# Choose ExpressRoute Direct encapsulation with the correct VLAN uniqueness boundary

> QinQ and Dot1Q use different C-Tag uniqueness scopes, and the Direct resource's encapsulation cannot be changed afterward.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:32+00:00
- Modified: 2026-09-10T01:40:03+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

QinQ and Dot1Q use different C-Tag uniqueness scopes, and the Direct resource's encapsulation cannot be changed afterward.

## Potentially affected

Azure ExpressRoute Direct resources and their circuit VLAN-tag plans.

## DSE recommendation

Approve the encapsulation and tag allocation scope together before creating the Direct resource.

## Article

## Source facts

ExpressRoute Direct supports QinQ and Dot1Q. With QinQ, Azure dynamically assigns each circuit an S-Tag unique across the Direct resource; C-Tags must be unique within the circuit, but not across the entire Direct resource.

With Dot1Q, the customer must ensure C-Tag uniqueness across the whole Direct resource. Microsoft states that a Direct resource can use only one encapsulation type and that this choice cannot be changed after creation. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal).

## Applicability

Identify the planned Direct resource, participating circuits and connected equipment’s approved encapsulation. Keep the resource’s allocation boundary distinct from the VLAN convention used elsewhere in the organization.

## DSE recommendation

DSE recommends an allocation record showing every circuit and the scope in which each tag must be unique. Review it with the teams responsible for the physical cross-connections and router configuration before resource creation. Resolve duplicate or ambiguous assignments at design time. Do not assume a later portal edit can switch the encapsulation to accommodate an inconsistent tag plan.

## Verification

Compare the created resource’s encapsulation and circuit tags with the approved allocation record. During the authorized connectivity test, verify the intended circuit and tagging at the relevant interfaces. Record any mismatch before adding another circuit. Retain both the Azure values and the corresponding equipment configuration so a successful link state is not mistaken for proof that every planned logical circuit is mapped correctly.

## Official references

[Microsoft Learn: Configure Azure ExpressRoute Direct](https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure Azure ExpressRoute Direct | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/expressroute/how-to-expressroute-direct-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose ExpressRoute Direct encapsulation with the correct VLAN uniqueness boundary,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-324-choose-expressroute-direct-encapsulation-with-the-correct-vlan-uniqueness-boundary/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
