AZ-700 exam dumps

AZ-700 practice question 95 of 310

Designing and Implementing Microsoft Azure Networking Solutions. Professional level, Microsoft. Free question with the correct answer and a full explanation.

AZ-700 Question 95

Select 3

You recently changed the IP ranges in your on-premises environment, and now your site-to-site VPN connection to Azure is failing. The Azure VPN Gateway status shows 'Connected', but no traffic traverses the tunnel. Diagnostics indicate an established IPsec tunnel, yet routing tests fail. Which of the following actions should you take to restore connectivity?

  1. A

    Add the new on-premises subnet range to the local network gateway� address space in Azure

  2. B

    Switch to a policy-based VPN configuration for improved route management

  3. C

    Update the on-premises firewall rules to allow traffic from the newly assigned subnet range

  4. D

    Enable BGP on the Azure VPN gateway to automatically learn the new subnet range

  5. E

    Reset the VPN gateway from the Azure portal to ensure configuration updates are applied

Show answer and explanation

Correct answers: A, C, E

Explanation

When changing your on-premises network IP configuration, you must update the local network gateway� address space in Azure so the VPN tunnel knows which subnets to route. Additionally, your on-premises firewall must allow traffic from the new subnets. If configurations do not propagate, resetting the Azure VPN gateway can help. For reference, see Microsoft� documentation on Troubleshoot Azure VPN gateways: https://learn.microsoft.com/azure/vpn-gateway/vpn-gateway-troubleshoot-site-to-site-cannot-connect.

  • A. Correct.

    Correct. If the local network gateway� address space does not include your new on-premises subnet range, traffic will not be routed correctly. Adding the missing subnet range is a crucial troubleshooting step, per Microsoft documentation.

  • B. Incorrect.

    Incorrect. Policy-based VPNs use static IPsec tunnels and require manual updates for address changes. Route-based VPNs are generally more flexible for dynamic changes and are recommended for most Azure VPN scenarios.

  • C. Correct.

    Correct. The on-premises firewall must allow traffic from the newly added subnet range. If the firewall is not configured correctly, traffic will be dropped despite the tunnel showing as 'Connected.'

  • D. Incorrect.

    Incorrect. Enabling BGP is only necessary if you require dynamic routing between your on-premises infrastructure and Azure. Simply enabling BGP will not resolve missing or incorrect address space configurations in this scenario.

  • E. Correct.

    Correct. After updating the local network gateway settings, a gateway reset can help ensure the tunnel renegotiates with current configuration parameters. While not always mandatory, a reset is a recognized troubleshooting step if routes do not apply correctly.

Timed practice exam

Take a AZ-700 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam