Designing and implementing the core network
- Planning IP addressing: segmentation, address spaces, virtual networks and subnets
- Subnets for gateways, private endpoints, service endpoints, firewall, Application Gateway and Azure Bastion
- Public IP addresses and IP prefixes, including with your own address ranges
- Name resolution: public and private DNS zones, Azure DNS Private Resolver
- Connectivity and routing: VNet peering, Azure Virtual Network Manager, user-defined routes, forced tunneling, Route Server, NAT Gateway
- Monitoring with Network Watcher, Azure Monitor for Networks and DDoS protection
Connectivity services
- Site-to-site VPN: choosing a gateway SKU, IPsec/IKE policies, local network gateway, high availability, troubleshooting
- Point-to-site VPN: tunnel type, authentication via RADIUS or Microsoft Entra ID, client configuration
- ExpressRoute: connectivity model and SKU, private peering and Microsoft peering, Global Reach, FastPath, ExpressRoute Direct, encryption
- Azure Virtual WAN: architecture, virtual hubs, gateways, hub routing, connecting third-party appliances
Application delivery
- Azure Load Balancer and Traffic Manager: SKU and tier, public or internal, regional or cross-regional, rules and NAT
- Application Gateway: backend pools, health probes, listeners, routing rules, TLS, rewrite rules
- Azure Front Door: tier, routing, origins and endpoints, TLS termination, caching, URL rewrite and redirect
Private access to Azure services
- Planning, creating and connecting Private Link and private endpoints with DNS
- Connecting Private Link services to on-premises clients
- Service endpoints and service endpoint policies
Network security
- Network security groups and application security groups, evaluating flow logs, checking IP flow
- Azure Firewall and Firewall Manager: SKU, rules, policies, Secure Hub in Virtual WAN
- Web Application Firewall on Front Door and Application Gateway: detection and prevention mode, rule sets, policies