GlobalLogistics needs to insert a third-party NVA (virtual appliance) into their Virtual WAN transit to perform deep packet inspection for spoke-to-spoke traffic. They plan to use an NVA from the marketplace which requires a fixed private IP. How should they integrate the NVA so hub-transit traffic flows through it?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy the NVA as a virtual machine scale set in a VNet that is attached to the same Virtual WAN hub, add a static route in the hub route table that points the desired prefixes to the NVA's private IP, and associate the route table to the spokes that must use the NVA..
Why this is the answer
The correct approach is to deploy the NVA in a VNet attached to the Virtual WAN hub. By adding a static route in the hub's route table that directs traffic for specific prefixes (representing the spoke VNets requiring inspection) to the NVA's private IP, and then associating this route table with those spokes, you ensure that spoke-to-spoke traffic transits through the NVA. A Virtual Machine Scale Set provides high availability and scalability for the NVA. Deploying the NVA in a spoke VNet and using VNet peering is inefficient and complex for a hub-and-spoke model, as it requires managing numerous peerings. Azure Security Center is for security posture management, not for deploying and routing traffic through third-party NVAs. Azure Route Server is used for dynamic routing with BGP, but for a fixed private IP NVA in Virtual WAN, static routes are the direct and recommended method for traffic steering within the hub.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed