🎤 Microsoft Azure Networking — Interview Q&A

❓ دو VNets کے درمیان VNet peering کیسے setup کرتے ہیں، اور کیا غلط ہو سکتا ہے؟Do VNets ke darmiyan VNet peering kaise setup karte hain, aur kya ghalat ho sakta hai?How do you set up VNet peering between two VNets, and what can go wrong?

Peering ایک طرفہ ہوتی ہے، اس لیے ہر VNet پر ایک peering بناتے ہیں (A→B اور B→A)۔ دونوں کا اسٹیٹس Connected ہونا چاہیے۔ دونوں VNets کے address spaces overlap نہیں ہونے چاہئیں۔Peering ek-tarfa hoti hai, is liye har VNet par ek peering banate hain (A→B aur B→A). Dono ka status Connected hona chahiye. Dono VNets ke address spaces overlap nahi hone chahiyein.Peering is one-directional, so you create one peering on each VNet (A→B and B→A). Both must show Connected status. The address spaces of the two VNets must not overlap.

❓ NSG اور Azure Firewall میں کیا فرق ہے؟NSG aur Azure Firewall mein kya farq hai?What is the difference between an NSG and Azure Firewall?

NSG Layer 3–4 ٹریفک کو IPs، ports اور protocols پر allow/deny rules سے فلٹر کرتا ہے — simple اور cheap۔ Azure Firewall stateful، managed firewall ہے Layer 7 features کے ساتھ: FQDN filtering، threat intelligence، TLS inspection اور NAT rules۔NSG Layer 3–4 traffic ko IPs, ports aur protocols par allow/deny rules se filter karta hai — simple aur cheap. Azure Firewall stateful, managed firewall hai Layer 7 features ke saath: FQDN filtering, threat intelligence, TLS inspection aur NAT rules.An NSG filters Layer 3–4 traffic with allow/deny rules on IPs, ports, and protocols — simple and cheap. Azure Firewall is a stateful, managed firewall with Layer 7 features: FQDN filtering, threat intelligence, TLS inspection, and NAT rules.

❓ VPN Gateway کب استعمال کرتے ہیں، اور VNet میں اسے کیا چاہیے ہوتا ہے؟VPN Gateway kab use karte hain, aur VNet mein isay kya chahiye hota hai?When do you use a VPN Gateway, and what does it need in the VNet?

VPN Gateway انٹرنیٹ پر IPsec سے on-premises اور Azure کے درمیان ٹریفک encrypt کرتا ہے۔ اسے VNet میں GatewaySubnet چاہیے؛ modern site-to-site VPNs کے لیے RouteBased standard انتخاب ہے۔VPN Gateway internet par IPsec se on-premises aur Azure ke darmiyan traffic encrypt karta hai. Isay VNet mein GatewaySubnet chahiye; modern site-to-site VPNs ke liye RouteBased standard choice hai.A VPN Gateway encrypts traffic between on-premises and Azure over the internet using IPsec. It needs a GatewaySubnet in the VNet; RouteBased is the standard choice for modern site-to-site VPNs.

❓ ExpressRoute کیا ہے اور VPN Gateway سے کیسے مختلف ہے؟ExpressRoute kya hai aur VPN Gateway se kaise mukhtalif hai?What is ExpressRoute and how does it differ from a VPN Gateway?

ExpressRoute connectivity provider کے ذریعے order کی گئی on-premises سے Azure تک private، dedicated connection ہے — یہ کبھی عوامی انٹرنیٹ cross نہیں کرتی۔ یہ VPN سے زیادہ bandwidth اور کم، قابلِ پیشگوئی latency دیتی ہے۔ExpressRoute connectivity provider ke zariye order ki gayi on-premises se Azure tak private, dedicated connection hai — yeh kabhi public internet cross nahi karti. Yeh VPN se zyada bandwidth aur kam, predictable latency deti hai.ExpressRoute is a private, dedicated connection from on-premises to Azure ordered through a connectivity provider — it never crosses the public internet. It gives higher bandwidth and lower, predictable latency than VPN.

❓ Private Endpoint کیا ہے اور اسے Private DNS zone سے کیوں جوڑتے ہیں؟Private Endpoint kya hai aur isay Private DNS zone se kyun jorte hain?What is a Private Endpoint and why do you pair it with a Private DNS zone?

Private Endpoint آپ کے VNet کے اندر ایک NIC ہے جو PaaS resource کو private IP دیتا ہے — ٹریفک VNet کے اندر رہتی ہے۔ جوڑی ہوئی Private DNS zone (privatelink.<service>) service FQDN کو اس private IP سے resolve کرتی ہے۔Private Endpoint aap ke VNet ke andar ek NIC hai jo PaaS resource ko private IP deta hai — traffic VNet ke andar rehti hai. Juri hui Private DNS zone (privatelink.<service>) service FQDN ko us private IP se resolve karti hai.A Private Endpoint is a NIC inside your VNet that gives a PaaS resource a private IP — traffic stays inside the VNet. The paired Private DNS zone (privatelink.<service>) resolves the service FQDN to that private IP.

❓ Application Gateway بمقابلہ Load Balancer — ہر ایک کب استعمال کرتے ہیں؟Application Gateway vs Load Balancer — har ek kab use karte hain?Application Gateway vs Load Balancer — when do you use each?

Application Gateway Layer 7 پر کام کرتا ہے — یہ HTTP/HTTPS پڑھتا ہے اور URL path یا hostname سے route کرتا ہے، SSL termination اور WAF کے ساتھ۔ Load Balancer Layer 4 (TCP/UDP) پر کام کرتا ہے اور hash سے ٹریفک بانٹتا ہے۔ Web apps کے لیے App Gateway، باقی کے لیے Load Balancer استعمال کریں۔Application Gateway Layer 7 par kaam karta hai — yeh HTTP/HTTPS parhta hai aur URL path ya hostname se route karta hai, SSL termination aur WAF ke saath. Load Balancer Layer 4 (TCP/UDP) par kaam karta hai aur hash se traffic baant-ta hai. Web apps ke liye App Gateway, baqi ke liye Load Balancer use karein.Application Gateway works at Layer 7 — it reads HTTP/HTTPS and routes by URL path or hostname, with SSL termination and WAF. Load Balancer works at Layer 4 (TCP/UDP) and spreads traffic by hash. Use App Gateway for web apps, Load Balancer for everything else.

❓ Network Watcher کیا ہے اور اس کے main tools کون سے ہیں؟Network Watcher kya hai aur is ke main tools kaunse hain?What is Network Watcher and what are its main tools?

Network Watcher Azure کا regional monitoring toolkit ہے: NSG flow logs ہر allow/deny decision ریکارڈ کرتے ہیں، Connection troubleshoot ہر hop ٹیسٹ کرتا ہے، اور Packet capture اصل packets grab کرتا ہے۔ کوئی بھی tool استعمال کرنے سے پہلے اسے ہر region میں enable کریں۔Network Watcher Azure ka regional monitoring toolkit hai: NSG flow logs har allow/deny decision record karte hain, Connection troubleshoot har hop test karta hai, aur Packet capture asal packets grab karta hai. Koi bhi tool use karne se pehle isay har region mein enable karein.Network Watcher is Azure's regional monitoring toolkit: NSG flow logs record every allow/deny decision, Connection troubleshoot tests each hop, and Packet capture grabs real packets. Enable it per region before using any tool.