BSCNE - MICROSOFT AZURE TRACK
Hybrid-Cloud Implementation
and Verification Report
WGU E031 (ITCL 4203) - Task 2
Prepared by [Student Name]
Student ID [Student ID]
Course E031 / ITCL 4203
Project Secure Azure Hybrid-Cloud Network
Implementation date [Actual lab date/time range]
Submission date [Month Day, Year]
EVIDENCE INTEGRITY
This report is complete in structure and technical narrative, but authentic screenshots and actual results must be inserted from the
student's lab. Do not submit placeholder frames or represent illustrative values as observed evidence.
, Document map and completion status
Section Coverage Evidence status
1. Implementation baseline Architecture, inventory, change record Narrative complete; screenshots
pending
2. On-premises Interfaces, VLANs, routing, firewall, NAT Insert Figures 1-3
configuration
3. Azure infrastructure VNet, subnets, NSGs, routes, workload Insert Figures 4-6
4. Hybrid connectivity VPN policy, status, route verification Insert Figures 7-9
5. Required/default testing Traceable test matrix Populate official cases and results
6. Custom scenario CS-01 DMZ containment Insert Figures 10-11
7. Custom scenario CS-02 Granular Azure access Insert Figures 12-14
8. Troubleshooting Symptom, diagnosis, fix, regression test Insert Figure 15
reflection
9. Acceptance and Evidence index, redaction and rubric check Complete after screenshots
appendices
Report conventions
Observed statements must be supported by a dated screenshot or exported log. Planned/example values are marked
with brackets until verified. The words PASS, Connected, established, and successful must not be used as final results
unless the corresponding evidence is present. All screenshots should show the full remote desktop or portal context,
taskbar clock/date, command prompt, source identity, and relevant output.
Task 1-to-Task 2 consistency
Design element Task 1 baseline Task 2 verification
Management VLAN .168.10.0/24 eth1.10, gateway .1, admin-only policies
Production VLAN .168.20.0/24 eth1.20, gateway .1, app HTTPS path
DMZ VLAN .168.30.0/24 eth1.30, gateway .1, private-network denial
Azure 10.100.0.0/16; app 10.100.1.0/24 VNet/subnet blade, NSG, effective routes
Hybrid Route-based IKEv2/IPsec VyOS SAs + Azure Connected + end-to-end traffic
CONSISTENCY CORRECTION
The supplied Task 2 outline called VLAN 30 a Guest zone and proposed blocking Management from the Azure target. This report
retains the approved Task 1 definitions: VLAN 30 is DMZ, Management is allowed only on the administration port, and Production is
allowed only on TCP 443.
E031 Task 2 | Implementation and Verification Report | Evidence Template Page 2
, 1. Implementation baseline and final architecture
The environment was implemented as a proof-of-concept hybrid network spanning a GNS3 headquarters site and a
Microsoft Azure virtual network. VyOS centralized 802.1Q termination, Layer 3 forwarding, stateful firewall enforcement,
NAT for approved internet egress, and IPsec termination. Azure provided the application subnet, private workload, network
security controls, and route-based Virtual Network Gateway.
Implemented hybrid data path and verification points
GNS3 / HQ AZURE VPN EDGE
Mgmt 192.168.10.0/24 IPSEC / IKEv2 LNG: HQ prefixes
Prod 192.168.20.0/24 encrypted matched policy + PSK encrypted VNG: route-based
DMZ 192.168.30.0/24 active IKE and child SAs GatewaySubnet /27
VyOS zones + NAT status: [VERIFY]
VyOS counters routes / NSG
LOCAL POLICY AZURE APP
Mgmt -> admin allow 10.100.1.10
Prod -> app 443 allow NSG enforced
DMZ -> private deny host firewall enforced
collect collect
EVIDENCE CHAIN
CLI/portal status + full timestamps
positive and negative endpoint tests
rule counters/logs at enforcing device
Figure A. End-to-end implementation model and evidence points. Replace each [VERIFY] item with the actual observed
status.
E031 Task 2 | Implementation and Verification Report | Evidence Template Page 3
Hybrid-Cloud Implementation
and Verification Report
WGU E031 (ITCL 4203) - Task 2
Prepared by [Student Name]
Student ID [Student ID]
Course E031 / ITCL 4203
Project Secure Azure Hybrid-Cloud Network
Implementation date [Actual lab date/time range]
Submission date [Month Day, Year]
EVIDENCE INTEGRITY
This report is complete in structure and technical narrative, but authentic screenshots and actual results must be inserted from the
student's lab. Do not submit placeholder frames or represent illustrative values as observed evidence.
, Document map and completion status
Section Coverage Evidence status
1. Implementation baseline Architecture, inventory, change record Narrative complete; screenshots
pending
2. On-premises Interfaces, VLANs, routing, firewall, NAT Insert Figures 1-3
configuration
3. Azure infrastructure VNet, subnets, NSGs, routes, workload Insert Figures 4-6
4. Hybrid connectivity VPN policy, status, route verification Insert Figures 7-9
5. Required/default testing Traceable test matrix Populate official cases and results
6. Custom scenario CS-01 DMZ containment Insert Figures 10-11
7. Custom scenario CS-02 Granular Azure access Insert Figures 12-14
8. Troubleshooting Symptom, diagnosis, fix, regression test Insert Figure 15
reflection
9. Acceptance and Evidence index, redaction and rubric check Complete after screenshots
appendices
Report conventions
Observed statements must be supported by a dated screenshot or exported log. Planned/example values are marked
with brackets until verified. The words PASS, Connected, established, and successful must not be used as final results
unless the corresponding evidence is present. All screenshots should show the full remote desktop or portal context,
taskbar clock/date, command prompt, source identity, and relevant output.
Task 1-to-Task 2 consistency
Design element Task 1 baseline Task 2 verification
Management VLAN .168.10.0/24 eth1.10, gateway .1, admin-only policies
Production VLAN .168.20.0/24 eth1.20, gateway .1, app HTTPS path
DMZ VLAN .168.30.0/24 eth1.30, gateway .1, private-network denial
Azure 10.100.0.0/16; app 10.100.1.0/24 VNet/subnet blade, NSG, effective routes
Hybrid Route-based IKEv2/IPsec VyOS SAs + Azure Connected + end-to-end traffic
CONSISTENCY CORRECTION
The supplied Task 2 outline called VLAN 30 a Guest zone and proposed blocking Management from the Azure target. This report
retains the approved Task 1 definitions: VLAN 30 is DMZ, Management is allowed only on the administration port, and Production is
allowed only on TCP 443.
E031 Task 2 | Implementation and Verification Report | Evidence Template Page 2
, 1. Implementation baseline and final architecture
The environment was implemented as a proof-of-concept hybrid network spanning a GNS3 headquarters site and a
Microsoft Azure virtual network. VyOS centralized 802.1Q termination, Layer 3 forwarding, stateful firewall enforcement,
NAT for approved internet egress, and IPsec termination. Azure provided the application subnet, private workload, network
security controls, and route-based Virtual Network Gateway.
Implemented hybrid data path and verification points
GNS3 / HQ AZURE VPN EDGE
Mgmt 192.168.10.0/24 IPSEC / IKEv2 LNG: HQ prefixes
Prod 192.168.20.0/24 encrypted matched policy + PSK encrypted VNG: route-based
DMZ 192.168.30.0/24 active IKE and child SAs GatewaySubnet /27
VyOS zones + NAT status: [VERIFY]
VyOS counters routes / NSG
LOCAL POLICY AZURE APP
Mgmt -> admin allow 10.100.1.10
Prod -> app 443 allow NSG enforced
DMZ -> private deny host firewall enforced
collect collect
EVIDENCE CHAIN
CLI/portal status + full timestamps
positive and negative endpoint tests
rule counters/logs at enforcing device
Figure A. End-to-end implementation model and evidence points. Replace each [VERIFY] item with the actual observed
status.
E031 Task 2 | Implementation and Verification Report | Evidence Template Page 3