Design & implement azure ExpressRoute Flashcards

1
Q

What is ExpressRoute and what does it offer?

A

ExpressRoute extends on-premises networks into the Microsoft cloud over a private connection with the help of a connectivity provider. ExpressRoute establishes connections to various Microsoft cloud services, such as Microsoft Azure and Microsoft 365.
It offers more reliability, faster speeds, consistent latencies, and higher security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What type of connections can form ER?

A

Connectivity can be from an any-to-any (IP VPN) network, a point-to-point Ethernet network, or a virtual cross-connection through a connectivity provider at a colocation facility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name and briefly explain 4 use cases for ER in azure.

A
  1. Faster and Reliable connection to Azure services - Organizations using Azure services look for reliable connections to Azure services and data centers. Public internet is dependent upon many factors and may not be suitable for a business. Using ExpressRoute connections to transfer data between on-premises systems and Azure can also give significant cost benefits.
  2. Storage, backup, and Recovery - Backup and Recovery are important for an organization for business continuity and recovering from outages. ExpressRoute gives you a fast and reliable connection to Azure with bandwidths up to 100 Gbps. ExpressRoute is excellent for scenarios such as periodic data migration, replication for business continuity, disaster recovery, and other high-availability strategies.
  3. Extends Data center capabilities - ExpressRoute can be used to connect and add compute and storage capacity to your existing data centers. With high throughput and fast latencies, Azure feels like a natural extension to or between your data centers, so you enjoy the scale and economics of the public cloud without having to compromise on network performance.
  4. Predictable, reliable, and high-throughput connections - With predictable, reliable, and high-throughput connections offered by ExpressRoute, enterprises can build applications that span on-premises infrastructure and Azure without compromising privacy or performance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 4 connectivity models for ER?

A
  1. Co-located at a cloud exchange

In a facility with a cloud exchange, virtual cross-connections to the Microsoft cloud are provided through the colocation provider’s Ethernet exchange. Colocation providers can offer either Layer 2 cross-connections, or managed Layer 3 cross-connections between your infrastructure in the colocation facility and the Microsoft cloud.

  1. Point-to-point Ethernet connections

Point-to-point Ethernet providers can offer Layer 2 connections, or managed Layer 3 connections between your site and the Microsoft cloud.

  1. Any-to-any (IPVPN) networks

IPVPN providers offer any-to-any connectivity between your branch offices and datacenters. The Microsoft cloud can be interconnected to your WAN to make it look just like any other branch office. WAN providers typically offer managed Layer 3 connectivity.

  1. Direct from ExpressRoute sites

ExpressRoute Direct provides dual 100 Gbps or 10-Gbps connectivity, which supports Active/Active connectivity at scale.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name the differences between ER service provider & ER Direct.

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name and describe the 2 ways in which redundancy can be deployed for ER.

A
  1. Configure ExpressRoute and site to site coexisting connections
    Configuring Site-to-Site VPN and ExpressRoute coexisting connections has several advantages:

A Site-to-Site VPN is a secure failover path for ExpressRoute.
Site-to-Site VPNs to connect to sites that aren’t connected through ExpressRoute.
No downtime occurs when adding a new gateway or gateway connection.

  1. Create a zone redundant virtual network gateway in Azure availability zones

You can deploy VPN and ExpressRoute gateways in Azure Availability Zones. Deploying gateways in Azure Availability Zones physically and logically separates gateways within a region, while protecting your on-premises network connectivity to Azure from zone-level failures.

2 types are Zone-redundant gateways & Zonal gateways

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How are Zone-Redundant & Zonal gateway SKUs identified?

A

You can identify these SKUs by the “AZ” in the SKU name.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What PIP SKU do both ZR & Zonal GWs rely on?

A

Zone-redundant gateways and zonal gateways both rely on the Azure public IP resource Standard SKU. The configuration of the Azure public IP resource determines whether the gateway that you deploy is zone-redundant, or zonal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the 3 ER circuit SKUs?

A
  • Local SKU - With Local SKU, you’re automatically charged with an Unlimited data plan.
  • Standard and Premium SKU - You can select between a Metered or an Unlimited data plan. All ingress data are free of charge except when using the Global Reach add-on.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the difference between an Azure region & an ER peering location?

A

Azure regions are global datacenters where Azure compute, networking, and storage resources are located. The resource location determines which Azure datacenter (or availability zone) the resource is created in.

ExpressRoute locations (sometimes referred to as peering locations or meet-me-locations) are colocation facilities where Microsoft Enterprise Edge (MSEE) devices are located. ExpressRoute locations are the entry point to Microsoft’s network – and are globally distributed, providing customers the opportunity to connect to Microsoft’s network around the world.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What other options are available for customers without fibre-connectivity as an option?

A
  • Other service providers
  • Datacenter providers
  • National Research and Education networks (NERN)
  • System integrators
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How would you go about choosing the right ER circuit & billing model?

A
  1. evaluate the current usage and determine how much data is used monthly to start with.
  2. The next step is to figure out which of the available ExpressRoute is the best choice depending upon the requirements of the Enterprise keeping in mind the budget and SLA requirements.
  3. Decide between the Local, Standard, and Premium SKUs.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What peering options are available for ER circuits?

A

An ExpressRoute circuit has two peering options associated with it: Azure private, and Microsoft. Each peering is configured identically on a pair of routers (in active-active or load sharing configuration) for high availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Name a few pre-requisites that are needed when configuring peering?

A
  • Peering can be configured in any order you choose. However, you must make sure that you complete the configuration of each peering one at a time.
  • You must have an active ExpressRoute circuit. To configure peerings, the ExpressRoute circuit must be in a provisioned and enabled state.
  • If you plan to use a shared key/MD5 hash, be sure to use the key on both sides of the tunnel. The limit is a maximum of 25 alphanumeric characters. Special characters aren’t supported.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Name some differences between Private & Microsoft peering.

A
  1. Private Peering:
    - Supports 4000 prefixes by default, 10,000 with ExpressRoute Premium.
    - Supports Any valid IP address range within your WAN.
    - Private and public AS numbers supported. You must own the public AS number if you choose to use one.
    - Supports IPv4, IPv6 (preview)
    - RFC1918 and public IP addresses can be used on the routing interface.
    - Supports MD5
  2. Microsoft Peering:
    - Supports 200 prefixes by default.
    - Supports Public IP addresses owned by you or your connectivity provider.
    - Private and public AS numbers supported. However, you must prove ownership of public IP addresses.
    - Supports IPv4, IPv6
    - public IP addresses can be used on the routing interface, but they must be registered to you in routing registries.
    - Supports MD5
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the recommended config for both peerings?

A

The recommended configuration is that private peering is connected directly to the core network, and the public and Microsoft peering links are connected to your DMZ.

17
Q

What is the pre-requisite should you want to connect a VNet to an IPv6 based ER circuit?

A

make sure that your virtual network is dual stack

18
Q

How are both peering options configured?

A
  1. Private Peering:
    - Azure compute services, namely virtual machines, and cloud services, that are deployed within a virtual network can be connected through the private peering domain.
    - You can set up bi-directional connectivity between your core network and Azure virtual networks which lets you connect to virtual machines and cloud services directly on their private IP addresses.
  2. Microsoft peering:
    - Connectivity to Microsoft online services (Microsoft 365 and Azure PaaS services) occurs through Microsoft peering.
    - You can enable bidirectional connectivity between your WAN and Microsoft cloud services through the Microsoft peering routing domain.
    - You must connect to Microsoft cloud services only over public IP addresses owned by you or your connectivity provider and you must adhere to all the defined rules.
19
Q

What is the purpose of Route Filters when configuring an ER peering?

A

A route filter lets you identify services you want to consume through your ExpressRoute circuit’s Microsoft peering. It’s essentially an allowed list of all the BGP community values. Once a route filter resource gets defined and attached to an ExpressRoute circuit, all prefixes that map to the BGP community values gets advertised to your network.
To attach route filters with Microsoft 365 services, you must have authorization to consume Microsoft 365 services through ExpressRoute.

20
Q

What steps must be performed when connecting your VNet to your ER Circuit?

A
  • You must have an active ExpressRoute circuit.
  • Ensure that you have Azure private peering configured for your circuit.
  • Ensure that Azure private peering gets configured and establishes BGP peering between your network and Microsoft for end-to-end connectivity.
  • Ensure that you have a virtual network and a virtual network gateway created and fully provisioned. A virtual network gateway for ExpressRoute uses the GatewayType ‘ExpressRoute’, not VPN.
  • You can link up to 10 virtual networks to a standard
    ExpressRoute circuit. All virtual networks must be in the same geopolitical region when using a standard ExpressRoute circuit.
  • A single virtual network can be linked to up to 16 ExpressRoute circuits. The ExpressRoute circuits can be in the same subscription, different subscriptions, or a mix of both.
  • If you enable the ExpressRoute premium add-on, you can link virtual networks outside of the geopolitical region of the ExpressRoute circuit. The premium add-on allows you to connect more than 10 virtual networks to your ExpressRoute circuit depending on the bandwidth chosen.
  • To create the connection from the ExpressRoute circuit to the target ExpressRoute virtual network gateway, the number of address spaces advertised from the local or peered virtual networks needs to be equal to or less than 200. Once the connection is successfully created, you can add other address spaces, up to 1,000, to the local or peered virtual networks.
21
Q

How are VPNs established over ER private connections?

A

You can use Microsoft peering to establish a site-to-site IPsec/IKE VPN tunnel between your selected on-premises networks and Azure VNets.

Note!:
When you set up site-to-site VPN over Microsoft peering, you are charged for the VPN gateway and VPN egress.

22
Q

What are some of the steps for configuring a S2S-VPN over ER connection?

A
  • Configure Microsoft peering for your ExpressRoute circuit.
  • Advertise selected Azure regional public prefixes to your on-premises network via Microsoft peering.
  • Configure a VPN gateway and establish IPsec tunnels
  • Configure the on-premises VPN device.
  • Create the site-to-site IPsec/IKE connection.
  • (Optional) Configure firewalls/filtering on the on-premises VPN device.
  • Test and validate the IPsec communication over the ExpressRoute circuit.
23
Q

Name 4 different ways ER can be implemented.

A
  1. You can connect to Microsoft in one of the peering locations and access regions within the geopolitical region.
  2. You can enable ExpressRoute Premium to extend connectivity across geopolitical boundaries. For example, if you connect to Microsoft in Amsterdam through ExpressRoute, you have access to all Microsoft cloud services hosted in all regions across the world.
  3. You can transfer data cost-effectively by enabling the Local SKU. With Local SKU, you can bring your data to an ExpressRoute location near the Azure region you want.
  4. You can enable ExpressRoute Global Reach to exchange data across your on-premises sites by connecting your ExpressRoute circuits. With ExpressRoute Global Reach, you can connect your private data centers together through these two ExpressRoute circuits. Your cross-data-center traffic traverses through Microsoft’s network.
24
Q

What is ER FastPath?

A

FastPath is designed to improve the data path performance between your on-premises network and your virtual network. When enabled, FastPath sends network traffic directly to virtual machines in the virtual network, bypassing the gateway.

25
Name some requirements of FastPath.
- FastPath still requires a virtual network gateway to be created. - To configure FastPath, the virtual network gateway must be either: Ultra-Performance ErGw3AZ
26
Name 3 area's which can be looked at when troubleshooting ER connectivity.
- Customers network - Providers network (if not using ER Direct) - Microsofts Datacenters
27
What is a service Key?
A service key uniquely identifies an ExpressRoute circuit. Should you need assistance from Microsoft or from an ExpressRoute partner to troubleshoot an ExpressRoute issue, provide the service key to readily identify the circuit.
28
Name 3 things to confirm when troubleshooting an ER Circuit.
1. Validate peering config - Status of an ExpressRoute circuit peering can be checked under the ExpressRoute circuit blade. 2. Validate ARP - The ARP table provides a mapping of the IP address and MAC address for a particular peering. Can be used to verify Age of the L2-L3 mappings. 3. ER Monitoring tools - Using Azure monitor services such as Network insight and Metrics to troubleshoot the ER deployment and its components.