Fabrikam runs multiple third-party network virtual appliances (NVAs) in an availability set to perform stateful inspection. Each NVA needs to receive the original destination TCP port for many concurrent sessions (not one-to-one NAT port translations). Which Azure Load Balancer feature should Fabrikam enable to support full-port, many-to-one NAT to the NVAs for high availability?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable an inbound load-balancing rule with HA Ports (All ports) on a Standard Load Balancer so the LB forwards all ports to the NVA backend IPs..
Why this is the answer
The correct answer is to enable an inbound load-balancing rule with HA Ports (All ports) on a Standard Load Balancer. HA Ports allow a Standard Load Balancer to load-balance traffic on all TCP and UDP ports simultaneously. This is crucial for stateful NVAs that need to see the original destination port for many concurrent sessions, enabling full-port, many-to-one NAT. This approach ensures high availability as the load balancer distributes traffic across healthy NVA instances. Using a Public Load Balancer with Floating IP disabled and individual rules would not scale for "all ports" and "many concurrent sessions." An Application Gateway v2 is a Layer 7 load balancer and is not suitable for stateful inspection across all ports. Azure NAT Gateway is for outbound connections and does not preserve original destination ports for inbound traffic to backend instances.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed