Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium
A company has an existing Azure Virtual Network (VNet) named 'VNetHub' in a hub-spoke topology. A new spoke VNet, 'VNetSpoke01', needs to be connected to 'VNetHub' for seamless communication between resources in both VNets. This connection must be low-latency and high-bandwidth, and all traffic between the VNets should remain within the Microsoft backbone network. How should these two VNets be connected?
- ADeploy an Azure ExpressRoute circuit connecting 'VNetHub' and 'VNetSpoke01'.
- BEstablish a Site-to-Site VPN connection between 'VNetHub' and 'VNetSpoke01'.
- CCreate a Point-to-Site VPN connection from a VM in 'VNetSpoke01' to 'VNetHub'.
- DConfigure VNet peering between 'VNetHub' and 'VNetSpoke01'.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure VNet peering between 'VNetHub' and 'VNetSpoke01'.
VNet peering is the recommended method for connecting two Azure VNets directly. It provides low-latency, high-bandwidth communication, and traffic remains within the Microsoft backbone network, fulfilling all specified requirements.
Why the other options are wrong
- A. ExpressRoute connects on-premises networks to Azure, not directly two Azure VNets. While it uses the Microsoft backbone, it's not the correct service for VNet-to-VNet connection.
- B. Site-to-Site VPNs are primarily for connecting Azure VNets to on-premises networks, or for connecting VNets in different regions when peering isn't optimal, but adds VPN overhead.
- C. Point-to-Site VPNs connect individual client machines to an Azure VNet, not two VNets together.
VNet Peering
A mechanism to connect two Azure virtual networks, allowing resources in both VNets to communicate with each other directly using private IP addresses.
- Traffic stays within the Microsoft backbone network.
- Provides low-latency, high-bandwidth connectivity.
- Supports transitive routing if configured with a Network Virtual Appliance (NVA).
Memory trick: Peering for VNet-to-VNet, VPN for on-prem, ExpressRoute for dedicated on-prem.