Question: 1/25
You are planning connectivity for SAP systems in Azure. The SAP application servers will be in a spoke VNet and must access an on-premises SAProuter over a private connection. You also want to minimize the chance of asymmetric routing. What is the recommended approach?
Deploy a VPN gateway in the spoke VNet and connect it directly to on-premises
Use a hub-and-spoke model and connect on-premises to the hub using ExpressRoute, then use VNet peering from hub to spoke with gateway transit
Use public IPs on the SAP application servers and restrict access with NSGs
Use Azure Traffic Manager to route SAP application traffic to on-premises SAProuter