A company has two datacenters, each with redundant VPN devices. They require highly available active-active VPN termination in an Azure hub VNet with dynamic routing. They plan to add ExpressRoute later, using ExpressRoute as primary and keeping VPN as failover, all on the same hub. What gateway design should you recommend?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy a VpnGw2AZ VPN gateway in active-active configuration with BGP to both sites. Later, add an ExpressRoute gateway (ErGw2AZ) in the same VNet to enable coexistence and prefer ExpressRoute via BGP metrics..
Why this is the answer
The VpnGw2AZ SKU supports active-active VPN connections with BGP, which is essential for dynamic routing and high availability to both datacenters. This SKU also supports coexistence with an ExpressRoute gateway (ErGw2AZ) in the same VNet, allowing for a seamless transition to ExpressRoute as the primary connection. BGP metrics can then be used to prefer ExpressRoute. Basic VPN gateways do not support BGP or active-active configurations, nor do they support coexistence with ExpressRoute in the same VNet. Single-instance gateways lack high availability. VpnGw5 without BGP doesn't meet the dynamic routing requirement, and FastPath is a feature, not a gateway type for coexistence. Azure Virtual WAN Basic hub doesn't support ExpressRoute and VPN coexistence; Standard hub is required for that.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed