exam questions

Exam AZ-700 All Questions

View all questions & answers for the AZ-700 exam

Exam AZ-700 topic 9 question 1 discussion

Actual exam question from Microsoft's AZ-700
Question #: 1
Topic #: 9
[All AZ-700 Questions]

DRAG DROP -
You need to prepare Vnet1 for the deployment of an ExpressRoute gateway. The solution must meet the hybrid connectivity requirements and the business requirements.
Which three actions should you perform in sequence for Vnet1? To answer, move the appropriate actions from the list of actions to the answer.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Step 1: Delete the VPN GW1.
The existing VPN GW1 GatewaySubnet is too small with /29.
Users must be able to connect to Vnet1 by using a Point-to-Site (P2S) VPN when working remotely. Connections must be authenticated by Azure AD.
Litware wants to minimize costs whenever possible, as long as all other requirements are met.

Step 2: Create a VPN gateway by using Basic SKU.
Basic SKU is good enough.

Note -
The Basic gateway SKU does not support IKEv2 or RADIUS authentication. If you plan on having Mac clients connect to your virtual network, do not use the Basic
SKU.
Step 3: Set the subnet mask of Gateway Subnet to /27.
When you create the gateway subnet, you specify the number of IP addresses that the subnet contains. The number of IP addresses needed depends on the VPN gateway configuration that you want to create. Some configurations require more IP addresses than others. We [Microsoft] recommend that you create a gateway subnet that uses a /27 or /28.
It's best to specify /27 or larger (/26,/25 etc.). This allows enough IP addresses for future changes, such as adding an ExpressRoute gateway.
Reference:
https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-howto-point-to-site-resource-manager-portal

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 1 month ago
1. Delete VPN GW1. 2. Set the subnet mask of Gateway Subnet to /27. 3. Create a VPN gateway by using the VPN GW1 SKU. Basic VPN Gateway does not support P2S. If the gateway subnet is /29, you've to first delete the virtual network gateway and increase the gateway subnet size. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways https://docs.microsoft.com/en-us/azure/expressroute/how-to-configure-coexisting-gateway-portal
upvoted 27 times
[Removed]
1 year, 1 month ago
I agree, but basic VPN gateway does support P2S (SSTP Connections) but not P2S IKEv2/OpenVPN Connections. And openVPN is needed for AzureAD. So basic can't be used here
upvoted 5 times
...
...
Alessandro365
Highly Voted 1 year, 1 month ago
1. Delete VPN GW1. 2. Set the subnet mask of Gateway Subnet to /27. 3. Create a VPN gateway by using the VPN GW1 SKU. https://learn.microsoft.com/en-us/azure/expressroute/how-to-configure-coexisting-gateway-portal "To configure coexisting connections for an already existing VNet: 1- Delete the existing ExpressRoute or Site-to-site VPN gateway. 2 - Delete and recreate the GatewaySubnet to have prefix of /27 or shorter. 3- Configure a VNet with a Site-to-Site connection and then Configure the ExpressRoute gateway. 4 - Once the ExpressRoute gateway is deployed, you can link the virtual network to the ExpressRoute circuit."
upvoted 12 times
Prutser2
1 year ago
also to reaffirm VPN gateway type: ExpressRoute-VPN Gateway coexist configurations are not supported on the Basic SKU. as per https://learn.microsoft.com/en-us/azure/expressroute/how-to-configure-coexisting-gateway-portal s. so concur
upvoted 1 times
...
...
Apptech
Most Recent 7 months ago
About the Gateway Subnet: "When you're planning your gateway subnet size, refer to the documentation for the configuration that you're planning to create. For example, the ExpressRoute/VPN Gateway coexist configuration requires a larger gateway subnet than most other configurations. Further more, you may want to make sure your gateway subnet contains enough IP addresses to accommodate possible future configurations. While you can create a gateway subnet as small as /29, we recommend that you create a gateway subnet of /27 or larger (/27, /26 etc.). If you plan on connecting 16 ExpressRoute circuits to your gateway, you must create a gateway subnet of /26 or larger. If you're creating a dual stack gateway subnet, we recommend that you also use an IPv6 range of /64 or larger. This set up will accommodate most configurations." https://learn.microsoft.com/en-us/azure/expressroute/expressroute-about-virtual-network-gateways#gwsub
upvoted 1 times
...
sellamibassem
7 months, 3 weeks ago
Sorry. VPN GW basic sku should not work as we have Azure AD authentication
upvoted 1 times
...
sellamibassem
7 months, 3 weeks ago
VPN GW Basic sku is enough as we have only 10 devices.
upvoted 1 times
...
JennyHuang36
8 months, 1 week ago
In exam Feb 2023
upvoted 1 times
...
magikmarcus
9 months ago
Also as they need to auth on the VPN PS2 with Azure AD. It needs to be OpenVPN OpenVPN is not supported on basic SKU https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways#gwsku
upvoted 1 times
...
jellybiscuit
1 year, 1 month ago
Once you realize you need to resize the subnet, the first two should be obvious. 1) delete gw 2) set subnet mask 3) I personally went with the "what's there is probably fine" assumption, but as others have pointed out, Basic would not work. Sometimes you get lucky.
upvoted 4 times
...
smosmo
1 year, 1 month ago
Following this documentation Basic Gateway is not enough for P2S Connection, but there is no other option to choose. Any comments/ideas? Should we create based on the VPN GW 1 SKU instead?
upvoted 1 times
...
tdienst
1 year, 1 month ago
1. Delete GW1 2. Create VPN GW with GW1 SKU 3. Edit subnet mask to /27 ExpressRoute-VPN Gateway coexist configurations are not supported on the Basic SKU. https://docs.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpngateways although i feel that 2-3 are interchangable.
upvoted 5 times
...
Cristoicach91
1 year, 2 months ago
You need to prepare Vnet1 for the deployment of an ExpressRoute gateway. You need to have a standard SKU VPN gate for express route p2s and s2s.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago