Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium

A technician needs to connect an on-premises network to an Azure Virtual Network (VNet) securely over the public internet. The connection must use standard, industry-proven tunneling protocols, and the on-premises network has a VPN device capable of IPsec IKEv1 and IKEv2. Which Azure networking component should they use?

  1. AAzure VPN Gateway
  2. BAzure Virtual WAN
  3. CVNet Peering
  4. DAzure ExpressRoute
Show answer & explanation

Correct answer: A. Azure VPN Gateway

Azure VPN Gateway is specifically designed to connect on-premises networks to Azure VNets securely over the public internet using IPsec/IKE VPN tunnels. It supports both IKEv1 and IKEv2 protocols, making it suitable for standard VPN device connectivity.

Why the other options are wrong

  • B. Virtual WAN is a broader solution for large-scale networking, usually integrating VPN Gateways, but VPN Gateway is the specific component for this scenario.
  • C. VNet Peering connects Azure VNets to each other, not on-premises networks.
  • D. ExpressRoute provides a private, dedicated connection, not over the public internet.

Azure VPN Gateway

An Azure networking service that creates encrypted cross-premises connections between on-premises networks and Azure Virtual Networks over the public internet.

  • Uses IPsec/IKE VPN tunnels.
  • Supports Site-to-Site and Point-to-Site connections.
  • Connects over the public internet.
  • Supports both IKEv1 and IKEv2.

Memory trick: VPN over public internet, ExpressRoute is private fiber.

More Implement and manage virtual networking questions