You have a Site-to-Site VPN (no BGP) between on-premises and an Azure VPN gateway. Vnet1 had Subnet1 with Server1 reachable from on-premises. You extended Vnet1’s address space, added Subnet2 (in the new range) and deployed Server2 to Subnet2. Server1 can reach Server2, but on-premises cannot. What must you do so on-premises can reach Subnet2?
Choose an answer
Tap an option to check your answer.
Correct answer: Update the routing information on the on-premises routers..
Why this is the answer
The correct answer is to update the routing information on the on-premises routers. When you extend a virtual network's address space and add new subnets, the on-premises VPN device needs to be aware of these new address ranges to route traffic correctly through the existing Site-to-Site VPN tunnel. Without BGP, routing updates are not automatic. Adding an additional Site-to-Site VPN is unnecessary and complex, as the existing tunnel can carry traffic for the extended address space. Adding a private endpoint is for securely accessing Azure services, not for enabling on-premises connectivity to a new subnet within a VNet. Adding a route table to Subnet2 is not the primary issue; the problem lies with the on-premises network not knowing how to reach Subnet2.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed