How to Resolve IP Address Overlaps for Azure Site-to-Site VPN?

Your on-premises network has an IP address range of 10.0.0.0/23. You have an Azure virtual network named VNet1 that contains a virtual machine named VM1. VNet1 has an IP address range of 10.0.1.0/24. You need to deploy a Site-to-Site (S2S) VPN to connect the on-premises network to VNet1. What should you do first?

  1. Deploy Azure Bastion to VNet1.
  2. Deploy Azure Extended Network.
  3. Configure VNet1 to use the IP address range of 10.0.2.0/24. Source Reference Answer
  4. Configure VNet1 to use an IP address range of 10.0.1.128/25.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests practical subnetting skills and VNet CIDR prerequisites for hybrid connectivity, with the common trap being reliance on advanced overlay features instead of correcting the fundamental routing conflict.

Establishing an Azure Site-to-Site VPN requires strictly non-overlapping IP address ranges between on-premises networks and Azure virtual networks; the community unanimously agrees that reconfiguring the VNet CIDR block to eliminate conflicts is the mandatory first step.

Option B (Azure Extended Network) is frequently selected because it technically supports overlapping IP ranges, but it introduces unnecessary architectural complexity and cost when a straightforward CIDR adjustment solves the problem.

Community Discussion (11 comments)

Ni_yot 👍 1
To determine if the subnets 10.0.0.0/23 and 10.0.1.0/24 overlap, we need to analyze their IP address ranges. 1. Subnet 10.0.0.0/23: - The /23 CIDR notation means it has a subnet mask of 255.255.254.0. - The range of addresses for this subnet is: - Start: 10.0.0.0 - End: 10.0.1.255 2. Subnet 10.0.1.0/24: - The /24 CIDR notation means it has a subnet mask of 255.255.255.0. - The range of addresses for this subnet is: - Start: 10.0.1.0 - End: 10.0.1.255 ### Overlap Analysis - The range of 10.0.0.0/23 is 10.0.0.0 to 10.0.1.255. - The range of 10.0.1.0/24 is 10.0.1.0 to 10.0.1.255. Since the range 10.0.1.0 to 10.0.1.255 falls within the range of 10.0.0.0/23, these two subnets do overlap. Specifically, the overlapping addresses are from 10.0.1.0 to 10.0.1.255.
Ksk08 👍 1
C is correct
sardonique 👍 2
Answer is C, it is a no brainer. Do some math, 10.0.0.0/23 overlaps to the whole vNet range. you can check it on a free online IP calculator.
Krayzr 👍 1 Selected: C
Change IP so IPs are not conflicting.
PrettyFlyWifi 👍 2 Selected: C
This has overlapping IP ranges, but there is no requirement to maintain the same IP addresses for both on-premises and Azure host VMs, so it's C for me, as it's a separate range. IF you had to maintain the IPs, then the extended network would win here.
AK_1234 👍 2
Answer C
SIAMIANJI 👍 3 Selected: C
Since your on-premises network has an IP address range of 10.0.0.0/23 and VNet1 currently has an IP address range of 10.0.1.0/24, which overlaps with the on-premises network, you need to change the IP address range of VNet1 to ensure that it does not overlap with the on-premises network. Therefore, the correct option is: C. Configure VNet1 to use the IP address range of 10.0.2.0/24.
Kuikz 👍 1 Selected: C
there is an overlap in the ranges 10.0.0.0/23 and 10.0.1.0/24 as the 10.0.1.0/24 range is entirely contained within the 10.0.0.0/23 range.
pnewcap 👍 1
is it C or D ?
AlexFlorea 👍 1 Selected: C
C. Configure VNet1 to use the IP address range of 10.0.2.0/24. This step ensures that there are no overlapping IP ranges between the on-premises network and the Azure virtual network, which is essential for a successful S2S VPN connection.
Lionred 👍 2
Answer is B because of the overlapping of address. On-prem has the range of 10.0.0.0 - 10.0.127.255 Azure VNet1 has the range of 10.0.1.0 - 10.0.1.255 Azure Extended Network can work with overlapping address ranges

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The on-premises range 10.0.0.0/23 spans from 10.0.0.0 to 10.0.1.255, which completely contains the VNet1 range of 10.0.1.0/24. Azure Gateway routers cannot generate valid routing tables for overlapping address spaces, making a Site-to-Site VPN impossible until the conflict is resolved. Reassigning VNet1 to 10.0.2.0/24 places it outside the on-premises boundary, allowing immediate route propagation and tunnel establishment.

Why the Other Options Are Wrong

Azure Bastion (Option A) secures VM access via browser-based RDP/SSH but does not modify network routing or address plans. Azure Extended Network (Option B) permits overlapping CIDRs for complex enterprise migrations, but it is not a prerequisite for standard S2S deployments and violates the do-first simplicity expected in certification exams. Option D changes the VNet size but keeps the 10.0.1.128/25 block entirely inside the original /23 on-premises range, preserving the fatal overlap.

Community Comment Notes

Commenters [1], [2], and [7] correctly perform the CIDR math to demonstrate complete subnet containment, which directly invalidates the current configuration. Comment [3] provides valuable context by acknowledging that while Extended Network handles overlaps, standard exam logic prioritizes clean IP reallocation unless IP retention is explicitly mandated. Comment [5] offers a highly structured breakdown of the start/end IP boundaries, serving as an excellent study reference for quick subnet verification during the test.

Official Reference

Exam Strategy

Always calculate CIDR range boundaries mentally before reviewing configuration options, as overlapping address spaces instantly disqualify standard hybrid connectivity solutions. Memorize common /23, /24, and /25 subnet masks to rapidly identify containment issues and avoid overcomplicating straightforward routing prerequisites.

Related Analysis

← Back to AZ-800 Study Guide