Dedicated Cloud Access External Service Guide
Contents
Introduction
Enterprises are increasingly turning towards private network connectivity solutions to access public cloud platforms. Private connectivity in to cloud platforms provides improved performance and security compared to the internet, and allows enterprise customers to connect to the public cloud in a seamless manner.
Dedicated Cloud Access provides secure, flexible, highly scalable and reliable Ethernet and IP connectivity into public cloud providers.
Colt currently has direct partnerships with a number of direct cloud service providers (CSPs), including Amazon Web Services, Microsoft Azure, IBM Cloud, Google Cloud, Oracle Cloud and Alibaba Cloud. In addition, we can deliver to an extensive list of longtail CSP’s (like: SAP and Salesforce and other CSP’s on customer request), through our partner with Equinix.

Colt Dedicated Cloud Access service is widely available in Europe, Asia and in the US. Please find below a schematic overview of the current Cloud access locations, detailed information per Cloud Service Provided (CSP) can be found in section 3.

1. Overview of cloud connectivity services
Colt Dedicated Cloud Access (DCA) includes a range of solutions that have been customised for better integration into the cloud:
- DCA Ethernet, Cloud On Demand enabled
- DCA Ethernet with managed router (CPE Solutions)
- DCA Router (MPLS)
- DCA Wave
- IP-VPN
- SD-WAN Multicloud
- PrizmNet

1.1. DCA Ethernet services (Cloud On Demand)
Ethernet connectivity is defined by the presentation at the customer A end site. Where the service is presented on a port dedicated to the DCA service, the service is treated as point to point.
Similarly, where the presentation is on an existing Ethernet hub the service is defined as a DCA Ethernet spoke. DCA Ethernet spokes do not require dedicated hubs, the services co-exist with business as usual (BAU) Ethernet traffic on the hub.
Presentation at the cloud access PoP (the B end site) can be based either (depending on availability of CSP product flavour) on a dedicated port or a shared NNI, but it is ultimately the A end presentation that defines the service.
Customers who buy DCA Ethernet services are responsible for establishing layer 3 connectivity into the cloud and managing the cloud portal for any authorization that is needed to activate the services.
DCA Ethernet is SDN-enabled, On-Demand capability for Ethernet connectivity into the public cloud.

This service allows Enterprises to order connectivity from their data center or premises into leading public cloud providers via a simple portal.


1.2. DCA Ethernet with managed router services (CPE Solutions)
Colt can also provide a managed layer 3 solution based on Colt’s CPE Solutions service, which appeals to customers who want Colt to manage the layer 3 connectivity into the cloud but do not require the multi-site VPN connectivity.
The service is always used in conjunction with Ethernet P-P connectivity. Ethernet spoke connectivity is NOT supported for the managed router option.
The service is based on a single router* at the customer A end site (no router is required at the cloud B end), and the BGP peering’s with the cloud service provider are terminated on this router.
*For Microsoft ExpressRoute services, a dual router configuration is also supported.
1.3. DCA Router
Offering for customers who require a managed L3 routed service to support multicloud and cloud-to-cloud topologies. Specifically for customers with a single customer location or no customer location, connecting to/between the main public CSP’s.

Features:
- Connectity between different CSP’s or connectivity between different cloud regions of same CSP
- Avoid backhauling your network traffic between customer location and the cloud 11 / 91
- Reduce the amount of physical infrastructure to manage
The service is a fully managed L3 service, delivered through Colt existing MPLS network. The service supports multi-cloud and cloud-to-cloud topologies. Service availability is in Europe and US (Asia bespoke) and a customer location can be off-net.
Both hosted and dedicated CSP ports offering supported, upto 10Gbps CSP port bandwidth. Connectivity to the CSP private domain is supported, CSP public domain connectivity and On Demand functionality will be available in the near future.
1.4. DCA Wave
Wave services can also be used to connect to public Cloud Service Providers (CSP’s). Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100GE over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
•Colt connectivity: Point-to-point connectivity
•Unprotected / protected service options
•Diversity options
•Encryption feature
Colt provides direct cloud connectivity towards the following CSP’s: Amazon (Direct Connect Dedicated), Microsoft Azure (ExpressRoute Direct), Google (GCI Dedicated), Oracle (Third Party Provider), IBM (Direct Link Dedicated), OVHcloud (Direct) and Alibaba Cloud (Express Connect Dedicated) platforms.
1.5. IP-VPN
The DCA cloud PoP can be added as a new site to an existing IP-VPN. Whilst the technical architecture is usually based on IP-VPN Corporate Access (i.e. the cloud interconnect does not involve dedicated CPE), the DCA site is classified the same way as other sites on the IP-VPN. For example, a cloud site added to an existing IP-VPN Corporate Plus network will be classed as a Plus site, even though the technical architecture is based on a “CPE-less” Access site.
For IP-VPN, Colt is responsible for establishing layer 3 (BGP) connectivity with the cloud provider.
1.6. SD-WAN multicloud
With SD WAN Multi-Cloud, customers are able to connect their branch sites directly to all their cloud-based SaaS and IaaS and manage this connectivity centrally via the Colt SD WAN portal. It brings together a single cohesive view of the enterprise network, tying together WAN sites, IaaS/Cloud sites, and traffic towards SaaS cloud – all easily viewed and managed via the Colt SD WAN portal. It extends the SD WAN benefits of security, analytics and optimization to connectivity to the CSP and provides an end-to-end SLA for all connectivity types (MPLS, Internet, Wireless and Cloud) for enterprise networks.
Cloud connectivity / SD-WAN Multicloud can be offer as a commercial feature at each of the SD-WAN locations. Pricing is available in the SD-WAN pricing tool. For SD-WAN Multi-Cloud, Colt is responsible for establishing layer 3 (BGP) connectivity with the Cloud Service Providers.

1.7. PrizmNet
PrizmNet is Colt’s global financial extranet to provide connectivity for clients to financial providers like Stock Exchanges (e.g. Euronext, NYSE, HKEX), Clearing/Settlement houses and other Financial institutions. For example, clients can trade shares and other assets via PrizmNet on all major Stock Exchanges worldwide. Many Capital Markets clients and providers are moving their services into the cloud and PrizmNet support this transition with Cloud Access for PrizmNet. Clients can consume Provider services that are provided from the cloud and visa-versa.
1.8. Product Features
The following features are supported:
Feature | Supported Variants1.9. Service availability |
---|---|
Automatic Monitoring & Notification (AMN) | DCA Ethernet and DCA Spoke DCA IP-VPN / SD-WAN [CPE based (“Plus”) networks only] DCA Wave |
Historic performance reporting (“Infovista”) | DCA Ethernet and DCA Spoke (not supported on Microsoft Azure) DCA IP-VPN / SD-WAN supported on customer locations only [CPE based (“Plus”) networks only]. Bespoke performance reporting on DCA-NNI using CPE solutions DCA Wave, available as standard |
Class of Service | Not supported |
Load sharing | DCA IP-VPN / SD-WAN supported on customer locations only [CPE based (“Plus”) networks only]. For DCA-NNI site (supported where dual access is used to access the cloud provider platform) |
Encryption | Colt Encryption on DCA Ethernet (only supported on dedicated port option, for all CSP’s) CSP Encryption on DCA Ethernet and DCA Wave (only supported on dedicated port option, for all CSP’s) |
1.9. Service availability
Geo-graphic region / offering | DCA Ethernet (point to point) | DCA Ethernet Spoke (H&S) | DCA Router | Wave | IP-VPN | Managed routers | SD-WAN MultiCloud | PrizmNet |
---|---|---|---|---|---|---|---|---|
Europe | Yes, all direct CSP’s | Yes, all direct CSP’s | Yes, (on request for Google, IBM and Oracle) | Yes (dedicated port only) | Yes, (on request for Google, IBM, Oracle and OVHcloud) | Yes, (on request for Google, IBM, Oracle and OVHcloud) | Yes, (available for AWS, Microsoft Azure and Google) | Yes, (available for AWS, Microsoft Azure and Google) |
Asia | Yes, all CSP’s | Yes, on request | On request, bespoke | Yes (dedicated port only) | Yes, on request | Yes, on request | Yes, (available for AWS, Microsoft Azure and Google) | Yes, (available for AWS, Microsoft Azure and Google) |
USA | Available on AWS, Microsoft Azure, Google, IBM and Oracle | Available on AWS, Microsoft, Google, IBM and Oracle | Yes, (on request for Google, IBM and Oracle) | Yes (dedicated port only) | Yes, on request | Yes, on request | Yes, (available in NY, LA in delivery for resiliency. available for AWS, Microsoft Azure and Google) | Yes, (available for AWS, Microsoft Azure, Google) |
The use cases for each service are summarised below:
Service | Use case |
---|---|
DCA Ethernet (point to point) | Customers who own and operate their own layer 3 network and have the necessary networking skills to establish BGP connectivity into the cloud |
DCA Ethernet: spoke | Customers who have existing hubs and want to leverage this infrastructure Customers who require multiple (2 or more) connections into the cloud |
DCA Router | Customers who require a managed L3 routed service to support multicloud and cloud-to-cloud topologies. For customers with a single customer location or no customer location, connecting into to/between the main public cloud providers (CSP’s) |
DCA Wave | Customers who require very high bandwidth upto 100Gbps over L1 transparent Optical network and/or Customer-defined route or ‘hard’ diversity end-to-end with KMZ diagrams |
IP-VPN | Customers who have an existing multisite VPN with Colt, and need to connect to the cloud Customers who need to connect multiple A end sites to the cloud |
SD-WAN | Customers who have an existing multisite SD-WAN with Colt, and need to connect to the cloud Customers who need to connect multiple A end sites to the cloud |
CPE Solutions | Customers who don’t have an existing VPN with Colt, and need layer 3 connectivity into the cloud from a single site |
PrizmNet | Customer who is already on the PrizmNet platform and need to connect to a provider in the cloud Customer with virtual environment in the cloud who want to connect to providers inside/outside the cloud |
2. Connected Cloud Service Providers
Connectivity into a cloud service provider is made at a network access PoP. Colt provides connectivity into all of the major cloud provider PoPs.
2.1. AWS (Amazon Web Services) Cloud
2.1.1. AWS Network Access PoPs
Connectivity into a cloud service provider is made at a network access PoP. Colt provides connectivity into all of the major cloud provider PoPs in Europe and Asia. Note that Direct Connect PoPs are mapped to a ‘primary’ AWS region Customers can connect to other regions via the VPC gateway feature. Please note that this feature may not be available in all regions at the time of release of this document. Colt DCA Amazon Web Services (AWS) connected PoPs are shown below.

2.1.2 Regions and Network Access PoP’s
Colt has established at least two interconnects with AWS in each city/metro, where possible connected at different AWS Cloud PoP datacenters (in order to provide Cloud PoP diversity). If there is only one AWS Cloud PoP datacenters per city/metro in the Colt AWS Cloud PoP locations list, then 2 interconnects are available at that particular AWS Cloud PoP datacenter.


2.1.3 AWS – Direct Connect
Amazon supports two main options for their Direct Connect service:
- Services presented on a Dedicated Port – where the end customer contracts a 1Gbps, 10Gbps or 100Gbps port from Amazon and the port is dedicated for contracted customer use only.
- Services presented on a Hosted Connection – where the service is handed over on a shared NNI port, the bandwidth of a hosted connection is upto 10Gbps. Please check the location list which bandwidth is supported at each AWS Cloud PoP.
Each AWS peering is configured via the AWS Console to support one of the following AWS Virtual Interface types:
- Private VIF – access to one or more Virtual Private Clouds, using private IP addresses
- Public VIF – access to public AWS services (such as S3), using public IP addresses
- Transit VIF – access to an AWS Transit Gateway
Transit VIFs are supported both on AWS Direct Connect Hosted and AWS Direct Connect Dedicated connections. Transit VIFs are available across the majority of Colt’s Direct Connect PoP locations in Europe, Asia and US.
Customers should consult their AWS account team for advice on which solution is best for them.
2.1.4 Dedicated Port Option
Within the dedicated cloud access offering the AWS dedicated port options 1Gbps and 10Gbps ports are supported on DCA Ethernet, Cloud On Demand, SD-WAN and CPE Solutions. The 100Gbps dedicated port is supported on DCA Ethernet. The AWS dedicated port option is supported on DCA Ethernet, Cloud On Demand, IP-VPN, SD-WAN and CPE Solutions (please select available options per product).

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from AWS when they place an order for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering (adjacency) with Amazon using the AWS portal.
The dedicated port option provides a high degree of flexibility, as customers are in control of Amazon VLAN provisioning (multiple VLAN’s / BGP peering sessions are allowed). VLANs on Dedicated Ports are not rate limited or shaped. Colt Ethernet service acts as a transparent pipe between the customer and AWS services. For the Dedicated Port option, Colt connects each individual customer circuit to a dedicated 1Gbps, 10Gbps or 100Gbps port on Amazon’s router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the AWS infrastructure. The Customer ‘A End’ can provision multiple VLANs into the AWS cloud using the AWS Console (portal) – essentially Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the AWS cloud; allowing the customer full flexibility over their traffic into AWS network.
Amazon do not impose any restrictions on number of VLANs; VLANs can be scaled depending on the customer traffic.
For the DCA spoke use case, Colt presents the service at an Ethernet hub at the customer ‘A End’ site – all other service characteristics are identical to the Ethernet Line service. It is important to note that the customer
MUST support VLAN double tagging at the hub site, this will allow provisioning of multiple VLANs into AWS cloud.
Colt supports sub-rate bandwidths as well as full throughput 1Gbps on a 1Gbps Amazon port – for example 100Mbps on a 1Gbps port. Note that Colt bandwidth upto 40Gbps will be delivered via the packet network – Ethernet. The 100Gbps option will be delivered via the Optical network with Ethernet interface – Wave services.
Feature | Dedicated Port |
---|---|
AWS handover | New port and fibre cross connect |
Delivery experience | Multiple days for physical fibre build |
AWS port bandwidths | 1Gbps/10Gbps/100Gbps |
BGP peering / Virtual Interface | Multiple BGP peerings / VIFs per port (but only 1 transit VIF) |
Multiple VPC support via Direct Connect Gateway | Yes |
AWS Transit Gateway support | Yes |
2.1.5 Hosted Connection Option
For the Hosted Connection option, Colt connects each customer circuit to a single VLAN on a shared NNI into the Amazon network. Each circuit is 1:1 mapped to a single VLAN. On Hosted Connections a single VLAN, one single BGP peering is provisioned. The customer needs to place a request for a new circuit through Colt for each new VLAN. The maximum bandwidth of a hosted connection is 10Gbps.
Hosted connection supports a single VLAN / 1 BGP peering: 1 private-, 1 public or 1 transit VIF. AWS Hosted Connections are based on a range of bandwidths (50Mbps-10Gbps).
This is illustrated below, using an Ethernet P-P service (i.e. where the presentation at the A end site is a port based handover.

Colt can also provide DCA spokes that terminate on a Hosted Connection – note that the presentation at the hub site is always based on single tagging.
Feature | Hosted Connection |
---|---|
AWS handover | Existing interconnect |
Delivery experience | Near real time, via On Demand automation |
AWS port bandwidths | 50M – 10Gbps |
BGP peering / Virtual Interface | Single BGP peering / VIF per hosted connection |
Multiple VPC support via Direct Connect Gateway | Yes |
AWS Transit Gateway support | Yes (all bandwidths) |
2.1.6 Differences and summary AWS dedicated- vs. AWS hosted port
The below summarises the Hosted vs. Dedicated connection:

Note:
- Dedicated Ports need to be requested by the customer in the AWS console, whereas Hosted Connections are requested by Colt.
- AWS also supports Jumbo frames: https://docs.aws.amazon.com/directconnect/latest/UserGuide/set-jumbo-frames-vif.html
The below table provides a quick summary of the hosted and dedicated Direct Connect options:
Feature | Hosted Connection | Dedicated Port |
---|---|---|
AWS handover | Existing interconnect | New port and fibre cross connect |
Delivery experience | Near real time, via On Demand automation | Multiple days for physical fibre build |
AWS port bandwidths | 50M – 10Gbps | 1Gbps/10Gbps/100Gbps |
BGP peering / Virtual Interface | Single BGP peering / VIF per hosted connection | Multiple BGP peerings / VIFs per port (but only 1 transit VIF) |
Multiple VPC support via Direct | Connect Gateway | Yes |
AWS Transit Gateway support | Yes (all bandwidths) | Yes |
2.1.7 Bandwidth and Interface Options (All Colt Services)
The bandwidth options are shown below:
Colt Service Bandwidth | Amazon Direct Connect Bandwidth | Physical Cross- connect | Ethernet Point to Point | Ethernet Spoke | Wave | Service IPVPN | SD- WAN | Managed Router |
---|---|---|---|---|---|---|---|---|
10 Mbps |
50 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
50 Mbps |
50 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
100 Mbps |
100 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
200 Mbps |
200 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
300 Mbps |
300 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
400 Mbps |
400 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
500 Mbps |
500 Mbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
1 Gbps |
1 Gbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
2 Gbps |
2 Gbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
No |
Yes |
5 Gbps |
5 Gbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
No |
Yes |
10 Gbps |
10 Gbps Hosted connection |
No |
Yes |
Yes |
No |
Yes |
No |
Yes |
10 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
50 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
100 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
200 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
300 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
400 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
500 Mbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
1 Gbps |
Dedicated 1Gbps port |
Yes |
Yes |
Yes |
No |
No |
Yes |
Yes |
1-2-5-10 Gbps |
Dedicated 10Gbps port |
Yes |
Yes |
Yes |
Yes** |
No |
1Gbps only |
Yes |
10-20-30- 40Gbps |
Dedicated 100Gbps port |
Yes |
Yes* |
No |
Yes** |
No |
No |
On request |
100 Gbps |
Dedicated 100Gbps port |
Yes |
No |
No |
Yes |
No |
No |
On request |
Note: Hosted connections are via NNI
- Only between Key-DC’s on request
** only 10Gbps and 100Gbps bandwidth is supported on Wave
2.1.8 Ethernet Services into AWS (Amazon Web Services)
Colt offers DCA Ethernet Line (“point to point”) and DCA Ethernet spoke services into AWS on both Dedicated Ports and Hosted Connections.
Bandwidths up to and including 10Gbps are provided on Colt’s packet Ethernet platform by default (Colt can deliver upto 40Gbps on the packet network, only between Key-DC’s).
Colt also offers 10Gbps and 100Gbps services as an optical service across DWDM wavelengths (e.g. due to KMZ files requirement).
Hosted connections are always handed over on a shared NNI port.
In terms of resiliency and Cloud PoP diversity can Colt offer following options:

2.1.9 IP-VPN Services into Amazon (Amazon Web Services)
The Amazon network access PoPs can be added to an existing IP-VPN Plus or IP-VPN Access network, or ordered as part of a new IP-VPN deployment.
In both cases, the Amazon site is treated as an additional site on the customer’s VPN, and from a technical perspective is a VPN Access site – connectivity into Amazon is “wires only” and no CPE router is required.
However, Colt treat the Amazon site the same as the other sites on the VPN – a Plus site where the VPN is based on Plus sites and an Access site where the VPN is based on Access sites.
For a new IP-VPN network, the customer must order at least two new sites – one “standard” customer site and the Amazon site.
The standard Colt DCA offer is based on hosted connections into Amazon– with Dedicated Ports, the customer is in control of provisioning into AWS and this option is not available for IP-VPN. Each hosted connection is treated as a new site and Amazon cloud instance (VIF) which is in turn mapped to Virtual Private Clouds (VPC’s).
The standard offer is based on “private” Amazon services (which also includes the Transit Virtual VIF) – that is, connectivity between the Amazon edge router and the other sites on the customer’s VPN is based on private IP addresses. Private IP addresses are integrated into the customers VPN so any of the VPN sites (hub or branch/spoke) can access the Amazon private services.
Access to Amazon public services – i.e. Amazon services that use public IP addresses – can only be accessed via Colt’s “multi-VPN” feature. The multi-VPN feature is effectively an additional Amazon VPN site which requires the customer to order a 2nd hosted connection.
IMPORTANT – if the customer requires access to AWS public services, the multi-VPN feature MUST be requested at the same time as the main site order. Access to public services is only provided on request and not by default. A separate hosted connection is required for public access and the customer will be charged separately for the hosted connection port and data usage
At the customer’s designated hub site, the public service will be terminated on the CPE router for onward connection to the customer’s firewall.
The IP-VPN site order is based on private access to a single hosted connection, which in turn is mapped to support multiple Amazon virtual private clouds (VPC’s) – the mapping is one site order supporting multiple VPC’s.

Dual access is also supported, based on a 1+1 active-active configuration. PoP diversity is supported, but preferably both locations should be in the same Amazon region, for example:
- One link to London Telecity, one link to Eircom Dublin (EU Ireland region)
- One link to Frankfurt Equinix, one link to Frankfurt Interxion (EU Frankfurt region)
Alternatively when AWS locations are not in the same region, customers should use the AWS gateway feature for this. Dual access is illustrated below:

Colt typically has single NNIs in the Amazon PoPs – where both links terminate in a single Amazon PoP a 2nd NNI will normally be required, which should be provided as part of the customer delivery.
2.1.10 SD-WAN Services into Amazon (Amazon Web Services)
Connectivity to Amazon Web Services can be added towards the SD WAN network. Connectivity to AWS can be added to an existing SD WAN network, or ordered as part of a new SD WAN deployment. Colt advises customers to establish resilient connects into AWS by default, in order to create high Cloud
connectivity performance towards the SD-WAN locations. In both cases, connectivity towards AWS from/to the SD WAN network goes via a Cloud Gateway in the Colt IQ-network.

Colt support both the ‘hosted’ AWS Direct Connect option and the ‘dedicated” AWS Direct Connect port options into AWS.
For hosted connections customers can choose bandwidth from 50Mbps-1Gbps. For dedicated connections bandwidth from 50Mbps up to 1Gbps are supported, please find an overview below:

The existing maximum capacity per Cloud Gateway per customer is 2Gbps. Bandwidths >2Gbps can be supported by distributing connections across 2 or more Cloud Gateways. The Cloud Gateway supports features like NAT and firewall (for enhanced security).
SD WAN solution into AWS by default supports Cloud-to-Cloud communications between different CSP’s, which means that traffic between CSP’s does not have to enter the SD WAN network which reduces latency. Customers can order connectivity to any AWS location/region, connected by Colt. Colt has deployed multiple Cloud Gateways in Europe and Asia in order to support resilient connectivity into AWS. To provide high performance of Cloud connectivity services on the SD-WAN the customer is asked to order resilient service towards AWS.
Colt is a direct partner of AWS and is able to interconnect towards multiple AWS Cloud on-Ramps locations within a metro or cloud region. To offer best performance, Colt routes the Cloud traffic through diverse Cloud Gateways in the Colt IQ network.
Each AWS peering is configured via the AWS Console to support one of the following AWS Virtual Interface types: Private VIF, Public VIF or Transit VIF. For SD-WAN Transit VIF is considered as a Private VIF. Transit VIFs require a bandwidth of 1Gbps and are supported both on AWS Direct Connect Hosted and AWS Direct Connect Dedicated connections. Transit VIFs are available across the majority of Colt’s Direct Connect PoP locations in Europe, Asia and US. Customers are advised to check availability of 1Gbps hosted connections for the required AWS PoP location.
For more details on cloud connectivity on Multi-Cloud, please check the SD-WAN multicloud external service guide.
2.1.11 Managed Router Solutions (CPE)
For both the Dedicated Port and Hosted Connection options, customers have the option to add a managed CPE router to the Ethernet point to point service, so that Colt manages the layer 3 (BGP) routing into the Amazon network.
Under the managed router solution, it is possible to establish BGP adjacency to multiple AWS Virtual Private Clouds (VPCs). It is also possible to support layer 3 connectivity to the AWS public domain.
2.1.12 DCA Wave
Wave services can also be used to connect to AWS. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
2.1.13 PrizmNet
With the PrizmNet service, connectivity towards AWS can be established. This is available both on AWS Dedicated Port and Hosted Connection options.
The Standard service is based on private peering with the cloud provider. Colt is responsible for establishing layer 3 (BGP) connectivity with the cloud provider.
2.1.14 Encryption options
Colt is able to support two types of encryption within the DCA portfolio:
- Colt Encryption as add-on on top of DCA Ethernet and CSP encryption. Please see section 4 (DCA Encryption options) for more details.
- For CSP encryption on AWS Direct Connect Dedicated service (dedicated port only), please find more information on: https://aws.amazon.com/about-aws/whats-new/2021/03/aws-direct-connect-announces-macsec-encryption-for-dedicated-10gbps-and-100gbps-connections-at-select-locations/ Below you can find the link at which locations MACsec is supported by AWS: https://aws.amazon.com/directconnect/locations/. Please note that the Colt IQ network, offers based on Cloud on Demand, DCA Ethernet, and DCA Wave (Ethernet interface) is fully transparent to MACsec and therefore support the AWS feature.
2.1.15 AWS Direct Connect, Transit Gateway, VPC limits
Please find below an overview on the Amazon Web Services website in regards to the AWS Direct Connect limits: https://docs.aws.amazon.com/directconnect/latest/UserGuide/limits.html
Please find below an overview on the Amazon Web Services website in regards to the AWS VPC limits: https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_Limits.html
High level options for Transit Gateway and AWS Direct Connect:
- Dedicated Connections: supports 1 transit VIF per Dedicated Connection
- Hosted Connection from 50Mbps onwards supports 1 transit VIF
For general information on AWS Direct Connect, please find below link towards FAQ on AWS Direct Connect:
https://aws.amazon.com/directconnect/faqs/
2.2 Microsoft Azure Cloud
2.2.1 Microsoft Azure Region PoPs
The Microsoft network access PoPs are shown below – Microsoft regions are interconnected, customers can access all regions from a single PoP.

2.2.2 Network Access PoP’s
Each ExpressRoute PoP is naturally associated with a local/primary Azure region – for example Dublin DRT DUB2 is naturally associated with North Europe. However, Microsoft provide “multi region” connectivity for regions that are in the same geographic territory (e.g. Europe). For example, a customer connected to London can access Azure services in the West Europe West (Amsterdam) region.


2.2.3 ExpressRoute Service Offering
Both Microsoft Azure ExpressRoute variants are supported by Colt:
Microsoft ExpressRoute: | • Microsoft ExpressRoute • Microsoft ExpressRoute Direct |
Microsoft ExpressRoute METRO: | • Microsoft ExpressRoute Metro • Microsoft ExpressRoute Metro Direct |

2.2.4 Colt ExpressRoute Service Offering
Colt can provide DCA Ethernet, DCA Wave, IP-VPN (DCA Router) and SD-WAN Multicloud connectivity to ExpressRoute. Managed router solutions on top of Ethernet can also be provided.
Microsoft Azure offer customers the option of UBB (“metered”) or flat monthly (“unlimited”) pricing to customers. Colt provides flat pricing based on the requested capacity.
ExpressRoute:

ExpressRoute Metro:

Note:
- ExpressRoute customers cannot upgrade the ExpressRoute towards an ExpressRoute metro (both options have different interconnects). A new ExpressRoute metro service has to be purchased from Microsoft
- Microsoft ExpressRoute SLA for ExpressRoute is 99% and for ExpressRoute Metro is 99,9%
- For ExpressRoute metro, customers are not able to connect both circuits towards different Cloud PoP’s in different metro’s – only in the same metro (e.g. 2 connections in Zurich metro)
- Initially available metros: Amsterdam, Zurich and Singapore. Other metro’s will follow shortly per roadmap Microsoft.

The bandwidth options for Azure ExpressRoute and ExpressRoute Metro are shown below:
Colt Service Bandwidth | Azure ExpressRoute Bandwidth | Connection to Azure | Ethernet Point to Point | Ethernet Spoke | Wave | IPVPN | SD-WAN | Managed Router |
---|---|---|---|---|---|---|---|---|
10 Mbps |
50 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
50 Mbps |
50 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
100 Mbps |
100 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
200 Mbps |
200 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
300 Mbps |
500 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
400 Mbps |
500 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
500 Mbps |
500 Mbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
1 Gbps |
1 Gbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
Yes |
Yes |
2 Gbps |
2 Gbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
No |
Yes |
5 Gbps |
5 Gbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
No |
Yes |
10 Gbps |
10 Gbps |
(Hosted NNI) |
Yes |
Yes |
No |
Yes |
No |
Yes |
1-10Gbps |
10Gbps |
Dedicated port |
Yes |
Yes |
Yes |
Yes |
On request |
Yes |
10-40Gbps |
100Gbps |
Dedicated port |
Yes |
No |
No |
No |
No |
No |
10Gbps |
100Gbps |
Dedicated port |
No |
No |
Yes |
No |
No |
No |
100Gbps |
100Gbps |
Dedicated port |
No |
No |
Yes |
No |
No |
No |
Note:
- Express Route service bandwidths start at 50Mbps. For the 10Mbps DCA service, the customer must buy a 50Mbps ExpressRoute service
- Resilience: ExpressRoute services are always made up of two parallel circuits. Handover over dual NNIs between Colt and Azure.
- Routing domains: Customer can choose to enable one or two of the routing domains as part of their ExpressRoute circuit.
- Upto 40Gbps on Ethernet is only supported between Key DC’s on request
Each ExpressRoute service contains two individual routing domains (BGP peering):
- Private domain – provides access to Azure compute services contained within virtual networks
- Microsoft domain – Public domain provides access to Azure services such as SQL database and storage, which use a public IP addresses. Microsoft domain for access to O365 and other Microsoft application services (MICROSOFT APPROVAL REQUIRED)
Using ExpressRoute for Microsoft 365 Services | Microsoft Learn

Each routing domain is mapped to a separate VLAN within the ExpressRoute service. Each peering is contained within a separate VLAN. Handover to Microsoft is always based on double tagging, handover to the customer depends on the service.
Under our DCA Ethernet P-P service, Colt transports both the VLANs across our Ethernet network and presents them on a dedicated customer port as single tagged traffic. This is illustrated below.

Under our DCA Ethernet spoke service, the concept is similar to P-P but the default presentation at the hub site(s) is double tagging. (Single tagging is supported on request but is not recommended).
For our IP-VPN service, the VLAN containing the private peering terminates on Colt’s SAR routers and effectively becomes another site on the customer’s VPN. The public and O365 peerings are delivered to the customer via multi-VPN, on request.
2.2.5 Sharing ExpressRoute Services
Colt often receives requests from customers for sharing individual ExpressRoute services across multiple customers. It is important to note that Microsoft advises against hosting multiple customers within a single ExpressRoute connection.
Whilst it is possible for a customer to share a single ExpressRoute service across multiple Azure subscriptions, the subscription sharing feature is intended for customers who manage multiple Azure subscriptions within the same corporate entity. For example, the IT, HR &, sales departments need to share the same ExpressRoute circuit, each via their own department’s subscription.
The subscription sharing feature is NOT intended for sharing across multiple customers, nor is it possible to sub-divide a single ExpressRoute circuit into customer-specific VLANs – the rule is one ExpressRoute circuit per customer.
On this basis, Colt will therefore not accept ER orders which are specifically intended to be shared across multiple customers. Colt is not able to discuss or negotiate on the technical reasons for this: customers should seek clarification from Microsoft.
2.2.6 Ethernet Services into Microsoft Azure
Colt can provide DCA Ethernet Line point-to-point and DCA Ethernet spoke services. Ethernet services sold into Azure are provided as two individual circuits in a 1+1 active-active configuration.- this applies to Point-to-Point and spoke services. Both circuits terminate in a single Azure PoP or at different Azure PoP’s in the same metro.
All services are provided across resilient interconnects between the Colt and Microsoft networks and can be provided via on-net (Colt fibre) or off-net access at the customer A-end.

Key features
- By default 2 Colt circuits are delivered at the same Microsoft Azure cloud PoP or different at Microsoft Azure cloud PoP’s within the same metro.
- The circuits are connected to two different NNI’s (Each circuit has two ends, a customer-end and a cloud-end. The customer can decide to connect both circuits to the same or different customer buildings). Please see also the picture below.
- Handover – handed over on dual NNIs between Colt and Azure


For the single site option, the two circuits will by default be presented on the same NTE/hub, based on two options:
Unprotected resilience & Protected resilience:
Unprotected resilience:

Protected resilience:

If a customer requires a higher resilience, Colt offers the access diversity option, which implies that a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes.
Diversity on unprotected resilience

Diversity on protected resilience

2.2.7 Microsoft ExpressRoute Direct
Microsoft ExpressRoute Direct (a Dedicated Interconnect) provides direct physical connections between your on-premises network and Microsoft’s network. The Microsoft dedicated port option is supported on DCA Ethernet, Cloud On Demand, IP-VPN (DCA Router), SD-WAN and CPE Solutions.

Services presented on a Dedicated Port – where the end customer contracts a pair of 10Gbps or 100Gbps port from Microsoft and the port is dedicated for contracted customer use only. This option is available with Colt’s DCA Ethernet Line (point to point).
Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the Google infrastructure. Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the Microsoft cloud; allowing the customer full flexibility over their traffic into the Microsoft network.
For the Dedicated Port option, Colt connects each individual customer circuit to a pair of dedicated 10Gbps or 100Gbps port on Microsoft router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from Microsoft when they place an order* for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering with Microsoft.
Note that Colt bandwidth upto 10Gbps (and 40Gbps between Key-DC’s) will be delivered via the packet network – Ethernet. Alternatively (e.g. due to KMZ file requirement) Colt can deliver 10Gbps and 100Gbps service option via the Optical network – Wave. By default 2 circuits have to be ordered in order to deliver services to Microsoft Azure.
*Before using ExpressRoute Direct, the customer must first enroll their subscription by Microsoft: https://docs.microsoft.com/en-us/azure/expressroute/expressroute-erdirect-about
2.2.8 IP-VPN into Microsoft Azure
The Microsoft Azure ExpressRoute access PoPs can be added to an existing IP-VPN Access or IP-VPN Plus network, or ordered as part of a new IP-VPN deployment.
In both cases, the Microsoft sites are treated as an additional site on the customer’s VPN, and from a technical perspective is a VPN Access site – connectivity into Azure is “wires only” and no CPE router is required.
However, the Azure site is treated the same as the other sites on the VPN – a Plus site where the VPN is based on Plus sites and an Access site where the VPN is based on Access sites.
Connectivity is always based on dual access – that is, dual circuits between the Colt IP backbone router and Azure, in a 1+1 active-active configuration. For a new IP-VPN network, the customer must order at least two new sites – one “standard” customer site and the Azure cloud site.
For a 2 site VPN, dual access is not mandatory for the “standard” site, but customers will not benefit from the full resilience offered by Azure.
The standard offer is based on “private” Azure services – that is, connectivity between the Azure edge router and the other sites on the customer’s VPN is based on private IP addresses. Private IP addresses are integrated into the customers VPN so any of the VPN sites (hub or branch/spoke) can access the Azure private services.
Azure public services / Office 365 (i.e. access to public IP addresses) can only be accessed via the existing “multi-VPN” feature, which is effectively an additional site over a 2nd VLAN. At the customer’s hub site, the public/O365 services will be terminated on the CPE router for onward connection to the customer’s firewall.

IMPORTANT – if the customer requires access to Azure public services or Office 365, the multi-VPN feature MUST be requested at the same time as the main site order. Access to public services is only provided on request and not by default. For IP-VPN connectivity into Office 365 and Azure public domain, your Colt account team will request a custom design on your behalf.
Multiple Azure cloud sites can be added to a single VPN network, but the 1+1 active-active links must always terminate at a single Azure PoP.
If a customer requires access to multiple PoPs, each PoP requires a separate ExpressRoute service and a new IP-VPN site order. Pre-sales engagement is essential for IP-VPN services into Azure.
2.2.9 SD-WAN Services into Microsoft Azure (ExpressRoute)
Connectivity to Microsoft Azure ExpressRoute services can be added towards the SD WAN network. Connectivity to Microsoft Azure can be added to an existing SD WAN network, or ordered as part of a new SD WAN deployment.
Colt advises customers to establish resilient connects into Microsoft by default, in order to create high Cloud connectivity performance towards the SD-WAN locations. In both cases, connectivity towards Microsoft Azure from/to the SD WAN network goes via a Cloud Gateway in the Colt IQnetwork. Note that Colt delivers 2 circuits by default into the Microsoft PoP (each circuit on different Microsoft interconnects).

Colt support ‘hosted’ Microsoft Azure ExpressRoute into Microsoft. It supports both connectivity to the “private” Microsoft domain and “Microsoft/public” domain of Microsoft.
For hosted connections customers can choose bandwidth from 50Mbps – 1Gbps, please find an overview below:
Microsoft Port Size | Colt Service Bandwidth |
---|---|
50Mbps | 50Mbps |
100Mbps | 100Mbps |
200Mbps | 200Mbps |
500Mbps | 500Mbps |
1Gbps | 1Gbps |
The existing maximum capacity per Cloud Gateway per customer is 2Gbps. Bandwidths >2Gbps can be supported by distributing connections across 2 or more Cloud Gateways. The Cloud Gateway supports features like NAT and firewall (for enhanced security).
SD WAN solution into Microsoft Azure by default supports Cloud-to-Cloud communications between different CSP’s, which means that traffic between CSP’s does not have to enter the SD WAN network which reduces latency. Customers can order connectivity to any Microsoft location/region, connected by Colt.
Colt has deployed multiple Cloud Gateways in Europe and Asia in order to support resilient connectivity into Microsoft. To provide high performance of Cloud connectivity services on the SD-WAN the customer is asked to order resilient service towards Microsoft.
Colt is a direct partner of Microsoft and is able to interconnect towards multiple Microsoft Cloud on-Ramps locations within a metro or cloud region. To offer best performance, Colt routes the Cloud traffic through diverse Cloud Gateways in the Colt IQ network.
For more details on cloud connectivity on Multi-Cloud, please check the SD-WAN multicloud external service guide.
2.2.10 Managed Router Solutions (CPE)
Colt can also support CPE Solutions connections into Azure. For both the Dedicated Port and Hosted Connection options, customers have the option to add a managed CPE router to the Ethernet point to point service, so that Colt manages the layer 3 (BGP) routing into the Microsoft Azure network.
For Ethernet Private Network customers who require access into Azure, Ethernet Line connections should be provided. The Azure service is not compatible with switched Ethernet services.
2.2.11 DCA Wave
Wave services can also be used to connect to Azure. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
- Connectivity into Microsoft Azure is always based on two Wave services
2.2.12 PrizmNet
With the PrizmNet service, connectivity towards Azure can be established. This is available both on Azure ExpressRoute (hosted port options) and ExpressRoute Direct (dedicated port options).
The Standard service is based on private peering with the cloud provider. Colt is responsible for establishing layer 3 (BGP) connectivity with the cloud provider.
2.2.13 Encryption options
Colt is able to support two types of encryption withing the DCA portfolio:
Colt Encryption as add-on on top of DCA Ethernet and CSP encryption. Please see section 4 (DCA Encryption options) for more details.
For CSP encryption on Microsoft ExpressRoute Direct (dedicated port only), please find more information on: https://docs.microsoft.com/en-us/azure/expressroute/expressroute-about-encryption.
Please note that the Colt IQ network, offers based on Cloud on Demand, DCA Ethernet, and DCA Wave (Ethernet interface) is fully transparent to MACsec and therefore support the Microsoft feature.
2.2.14 Provider selection when creating ExpressRoute service-key
When ordering an ExpressRoute service on the Microsoft Azure portal:
https://learn.microsoft.com/en-us/azure/expressroute/expressroute-howto-circuit-portal-resource-manager?pivots=expressroute-current
Please select always ‘Colt Ethernet’ as provider (not Colt IP-VPN)

2.3 Google Cloud (Google Cloud Interconnect)
2.3.1 Google Cloud Interconnect Partner – Region PoPs
Google worldwide regions are interconnected (Europe, North America, Asia, Australia and Latin America). For example, a customer in Europe can connect to any Google location in the same region were Colt has established a Cloud PoP interconnect with Google. Customers will normally select the closest Colt PoP toward the Google Data Centre, where the customer allocates it’s cloud resources due to latency reasons.
The Google Cloud Interconnect (GCI) Partner Cloud network access PoPs are shown below Colt has connected most Google Cloud PoP’s in Europe vs. our competition.

2.3.2 Network POP’s


Separate from the connectivity costs of Colt, there will also be charges from Google for the private connection into the cloud. Please find charges of Google GCI services:
https://cloud.google.com/network-connectivity/docs/interconnect/pricing
2.3.3 Google Cloud Interconnect Partner – Service Offerings
Google Cloud Interconnect provides connectivity between a customer on-premise network and the Google Cloud network edge, allowing the customer to extend their private network into their cloud network.
This offering typically provides connectivity at a very competitive rate, the physical connectivity between Colt and Google Cloud is already in place.

Only the private domain can be reached (directly from on-prem using private IP access – no public IP’s required and no internet access required) supporting Google Compute Engine.
2.3.4 Ethernet Services into Google Cloud Interconnect Partner
The service is provided through a VLAN with specific bandwidth towards the Google Cloud Interconnect, delivered through the DCA shared NNI.

The Colt DCA service for Google Cloud Interconnect Partner has the following specific characteristics:
- Colt Bandwidth between 10M & 10Gbps
- Based on Single BGP peering / VLAN
- VLAN has specific Colt bandwidth
- Ideal for cost optimization
- Leased line connection at minimal cost
- Delivered on Google shared DCA-NNI
Colt can provide Cloud PoP diversity in each city – Interconnects are established in two different metro locations in: Amsterdam, London and Paris. In Frankfurt 2x interconnects within the same Cloud PoP location.
Please find below the bandwidth options available:

As Google Cloud Interconnect Partner is based on a hosted model, connectivity into the Cloud is delivered through a shared DCA-NNI. Following Google network topology, Colt has established 2x DCA-NNI’s within two different Google cities (applicable for Amsterdam, London and Paris). In Frankfurt Colt has established 2x DCA-NNI’s in one Google PoP. The following resilience and diversity options are available.

2.3.5 Google Cloud Interconnect – dedicated option
Google also support within their Cloud Interconnect program a dedicated option. The Microsoft dedicated port option is supported on DCA Ethernet, Cloud On Demand, IP-VPN, SD-WAN and CPE Solutions (please select available options per product).

Services presented on a Dedicated Port – where the end customer contracts a 10Gbps or 100Gbps port from Google and the port is dedicated for contracted customer use only. This option is available with Colt’s DCA Ethernet Line (point to point) or through our DCA Wave offering.
Customers are in control of Google VLAN provisioning (multiple VLAN’s / BGP sessions are allowed). VLANs on Dedicated Ports are not rate limited or shaped. Colt Ethernet service acts as a transparent pipe between the customer and Google services. Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the Google infrastructure. The Customer ‘A End’ can provision multiple VLANs into the Google cloud – essentially Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the Google cloud; allowing the customer full flexibility over their traffic into the Google network.
For the Dedicated Port option, Colt connects each individual customer circuit to a dedicated 10Gbps or 100Gbps port on Google’s router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from Google when they place an order for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering with Google.
Note that Colt bandwidth up to 10Gbps (and 40Gbps between Key-DC’s) will be delivered via the packet network – Ethernet. Alternatively (e.g. due to KMZ file requirement) Colt can deliver 10Gbps and 100Gbps service option via the Optical network – Wave.
2.3.6 SD-WAN Services into Google Cloud Interconnect (GCI)
Connectivity to Google Cloud Interconnect Services can be added towards the SD WAN network. Connectivity to Google Cloud Interconnect can be added to an existing SD WAN network, or ordered as part of a new SD WAN deployment.
Colt advises customers to establish resilient connects into Google by default, in order to create high Cloud connectivity performance towards the SD-WAN locations. In both cases, connectivity towards Google Cloud Interconnect from/to the SD WAN network goes via a Cloud Gateway in the Colt IQ-network.

Colt support the ‘GCI partner / hosted’ Google Cloud Interconnect option into Google Cloud. It supports connectivity to the “private” Google Cloud domain.
For hosted connections customers can choose bandwidth from 50Mbps – 1Gbps., please find an overview below:

The existing maximum capacity per Cloud Gateway per customer is 2Gbps. Bandwidths >2Gbps can be supported by distributing connections across 2 or more Cloud Gateways.
SD WAN solution into Google by default supports Cloud-to-Cloud communications between different CSP’s, which means that traffic between CSP’s does not have to enter the SD WAN network which reduces latency. Customers can order connectivity to any Google location/region, connected by Colt.
Colt has deployed multiple Cloud Gateways in Europe and Asia in order to support resilient connectivity into Google. To provide high performance of Cloud connectivity services on the SD-WAN the customer is asked to order resilient service towards Google.
Colt is a direct partner of Google and is able to interconnect towards multiple Google Cloud on-Ramps locations within a metro or cloud region. To offer best performance, Colt routes the Cloud traffic through diverse Cloud Gateways in the Colt IQ network.
For more details on cloud connectivity on Multi-Cloud, please check the SD-WAN multicloud external service guide.
2.3.7 Managed CPE and IP-VPN integration into Google Cloud Interconnect
On request Colt can deliver:
- Managed CPE as option on the Ethernet service
- Bespoke Google Cloud Access onto IP-VPN
2.3.8. DCA Wave
Wave services can also be used to connect to Google. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
2.3.9 PrizmNet
With the PrizmNet service, connectivity towards Google can be established. This is available both on GCI partner (hosted port options) and GCI Dedicated (dedicated port options).
The Standard service is based on private peering with the cloud provider. Colt is responsible for establishing layer 3 (BGP) connectivity with the cloud provider.
2.3.10 Encryption
Colt is able to provide Colt encryption on top of the DCA Ethernet service, please see section 4 (Colt Encryption for more details).
2.4 IBM Cloud (Direct Link Connect)
2.4.1 IBM Cloud Direct Link Connect – Region PoPs
The IBM Cloud network access PoPs are shown below. A region is a geographic area which a customer can connect to, the IBM regions are interconnected. Customers can access all regions from a single PoP through Global routing add-on. Colt has connected most IBM Cloud PoP’s in Europe vs. our competition.

2.4.2 Network POP Addresses

With IBM Cloud Direct Link, customers have access to Local Routing, or POPs within the same city as a target data center
- Inbound and outbound bandwidth is free
Optionally, customers can choose Global Routing to access POPs and data centers anywhere in the world
- Inbound bandwidth is free
- Outbound bandwidth in same region as POP is free
Please find the IBM charges of IBM Direct link: https://www.ibm.com/cloud/direct-link/pricing
2.4.3 IBM Cloud Direct Link Connect – Service Offerings
Customers can receive consistent, high-throughput connectivity between a remote network and an IBM Cloud customer with secure connectivity that never touches the public Internet. The physical connectivity between Colt and IBM Cloud is already in place and hosted to customers.

Note: Dedicated port requests can by requested on non-standard base.
- Colt has a direct relationship with IBM Cloud – no third party in between.
- Cloud PoP interconnections available in Europe and Asia
2.4.4 Ethernet Services into IBM Cloud Direct Link Connect
The IBM Direct Link Connect service is provided through a VLAN with specific bandwidth towards the IBM Cloud Direct Link Connect Interconnect, delivered through the DCA shared NNI.

The service is offered through a VLAN to IBM Cloud Service with specific characteristics:
- Colt Bandwidth between 10Mbps-5Gbps
- Single BGP peering / VLAN
- Connectivity only available towards IBM ‘private domain’
- Ideal for cost optimization
- Leased line connection at minimal cost
- Delivered on a shared DCA-NNI
- Colt has connected most IBM Cloud PoP’s in Europe
- Colt can provide Cloud PoP diversity in each city – based on two separate interconnects in each location
Please find below the bandwidth options available for IBM Direct Link Connect:

As IBM Direct Link Connect is based on a hosted model, connectivity into the Cloud is delivered through a shared DCA-NNI in each IBM network PoP’s. Following IBM network topology, Colt has established 2x DCA-NNI’s within each IBM network PoP and therefore the following resilience and diversity options are available.

2.4.5 IBM Cloud Direct Link – Dedicated option
IBM also support within their IBM Cloud Direct program a dedicated option for customers. Please find below a short overview:

Services presented on a Dedicated Port – where the end customer contracts a 10Gbps port (note that 1-2-5Gbps ports are also supported), from IBM and the port is dedicated for contracted customer use only. This option is available with Colt’s DCA Ethernet Line (point to point), DCA Ethernet Spoke (point to multipoint) and DCA Wave service offering.
IBM Direct Link Dedicated supports 1 VLAN / BGP session. The VLAN is rate limited. Colt Ethernet service acts as a transparent pipe between the customer and Google services. Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the IBM infrastructure. Essentially Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the IBM cloud.
For the DCA spoke use case, Colt presents the service at an Ethernet hub at the customer ‘A End’ site – all other service characteristics are identical to the Ethernet Line service.
For the Dedicated Port option, Colt connects each individual customer circuit to the dedicated port on IBM’s router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from IBM when they place an order for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering with IBM.
2.4.6 IP-VPN, SD-WAN and Managed CPE
On request Colt can deliver:
- IBM Cloud integration into customer’s IP-VPN
- on bespoke base IBM Cloud integration on SD-WAN
- Managed CPE as option on the Ethernet service
2.4.7 DCA Wave
Wave services can also be used to connect to IBM. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
2.4.8 PrizmNet
With the PrizmNet service, connectivity towards IBM can be established. This is available both on IBM Direct Link Connect (hosted port options) and IBM Direct Link Dedicated (dedicated port options). The Standard service is based on private peering with the cloud provider. Colt is responsible for establishing layer 3 (BGP) connectivity with the cloud provider.
2.4.9 Encryption
Colt is able to provide Colt encryption on top of the DCA service, please see section 4 (Colt Encryption for
more details).
2.5 Oracle Cloud (Oracle Cloud Infrastructure – OCI FastConnect)
2.5.1 OCI FastConnect – Region PoPs
The Oracle Cloud Infrastructure (OCI) FastConnect network access PoPs are shown below. A region is a geographic area which a customer can connect to, Colt has connected Oracle Cloud PoP’s in Europe, US and Asia.

2.5.2 Network POP Addresses & service availability
Colt can offer connectivity based on shared infrastructure/interconnect with Oracle where customers order VLAN’s to their location, or via dedicated port option where the full port is allocated to the customer. Below overview which options are available per location.

2.5.3 OCI FastConnect – Service Offerings (via shared interconnect – Oracle Provider)
Customers can receive consistent, high-throughput connectivity between a remote network and an Oracle Cloud (OCI FastConnect) customer with secure connectivity that never touches the public Internet. The physical connectivity between Colt and Oracle Cloud is already in place and hosted to customers.

Cloud PoP interconnections available in Europe, Asia and US.
2.5.4 Ethernet Services into Oracle Cloud
Connectivity to Oracle Cloud – OCI FastConnect service is provided through a VLAN to the Oracle/Colt Cloud Interconnect, delivered through our DCA solution based on a shared NNI.

The service is offered through a VLAN to Oracle Cloud with specific characteristics:
- Colt Bandwidth between 10Mbps-10Gbps
- Single BGP peering / VLAN
- Connectivity available towards Oracle ‘private domain or public domain’
- Ideal for cost optimization
- Leased line connection at minimal cost
- Delivered on a shared DCA-NNI
- Colt can provide Cloud PoP diversity in each city – based on two separate interconnects in each location
Please find below the bandwidth options available for Oracle Cloud – OCI FastConnec

As Oracle Cloud – OCI FastConnect, hosted/shared option is based on a hosted model, connectivity into the Cloud is delivered through a shared DCA-NNI in each Oracle network PoP’s.
Following Oracle network topology, Colt has established 2x DCA-NNI’s within each Oracle network PoP and therefore the following resilience and diversity options are available.

2.5.5 Oracle Cloud – OCI FastConnect Dedicated option (Oracle 3rd party)
Oracle also support within their Oracle Cloud program a dedicated option for customers. The Microsoft dedicated port option is supported on DCA Ethernet, Cloud On Demand, IP-VPN and CPE Solutions (please select available options per product).Please find below a short overview:

Services presented on a Dedicated Port – where the end customer contracts a 1Gbps or 10Gbps port from Oracle and the port is dedicated for contracted customer use only. This option is available with Colt’s DCA Ethernet Line (point to point), DCA Ethernet Spoke (point to multipoint) and DCA Wave service offering.
OCI FastConnect Dedicated supports multiple VLAN’s / BGP session. The VLAN is not rate limited. Colt Ethernet service acts as a transparent pipe between the customer and Oracle services. Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the Oracle infrastructure. Essentially Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the Oracle cloud.
For the DCA spoke use case, Colt presents the service at an Ethernet hub at the customer ‘A End’ site – all other service characteristics are identical to the Ethernet Line service.
For the Dedicated Port option, Colt connects each individual customer circuit to the dedicated port on Oracle’s router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from Oracle when they place an order for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering with Oracle.
2.5.6 IP-VPN and Managed CPE
On request Colt can deliver:
- Managed CPE as option on the Ethernet service
- IP-VPN service
2.5.7 DCA Wave
Wave services can also be used to connect to Oracle. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
2.5.8 Integration of the Colt On Demand & Oracle Cloud Platform portals
- Enjoy a seamless and integrated experience in setting up secure, private, end-to-end cloud connectivity, due to the deeper integration of the Colt On Demand & Oracle Cloud Platform portals.
- This API-based integration enables Oracle FastConnect customers to request & provision Colt On Demand connectivity directly from the Oracle FastConnect console, without the need to switch between portals.
See a preview of the customer journey:

2.5.9 Encryption
Colt is able to support two types of encryption withing the DCA portfolio: Colt Encryption as add-on on top of DCA Ethernet and CSP encryption. Please see section 4 (DCA Encryption options) for more details.
For CSP encryption on OCI FastConnect (dedicated port only), please find more information on: https://blogs.oracle.com/cloud-infrastructure/post/announcing-macsec-for-oracle-cloud-infrastructure-fastconnect
Please note that the Colt IQ network, offers based on Cloud on Demand, DCA Ethernet, and DCA Wave (Ethernet interface) is fully transparent to MACsec and therefore support the Oracle feature.
2.6 OVHcloud
2.6.1 OVHcloud cloud access PoPs
The OVHcloud access PoPs are shown below. Colt has connected OVHcloud PoP’s in Europe and Asia.

2.6.2 Network POP Addresses & service availability
There are two OVHcloud Connect options which will be supported by Colt:
- OVHcloud Connect Direct (via dedicated port option where the full port is allocated to the customer)
- OVHcloud Connect Provider (delivered via Equinix Fabric-Equinix)

2.6.3 Ethernet Services into OVHcloud Connect – Provider
Under OVHcloud Connect, customers can establish private connectivity between OVHcloud and their datacenter, office, or colocation environment using Colt DCA connectivity services. This provides customers with a secure connectivity that never touches the public Internet. The connectivity is set-up between a customer on-premise network and the OVHcloud network edge, allowing the customer to extend their private network into their cloud network.
The service is offered through a VLAN to OVH Cloud Provider with specific characteristics:
- Provides secure and reliable connectivity at a reasonable price
- Based on Single BGP peering / VLAN
- Ideal for cost optimization
- Leased line connection at minimal cost
- Fast delivery over existing DCA-NNI infrastructure
- Single domain (e.g. to connect to both OVHcloud Compute and Storage services)
- Using OVHcloud Service Key, inside
- Using Equinix Fabric for delivery
Please find below the bandwidth options available for OVHcloud Connect – Provider:

2.6.4 OVHcloud Connect – Direct (dedicated port option)
OVHcloud Connect Direct – a dedicated port option is also supported within their OVH Connect program. Please find below a short overview:
- For customers who need maximum level of security
- Customer is assigned a port dedicated to them – no other customer can use this port
- Built to handle large volume data
- Dedicated 1Gbps or 10Gbps port with OVHcloud
- Colt bandwidth 500Mbps-10Gbps on Ethernet services
- Colt bandwidth 10Gbps on Wave services
- Support multiple BGP sessions / VLAN’s
- Ideal for sharing across multiple departments
- Colt offers cross-connect to dedicated port via OVHcloud LOA
- Encryption option on dedicated port
Services presented on a Dedicated Port – where the end customer contracts a 1 or 10Gbps port from OVHcloud and the port is dedicated for contracted customer use only. This option is available with Colt’s DCA Ethernet Line (point to point), DCA Ethernet Spoke (point to multipoint) and DCA Wave service offering.

OVHcloud Connect Direct supports multiple VLAN’s / BGP session. The VLAN is not rate limited. Colt Ethernet service acts as a transparent pipe between the customer and OVHcloud services. Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the Alibaba infrastructure. Essentially Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the Oracle cloud.
For the DCA spoke use case, Colt presents the service at an Ethernet hub at the customer ‘A End’ site – all other service characteristics are identical to the Ethernet Line service.
For the Dedicated Port option, Colt connects each individual customer circuit to the dedicated port on Alibaba’s router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from OVHcloud when they place an order for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering with OVHcloud.
2.6.5 DCA Wave
Wave services can also be used to connect to OVHcloud. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
2.6.6 IP-VPN, SD-WAN and Managed CPE
On request Colt can deliver:
- Cloud integration into customer’s IP-VPN
- Managed CPE as option on the Ethernet service
2.6.7 Encryption
Colt is able to provide encryption on DCA Ethernet services, please see section 4 (Colt Encryption options for more details).
2.7 Alibaba Cloud
2.7.1 Alibaba Cloud – Region PoPs
The Alibaba Cloud network access PoPs are shown below. A region is a geographic area which a customer can connect to, Colt has connected Alibaba Cloud PoP’s in Europe and Asia.

2.7.2 Network POP Addresses & service availability
There are two Express Connect options which will be supported by Colt:
- Express Connect (delivered via Equinix Fabric-Equinix)
- Express Connect Dedicated (via dedicated port option where the full port is allocated to the customer)

2.7.3 Ethernet Services into Alibaba Cloud – Express Connect
Customers can receive consistent, high-throughput connectivity between a remote network and an Alibaba Express Connect customer with secure connectivity that never touches the public Internet. Express Connect services are delivered through our partnership with Equinix – Equinix Fabric.
The service is offered through a VLAN to Alibaba Cloud with specific characteristics:
- Colt Bandwidth between 10Mbps-1Gbps
- Single BGP peering / VLAN
- Connectivity available towards Oracle ‘private domain’
- Ideal for cost optimization
- Leased line connection at minimal cost
- Delivered through Equinix Fabric
Please find below the bandwidth options available for Alibaba Cloud – Express Connect:

2.7.4 Alibaba Cloud – Express Connect Dedicated – Dedicated port option
Alibaba Cloud also support within their Alibaba Cloud program a dedicated option for customers. Please find below a short overview:

Services presented on a Dedicated Port – where the end customer contracts a 1 or 10Gbps port from Alibaba and the port is dedicated for contracted customer use only. This option is available with Colt’s DCA Ethernet Line (point to point), DCA Ethernet Spoke (point to multipoint) and DCA Wave service offering.
Alibaba Express Connect Dedicated supports multiple VLAN’s / BGP session. The VLAN is not rate limited. Colt Ethernet service acts as a transparent pipe between the customer and Alibaba services. Colt DCA Ethernet service is configured to transparently pass customer frames (traffic) between the ‘A End’ site and the Alibaba infrastructure. Essentially Colt Ethernet based DCA service acts as a transparent pipe between the customer’s router and the Oracle cloud.
For the DCA spoke use case, Colt presents the service at an Ethernet hub at the customer ‘A End’ site – all other service characteristics are identical to the Ethernet Line service.
For the Dedicated Port option, Colt connects each individual customer circuit to the dedicated port on Alibaba’s router network via a physical cross connect. This is illustrated below, using an Ethernet point to point service as an example.

With the dedicated port option, Colt provides a physical cross connect in addition to connectivity. The cross connect is ordered via a Letter of Authorisation (LOA) process, under which the customer receives a letter/acknowledgement from Alibaba Cloud when they place an order for the dedicated port with them. Once the Colt circuit and cross connect have been provisioned, the customer is able to establish BGP peering with Alibaba.
2.7.5 DCA Wave
Wave services can also be used to connect to Alibaba Cloud. Cloud connectivity on Wave is based on layer 1 optical connectivity and provides dedicated high bandwidth cloud connectivity up to 100G over Colt’s extensive, wholly owned fibre end-to-end footprint. Specified KMZ path and option for customer-defined routes are supported. The Customer is responsible for establishing layer 3 connectivity into the CSP’s platform.

Other characteristics:
- Colt connectivity: Point-to-point connectivity
- Unprotected / protected service options
- Diversity options
- Encryption feature
2.7.6 IP-VPN, SD-WAN and Managed CPE
On request Colt can deliver:
- Cloud integration into customer’s IP-VPN
- on bespoke base IBM Cloud integration on SD-WAN
- Managed CPE as option on the Ethernet service
2.7.7 Encryption
Colt is able to provide encryption on DCA Ethernet services, please see section 4 (Colt Encryption options for more details).
2.8 Longtail CSPs (other CSP’s)
In addition to directly connected CSPs, Colt is able to deliver to an extensive list of other CSP providers including but not limited to – Oracle Gov, SAP, Salesforce, OVHcloud and AliCloud (and many others on request basis) through our partner Equinix via its Equinix Fabric.
Ethernet connectivity is similar to hosted connections – i.e. NNI based handover with a single VLAN.
The Equinix Fabric is a cloud aggregation platform, this interconnect with Equinix Fabric allows Colt to offer connectivity to multiple cloud service providers from any of its connected location.
Colt can offer both Ethernet point to point and Ethernet spoke services through its Equinix Fabric interconnect. CPE Solutions and IP-VPN connectivity into these cloud providers is available on request.
This longtail CSP service offering is on bespoke base.

2.8.1 Locations


It is important to note that not every cloud provider service is available at every location – please see cloud access PoP table below.

End-users directly orders the cloud subscription from the applicable longtail CSP. Please note that some longtail CSP’s mandate (due to their policy) dual connections into their cloud environment (e.g. SAP and Webex). Please double-check with your longtail CSP’s the full requirement in order have the right expectations in regards to the Colt connectivity proposal.
2.8.2 Bandwidth and Interface Options (All Services)
Please note that all connections are delivered through a hosted connection (NNI) via the Equinix Fabric (on bespoke base). Other DCA service like CPE Solutions and IP-VPN connectivity into these cloud providers is available on request.
The bandwidth options are shown below:

2.8.3 Other Cloud providers on the Equinix Fabric – Equinix
Please note that outside the CSP’s mentioned above Colt can also provide on bespoke base connectivity to other CSP’s on request. In below link you will be able to see which other Cloud providers are active in the connected locations:
https://www.equinix.com/interconnection-services/equinix-fabric/provider-availability
2.8.4 IP-VPN and Managed CPE
On request Colt can deliver:
- Cloud integration into customer’s IP-VPN
- Managed CPE as option on the Ethernet service
3. DCA Encryption options
DCA Encryption has been added Colt’s Cybersecurity portfolio. The portfolio is designed to address the growing market need for effective network security solutions, driven by increasing threats and new regulatory requirements such as EU GDPR.
3.1 CSP Encryption
CSP MACsec encryption:
- Highest standard of security to the Cloud – growing market need for effective network security solution, also driven by increasing threats
- End-to-End encryption upto the CSP cloud network, supported on Cloud on Demand, DCA Ethernet and DCA Wave dedicated port offering globally (point-to-point)
- It is supported by Microsoft ExpressRoute Direct, AWS Direct Connect Dedicated and OCI FastConnect.
- Option is available on dedicated CSP ports with speeds upto 100Gbps


Please note that the Encryption feature does not change the standard SLA of the underlying DCA Ethernet services.

4. Cloud to Cloud connectivity
Today, with the growth of use case specific cloud offerings, customers require a mult-cloud strategy whereby also Cloud to Cloud connectivity is requested. As a result, the need for cloud to cloud solutions is on the rise.
General benefits:
- Ease integration of various content platforms
- Leverage best-of-breed options for each content type
Use cases:
- Customers who have NO on-premise equipment, 100% webbased companies e.g. large webshops, UBER etc.
- Customers who want to move all the services to the Cloud, among different CSP’s.
- Or customers who want to use short term Cloud to Cloud service for migration purposes (e.g. AWS towards Azure)
Example:
- A webshop who has a front end E-commerce platform at one Cloud Service Provider and at the back-end an inventory management- or financial management system at another Cloud Service Provider. Due to latency, reliability and security reasons customer prefers a DCA point to point circuit between the two CSP’s, instead of via the Internet
- Colt is able to address Cloud to Cloud connectivity through L2 DCA Ethernet Line and through our L3 solutions like IP-VPN and SD-WAN multicloud (please go to selected sections / products to learn more about cloud-to-cloud connectivity.
4.1. L2 DCA Ethernet Cloud-to-Cloud
Customers are able to connect between different Cloud providers (without physical connectivity towards customer locations) with lowest latency, directly between NNI’s or dedicated CSP ports

- Product: DCA Ethernet Line – Cloud to Cloud connectivity
- Connectivity between CSP’s, between dedicated ports or NNI’s directly
- Providing lowest latency possible
- Customer to manage BGP
- Between AWS-Azure & Azure-Oracle only (due to CSP technical portal compatibility restriction)
5. DCA Pricing
All DCA pricing is based on fixed 1 year contracts, with installation (NRC) and monthly recurring (MRC) components. Per Gigabyte usage based billing and monthly contracts are currently NOT supported by Colt.
Pricing for on-net DCA Ethernet services can be found in the custom-built DCA pricebook, which includes both DCA Ethernet Line, Ethernet spoke pricing and DCA Wave pricing.

5.1 Amazon Ethernet pricing
Pricing for services presented hosted connection and on dedicated port 1Gbps and 10Gbps ports is similar to standard Ethernet pricing, with the exception that for dedicated port the cross connect between Colt and Amazon is included in the price.
Standard resilience options apply (protected, unprotected). When access diversity is required a 2nd service has to be ordered. For the second order a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes will be implemented on both orders.
Where access diversity is required between a pair of services, the price shall be uplifted in line with the standard Colt diversity guidelines.
5.2 Microsoft ExpressRoute Ethernet pricing
Pricing for Ethernet services into Microsoft is based on a dual circuit package, single circuit pricing is not supported. The following options apply:
Resilience | Description | Price |
---|---|---|
Unprotected | Both circuits are presented on a single NTE | Default pricing |
Protected | Each protected circuit in the dual circuit pair is presented on a single NTE | Higher vs unprotected |
Diversity | a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes | Higher vs protected |
5.3 Google pricing
Pricing for Google is similar to standard Ethernet pricing (with the exception that for dedicated option the cross connect between Colt and Google is included in the price). Standard resilience options apply (protected, unprotected). When access diversity is required a 2nd service has to be ordered. For the second order a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes will be implemented on both orders.. Where diversity is required between a pair of services, the price shall be uplifted in line with the standard Colt diversity guidelines.
5.4 IBM pricing
Pricing for IBM is similar to standard Ethernet pricing (with the exception that for dedicated option the cross connect between Colt and IBM is included in the price). Standard resilience options apply (protected, unprotected). When access diversity is required a 2nd service has to be ordered. For the second order a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes will be implemented on both orders. Where diversity is required between a pair of services, the price shall be uplifted in line with the standard Colt diversity guidelines.
5.5 Oracle pricing
Pricing for Oracle is similar to standard Ethernet pricing (with the exception that for dedicated option the cross connect between Colt and Oracle is included in the price). Standard resilience options apply (protected, unprotected). When access diversity is required a 2nd service has to be ordered. For the second order a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes will be implemented on both orders. Where diversity is required between a pair of services, the price shall be uplifted in line with the standard Colt diversity guidelines.
5.6 Alibaba Cloud pricing
Pricing for Alibaba Oracle is similar to standard Ethernet pricing (with the exception that for dedicated option the cross connect between Colt and Alibaba is included in the price). Standard resilience options apply (protected, unprotected). When access diversity is required a 2nd service has to be ordered. For the second order a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes will be implemented on both orders. Where diversity is required between a pair of services, the price shall be uplifted in line with the standard Colt diversity guidelines. At some locations Alibaba Cloud will be delivered as longtail CSP (please see 3.8).
5.7 OVHcloud pricing
Pricing for OVHcloud is similar to standard Ethernet pricing (with the exception that for dedicated option the cross connect between Colt and OVHcloud is included in the price). Standard resilience options apply (protected, unprotected). When access diversity is required a 2nd service has to be ordered. For the second order a 2nd NTE will be provided at the customer site and diverse access path between the customer site and the Colt homing nodes will be implemented on both orders. Where diversity is required between a pair of services, the price shall be uplifted in line with the standard Colt diversity guidelines. At some locations AliCloud will be delivered as longtail CSP (please see 3.8).
5.8 Longtail CSP pricing
Pricing is similar to standard Ethernet pricing plus additional 3rd party connectivity charges. Standard resilience options apply (protected, unprotected). When access diversity in the access is required a 2nd service has to be ordered.
5.9 DCA Ethernet off-net pricing
The standard Colt Ethernet price book shall be used for off-net sites. For services into Microsoft ExpressRoute, 2 individual circuits should be selected.
5.10 Managed Router Pricing
The standard CPE Solutions price book should be used, in conjunction with DCA Ethernet P-P pricing for the relevant cloud provider.
5.11 IP-VPN pricing
Pricing for DCA IP-VPN services is based on the existing IP-VPN Access pricebook. Pricing for the cloud site is based on the country where the cloud PoP is located. For example, connectivity into the Amazon PoP in Frankfurt is based on Germany IP-VPN pricing, no matter where the rest of the VPN sites are located
Pricing into Amazon is based on single access by default. Dual access can also be provided as an additional option. In contrast, pricing into Microsoft Azure is ALWAYS based on dual access. Other CSP’s outside are on request. Please contact your Colt account team for further details.

5.12 SD-WAN Multicloud pricing
Pricing for Cloud services integrated in SD-WAN MultiCLoud, please use the SD-WAN pricing tool.
There you can select the applicable CSP and you can select per branch locations if cloud access is required. Please see the SD-WAN multicloud pricebook for more information.
5.13 DCA Wave
Please refer to the tab DCA Wave in the DCA Ethernet Pricing sheet. Wave services can also be used to connect to public Cloud Service Providers (CSP’s) and only CSP dedicated port option is supported for 10Gbps and 100Gbps bandwidth offerings.
5.14 Cloud access on PrizmNet pricing
Please see the PrizmNet pricebook for more information.
6. Ordering DCA Services
6.1 DCA Ethernet Services
The Colt order team will require a ‘CSP customer identifier’ at the point the order is signed. The CSP customer identifier is used by the Colt delivery team to activate the service, please find below the different ‘CSP customer identifier’ keys for each of the Cloud provider:
Service | CSP customer identifier |
---|---|
Amazon Dedicated Port Google Dedicated Port IBM Dedicated Port | Letter of Authorisation (LOA) |
Amazon Hosted Connection | Customer’s Amazon account ID |
Microsoft ExpressRoute | ExpressRoute Service Key |
IBM Direct Link Connect | Ticket number + VLAN ID + NNI identifier |
Google Cloud Interconnect Partner | Pairing Key |
Oracle OCI-FastConnect | Virtual Circuit OCID |
VMware Horizon | Service ID |
SAP Cloud-Hana Enterprise | SAP Ticket ID |
SAP Cloud-SaaS | SAP Ticket ID |
Salesforce Express Connect | Authentication Key |
OVHcloud | Service Key |
For services delivered on dedicated ports (typically full rate 1Gbps & 10Gbps services), the Colt service delivery team will need an CSP Letter of Authority (LOA), is obtained from the end customer.
The LOA is issued when the end customer orders e.g. a Direct Connect Dedicated service from Amazon, and should be sent to the Colt service delivery team to attach to the Siebel order. The end customer (or operator/reseller) is not authorised to order the cross connect to the Colt rack – only Colt can order a CSP cross connect into a Colt rack location.
The following items should be checked before a DCA Ethernet spoke is placed:
- Does the customer require presentation on 1 or 2 hubs?
- Can the customer support double tagging? Colt recommend double tagging, but we can support single tagging for the 2 hub option (on request)
6.2 Managed Router
The standard CPE Solutions order form should be completed, in addition to a DCA Ethernet P-P order.
6.3 DCA IP-VPN Services
Dedicated Cloud Access IP-VPN services are ordered via the standard IP-VPN Access and Plus site order forms.
6.4 DCA Wave
The Wave QtO EoF (order form) should be completed and container process should be followed.
6.5 DCA PrizmNet Services
The standard PrizmNet order forms should be completed.
7. Delivery
Note – the DCA Customer Configuration Guide provides useful information for customers to configure their service.
7.1 DCA Ethernet Services into Amazon
For dedicated port based services, the Colt delivery team shall use the LOA to order the cross connect into the Amazon router. Once the DCA Ethernet P-P service and cross connect have been delivered, the Amazon port will be activated automatically. Hosted connections are activated via the Microsoft portal, using the customer’s account ID.
7.2 DCA Ethernet Services into ExpressRoute
ExpressRoute services are activated via the Service Key, which is used to generate key routing information and activate the service. The below schematic illustrates the process flow for an ExpressRoute delivery.

For dedicated port based services, the Colt delivery team shall use the LOA to order the cross connect into the Microsoft router. Once the DCA Ethernet P-P service and cross connect have been delivered, the Microsoft port will be activated automatically.
7.3 DCA Ethernet Services into Google Cloud Interconnect
Colt received an unique ‘pairing key’ which the customer has created in GCloud SDK (in near future this will be the Google portal). The pairing key represents a connection identifier.
Colt will provision the partner attachment/VLAN attachment on the GCloud SDK based on the pairing key and specifies the VLAN ID and applicable CSP bandwidth selected by the customer. This partner attachment has to be accepted by the customer. In parallel Colt delivers the customer layer 2 circuit with the specific Colt bandwidth towards the customer location. The customer can then configure the layer 3 BGP peering.
For dedicated port based services, the Colt delivery team shall use the LOA to order the cross connect into the Google router. Once the DCA Ethernet P-P service and cross connect have been delivered, the Google port will be activated automatically.
7.4 DCA Ethernet Services into IBM Direct Link
Colt will receive from the customer an IBM ticket number + VLAN ID + NNI Identifier. Colt will provision the circuit on the IBM interconnect. In parallel Colt delivers the customer layer 2 circuit with specific Colt bandwidth to customer location. The customer can then configure the layer 3 BGP peering.
For dedicated port based services, the Colt delivery team shall use the LOA to order the cross connect into the IBM router. Once the DCA Ethernet P-P service and cross connect have been delivered, the IBM port will be activated automatically.
7.5 DCA Ethernet Services into Oracle – OCI FastConnect
Colt will receive from the customer a Virtual Circuit OCID. Colt will provision the circuit on the Oracle interconnect. In parallel Colt delivers the customer layer 2 circuit with specific Colt bandwidth to customer location. The customer can then configure the layer 3 BGP peering.
For dedicated port based services, the Colt delivery team shall use the LOA to order the cross connect into the Oracle router. Once the DCA Ethernet P-P service and cross connect have been delivered, the Oracle port will be activated automatically.
7.6 DCA Ethernet Services into Alibaba – Express Connect
Colt will receive from the customer a CSP key. Colt will provision the circuit on the Alibaba interconnect (using Equinix Fabric platform). In parallel Colt delivers the customer layer 2 circuit with specific Colt bandwidth to customer location. The customer can then configure the layer 3 BGP peering.
For dedicated port based services, the Colt delivery team shall use the LOA to order the cross connect into the Alibaba router. Once the DCA Ethernet P-P service and cross connect have been delivered, the Alibaba port will be activated automatically.
7.7 DCA Ethernet Services into OVHcloud – Express Connect
Colt will receive from the customer a Service Key. Colt will provision the circuit on the OVHcloud Connect Provider (using Equinix Fabric platform). In parallel Colt delivers the customer layer 2 circuit with specific Colt bandwidth to customer location. The customer can then configure the layer 3 BGP peering.
For dedicated port-based services, the Colt delivery team shall use the LOA to order the cross connect into the Alibaba router. Once the DCA Ethernet P-P service and cross connect have been delivered, the OVHcloud Connect Direct port will be activated automatically.
7.8 DCA Ethernet Services into other CSP’s through Equinix – longtail CSP’s
Colt received an unique ‘customer identifier’ (please see the different customer identifiers per CSP in matrix below).
Service | CSP customer identifier |
---|---|
Oracle OCI-FastConnect | Virtual Circuit OCID |
OVHcloud Connect Provider | Service Key |
SAP Cloud-Hana Enterprise | SAP Ticket ID |
Salesforce Express Connect | Not required |
Colt will provision the cloud access on the Equinix Portal and specifies the VLAN ID and applicable CSP bandwidth as selected by customer. This connection has to be accepted by the customer. In parallel Colt delivers the customer layer 2 circuit with specific Colt bandwidth. The customer can then configure the layer 3 BGP peering. Currently service towards longtail CSP’s are on bespoke base.
7.9 IP-VPN & Managed Router Services into Amazon
The subscription owner is responsible for configuring IP services in the Amazon portal. Therefore, for IP-VPN services Colt will ask the customer to enter the IP config in the Amazon portal.
7.10 IP-VPN & Managed Router Services into ExpressRoute
The process is similar to the Ethernet steps described above. The customer will sometimes be required to enter the IP config via the Azure portal.
8. MTU
Colt ethernet services are fully transparent and for on-net sites we support up to 9100 Byte frames by default (for off-net it depends on the OLO carrier, our minimum to accept an OLO is quite low with only 1534 Bytes).
9. Service Assurance
Standard Colt processes for service assurance shall apply.
The Colt support team will be able to clarify if there is a fault within the service boundaries of the DCA service, i.e. between the demarcation at the A end customer site and the handover at the cloud provider B end site.
Please note that Colt is NOT responsible for the cloud provider router network. If customers suspect that a cloud provider router or service is faulty, they should raise a ticket directly with the cloud service provider (e.g. Amazon, Microsoft, Google, Oracle, IBM).
The Colt support team will sometimes need to work with the cloud provider support team to establish whether the fault is on the Colt or cloud provider network.
10. Performance Reporting
Service Performance Reporting is available as a ‘bundled’ feature for Colt Ethernet services. This is offered via Colt Analytics, a reporting tool that enables customers to view the performance of their Colt Ethernet services in near ‘real time’ and provides the following features:
- Ability to view general service characteristics
- Service Availability, Circuit Bandwidth Utilisation, Port Utilisation
- Detailed Reports on Key Performance Indicators (KPIs)
- Round Trip Delay (RTD), Jitter, Frame Loss
- Customer selectable reporting period including historic data (up to 1 year)
- Option to download reports – CSV and PDF
- Support for all Ethernet topologies – Ethernet Line, Ethernet H&S, E-VPN, Private Ethernet
Customers can access the reporting tool via the Colt Online web portal. The service data is stored for a period of 1 year allowing historical reporting and trend analysis to be performed.
Online Performance Reporting is a standard feature for Ethernet services delivered on the Colt IQNet platform and for Off-Net services where a Colt demarcation device is installed at the customer’s premises
11. Decision tree
Colt has a full solution offering for connectivity to the cloud. Need a helping hand? please see below high level decision tree and ask your account manager in case you have questions.

12. Recognition – awards


13. Document history
Version | Author | Date | |
---|---|---|---|
1.0 | Initial draft | M South | Oct 2014 |
2.0 | Various amendments | M South | Nov 2014 |
3.1 | Various amendments | M South | Jan 2015 |
4.0 | Re-branding, new pricing, new sales process, IP-VPN update, general refresh | M South | April 2015 |
4.1 | Updated eOrder notes fields | M South | May 2015 |
4.2 | Microsoft sharing policy Service Key clarification Office 365 statement | M South | Aug 2015 |
5 | Addition of DCA Ethernet spokes New Amazon and Microsoft PoPs New ExpressRoute offer (EXP/NSP combined, new BWs) General review | M South | Nov 2015 |
6 | Conversion from internal to external service guide | M South | June 2016 |
7 | Asian locations added, general amends | M South | Dec 2016 |
8 | 5 & 10Gbps Azure bandwidths, Equinix FabricExchange, managed router updates | M South | Sep 2017 |
9 | Update on AWS hosted connection, Microsoft Azure Express peering and Equinix Fabric | M South/M. Heijnen | Dec 2017 |
9 | Update on Google, IBM and Equinix Fabric. Managed routers update | M. Heijnen/S.Shaikh | May 2018 |
10 | Update on Google, IBM and Equinix Fabric – dedicated option | M. Heijnen/S. Hiroyoshi | June 2018 |
11 | Update on Azure location for Asia | M. Heijnen/S. Hiroyoshi | Sep 2018 |
12 | Updates on all CSP’s & CSP map | M. Heijnen/S. Hiroyoshi | Oct 2018 |
13 | Update on Azure | M. Heijnen | Jan 2019 |
14 | Update on Azure & AWS | M. Heijnen | March 2019 |
15 | Update on Azure resilience & Colt IQnetwork update | M. Heijnen/S. Hiroyoshi | April 2019 |
16 | Update Cloud to Cloud | M. Heijnen/S. Hiroyoshi | April 2019 |
17 | General restructuring / update including direct option for Azure and Google | M. Heijnen/S. Hiroyoshi | July 2019 |
18 | General update & adding hosted locations in US | M. Heijnen/S. Hiroyoshi | Nov 2019 |
19 | General update & adding/update Azure dedicated port option, Oracle and AliCloud | M. Heijnen/S. Hiroyoshi | Jan 2020 |
20 | General update, including SD-WAN | M. Heijnen/S. Hiroyoshi | June 2020 |
21 | General update, including SD-WAN | M. Heijnen/S. Hiroyoshi | Oct 2020 |
22 | General update | M. Heijnen/S. Hiroyoshi | Dec 2020 |
23 | General update (DCA offering) | M. Heijnen/S. Hiroyoshi | Jan 2021 |
24 | General update (equinix update) | M. Heijnen/S. Hiroyoshi | Feb 2021 |
25 | General update (portfolio update) | M. Heijnen/S. Hiroyoshi | March 2021 |
26 | General update (encryption) | M. Heijnen/S. Hiroyoshi | April 2021 |
27 | Update on all CSP’s | M. Heijnen/S. Hiroyoshi | June 2021 |
28 | Update on AWS high bandwidth | M. Heijnen/S. Hiroyoshi | Sept 2021 |
29 | PrizmNet update | M. Heijnen/S. Hiroyoshi | Oct 2021 |
30 | Oracle update | M. Heijnen/S. Hiroyoshi | Nov 2021 |
31 | AWS and other CSP Cloud PoP updates | M. Heijnen/S. Hiroyoshi | Feb 2022 |
32 | DCA Wave | M. Heijnen/Kostas.Christodoulou | May 2022 |
33 | General update (name change Interxion to DRT, Transit gateway,encryption etc.) | M.Heijnen/ [email protected] | Sept 2022 |
34 | Additional info CSP encryption | M.Heijnen/ [email protected] | Oct 2022 |
35 | Updating CSP info (AWS and CSP dedicated port) and DCA Ethernet high bandwidth | M.Heijnen/ [email protected] | Feb 2023 |
36 | General updates incl. adding OVHcloud | M.Heijnen/ [email protected] | June 2024 |
37 | General updates incl. adding ExpressRoute Metro | M.Heijnen/ [email protected] | July 2024 |
39 | General format update | M.Heijnen/ [email protected] | August 2024 |