Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium

A company is expanding its Azure footprint and needs to connect a new Azure Virtual Network (VNet) in the West US region to an existing VNet in the East US region. Both VNets have overlapping IP address spaces. Which networking solution should you implement to enable communication between resources in these VNets?

  1. AAzure Virtual WAN
  2. BVPN Gateway
  3. CVNet Peering
  4. DAzure ExpressRoute
Show answer & explanation

Correct answer: B. VPN Gateway

VNet Peering requires non-overlapping IP address spaces. Since the VNets have overlapping IP address spaces, VNet Peering cannot be used. A VPN Gateway can connect VNets with overlapping IP spaces by using Network Address Translation (NAT) and is the appropriate solution here.

Why the other options are wrong

  • A. Azure Virtual WAN is a networking service that brings many networking, security, and routing functionalities together, but for direct VNet-to-VNet with overlapping IPs, a VPN Gateway is the specific solution.
  • C. VNet Peering cannot be used when VNets have overlapping IP address spaces.
  • D. ExpressRoute connects on-premises networks to Azure, not VNet to VNet with overlapping IPs.

VNet Connectivity with Overlapping IPs

When Azure Virtual Networks have overlapping IP address spaces, VNet Peering is not possible, and a VPN Gateway with NAT functionality is required to enable communication.

  • VNet Peering requires non-overlapping IP spaces.
  • VPN Gateway can use NAT for overlapping IP spaces.
  • NAT translates addresses to avoid conflicts.
  • Crucial for multi-region or multi-subscription connectivity.

Memory trick: Peering is simple, VPN handles overlaps, ExpressRoute is dedicated, Virtual WAN is global hub.

More Implement and manage virtual networking questions