An encrypted tunnel over the internet or a dedicated private circuit into the provider: what does each buy, and why does only one start today?
answer
- two shapes, two lead times
- one is configuration, one is construction
- the difference is not average latency
- ceiling per tunnel, add tunnels not width
- private by path, not encrypted by path
basics
~20 sAn encrypted tunnel rides the public internet: usable within hours, but with variable latency and a throughput ceiling per tunnel. A dedicated circuit gives reserved capacity and latency inside a narrow band, after a lead time measured in weeks.
solid answer
~50 sBoth give a network you run yourself a private path into the address range you allocated on the platform, but they are bought in completely different ways. An **encrypted tunnel** runs over the internet connection you already have: you stand up a tunnel endpoint on the platform, point your own edge device at it, agree keys, and it carries traffic the same afternoon. Its capacity is bounded by what one tunnel's termination device can encrypt, and its latency is whatever the internet gives you that hour. A **dedicated private circuit** is a physical connection into a facility where the provider terminates circuits — ordered, scheduled, installed and tested, with a lead time of weeks. The wait buys reserved capacity and latency that stays inside a narrow band. In practice it is rarely either/or: start on the tunnel because the tunnel starts today, and keep it as the standby once the circuit lands.
go deeper
Recall that there are two ways to join your own datacentre to your private range on a platform: an encrypted tunnel over the internet, and a physical dedicated circuit. One is configured in an afternoon; the other is ordered and installed.
Explain the mechanics behind each: where the tunnel's throughput ceiling comes from, why the internet path gives variable latency, and what the circuit's lead time is actually spent on. Say why private is not the same as encrypted.
Show the sequenced answer a real programme uses: tunnel first because it starts today, circuit ordered in parallel, both live afterwards. Name what you would re-measure on the tunnel before trusting it as the standby.
Frame it as a commitment against an architecture that is still moving. A circuit is a term contract and a physical asset at a site you may be leaving; weigh the cost of carrying both paths against the risk profile of the traffic that will still be crossing in a year.
## What the two options actually are A hybrid link joins a network you operate yourself — a leased datacentre cage, a colocated rack, an office — to the private address range you allocated on a cloud platform, so hosts on each side reach each other by their private addresses instead of through public endpoints. Every large provider sells the same two shapes of that link, under different names. An **encrypted tunnel** is built over the public internet. Both sides already have internet connectivity. You create a tunnel endpoint on the platform side, configure your own edge device to match, agree on keys, and traffic flows inside an encrypted envelope over whatever internet path exists at that moment. Nothing is installed, nothing is scheduled, and the only external dependency is that both ends can reach each other over the internet at all. A **dedicated private circuit** is a physical connection between your side and a facility where the provider accepts circuits. Somebody orders it, somebody schedules it, somebody terminates fibre on a port, and the two ends are tested before a packet crosses. Your traffic on it does not travel over the public internet — which is not the same as saying it cannot fail. ## What each buys | Dimension | Encrypted tunnel over the internet | Dedicated private circuit | |---|---|---| | Time to first packet | Hours: it is configuration | Weeks: it is ordering, scheduling and physical work | | Capacity | A ceiling per tunnel, set by the device that encrypts | A committed rate on the port you bought | | Latency | The internet's, and it varies by hour and by path | Stable, inside a narrow band | | Path | Chosen by the internet, can change mid-session | Fixed, known, and yours for the term | | Confidentiality | Encrypted by construction | Private by path; encryption is a separate choice | | Failure mode | Your uplink, or congestion anywhere in between | The port, the facility, the carrier segment, your edge device | | Changing your mind | Reconfigure and it is gone | A contract and a decommission | ## Lead time is the decision, not the tiebreaker The reason this question is asked at all is that the two options are not available at the same time. A team told on Monday that the ledger must replicate into the platform before quarter-end cannot choose the circuit for that deadline, however much it prefers the circuit — the order, the facility booking and the carrier work do not compress to fit a sprint. So the honest answer is sequenced: the tunnel is what you have during the weeks the circuit is being delivered, and the design question is what you do with the tunnel once the circuit arrives (almost always: keep it, as the second path). ## The ceiling people discover late - A tunnel's throughput is capped by the device terminating it, not by the raw speed of your internet uplink. Buying a bigger uplink does not widen one tunnel. - You scale by adding tunnels and spreading traffic across them, not by widening one — and a single long-lived flow usually stays pinned to one tunnel, so one heavy replication stream does not benefit from the extra tunnels at all. - Wrapping traffic costs some payload per packet, so measured throughput on a tunnel is always a little below the line rate you would see without it. - The tunnel shares its uplink with everything else that leaves your building, so an unrelated bulk copy competes with it. ## How the choice usually resolves 1. Stand up the tunnel now, because it starts today and it proves out addressing, name resolution and firewall rules before any circuit exists. 2. Order the circuit in parallel if the steady-state traffic is either heavy or sensitive to latency variation. 3. When the circuit is delivered, move traffic onto it by preference and leave the tunnel configured and up. 4. Review the tunnel's capacity against the traffic that has grown since you sized it, because that capacity is what a failure of the circuit leaves you with. ## What the link does not decide A private path changes the **route** the packets take, the addresses that are reachable, and the name resolution behind them. It does not decide **who may call what**: authorization stays with the identity and policy layer, and a workload reachable over a private link is not thereby permitted to call anything. Nor does the private path imply cryptography — a dedicated circuit is private because of the path it takes, and teams with a confidentiality requirement run their own encryption over it exactly as they would over the internet.
- Does a dedicated private circuit encrypt the traffic that crosses it?No. It is private because of the path it takes, not because of cryptography — nobody else's traffic shares it, but the bytes are as readable as on any link you own. Teams with a confidentiality or compliance requirement run their own encryption over the circuit. That is a deliberate choice, and it costs throughput on whatever device performs it.
- The tunnel is saturated and the circuit is still weeks away — what do you do?Add tunnels and spread distinct flows across them, since one tunnel's ceiling is set by the device terminating it. That helps many flows and does not help one heavy stream, which tends to stay pinned to a single tunnel. So also move bulk copies off the peak window, or off that uplink entirely, so the latency-sensitive traffic is not queued behind them.
- Why does the tunnel usually survive the arrival of the circuit?Because a single circuit is a single physical path, and the tunnel fails for entirely different reasons — different devices, different path, different suppliers. Keeping it configured and up turns the delivered circuit into a two-path design at almost no engineering cost, provided you keep checking that the tunnel's capacity still matches the load it would inherit.
A tunnel is a courier on public roads: available this afternoon, and as predictable as the traffic. A circuit is a private access road built to your site: weeks of work, then the same journey time every day.
saying these in an interview costs you the question
- Assumes a dedicated private circuit encrypts traffic because it is private
- Thinks one tunnel can be widened by buying a faster internet uplink
- Treats lead time as a procurement detail rather than a design constraint
- Compares only average latency and ignores how much it varies
- Says the circuit makes the tunnel unnecessary, even as a standby
- Believes a private path also decides who is allowed to call the service