AZ-700 exam dumps

AZ-700 practice question 107 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 107

Single answer

Contoso has configured an Azure VPN Gateway to allow remote employees to connect via Point-to-Site (P2S) VPN. They have chosen RADIUS authentication and set up a Windows Server with Network Policy Server (NPS) on-premises to handle incoming requests. However, users report that they cannot connect, and the NPS logs show no sign of incoming RADIUS traffic from Azure. Which action should you take to ensure that RADIUS authentication requests from the Azure VPN Gateway successfully reach the on-premises NPS server?

  1. A

    Configure an inbound firewall rule allowing TCP port 443 from all Azure subnets to the NPS server.

  2. B

    Use a Site-to-Site or ExpressRoute connection with appropriate firewall rules open for UDP 1812 (authentication) and UDP 1813 (accounting).

  3. C

    Enable logging on the Azure VPN Gateway and reconfigure it to send RADIUS requests over the Azure backbone network only.

  4. D

    Configure a new Azure Virtual WAN and link it to the on-premises network to secure RADIUS communication end to end.

Show answer and explanation

Correct answer: B

Explanation

To configure RADIUS authentication successfully in Azure for an on-premises NPS, ensure that the RADIUS requests can travel over a secure connection (Site-to-Site VPN or ExpressRoute) and that the appropriate UDP ports (1812 and 1813) are open on any intermediary firewalls or Network Security Groups (NSGs). Refer to Microsoft documentation on 'Integrate RADIUS authentication with Azure VPN gateways' for best practices and required port configurations.

  • A. Incorrect.

    Option 1 is incorrect. While TCP 443 is often used for secure web traffic (HTTPS), RADIUS authentication typically uses UDP ports 1812 and 1813 by default. Opening TCP 443 alone would not allow RADIUS packets through.

  • B. Correct.

    Option 2 is correct. RADIUS traffic must traverse a secure tunnel (e.g., Site-to-Site VPN or ExpressRoute) from Azure to the on-premises data center, and UDP ports 1812 (authentication) and 1813 (accounting) must be allowed through the firewall. This setup ensures the Azure VPN Gateway can communicate with the on-premises NPS server.

  • C. Incorrect.

    Option 3 is incorrect. Simply enabling logging on the Azure VPN Gateway and sending RADIUS requests over the Azure backbone doesn�t address the need for a secure, configurable tunnel or correct firewall rules to pass UDP-based RADIUS traffic to the on-premises server.

  • D. Incorrect.

    Option 4 is incorrect. Configuring a new Azure Virtual WAN might be an option for complex connectivity scenarios, but it� unnecessary if you already have a Site-to-Site VPN or ExpressRoute. RADIUS traffic still requires properly opened firewall rules for UDP 1812 and 1813.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam