Virtual networks, routing, hybrid connectivity, private access, DNS and load balancing.
Sections from the books on networking, free to read:
How many usable addresses each prefix gives in Azure, why five are always reserved, and how to size subnets for gateways, Bastion and VMs. AZ-700
The order Azure applies subnet and NIC network security groups for inbound and outbound traffic, how priority works, and a worked example. AZ-104
Rule order, the default rules, and what happens to a flow between subnets and to return traffic. AZ-700
Longest prefix match, system routes versus user-defined routes, and how a 0.0.0.0/0 route forces internet traffic on-premises. AZ-700
Where each peering setting goes, what spokes can reach, and why peering isn't transitive. AZ-700
What each ExpressRoute feature does, which SKUs and gateways it needs, and where it fits on a circuit. AZ-700
What a private endpoint puts in your subnet, how private DNS zones make names resolve to it, and when to choose it over a service endpoint. AZ-104
How private endpoints and service endpoints differ, and how to design private DNS for hybrid networks. AZ-305
The CNAME chain from a public service name to a private endpoint, zone groups and zone links. AZ-700
Resolving Azure private zones from on-premises and on-premises names from Azure, with subnet sizing and ruleset rules. AZ-700
A decision guide by traffic type (HTTP or not) and scope (regional or global). AZ-700
Choosing between Azure's global and regional, layer 4 and layer 7 load-balancing services. AZ-305
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow. SC-500
Search the series glossary for VNet, or browse all 2,575 terms.
Know where the traffic flows, and why.
Free with Kindle Unlimited
Know which role, setting or tool does the job, and why.
Free with Kindle Unlimited
Choose the right design, and explain why.
Free with Kindle Unlimited
Know which control enforces it, and why.
Free with Kindle Unlimited