How to Resolve IP Address Overlaps for Azure Site-to-Site VPN?
Your on-premises network has an IP address range of 10.0.0.0/23. You have an Azure virtual network named VNet1 that contains a virtual machine named VM1. VNet1 has an IP address range of 10.0.1.0/24. You need to deploy a Site-to-Site (S2S) VPN to connect the on-premises network to VNet1. What should you do first?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests practical subnetting skills and VNet CIDR prerequisites for hybrid connectivity, with the common trap being reliance on advanced overlay features instead of correcting the fundamental routing conflict.
Establishing an Azure Site-to-Site VPN requires strictly non-overlapping IP address ranges between on-premises networks and Azure virtual networks; the community unanimously agrees that reconfiguring the VNet CIDR block to eliminate conflicts is the mandatory first step.
Option B (Azure Extended Network) is frequently selected because it technically supports overlapping IP ranges, but it introduces unnecessary architectural complexity and cost when a straightforward CIDR adjustment solves the problem.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The on-premises range 10.0.0.0/23 spans from 10.0.0.0 to 10.0.1.255, which completely contains the VNet1 range of 10.0.1.0/24. Azure Gateway routers cannot generate valid routing tables for overlapping address spaces, making a Site-to-Site VPN impossible until the conflict is resolved. Reassigning VNet1 to 10.0.2.0/24 places it outside the on-premises boundary, allowing immediate route propagation and tunnel establishment.Why the Other Options Are Wrong
Azure Bastion (Option A) secures VM access via browser-based RDP/SSH but does not modify network routing or address plans. Azure Extended Network (Option B) permits overlapping CIDRs for complex enterprise migrations, but it is not a prerequisite for standard S2S deployments and violates the do-first simplicity expected in certification exams. Option D changes the VNet size but keeps the 10.0.1.128/25 block entirely inside the original /23 on-premises range, preserving the fatal overlap.Community Comment Notes
Commenters [1], [2], and [7] correctly perform the CIDR math to demonstrate complete subnet containment, which directly invalidates the current configuration. Comment [3] provides valuable context by acknowledging that while Extended Network handles overlaps, standard exam logic prioritizes clean IP reallocation unless IP retention is explicitly mandated. Comment [5] offers a highly structured breakdown of the start/end IP boundaries, serving as an excellent study reference for quick subnet verification during the test.Official Reference
- https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq#can-i-use-the-same-ip-address-range-in-both-my-on-premises-network-and-an-azure-vnet
- https://learn.microsoft.com/en-us/azure/vpn-gateway/vpn-gateway-about-vpn-devices
- https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/virtual-networks-find-cidr-blocks
Exam Strategy
Always calculate CIDR range boundaries mentally before reviewing configuration options, as overlapping address spaces instantly disqualify standard hybrid connectivity solutions. Memorize common /23, /24, and /25 subnet masks to rapidly identify containment issues and avoid overcomplicating straightforward routing prerequisites.