exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 4 question 30 discussion

Actual exam question from Microsoft's AZ-304
Question #: 30
Topic #: 4
[All AZ-304 Questions]

HOTSPOT -
Your company has two on-premises sites in New York and Los Angeles and Azure virtual networks in the East US Azure region and the West US Azure region.
Each on-premises site has Azure ExpressRoute Global Reach circuits to both regions.
You need to recommend a solution that meets the following requirements:
✑ Outbound traffic to the Internet from workloads hosted on the virtual networks must be routed through the closest available on-premises site.
✑ If an on-premises site fails, traffic from the workloads on the virtual networks to the Internet must reroute automatically to the other site.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Azurefox79
Highly Voted 3 years, 4 months ago
Both are BGP and heres why from the link provided in the answer it is clearly stated that UDRs are used for S2S VPN while BGP is used for Express Route. "Forced tunneling in Azure is configured using virtual network custom user-defined routes. Redirecting traffic to an on-premises site is expressed as a Default Route to the Azure VPN gateway." 2 paragrpahs down from that section: "ExpressRoute forced tunneling is not configured via this mechanism, but instead, is enabled by advertising a default route via the ExpressRoute BGP peering sessions. " Answer: BGP, BGP
upvoted 14 times
...
sapien45
Most Recent 2 years, 11 months ago
Using an ExpressRoute circuit will use the BPG routes to go out to the Internet. https://purple.telstra.com/blog/forced-tunnelling-azure#:~:text=Microsoft%20Azure%20offers%20a%20feature,connection%20or%20an%20ExpressRoute%20circuit. Microsoft does not support any router redundancy protocols (for example, HSRP, VRRP) for high availability configurations. We rely on a redundant pair of BGP sessions per peering for high availability. https://docs.microsoft.com/en-us/azure/expressroute/expressroute-routing
upvoted 4 times
nidhogg
2 years, 8 months ago
Those links were exactly what we needed, very valuable info. Thanks a lot! BGP for both.
upvoted 1 times
...
...
agente232
3 years, 4 months ago
answer: default routes, BGP when you are configuring BGP to force outbound connections to on premise you are changing BGP default routes, why default routes is not an option here? Default routes makes more sense to me than just saying BGP
upvoted 1 times
...
ducph
3 years, 5 months ago
The first Question should be BGP, as stated below ExpressRoute forced tunneling is not configured via this mechanism, but instead, is enabled by advertising a default route via the ExpressRoute BGP peering sessions. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm#requirements-and-considerations Question 2 is BGP also.
upvoted 3 times
sapien45
2 years, 11 months ago
You do not understand network infrastructure. Your link is about S2S VPN, question is about Expresseroute.
upvoted 1 times
...
...
leo_az300
3 years, 6 months ago
2nd question is BGP for sure, but I would choose User-Defined Route for 1st question. When we ensure Azure gateway is using BGP. An on-premises network gateway can exchange routes with an Azure virtual network gateway using the border gateway protocol (BGP). For expressroute, you must use BGP to advertise on-premises routes to the Microsoft Edge router. Do NOT be confused with this statement. It's traffic from on-prem to azure. You can use user-defined routes for forcing traffic from the Express Route to, for example, a Network Virtual Appliance. This one is for redirect traffic from Azure to on-prem then go to Internet. With the next hop type for the route with the 0.0.0.0/0 address prefix is Internet, the traffic will go to internet. ref: https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-udr-overview
upvoted 4 times
rdemontis
3 years, 5 months ago
ExpressRoute forced tunneling is not configured via this mechanism, but instead, is enabled by advertising a default route via the ExpressRoute BGP peering sessions. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm
upvoted 1 times
...
rdemontis
3 years, 4 months ago
User-defined routes are used to redirect traffic from the virtual appliance to other Azure Services (not to go out on internet): "To enable connectivity to other Azure services and infrastructure services, you must make sure one of the following items is in place: 1- Azure public peering is enabled to route traffic to public endpoints. 2- You use user-defined routing to allow internet connectivity for every subnet requiring Internet connectivity." https://social.msdn.microsoft.com/Forums/en-US/f0453dc6-a3e6-469e-b21a-23ca36af8dcf/forced-tunneling-for-expressroute?forum=WAVirtualMachinesVirtualNetwork
upvoted 1 times
...
...
waqas
3 years, 6 months ago
BGP for both
upvoted 1 times
...
syu31svc
3 years, 6 months ago
https://docs.microsoft.com/en-us/azure/expressroute/expressroute-routing Microsoft does not support any router redundancy protocols (for example, HSRP, VRRP) for high availability configurations. We rely on a redundant pair of BGP sessions per peering for high availability. BGP for both
upvoted 3 times
...
poplovic
3 years, 7 months ago
It was discussed before. https://www.examtopics.com/discussions/microsoft/view/6100-exam-az-301-topic-4-question-7-discussion/ The first one is BGP. check it out here https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm The link is about S-S VPN with forced tunnel. The UDR is used. But for ExpressRoute, URD could not be used. "ExpressRoute forced tunneling is not configured via this mechanism, but instead, is enabled by advertising a default route via the ExpressRoute BGP peering sessions. "
upvoted 4 times
sjai
3 years, 7 months ago
Forced tunneling in Azure is configured using virtual network custom user-defined routes. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-forced-tunneling-rm#requirements-and-considerations
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago