Network path trước service name
Thiết kế VNet bắt đầu bằng address plan và request path: user → entry point → app subnet → data subnet; on-prem → gateway → private endpoint/API. Subnet là phân vùng IP, không tự làm resource secure.
Route và NSG
Route table chọn next hop; NSG lọc traffic theo rule. Với mỗi flow ghi source, destination, protocol/port, route, NSG inbound/outbound và return path. Một rule allow nhưng thiếu route hoặc response path vẫn tạo timeout.
VPN Gateway và ExpressRoute
VPN Gateway tạo tunnel mã hóa qua Internet, phù hợp bắt đầu nhanh và chi phí thường thấp hơn nhưng behavior phụ thuộc Internet path. ExpressRoute dùng private connectivity qua provider, có circuit/peering/routing, lead time, redundancy và cost riêng. Private link không tự giải quyết identity, authorization, firewall hay app-level encryption.
Bài tập
Viết decision record cho kết nối branch office tới Azure: latency, bandwidth, compliance, encryption, provider, RTO, redundancy và budget. Vẽ route/NSG matrix và failure mode khi một tunnel hoặc gateway lỗi.