or wavelength service.
  3. Your equipment or a partner's in that facility, in colocation space or on a partner's network fabric.
  4. A cross-connect, the physical cable inside the building from your equipment to the cloud provider's port. We explain these in what is a cross-connect.
  5. The cloud provider's router and your virtual network behind it.

Partner and hosted options can remove steps three and four from your plate, because the partner already has equipment and ports in place. That is why they suit smaller connections and faster starts.

Internet and VPN vs private on-ramp

Internet plus IPsec VPNPrivate on-ramp
PathPublic internet, variesYour circuit and the provider's network
PerformanceUsually good, not predictableMore consistent latency and throughput
EncryptionBuilt inNot by default; added separately
Setup timeHours to daysWeeks, longer if a new circuit or construction is needed
Fixed costsYour existing circuitPort or hosted-connection fee, cross-connect, carrier circuit
Data leaving the cloudCharged at the provider's internet ratesOften charged at a lower rate; check current pricing
RedundancyDepends on your circuitsNeeds a second connection, ideally at a second location

Routing over the private link

Private on-ramps use BGP, the routing protocol carriers use between networks, to exchange routes between your router and the cloud provider's. You advertise your office address ranges, the provider advertises your cloud network ranges, and traffic follows those routes. That means someone on your side needs to configure and look after BGP, or your carrier or a managed provider needs to do it for you. It also means you need a plan for address ranges: if your office network and your cloud network use overlapping private addresses, routing between them breaks. Sort that out before the circuit arrives, not after. Our guide to static IPs and BGP covers the basics.

Reaching more than one cloud

Many businesses use more than one provider: Microsoft for email and identity, AWS or Google for applications. Building separate physical connections to each gets expensive. Interconnection fabrics run by data center operators and network partners let one physical port carry virtual connections to several cloud providers, each turned up through a portal. If you expect to use two or more clouds, ask whether a fabric port is cheaper than separate on-ramps, and check that each virtual connection still has a backup path.

Software-as-a-service tools are a separate case. Email, office suites and CRM platforms are generally designed to be reached over the internet, and a private connection to the underlying cloud provider does not necessarily carry that traffic. A private on-ramp is mainly for your own servers and storage in the provider's infrastructure.

Private does not mean encrypted

A common misunderstanding is that a private connection is automatically encrypted. Traffic on these links does not cross the public internet, but it is not necessarily encrypted on the wire. Depending on the provider and port type, the options include link-layer encryption on some dedicated ports, an IPsec VPN running over the private connection, or relying on encryption at the application layer. If your compliance rules require encryption in transit, decide which approach you will use before you order.

Data transfer: where the money usually is

Cloud providers generally charge little or nothing for data coming in and charge for data going out. Over a private on-ramp, the per-gigabyte rate for outbound data is often lower than the internet rate, but you add fixed monthly costs for the port or hosted connection, the cross-connect and the carrier circuit. Whether it pays is arithmetic.

A worked example

Hypothetical figures to show the method. These are not any provider's prices; use the current price sheet for your region.

Suppose a business moves 40 TB a month out of the cloud: nightly data extracts, backup copies back to the office and large files pulled by staff. Say the difference between the provider's internet rate and its private-connection rate were 5 cents per gigabyte. Forty terabytes is roughly 40,000 GB, so the difference would be about $2,000 a month.

Against that, add up the fixed costs: the port or hosted connection, the cross-connect, and the carrier circuit from your office to the on-ramp facility. If those total less than $2,000 a month, the private connection saves money and buys you consistent performance on top. If the business only moves 2 TB a month, the same rate difference is worth about $100, and the private connection almost never pays on cost alone. It might still be justified for performance or compliance reasons, but that should be a deliberate decision.

One connection is one point of failure

A single private connection means one circuit, one cross-connect, one port. All three providers publish guidance recommending multiple connections, ideally at more than one location, for workloads that cannot go down. A practical middle ground for many businesses is a private connection as the primary path with an internet VPN as the backup, so a fiber cut slows things down rather than stopping them. Make sure the carrier circuits really take different routes; route diversity and redundancy explains how to check.

When a private on-ramp is worth it

  • You move large volumes of data out of the cloud every month.
  • Applications split between the office and the cloud are sensitive to latency or variation, such as databases, voice platforms or trading systems.
  • You need sustained throughput beyond what a VPN tunnel comfortably carries.
  • A regulator, client or auditor expects traffic to stay off the public internet.
  • You already have equipment in a facility where the provider connects.

If none of these apply, a symmetrical dedicated internet circuit and a well-configured VPN is usually the right answer, and cheaper.

Questions to ask your provider

  • Which on-ramp locations are nearest my office, and can you deliver a circuit to them?
  • Dedicated port or hosted connection: which fits my bandwidth, and how quickly can each be turned up?
  • Who supplies and pays for the cross-connect at the facility?
  • How will traffic be encrypted on the private link, if we need that?
  • What is the backup path if the private connection fails, and is it physically diverse?
  • Can the same circuit reach more than one cloud provider through a partner fabric?
  • Who do I call when it breaks: you, the carrier or the cloud provider?

Getting the path priced

The cloud provider's port is often the smallest part of the cost. The circuit to reach it, and the cross-connect at the far end, are where buyers overspend. We price the whole path across several carriers through our cloud connectivity service, and we will tell you if the arithmetic says to stay on the internet. The carrier pays us, so there is no markup, and the quote is free with a same-day response. Send us your address, call 478-758-8091 or text (347) 870-0965.

// QUESTIONS

Frequently Asked Questions

01What is AWS Direct Connect?

It is Amazon's service for connecting your network to AWS over a private connection instead of the public internet. You either order a dedicated port at a Direct Connect location or buy a hosted connection through an AWS partner. Speeds, locations and pricing change, so check current AWS documentation.

02Is Direct Connect or ExpressRoute encrypted?

Not automatically. The traffic does not cross the public internet, but it is not necessarily encrypted on the link. Options include link-layer encryption on some dedicated ports, running an IPsec VPN over the private connection, or encrypting at the application layer.

03Is a private cloud connection cheaper than the internet?

It can be if you move a lot of data out of the cloud, because outbound data over a private connection is often charged at a lower rate. You add fixed costs for the port or hosted connection, the cross-connect and the carrier circuit, so it only saves money above a certain monthly data volume.

04Do I need colocation to use a cloud on-ramp?

Not always. With a dedicated port you usually need equipment in a facility where the provider connects. With a hosted or partner connection, the partner already has equipment and ports there, so your carrier circuit can connect to the partner instead.

05How long does it take to set up a private cloud connection?

A hosted connection over an existing circuit can be turned up relatively quickly. A dedicated port with a new carrier circuit takes longer, typically weeks, and longer still if the circuit to your building needs construction.

06Should I keep an internet VPN as a backup?

Usually, yes. A single private connection is a single point of failure. An IPsec VPN over your internet circuit is an inexpensive backup that keeps traffic flowing, at lower performance, if the private path fails.

// FREE · NO OBLIGATION · SAME-DAY RESPONSE

Want This Priced for Your Address?

Reading is cheap; a real number for your building is better. Pick a time below, or call and we will talk it through.

EMAIL INFO@FIBERXINTERNET.COM · TEXT (347) 870-0965

FIBERX · APPOINTMENT CONSOLE
Book an Appointment

Talk to Phil. Pick a Time.

A quick call with your dedicated agent — internet quotes, AI automation, or both. No obligation, same-day response.

Pick your 30-minute slot ALL TIMES ET
or call 478-758-8091

REQUEST GOES STRAIGHT TO PHIL · SAME-DAY CONFIRMATION