Contoso Ltd. operates a hub virtual network in Azure that contains a third-party Palo Alto firewall NVA in the hub subnet. You deployed Azure Route Server in the hub and want the Palo Alto to dynamically exchange routes so the NVA can program routes into the UDRs for all spoke VNets. Which configuration on the Palo Alto is required to establish BGP peering with Azure Route Server and allow dynamic route exchange?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a BGP neighbor on the Palo Alto using one of the Route Server’s peering IP addresses (the private IP in the RouteServerSubnet), set the Palo Alto’s local ASN to a different ASN than the Route Server’s ASN (the peer ASN), and permit the learned routes to be installed into the firewall’s routing table..
Why this is the answer
The correct option describes the necessary BGP configuration for a Network Virtual Appliance (NVA) to peer with Azure Route Server. Azure Route Server uses BGP to exchange routes with NVAs. The NVA must be configured as a BGP neighbor, using one of the Route Server's peering IP addresses (private IPs within the RouteServerSubnet). Crucially, the NVA's local Autonomous System Number (ASN) must be different from the Route Server's ASN (which acts as the peer ASN for the NVA). Finally, the NVA must be configured to accept and install learned routes into its routing table. The first incorrect option suggests using the same ASN, which is incorrect for eBGP peering. The third option is incorrect because Azure Route Server peers with NVAs directly, not through a Virtual Network Gateway's public IP. The fourth option is incorrect because it disables BGP, preventing dynamic route exchange, and Azure Route Server does not learn static routes via "route propagation" in this context.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed