VNet, connectivity, DNS và private endpoints
Azure networking cần thiết kế đồng thời IP, routing, name resolution, egress, inspection và service exposure.
VNet và topology
VNet/subnet tạo address và routing boundary; NSG lọc L3/L4 nhưng không thay firewall application-aware. Hub-spoke tập trung shared connectivity/inspection; Virtual WAN phù hợp managed transit quy mô lớn. Peering không transitive mặc định.
Hybrid và routing
VPN cung cấp encrypted Internet connectivity; ExpressRoute cung cấp private circuit nhưng encryption cần quyết định riêng. UDR và BGP propagation có thể tạo asymmetric route; effective routes/NIC rules là evidence khi debug.
DNS
Private DNS zone phải được link đúng VNet; hybrid resolution cần Azure DNS Private Resolver hoặc forwarder có rule rõ. DNS split-horizon và negative caching thường gây lỗi tưởng là network ACL.
Private Link và egress
Private endpoint đưa private IP cho PaaS service nhưng không tự disable public access hoặc sửa DNS mọi nơi. Egress cần predictable SNAT, firewall policy và route; kiểm tra port exhaustion, FQDN dependencies và forced tunneling.