VNets, DNS, and endpoints

Virtual networks

A VNet is your private, isolated network in Azure. Everything inside can talk by default until NSGs say otherwise.

Address space is in CIDR (all the mechanics in my subnetting notes): a /16 is about 65k addresses, a /24 is 256, a /28 is 16.

VNet peering is a private connection between VNets over Microsoft’s backbone, same region or global. It’s non-transitive: A-B peered and B-C peered does not give A-C. Also avoid overlapping address spaces.

Azure DNS

Azure DNS hosts DNS zones so you don’t run DNS servers. (Resolution basics: how DNS works.)

The record types the exam wants: A (name to IPv4), CNAME (alias to another name), MX (mail servers), TXT (verification text).

Private DNS zones give internal-only resolution, and creating the zone is not enough: it must be explicitly linked to each VNet. With auto-registration on, VM records appear automatically.

For hybrid, point on-prem DNS forwarders at Azure’s resolver 168.63.129.16.

Endpoints (the bank analogy)

Compliance says “no public internet access”: private endpoint plus disable public access. Simpler backbone routing without new IPs: service endpoint.

Private endpoints auto-integrate with private DNS zones.