Memory hook: A hybrid path needs non-overlapping addresses, compatible routing and tested redundancy.
Must remember
- Plan address space, subnet growth, gateway subnets and route limits. Use system routes, UDRs and BGP deliberately; longest-prefix matching precedes equal-prefix route-source preference. Network virtual appliances need IP forwarding and a valid return path.
- Site-to-site VPN connects networks over IPsec; point-to-site connects individual clients. Select gateway SKU, route-based/policy compatibility, authentication and protocols according to the scenario. Active-active designs and BGP can improve availability, but client/on-premises equipment must support the topology.
- ExpressRoute uses provider connectivity and peering to reach supported Microsoft services; private peering serves Azure private networking. It is not inherently end-to-end encrypted. ExpressRoute gateways, circuit bandwidth, provider paths and regional/global reach features have separate constraints.
- Design redundant circuits/locations where the availability requirement demands it. A single provider path can remain a common failure point. VPN backup needs suitable routes, capacity and failover testing; equal physical capacity does not guarantee equal application throughput.
- Virtual WAN supplies managed hub connectivity and routing capabilities. Hub route tables, associations, propagation and routing intent affect which traffic reaches firewalls or other networks. VNet peering gateway transit and use-remote-gateway settings solve a different topology and have compatibility constraints.
- Hybrid DNS uses Private Resolver inbound/outbound endpoints and forwarding rulesets or another supported resolver design. Link the correct private zones, prevent loops and permit required UDP/TCP traffic. Network connectivity alone does not share DNS resolution.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Remote users need individual VPN access | Point-to-site VPN. |
| Managed hub connectivity across branches/VNets | Virtual WAN when its routing/operating model fits. |
| Dedicated provider connectivity | ExpressRoute, with separate encryption and resilience decisions. |
Traps
- A second logical connection may share the same physical failure domain.
- BGP advertisements do not create all subnet/return routes automatically.
- Peering and Virtual WAN do not erase overlapping-address constraints.
Active recall
1. What should be checked before joining networks?
Address overlap, routing policy, bandwidth, DNS and security requirements.
2. Does ExpressRoute itself guarantee application TLS?
No. Application encryption and circuit connectivity are separate.
3. Why test VPN backup under load?
It may have different throughput, latency and routing convergence than the primary circuit.
4. What makes a UDR through an NVA usable?
A healthy forwarding appliance and coherent forward/return paths.
5. Which DNS component accepts hybrid queries into Azure resolution?
An appropriately configured Private Resolver inbound endpoint.