Subscription1 has VNet1 and VNet2. VNet1 has a VPN gateway (VPNGW1) using static routing and a site‑to‑site connection to on‑premises. Client1 (Windows 10) has a point‑to‑site connection to VNet1. VNet1 and VNet2 are peered. On‑premises can reach VNet2, but Client1 cannot reach VNet2. What should you do to allow Client1 to connect to VNet2?
Choose an answer
Tap an option to check your answer.
Correct answer: Download and re‑install the VPN client configuration package on Client1..
Why this is the answer
The correct answer is to download and re-install the VPN client configuration package on Client1. When VNet peering is configured and you want point-to-site (P2S) clients to access the peered VNet, the P2S VPN gateway needs to be aware of the peered network routes. This is achieved by enabling "Allow gateway transit" on the VNet containing the VPN gateway (VNet1 in this case) and then regenerating and reinstalling the VPN client configuration package. The new package contains the updated routing information for the peered VNet (VNet2), allowing Client1 to correctly route traffic to it. "Select Allow gateway transit on VNet1" is a necessary step, but it's not sufficient on its own; the client configuration must be updated. "Select Allow gateway transit on VNet2" is incorrect because gateway transit is configured on the VNet that has the gateway, not the peered VNet. "Enable BGP on VPNGW1" is not required for P2S clients to access a peered VNet; static routing is sufficient, and BGP is typically used for more complex routing scenarios with site-to-site connections.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed