# Do not assume Route Server VPN preference excludes NVA routes

> The VPN preference groups VPN gateway and NVA routes together and compares their AS paths for the same destination.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-529-do-not-assume-route-server-vpn-preference-excludes-nva-routes/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:07+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

The VPN preference groups VPN gateway and NVA routes together and compares their AS paths for the same destination.

## Potentially affected

Azure Route Server hybrid designs receiving matching prefixes from VPN gateways, NVAs and ExpressRoute.

## DSE recommendation

Compare the VPN and NVA advertisements together before selecting the routing preference.

## Article

## Source facts

Azure Route Server’s VPN preference prioritizes routes from VPN gateways and NVAs over ExpressRoute routes. It does not distinguish the VPN gateway from the NVA: when both advertise the same route, the shorter BGP AS path is selected.

ExpressRoute preference is the default and prioritizes ExpressRoute routes. AS Path preference instead compares path length regardless of the route’s source. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/route-server/hub-routing-preference).

## Applicability

Inventory advertisements for the same destination prefix from each participating source. Do not infer the selected next hop solely from the preference label or from one peer’s established session.

## DSE recommendation

DSE recommends documenting the desired primary and fallback route for each important prefix before changing preference. Compare actual VPN and NVA AS paths and coordinate any approved path manipulation with their owners. Avoid a broad preference change intended to fix one prefix without reviewing other overlapping advertisements.

## Verification

Inspect learned and selected routes for representative prefixes, then exercise approved failure and recovery scenarios. Confirm the actual next hop matches the intended design while the relevant peers are available and after restoration. Retain advertisements, preference and traffic observations together. An established VPN session is not sufficient evidence that its route wins over an NVA.

## Official references

[Microsoft Learn: Routing preference with Azure Route Server](https://learn.microsoft.com/en-us/azure/route-server/hub-routing-preference). Source retrieved September 9, 2026.

## Primary reference

- Name: Routing preference with Azure Route Server - Azure Route Server | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/route-server/hub-routing-preference
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not assume Route Server VPN preference excludes NVA routes,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-529-do-not-assume-route-server-vpn-preference-excludes-nva-routes/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
