Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium
A technician needs to connect an on-premises network to an Azure Virtual Network (VNet) securely over the public internet. The connection must use standard, industry-proven tunneling protocols, and the on-premises network has a VPN device capable of IPsec IKEv1 and IKEv2. Which Azure networking component should they use?
- AAzure VPN Gateway
- BAzure Virtual WAN
- CVNet Peering
- DAzure ExpressRoute
Show answer & explanationAnswer & explanation
Correct answer: A. Azure VPN Gateway
Azure VPN Gateway is specifically designed to connect on-premises networks to Azure VNets securely over the public internet using IPsec/IKE VPN tunnels. It supports both IKEv1 and IKEv2 protocols, making it suitable for standard VPN device connectivity.
Why the other options are wrong
- B. Virtual WAN is a broader solution for large-scale networking, usually integrating VPN Gateways, but VPN Gateway is the specific component for this scenario.
- C. VNet Peering connects Azure VNets to each other, not on-premises networks.
- D. ExpressRoute provides a private, dedicated connection, not over the public internet.
Azure VPN Gateway
An Azure networking service that creates encrypted cross-premises connections between on-premises networks and Azure Virtual Networks over the public internet.
- Uses IPsec/IKE VPN tunnels.
- Supports Site-to-Site and Point-to-Site connections.
- Connects over the public internet.
- Supports both IKEv1 and IKEv2.
Memory trick: VPN over public internet, ExpressRoute is private fiber.