Microsoft Certified: Azure Administrator AssociateImplement and manage virtual networkingMedium

A client has an Azure Virtual Network (VNet) named 'VNetProd' in the 'East US' region. They need to establish a secure, site-to-site VPN connection between 'VNetProd' and their on-premises data center. The on-premises VPN device supports IKEv2 and BGP. Which Azure networking gateway type should you create to facilitate this connection?

  1. AExpressRoute Gateway - Standard SKU
  2. BVPN Gateway - VpnGw1 SKU
  3. CApplication Gateway - WAF_v2 SKU
  4. DVPN Gateway - Basic SKU
Show answer & explanation

Correct answer: B. VPN Gateway - VpnGw1 SKU

For a site-to-site VPN connection supporting BGP, you need a VPN Gateway with a SKU that supports BGP. The Basic SKU does not support BGP, whereas VpnGw1 and higher SKUs do. ExpressRoute Gateway is for ExpressRoute circuits, and Application Gateway is for web traffic load balancing.

Why the other options are wrong

  • A. ExpressRoute Gateway is used for connecting to an ExpressRoute circuit, not for site-to-site VPN connections.
  • C. Application Gateway is a Layer 7 load balancer for web traffic and is not used for VPN connectivity.
  • D. The Basic SKU for VPN Gateway does not support BGP, which is a requirement for this scenario.

Azure VPN Gateway SKUs

Different performance and feature tiers for Azure VPN Gateways, offering varying bandwidth, tunnel limits, and BGP support.

  • Basic SKU is the lowest cost but lacks BGP and Zone Redundancy.
  • VpnGw1-5 SKUs provide increasing bandwidth and tunnel capacity.
  • All VpnGw1+ SKUs support BGP and active-active configurations.

Memory trick: Connect to Cloud: VPN Gateway is your secure bridge.

More Implement and manage virtual networking questions