Module 5
Module 5
Azure Administrator
Contents
Module 5 Intersite Connectivity
In this module, you will learn about intersite connectivity features including VNet
Peering, Virtual Network Gateways, and VPN Gateway Connections.
4
AZ-900
Contents
Module 5 Intersite Connectivity
This module includes:
● VNet Peering
● VPN Gateway Connections
● ExpressRoute and Virtual WAN
● Lab 05 - Implement Intersite Connectivity
5
AZ-900
VNet Peering
Perhaps the simplest and quickest way to connect your VNets is to use VNet
peering.
Virtual network peering enables you to seamlessly connect two Azure virtual
networks.
VNet Peering
There are two types of VNet peering.
● Regional VNet peering connects Azure virtual networks in the same region.
● Global VNet peering connects Azure virtual networks in different regions.
Azure public cloud region is not peering with Government cloud regions.
Service Chaining
VNet Peering is nontransitive. This means that if you establish VNet Peering
between VNet1 and VNet2 and between VNet2 and VNet3, VNet Peering
capabilities do not apply between VNet1 and VNet3.
you can leverage user-defined routes and service chaining to implement custom
routing that will provide transitivity.
This allows you to:
● Implement a multi-level hub and spoke architecture.
● Overcome the limit on the number of VNet Peerings per virtual network.
Active/standby
The switch over will cause a brief interruption.
For planned maintenance, the connectivity should be
restored within 10 to 15 seconds.
For unplanned issues, the connection recovery will be
longer, about 1 minute to 1 and a half minutes in the
worst case.
Active/standby
For P2S VPN client connections to the gateway, the P2S connections will be
disconnected and the users will need to reconnect from the client machines.
Active/active
You can now create an Azure VPN gateway in an active-
active configuration, where both instances of the
gateway VMs will establish S2S VPN tunnels to your on-
premises VPN device.
each Azure gateway instance will have a unique public IP
address, and each will establish an IPsec/IKE S2S VPN
tunnel to your on-premises VPN device specified in your
local network gateway and connection.
Active/active
both VPN tunnels are actually part of the same
connection.
configure your on-premises VPN device to accept or
establish two S2S VPN tunnels to those two Azure VPN
gateway public IP addresses.
Because the Azure gateway instances are in active-active
configuration, the traffic from your Azure virtual network
to your on-premises network will be routed through both
tunnels simultaneously.
ExpressRoute Connections
Azure ExpressRoute lets you extend your on-premises networks into the
Microsoft cloud over a dedicated private connection facilitated by a
connectivity provider.
With ExpressRoute, you can establish connections to Microsoft cloud services,
such as Microsoft Azure, Office 365, and CRM Online.
ExpressRoute Capabilities
ExpressRoute is supported across all Azure regions and locations.
ExpressRoute locations refer to those where Microsoft peers with several service
providers.
ExpressRoute benefits
Layer 3 connectivity: Microsoft uses BGP, an industry standard dynamic
routing protocol, to exchange routes between your on-premises network, your
instances in Azure, and Microsoft public addresses.
Redundancy: Each ExpressRoute circuit consists of two connections to two
Microsoft Enterprise edge routers (MSEEs) from the connectivity provider/your
network edge.
ExpressRoute benefits
Connectivity to Microsoft cloud services: ExpressRoute connections enable
access to the following services: Microsoft Azure services, Microsoft Office 365
services, and Microsoft Dynamics 365.
Connectivity to all regions within a geopolitical region: You can connect to
Microsoft in one of our peering locations and access regions within the
geopolitical region.
Global connectivity with ExpressRoute premium add-on: You can enable
the ExpressRoute premium add-on feature to extend connectivity across
geopolitical boundaries.
ExpressRoute benefits
Across on-premises connectivity with ExpressRoute Global Reach: You can
enable ExpressRoute Global Reach to exchange data across your on-premises
sites by connecting your ExpressRoute circuits.
ExpressRoute benefits
Bandwidth options: You can purchase ExpressRoute circuits for a wide range of
bandwidths from 50 Mbps to 10 Gbps.
Flexible billing models: You can pick a billing model that works best for you. Choose
between the billing models listed below.
● Unlimited data. all inbound and outbound data transfer is included free of charge.
● Metered data. Outbound data transfer is charged per GB of data transfer. Data
transfer rates vary by region.
● ExpressRoute premium add-on. This add-on includes increased routing table
limits, increased number of VNets, global connectivity, and connections to Office 365
and Dynamics 365.
Virtual WANs
Azure Virtual WAN brings together many Azure cloud connectivity services such as
site-to-site VPN, User VPN (point-to-site), and ExpressRoute into a single
operational interface.
Module 05 Lab
Lab 05 - Implement Virtual Networking
Objectives
In this lab, you will:
● Task 1: Provision the lab environment.
● Task 2: Configure local and global virtual network peering.
● Task 3: Test intersite connectivity.
Thanks!
Any questions?
You can find me at:
[email protected]
+93 784670845
67