Topics
Skill: Design and Implement Core Networking Infrastructure
Part 1: Design and Implement IP Addressing for Azure Resources
Session 1: Planning Network Segmentation and Address Spaces
- Designing address spaces for network segmentation
- Creating virtual networks (VNets) for Azure resources
Session 2: Subnetting and Resource Configuration
- Planning subnets for VNet gateways, private endpoints, service endpoints, and firewalls
- Configuring subnet delegation and shared or dedicated subnets
Session 3: Managing Public IP Addresses
- Creating public IP address prefixes and individual IP addresses
- Associating public IPs to resources and upgrading IP address SKUs
Part 2: Design and Implement Name Resolution
Session 4: Configuring DNS Settings
- Designing public and private DNS zones
- Configuring DNS settings for VNets and linking private DNS zones
Session 5: Implementing Azure DNS Private Resolver
- Designing and implementing private DNS resolution
- Configuring DNS settings for hybrid environments
Part 3: Design and Implement VNet Connectivity and Routing
Session 6: Service Chaining and Gateway Transit
- Designing service chaining and gateway transit configurations
- Implementing VNet peering and managing connectivity with Azure Virtual Network Manager
Session 7: Advanced Routing Solutions
- Configuring user-defined routes (UDRs) and route tables
- Implementing forced tunneling and diagnosing routing issues
Session 8: Network Address Translation (NAT) Gateways
- Identifying use cases and implementing NAT gateways
- Configuring Azure Route Server for advanced routing scenarios
Part 4: Monitor Networks
Session 9: Monitoring and Diagnostics
- Configuring Azure Network Watcher for network diagnostics
- Monitoring network health with Azure Monitor Network Insights
Session 10: Network Security Recommendations
- Evaluating security recommendations using Microsoft Defender for Cloud Secure Score
- Identifying and monitoring external attack surfaces
Skill: Design, Implement, and Manage Connectivity Services
Part 1: Site-to-Site VPN Connections
Session 11: Designing High-Availability VPN Connections
- Selecting appropriate VNet gateway SKUs for site-to-site VPNs
- Configuring local network gateways and IPsec/IKE policies
Session 12: Troubleshooting VPN Connectivity
- Diagnosing and resolving virtual network gateway issues
- Implementing Azure Extended Network for hybrid connectivity
Part 2: Point-to-Site VPN Connections
Session 13: Configuring Point-to-Site VPNs
- Selecting tunnel types and authentication methods
- Configuring RADIUS and Microsoft Entra ID authentication
Session 14: VPN Client Configuration and Diagnostics
- Generating VPN client configuration files
- Diagnosing client-side connectivity issues
Part 3: Azure ExpressRoute
Session 15: Designing ExpressRoute Connectivity
- Selecting ExpressRoute connectivity models, SKUs, and tiers
- Configuring Azure private peering and Microsoft peering
Session 16: Advanced ExpressRoute Configurations
- Implementing Global Reach, FastPath, and encryption over ExpressRoute
- Diagnosing and resolving ExpressRoute issues
Part 4: Azure Virtual WAN Architecture
Session 17: Designing Virtual WANs
- Selecting Virtual WAN SKUs and designing architectures
- Configuring virtual hub routing and third-party NVA integration
Session 18: Deploying and Managing Virtual WAN Hubs
- Deploying gateways into Virtual WAN hubs
- Monitoring and optimizing Virtual WAN performance
Skill: Design and Implement Application Delivery Services
Part 1: Azure Load Balancer and Traffic Manager
Session 19: Configuring Load Balancers
- Mapping requirements to Azure Load Balancer features
- Creating and configuring public and internal load balancers
Session 20: Implementing Azure Traffic Manager
- Configuring gateway load balancers and load balancing rules
- Setting up inbound NAT and explicit outbound rules
Part 2: Azure Application Gateway
Session 21: Configuring Application Gateway
- Mapping requirements to Application Gateway features
- Configuring listeners, routing rules, and health probes
Session 22: Securing Application Gateway
- Configuring TLS settings and WAF rules
- Implementing rewrite sets and HTTP settings
Part 3: Azure Front Door
Session 23: Configuring Front Door
- Mapping requirements to Azure Front Door capabilities
- Setting up routing, SSL termination, and traffic acceleration
Session 24: Securing Azure Front Door
- Configuring URL rewrite, redirect, and caching rules
- Integrating Private Link for secure origins
Skill: Design and Implement Private Access to Azure Services
Part 1: Private Link and Endpoints
Session 25: Configuring Private Access
- Planning and creating private endpoints and Private Link services
- Integrating Private Link with DNS and on-premises clients
Part 2: Service Endpoints
Session 26: Configuring Service Endpoints
- Choosing scenarios for service endpoint usage
- Creating service endpoints and configuring policies
Skill: Design and Implement Azure Network Security Services
Part 1: Network Security Groups (NSGs) and Application Security Groups (ASGs)
Session 27: Managing NSGs and ASGs
- Creating NSGs and ASGs and associating them with resources
- Configuring NSG rules and validating flow rules
Part 2: Azure Firewall and Firewall Manager
Session 28: Deploying Azure Firewall
- Selecting Azure Firewall SKUs and designing deployments
- Configuring Firewall rules and policies
Session 29: Managing Firewall Manager
- Implementing secure hubs with Azure Firewall in Virtual WANs
- Configuring Firewall Manager for centralized management
Part 3: Web Application Firewall (WAF)
Session 30: Configuring WAF Deployments
- Mapping requirements to WAF features
- Implementing WAF rules and configuring detection/prevention modes