On-premises clients connect to an app by using the pod IP addresses in an AKS cluster. Which AKS networking option should you choose so on-premises clients can reach pod IPs directly?
Choose an answer
Tap an option to check your answer.
Correct answer: Azure Container Networking Interface (CNI).
Why this is the answer
Azure Container Networking Interface (CNI) assigns a unique IP address to each pod, directly from the Azure Virtual Network subnet. This allows on-premises clients, if connected to the same virtual network via VPN or ExpressRoute, to directly reach the pod IP addresses. Kubenet uses a separate, private IP address range for pods, and Network Address Translation (NAT) is used to translate pod IPs to node IPs for external communication. This prevents direct pod IP access from on-premises. Hybrid Connection endpoints are for connecting Azure App Services to on-premises resources, not for direct pod IP access in AKS. Azure Private Link provides private connectivity to Azure services over a private endpoint, not direct pod IP access within an AKS cluster for on-premises clients.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed