Book description
Pass the AZ-700 exam effortlessly with this comprehensive guide to Azure networking, covering all aspects of architecting, implementing, and managing Azure virtual networks Purchase of the print or Kindle book includes a free PDF eBook
Key Features
- Create and deploy a secure Azure network and implement dynamic routing and hybrid connectivity
- Master Azure network design for performance, resilience, scalability, and security
- Enhance your practical skills with hands-on labs aligned to the AZ-700 Network Engineer certification
Book Description
Designing and Implementing Microsoft Azure Networking Solutions is a comprehensive guide that covers every aspect of the AZ-700 exam to help you fully prepare to take the certification exam.
Packed with essential information, this book is a valuable resource for Azure cloud professionals, helping you build practical skills to design and implement name resolution, VNet routing, cross-VNet connectivity, and hybrid network connectivity using the VPN Gateway and the ExpressRoute Gateway. It provides step-by-step instructions to design and implement an Azure Virtual WAN architecture for enterprise use cases.
Additionally, the book offers detailed guidance on network security design and implementation, application delivery services, private platform service connectivity, and monitoring networks in Azure. Throughout the book, you’ll find hands-on labs carefully integrated to align with the exam objectives of the Azure Network Engineer certification (AZ-700), complemented by practice questions at the end of each chapter, allowing you to test your knowledge.
By the end of this book, you’ll have mastered the fundamentals of Azure networking and be ready to take the AZ-700 exam.
What you will learn
- Recap the fundamentals of Azure networking
- Design and implement name resolution
- Implement cross-VNet and VNet internet connectivity
- Build site-to-site VPN connections using the VPN gateway
- Create an ExpressRoute connection
- Secure your network with Azure Firewall and network security groups
- Implement private access to Azure services
- Choose the right load balancing option for your network
Who this book is for
Whether you're an Azure network engineer or a professional looking to enhance your expertise in designing and implementing scalable and secure network solutions, this book is an invaluable resource. A basic understanding of cloud solutions will help you to get the most out of this book.
Table of contents
- Designing and Implementing Microsoft Azure Networking Solutions
- Contributors
- About the author
- About the reviewers
- Preface
- Part 1: Design and Implement Core Networking Infrastructure in Azure
-
Chapter 1: Azure Networking Fundamentals
- Technical requirements
- Understanding Azure VNet
- Planning Vnet naming
- Planning VNet location
- Planning Vnet IP address spaces
- Planning Vnet subnet segmentation
- Hands-on exercise – creating a single-stack VNet in Azure
- Hands-on exercise – creating a dual-stack VNet in Azure
- Understanding private IP address assignment for subnet workloads
- Hands-on exercise – determining the VM location and sizes for future exercises
- Hands-on exercise – exploring private IP assignments
- Hands-on exercise – cleaning up resources
- Summary
- Further reading
-
Chapter 2: Designing and Implementing Name Resolution
- Technical requirements
- A hands-on exercise – provisioning resources for the chapter’s exercises
- Name resolution scenarios and options
-
Internal name resolution scenarios and options
- Option 1 – Azure-provided name resolution
- A hands-on exercise – exploring Azure-provided name resolution
- Option 2 – customer-managed DNS servers
- A hands-on exercise – implementing a customer-managed DNS server
- Option 3 – Azure Private DNS
- A hands-on exercise – implementing Azure Private DNS
- Option 4 – Azure Private DNS Resolver and Azure Private DNS zones
- External name resolution scenarios and options
- A hands-on exercise – clean up resources
- Summary
- Further reading
- Chapter 3: Design, Implement, and Manage VNet Routing
-
Chapter 4: Design and Implement Cross-VNet Connectivity
- Technical requirements
- Understanding cross-VNet connectivity options
- Connecting VNets using VNet peering
- Connecting VNets using a VPN gateway connection
- Connecting VNets using a vWAN
- Hands-on exercise – provisioning resources for the chapter
- Hands-on exercise – implementing cross-region VNet connectivity using the vWAN
- Comparing the three cross-VNet connectivity options
- Hands-on exercise – clean up resources
- Summary
- Further reading
- Part 2: Design, Implement, and Manage Hybrid Networking
-
Chapter 5: Design and Implement Hybrid Network Connectivity with VPN Gateway
- Technical requirements
- Understanding Azure hybrid network connection options
- Hands-on exercise – provision resources for chapter exercises
-
Hands-on exercise: implement a BGP-enabled VPN connection in Azure
- Task 1: Create the gateway subnet
- Task 2: Deploy the VPN gateway into the subnet (with an existing public IP)
- Task 3: Create the local network gateway
- Task 4: Configure the VPN connection
- Task 5: Verify VPN connection status and BGP peering
- Task 6: Verify connectivity between the on-premises network and the Azure VNet
- Understanding point-to-site connections
- Hands-on exercise – implement a P2S VPN connection with Azure certificate authentication
- Troubleshoot Azure VPN Gateway using diagnostic logs
- Hands-on exercise – clean up resources
- Summary
-
Chapter 6: Designing and Implementing Hybrid Network Connectivity with the ExpressRoute Gateway
- Technical requirements
- Understanding what ExpressRoute is and its main use cases
- Understanding ExpressRoute components
- Deciding on an ExpressRoute connectivity model
- Selecting the right ExpressRoute circuit SKU
- Selecting the right ExpressRoute gateway SKU
- Improving data path performance with ExpressRoute FastPath
- Designing and implementing cross-network connectivity over ExpressRoute
- Understanding the implementation of encryption over ExpressRoute
- Understanding the implementation of BFD
-
Hands-on exercise – implementing an ExpressRoute gateway
- Task 1 – create a VNet and gateway subnet
- Task 2 – deploy the ExpressRoute VNet gateway service
- Task 3 – create and provision an ExpressRoute circuit
- Task 4 – retrieve your service key (you need to send this to your SP)
- Task 5 – check serviceProviderProvisioningState status
- Task 6 – connect the ExpressRoute gateway to the ExpressRoute circuit
- Task 7 – deprovision an ExpressRoute circuit
- Task 8 – clean up resources
- Summary
-
Chapter 7: Design and Implement Hybrid Network Connectivity with Virtual WAN
- Technical requirements
- Designing a scalable network topology in Azure
- Understanding the design considerations of a vWAN hub
- Understanding the routing and SD-WAN configuration in a virtual hub
- Hands-on exercise 1 – provision resources for chapter exercises
- Configuring Site-to-Site connectivity using VWAN
-
Hands-on exercise 2 – implement site-to-site VPN connectivity using VWAN
- Task 1 – add a site-to-site gateway to VWAN
- Task 2 – create a VPN site in VWAN
- Task 3 – connect the VPN site to a VWAN hub
- Task 4 – obtain VPN configuration information
- Task 5 – configure the “on-premises” VPN device
- Task 6 – verify routes and connectivity to the “on-premises” site through VWAN
- Task 7 – clean up the resources
- Implementing a global transit network architecture using VWAN
- Understanding the security considerations of a virtual hub
- Summary
- Further reading
-
Chapter 8: Designing and Implementing Network Security
- Technical requirements
- Securing the Azure virtual network perimeter
- Implementing DDoS protection
- Hands-on exercise 1 – provisioning resources for Chapter 8’s exercises
-
Hands-on exercise 2 – implementing DDoS Protection, monitoring, and validation
- Task 1 – creating a DDoS Protection plan
- Task 2 – enabling DDoS Protection on a virtual network
- Task 3 – reviewing DDoS metrics for telemetry
- Task 4 – configure DDoS diagnostic logs forwarding
- Task 5 – configuring DDoS alerts
- Task 6 – creating a BreakingPoint Cloud account and authorizing your Azure subscription
- Task 7 – running a DDoS Test
- Task 8 – reviewing DDoS test results
- Implementing Azure Firewall
- Hands-on exercise 3 – deploying Azure Firewall into a VNet and a Virtual WAN Hub
- Implementing a WAF in Azure
- Implementing central management with Firewall Manager
- Summary
- Further reading
- Part 3: Design and Implement Traffic Management and Network Monitoring
-
Chapter 9: Designing and Implementing Application Delivery Services
- Technical requirements
- Understanding Azure’s load-balancing and application delivery services
- Designing and implementing an Azure Load Balancer service
- Designing and implementing an Azure Application Gateway service
- Designing and implementing an Azure Front Door load balancer service
- Designing and implementing an Azure Traffic Manager service
- Choosing an optimal load-balancing and application delivery solution
- Summary
-
Chapter 10: Designing and Implementing Platform Service Connectivity
- Technical requirements
-
Implementing platform service network security
- Understanding the platform service firewall and its exceptions
- Understanding service endpoints
- Hands-on exercise 1 – provisioning the resources for this chapter’s exercises
- Hands-on exercise 2 – configuring service endpoints for a storage account
- Designing and implementing Azure Private Link and Azure private endpoints
- Hands-on exercise 3 – configuring an Azure private endpoint for an Azure WebApp
- Summary
- Further reading
-
Chapter 11: Monitoring Networks in Azure
- Technical requirements
- Introducing Azure Network Watcher for monitoring, network diagnostics, and logs
- Understanding the network monitoring tools of Network Watcher
- Understanding the Network diagnostic tools of Network Watcher
- Hands-on exercise 1 – provisioning the resources for the chapter's exercises
- Hands-on exercise 2 – implementing the network monitoring tools of Network Watcher
- Understanding NSG flow logs
- Hands-on exercise 3 – enabling NSG flow logs
- Summary
- Further reading
- Index
- Other Books You May Enjoy
Product information
- Title: Designing and Implementing Microsoft Azure Networking Solutions
- Author(s):
- Release date: August 2023
- Publisher(s): Packt Publishing
- ISBN: 9781803242033
You might also like
book
Exam Ref AZ-700 Designing and Implementing Microsoft Azure Networking Solutions
Prepare for Microsoft Exam AZ-700 and help demonstrate your real-world mastery of planning, implementing, and maintaining …
video
Exam AZ-700 Designing and Implementing Microsoft Azure Networking Solutions (Video)
Duration 10+ Hours of Video Instruction Overview Kickstart your Microsoft Exam AZ-700 Designing and Implementing Microsoft …
book
Microsoft Azure Networking: The Definitive Guide
For cloud environments to operate and scale as they should, their networking components must be designed …
book
Designing and Implementing Microsoft DevOps Solutions AZ-400 Exam Guide - Second Edition
Written by Microsoft MVPs and Azure experts, this comprehensive guide comes with self-study exercises to help …