Q: 12
You have an Azure subscription that contains the following resources:
A virtual network named Vnet1
Two subnets named subnet1 and AzureFirewallSubnet
A public Azure Firewall named FW1
A route table named RT1 that is associated to Subnet1
A rule routing of 0.0.0.0/0 to FW1 in RT1
After deploying 10 servers that run Windows Server to Subnet1, you discover that none of the virtual
machines were activated.
You need to ensure that the virtual machines can be activated.
What should you do?
Options
Discussion
C tbh
I don’t think D is required here. C, since a DNAT rule for 1688 on FW1 looks like the trap option.
D
C seems tempting, but port 1688 is specific for KMS activations and just opening DNAT on the firewall won’t help if the route is forcing everything through FW1. I think D is better, but not totally sure.
Why wouldn't B work in this case? Is it just because KMS activation specifically needs internet access via that special Azure IP?
Be respectful. No spam.