Introduction |
|
xii | |
Organization of this book |
|
xii | |
Microsoft certifications |
|
xii | |
Errata, updates, and book support |
|
xiii | |
Stay in touch |
|
xiii | |
|
Chapter 1 Design, implement, and manage hybrid networking |
|
|
1 | (50) |
|
Skill 1.1 Design, implement, and manage a site-to-site VPN connection |
|
|
1 | (19) |
|
Design a site-to-site VPN connection for high availability |
|
|
2 | (2) |
|
Select an appropriate virtual network gateway SKU |
|
|
4 | (1) |
|
Identify when to use policy-based VPN versus route-based VPN |
|
|
5 | (1) |
|
Create and configure a local network gateway |
|
|
6 | (1) |
|
Create and configure a virtual network gateway |
|
|
7 | (4) |
|
Create and configure an IPsec/IKE policy |
|
|
11 | (3) |
|
Diagnose and resolve VPN gateway connectivity issues |
|
|
14 | (6) |
|
Skill 1.2 Design, implement, and manage a point-to-site VPN connection |
|
|
20 | (11) |
|
Select an appropriate virtual network gateway SKU |
|
|
21 | (1) |
|
Plan and configure RADIUS authentication |
|
|
22 | (2) |
|
Plan and configure certificate-based authentication |
|
|
24 | (2) |
|
Plan and configure Azure Active Directory (Azure AD) authentication |
|
|
26 | (2) |
|
Implement a VPN client configuration file |
|
|
28 | (2) |
|
Diagnose and resolve client-side and authentication issues |
|
|
30 | (1) |
|
Skill 1.3 Design, implement, and manage Azure ExpressRoute |
|
|
31 | (20) |
|
Choose between provider and direct model (ExpressRoute Direct) |
|
|
32 | (1) |
|
Design and implement Azure cross-region connectivity between multiple ExpressRoute locations |
|
|
33 | (1) |
|
Select an appropriate ExpressRoute SKU and tier |
|
|
34 | (1) |
|
Design and implement ExpressRoute Global Reach |
|
|
35 | (2) |
|
Design and implement ExpressRoute FastPath |
|
|
37 | (1) |
|
Choose between private peering only, Microsoft peering only, or both |
|
|
38 | (1) |
|
Configure private peering |
|
|
39 | (1) |
|
Configure Microsoft peering |
|
|
40 | (1) |
|
Create and configure an ExpressRoute gateway |
|
|
41 | (1) |
|
Connect a virtual network to an ExpressRoute circuit |
|
|
42 | (1) |
|
Recommend a route advertisement configuration |
|
|
43 | (1) |
|
Configure encryption over ExpressRoute |
|
|
44 | (1) |
|
Implement Bidirectional Forwarding Detection |
|
|
45 | (1) |
|
Diagnose and resolve ExpressRoute connection issues |
|
|
46 | (1) |
|
|
46 | (1) |
|
|
47 | (1) |
|
Thought experiment answers |
|
|
48 | (3) |
|
Chapter 2 Design and implement core networking infrastructure |
|
|
51 | (40) |
|
Skill 2.1 Design and implement private IP addressing for virtual networks |
|
|
51 | (9) |
|
|
52 | (2) |
|
Plan and configure subnetting for services |
|
|
54 | (5) |
|
Plan and configure subnet delegation |
|
|
59 | (1) |
|
Plan and configure subnetting for Azure Route Server |
|
|
60 | (1) |
|
Skill 2.2 Design and implement name resolution |
|
|
60 | (8) |
|
|
61 | (2) |
|
|
63 | (2) |
|
Design name resolution inside a virtual network |
|
|
65 | (1) |
|
Configure a public or private DNS zone |
|
|
66 | (1) |
|
Link a private DNS zone to a virtual network |
|
|
67 | (1) |
|
Skill 2.3 Design and implement cross-VNet connectivity |
|
|
68 | (6) |
|
Implement virtual network peering |
|
|
69 | (3) |
|
Design service chaining, including gateway transit |
|
|
72 | (2) |
|
Design VPN connectivity between virtual networks |
|
|
74 | (1) |
|
Skill 2.4 Design and implement an Azure Virtual WAN architecture |
|
|
74 | (17) |
|
Design an Azure Virtual WAN architecture, including selecting SKUs and services |
|
|
75 | (2) |
|
Create a hub in Virtual WAN |
|
|
77 | (1) |
|
Connect a virtual network gateway to Azure Virtual WAN |
|
|
78 | (5) |
|
Create a network virtual appliance in a virtual hub |
|
|
83 | (2) |
|
Configure virtual hub routing |
|
|
85 | (3) |
|
|
88 | (1) |
|
|
89 | (1) |
|
Thought experiment answers |
|
|
90 | (1) |
|
Chapter 3 Design and implement routing |
|
|
91 | (68) |
|
Skill 3.1 Design, implement, and manage virtual network routing |
|
|
91 | (9) |
|
Design and implement user-defined routes |
|
|
92 | (3) |
|
Associate a route table with a subnet |
|
|
95 | (2) |
|
Configure forced tunneling |
|
|
97 | (1) |
|
Diagnose and resolve routing issues |
|
|
97 | (3) |
|
Skill 3.2 Design and implement an Azure load balancer |
|
|
100 | (13) |
|
Choose an Azure Load Balancer SKU |
|
|
101 | (1) |
|
Choose between public and internal |
|
|
102 | (1) |
|
Create and configure an Azure load balancer |
|
|
102 | (4) |
|
Implement a load balancing rule |
|
|
106 | (4) |
|
Create and configure inbound NAT rules |
|
|
110 | (2) |
|
Create explicit outbound rules for a load balancer |
|
|
112 | (1) |
|
Skill 3.3 Design and implement Azure Application Gateway |
|
|
113 | (21) |
|
Recommend Azure Application Gateway deployment options |
|
|
114 | (1) |
|
Choose between manual and autoscale |
|
|
115 | (5) |
|
|
120 | (2) |
|
|
122 | (1) |
|
|
123 | (2) |
|
|
125 | (1) |
|
|
126 | (2) |
|
Configure Transport Layer Security (TLS) |
|
|
128 | (3) |
|
Configure rewrite policies |
|
|
131 | (3) |
|
Skill 3.4 Implement Azure Front Door |
|
|
134 | (11) |
|
Choose an Azure Front Door SKU |
|
|
134 | (3) |
|
|
137 | (1) |
|
Configure SSL termination and end-to-end SSL encryption |
|
|
138 | (5) |
|
Configure multisite listeners and configure backend targets |
|
|
143 | (1) |
|
|
143 | (2) |
|
Skill 3.5 Implement an Azure Traffic Manager profile |
|
|
145 | (5) |
|
Configure a routing method |
|
|
145 | (2) |
|
|
147 | (2) |
|
|
149 | (1) |
|
Skill 3.6 Design and implement an Azure Virtual Network NAT |
|
|
150 | (9) |
|
Choose when to use a Virtual Network NAT |
|
|
150 | (1) |
|
Allocate public IP addresses for a NAT gateway |
|
|
151 | (2) |
|
Associate a virtual network NAT with a subnet |
|
|
153 | (1) |
|
|
154 | (1) |
|
|
155 | (1) |
|
Thought experiment answers |
|
|
156 | (3) |
|
Chapter 4 Secure and monitor networks |
|
|
159 | (44) |
|
Skill 4.1 Design, implement, and manage an Azure Firewall deployment |
|
|
159 | (12) |
|
Design an Azure Firewall deployment |
|
|
160 | (1) |
|
Create and implement an Azure Firewall deployment |
|
|
161 | (2) |
|
Configure Azure Firewall rules |
|
|
163 | (3) |
|
Create and implement Azure Firewall Manager policies |
|
|
166 | (3) |
|
Create a secure hub by deploying Azure Firewall inside an Azure Virtual WAN hub |
|
|
169 | (2) |
|
Skill 4.2 Implement and manage network security groups (NSGs) |
|
|
171 | (13) |
|
Create a network security group |
|
|
172 | (1) |
|
Associate an NSG to a resource |
|
|
173 | (2) |
|
Create an application security group (ASG) |
|
|
175 | (1) |
|
Associate an ASG to a NIC |
|
|
176 | (1) |
|
Create and configure NSG rules |
|
|
177 | (3) |
|
Interpret and validate NSG flow logs |
|
|
180 | (2) |
|
|
182 | (2) |
|
Skill 4.3 Implement a Web Application Firewall (WAF) deployment |
|
|
184 | (5) |
|
|
184 | (4) |
|
|
188 | (1) |
|
Skill 4.4 Monitor networks |
|
|
189 | (14) |
|
Configure network health alerts and logging by using Azure Monitor |
|
|
190 | (4) |
|
Create and configure a Connection Monitor instance |
|
|
194 | (3) |
|
Configure and use Traffic Analytics |
|
|
197 | (1) |
|
Enable and configure diagnostic logging |
|
|
198 | (1) |
|
Configure Azure Network Watcher |
|
|
199 | (1) |
|
|
200 | (1) |
|
|
201 | (1) |
|
Thought experiment answers |
|
|
202 | (1) |
|
Chapter 5 Design and implement private access to Azure services |
|
|
203 | (22) |
|
Skill 5.1 Design and implement Azure Private Link service and private endpoints |
|
|
203 | (10) |
|
Create a Private Link service |
|
|
204 | (3) |
|
Plan and create private endpoints |
|
|
207 | (4) |
|
Integrate Private Link with DNS |
|
|
211 | (1) |
|
Integrate a Private Link service with on-premises clients |
|
|
211 | (2) |
|
Skill 5.2 Design and implement service endpoints |
|
|
213 | (5) |
|
|
213 | (2) |
|
Configure service endpoint policies |
|
|
215 | (3) |
|
|
218 | (1) |
|
Skill 5.3 Configure VNet integration for dedicated platform as a service (PaaS) services |
|
|
218 | (7) |
|
Configure App Service for regional VNet integration |
|
|
218 | (2) |
|
Configure Azure Kubernetes Service (AKS) for regional VNet integration |
|
|
220 | (1) |
|
Configure clients to access App Service Environment |
|
|
221 | (1) |
|
|
222 | (1) |
|
|
223 | (1) |
|
Thought experiment answers |
|
|
224 | (1) |
Index |
|
225 | |