A single dedicated circuit into the provider dropped during someone else's maintenance window — what does adding a second path actually require?
answer
- dedicated is exclusivity, not redundancy
- one chain, many single points
- two circuits can share one conduit
- the standby carries a declared fraction
- an untested standby is an assumption
basics
~20 sDedicated means nobody else's traffic shares the circuit, not that it is redundant. A second path must terminate on a different provider-side device and location, leave through a different device of yours, take a physically diverse route, and be proven to carry the load alone.
solid answer
~50 sOne circuit is one physical path through one set of devices, one facility and one carrier segment — any of which can be taken out of service by someone who does not know your ledger exists. Providers generally publish a higher availability commitment only for a configuration with two links terminating at separate locations, which is the clearest hint that a single circuit was never the redundant option. A real second path must not share the parts that failed: a different provider-side termination point, a different edge device on your side, and route diversity you asked for explicitly, because two circuits from the same supplier can quietly ride the same conduit. The cheap alternative is an encrypted tunnel as the standby — different devices, different suppliers, genuinely independent — accepted as a declared degraded mode because it carries a fraction of the circuit's capacity with a wider latency band.
code
json · 27 lines{
"paths": [
{
"name": "circuit-north",
"kind": "dedicated-circuit",
"terminatesAt": "facility-north",
"edgeDevice": "router-1",
"preference": 100,
"capacityShareOfPeak": 1.0
},
{
"name": "tunnel-standby",
"kind": "encrypted-tunnel",
"terminatesAt": "internet-uplink-a",
"edgeDevice": "router-2",
"preference": 40,
"capacityShareOfPeak": 0.25
}
],
"selectionRule": "use the highest preference among paths currently up",
"whenCircuitNorthIsDown": {
"activePath": "tunnel-standby",
"capacityShareOfPeak": 0.25,
"declaredMode": "degraded",
"pausedWhileDegraded": ["bulk-archive-copy", "report-extract"]
}
}go deeper
Remember the distinction: a dedicated circuit means no other tenant shares it, not that there are two of them. One link is one thing that can break.
Explain the components a single circuit depends on — provider device, facility, carrier segment, your own edge device — and why a second path must differ in each of them to count.
Show the operating detail: preference on both directions, detection time as part of the outage, the standby's capacity written down, and a degraded mode that names what gets paused. Say how you have exercised it.
Own the trade-off between a second circuit and a tunnel standby: what the residual risk is, what capacity the business will accept while degraded, and which traffic classes are allowed to depend on a single path at all.
## What "dedicated" promises, and what it does not A dedicated circuit means your traffic is not competing with other tenants for the path: the capacity is yours, the latency band is narrow, the route is fixed. None of that is a statement about availability. The circuit is still a single chain of components, and the chain breaks at the weakest link regardless of how exclusive the link is. This is the single most common misreading in hybrid designs, and it is usually discovered during maintenance performed by a party who was never told what crosses the fibre. A useful corroboration: providers publish their availability commitment for these links per configuration, and the commitment for a single circuit is materially lower than the one for a pair terminating at separate locations. The commercial document is telling you the same thing the topology does. ## Where a single circuit actually breaks - The provider-side termination device or port, including its planned maintenance. - The facility where the circuit lands — power, a cross-connect panel, a building event. - The carrier's own segment between your site and that facility, including a fibre cut by a digger who has never heard of your company. - Your own edge device: one chassis, one software upgrade, one configuration change. - The configuration itself, on either end, which is the failure nobody draws on the diagram. ## What a second path must not share 1. **The provider-side location.** Two links onto the same device, or into the same facility, survive a cable but not a building. 2. **Your own device and its power.** A second circuit into the same router is a second port, not a second path. 3. **The physical route.** Two circuits ordered from one supplier can ride the same conduit for most of their length. Route diversity has to be requested explicitly, and confirmed, not assumed from having two order numbers. 4. **The maintenance calendar.** Independent paths that are upgraded in the same window are not independent during that window. ## Two shapes of second path | | Second dedicated circuit, separate location | Encrypted tunnel as standby | |---|---|---| | Time to stand up | Weeks, the same as the first | Hours | | Capacity when it is the only path | The full load, if sized for it | A declared fraction of it | | Latency behaviour | The same narrow band | Wider, and time-of-day dependent | | Failure independence | Good, if diversity was genuinely delivered | Very good: different devices and different suppliers entirely | | What it commits you to | A second term contract and a second install | Defining, and accepting, a degraded mode | Most estates end up with both over time: the tunnel that carried them before the circuit arrived becomes the standby, and a second circuit is added later if the degraded mode turns out to be unacceptable for the traffic that has grown onto the link. ## Making the failover real rather than nominal - **Preference, not equality.** Both paths are up and both are advertised, with the circuit preferred. Traffic uses one; the other is warm. - **Detection time is part of the outage.** How long before the preferred path is declared down is a number you choose, and it is added to every recovery you will ever measure. - **Capacity when alone.** If the standby carries a quarter of peak, say so in writing, and decide in advance what is shed when it is the only path — otherwise the failover succeeds and the ledger still misses its window. - **Both directions.** The return path has to prefer the same link, or traffic goes out one way and back the other, and any stateful filtering in between drops the reply. - **Exercise it.** A standby nobody has moved production traffic onto is an assumption. Failover is automatic only where detection, capacity and configuration all hold at once, and the way you learn that they do is by trying it on purpose. - **Say what "degraded" means.** A declared degraded mode with a named capacity, a named latency expectation and a named list of what is paused is a design. "It'll fall back to the tunnel" is a hope.
- Two circuits were ordered from the same supplier. Why might they still fail together?Because route diversity is a property of the physical path, not of the paperwork. Two orders can be delivered over fibre that shares a conduit, a duct or a building entry for much of its length, and one digger takes both. Diversity has to be requested explicitly and confirmed by the supplier, and it is worth re-confirming after any re-route on their side.
- Failover moved traffic to the standby within seconds, yet the ledger still missed its cut-off. What went wrong?The path recovered and the capacity did not. A standby sized at a fraction of peak will carry the traffic, slowly, unless someone decided in advance what is shed while it is the only path. Degraded mode has to name the capacity and the list of work that pauses, or a technically successful failover still fails the business.
- Why does a second path sometimes make things worse before it makes them better?Because two live paths introduce asymmetry. If the return traffic prefers the other link, stateful filtering in between sees a reply for a flow it never saw opened and drops it. The fix is to make preference consistent in both directions and to test the failed-over state, not just the failover event.
A private access road to your site is not two roads. Nobody else uses it, and one closure still leaves you with nothing.
saying these in an interview costs you the question
- Says a dedicated circuit is redundant because the capacity is exclusive
- Counts two ports on the same edge device as two paths
- Assumes two orders from one supplier means physically diverse routes
- Treats failover as done once the standby link comes up
- Leaves the standby unconfigured, to be enabled if it is ever needed
- Ignores the return direction when setting path preference