{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
        "slug": "dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/"
        },
        "title": "Choose ExpressRoute Direct encapsulation with the correct VLAN uniqueness boundary",
        "summary": "QinQ and Dot1Q use different C-Tag uniqueness scopes, and the Direct resource's encapsulation cannot be changed afterward.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:26:32+00:00",
        "modified_at": "2026-09-10T01:40:03+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 238,
        "potentially_affected": "Azure ExpressRoute Direct resources and their circuit VLAN-tag plans.",
        "dse_recommendation": "Approve the encapsulation and tag allocation scope together before creating the Direct resource.",
        "primary_source": {
            "name": "Configure Azure ExpressRoute Direct | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>ExpressRoute Direct supports QinQ and Dot1Q. With QinQ, Azure dynamically assigns each circuit an S-Tag unique across the Direct resource; C-Tags must be unique within the circuit, but not across the entire Direct resource.</p>\n<p>With Dot1Q, the customer must ensure C-Tag uniqueness across the whole Direct resource. Microsoft states that a Direct resource can use only one encapsulation type and that this choice cannot be changed after creation. <a href=\"https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the planned Direct resource, participating circuits and connected equipment&#8217;s approved encapsulation. Keep the resource&#8217;s allocation boundary distinct from the VLAN convention used elsewhere in the organization.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends an allocation record showing every circuit and the scope in which each tag must be unique. Review it with the teams responsible for the physical cross-connections and router configuration before resource creation. Resolve duplicate or ambiguous assignments at design time. Do not assume a later portal edit can switch the encapsulation to accommodate an inconsistent tag plan.</p>\n<h2>Verification</h2>\n<p>Compare the created resource&#8217;s encapsulation and circuit tags with the approved allocation record. During the authorized connectivity test, verify the intended circuit and tagging at the relevant interfaces. Record any mismatch before adding another circuit. Retain both the Azure values and the corresponding equipment configuration so a successful link state is not mistaken for proof that every planned logical circuit is mapped correctly.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Azure ExpressRoute Direct</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nExpressRoute Direct supports QinQ and Dot1Q. With QinQ, Azure dynamically assigns each circuit an S-Tag unique across the Direct resource; C-Tags must be unique within the circuit, but not across the entire Direct resource.\nWith Dot1Q, the customer must ensure C-Tag uniqueness across the whole Direct resource. Microsoft states that a Direct resource can use only one encapsulation type and that this choice cannot be changed after creation. Microsoft Learn.\nApplicability\nIdentify the planned Direct resource, participating circuits and connected equipment’s approved encapsulation. Keep the resource’s allocation boundary distinct from the VLAN convention used elsewhere in the organization.\nDSE recommendation\nDSE recommends an allocation record showing every circuit and the scope in which each tag must be unique. Review it with the teams responsible for the physical cross-connections and router configuration before resource creation. Resolve duplicate or ambiguous assignments at design time. Do not assume a later portal edit can switch the encapsulation to accommodate an inconsistent tag plan.\nVerification\nCompare the created resource’s encapsulation and circuit tags with the approved allocation record. During the authorized connectivity test, verify the intended circuit and tagging at the relevant interfaces. Record any mismatch before adding another circuit. Retain both the Azure values and the corresponding equipment configuration so a successful link state is not mistaken for proof that every planned logical circuit is mapped correctly.\nOfficial references\nMicrosoft Learn: Configure Azure ExpressRoute Direct. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nExpressRoute Direct supports QinQ and Dot1Q. With QinQ, Azure dynamically assigns each circuit an S-Tag unique across the Direct resource; C-Tags must be unique within the circuit, but not across the entire Direct resource.\n\nWith Dot1Q, the customer must ensure C-Tag uniqueness across the whole Direct resource. Microsoft states that a Direct resource can use only one encapsulation type and that this choice cannot be changed after creation. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal).\n\n## Applicability\n\nIdentify the planned Direct resource, participating circuits and connected equipment’s approved encapsulation. Keep the resource’s allocation boundary distinct from the VLAN convention used elsewhere in the organization.\n\n## DSE recommendation\n\nDSE recommends an allocation record showing every circuit and the scope in which each tag must be unique. Review it with the teams responsible for the physical cross-connections and router configuration before resource creation. Resolve duplicate or ambiguous assignments at design time. Do not assume a later portal edit can switch the encapsulation to accommodate an inconsistent tag plan.\n\n## Verification\n\nCompare the created resource’s encapsulation and circuit tags with the approved allocation record. During the authorized connectivity test, verify the intended circuit and tagging at the relevant interfaces. Record any mismatch before adding another circuit. Retain both the Azure values and the corresponding equipment configuration so a successful link state is not mistaken for proof that every planned logical circuit is mapped correctly.\n\n## Official references\n\n[Microsoft Learn: Configure Azure ExpressRoute Direct](https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Choose ExpressRoute Direct encapsulation with the correct VLAN uniqueness boundary",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/",
                "headline": "Choose ExpressRoute Direct encapsulation with the correct VLAN uniqueness boundary",
                "description": "QinQ and Dot1Q use different C-Tag uniqueness scopes, and the Direct resource's encapsulation cannot be changed afterward.",
                "abstract": "QinQ and Dot1Q use different C-Tag uniqueness scopes, and the Direct resource's encapsulation cannot be changed afterward.",
                "articleBody": "Source facts\nExpressRoute Direct supports QinQ and Dot1Q. With QinQ, Azure dynamically assigns each circuit an S-Tag unique across the Direct resource; C-Tags must be unique within the circuit, but not across the entire Direct resource.\nWith Dot1Q, the customer must ensure C-Tag uniqueness across the whole Direct resource. Microsoft states that a Direct resource can use only one encapsulation type and that this choice cannot be changed after creation. Microsoft Learn.\nApplicability\nIdentify the planned Direct resource, participating circuits and connected equipment’s approved encapsulation. Keep the resource’s allocation boundary distinct from the VLAN convention used elsewhere in the organization.\nDSE recommendation\nDSE recommends an allocation record showing every circuit and the scope in which each tag must be unique. Review it with the teams responsible for the physical cross-connections and router configuration before resource creation. Resolve duplicate or ambiguous assignments at design time. Do not assume a later portal edit can switch the encapsulation to accommodate an inconsistent tag plan.\nVerification\nCompare the created resource’s encapsulation and circuit tags with the approved allocation record. During the authorized connectivity test, verify the intended circuit and tagging at the relevant interfaces. Record any mismatch before adding another circuit. Retain both the Azure values and the corresponding equipment configuration so a successful link state is not mistaken for proof that every planned logical circuit is mapped correctly.\nOfficial references\nMicrosoft Learn: Configure Azure ExpressRoute Direct. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:26:32+00:00",
                "dateModified": "2026-09-10T01:40:03+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Choose ExpressRoute Direct encapsulation with the correct VLAN uniqueness boundary"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 238,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Azure ExpressRoute Direct | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal"
                }
            }
        ]
    }
}