VPN Gateway Flashcards
6 cards from real AZ-700 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 VPN Gateway flashcards as text
Which protocol must be used for Point-to-Site VPN when Azure AD authentication is selected?
Answer: OpenVPN
Azure AD authentication for P2S VPN is only supported with the OpenVPN protocol.
What is the function of BGP in Azure VPN Gateway?
Answer: Dynamically exchanges routes between Azure and on-premises networks
BGP enables dynamic route exchange between Azure VPN Gateway and on-premises BGP-capable devices, removing the need for static route management.
In an active-active VPN Gateway configuration, what is created to ensure high availability?
Answer: Two gateway instances each with their own public IP and BGP peer
Active-active mode deploys two gateway instances, each with its own public IP, establishing dual tunnels for redundancy.
Which IKE version does Azure VPN Gateway use by default for Route-based VPN connections?
Answer: IKEv2
Azure VPN Gateway defaults to IKEv2 for route-based VPN connections, though IKEv1 is supported for policy-based connections.
What Azure resource must be provisioned in the GatewaySubnet before deploying a VPN Gateway?
Answer: A public IP address resource
A Public IP address resource must be created and associated with the VPN Gateway before deployment.
What is the recommended GatewaySubnet CIDR size for a production VPN Gateway deployment to support future scaling?
Answer: /27 or larger
Microsoft recommends using /27 or larger for GatewaySubnet to accommodate additional gateway resources and future ExpressRoute coexistence.