Chapter 39: Cloud Connectivity, Hybrid Networking, SASE, and Edge
This chapter follows the topics shown in the Networking chapter menu. Work through each section in order, then use the review questions to check recall and troubleshooting reasoning.
39.1 Traditional Enterprise Architecture
Traditional Enterprise Architecture is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Traditional Enterprise Architecture in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.2 Modern Enterprise Architecture
Modern Enterprise Architecture is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Modern Enterprise Architecture in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.3 Hybrid Cloud
Hybrid Cloud is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Hybrid Cloud in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.4 Cloud VPN
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
39.5 Dedicated Cloud Connectivity
Dedicated Cloud Connectivity is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Dedicated Cloud Connectivity in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.6 Cloud Routing
Cloud Routing affects how Layer 3 devices choose a path toward destination networks. Correct routing depends on the destination prefix, route source, next hop or exit interface, route preference, metric, and reachability of the next step.
Example: a router receives a packet for 10.20.30.40 and has several matching routes. It selects the most specific matching prefix, then forwards toward the route's next hop or exit interface if that path is usable.
What to check
- Check the destination prefix and the most-specific matching route.
- Verify next-hop reachability, route source, preference, metric, and return path.
- Confirm that ACLs, NAT, VPN policy, or upstream routing are not blocking an otherwise-correct route.
39.7 Security Groups
Security Groups is a network-security concept. A sound design identifies the protected asset, trust boundary, possible abuse path, preventive controls, detection signals, and recovery steps.
Example: place Security Groups in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
39.8 Cloud Network ACLs
Cloud Network ACLs is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Cloud Network ACLs in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify the trust boundary and the traffic that should be permitted or denied.
- Check authentication, authorization, encryption, policy order, logs, and time synchronization.
- Verify the control with an allowed test and a denied test so policy behavior is observable.
39.9 Public Subnets
Public Subnets is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Public Subnets in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.10 Private Subnets
Private Subnets is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Private Subnets in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.11 Three-Tier Cloud Design
Three-Tier Cloud Design is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Three-Tier Cloud Design in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.12 NAT Gateway
NAT changes IP address information as traffic crosses a translation boundary. PAT is a many-to-one form that also distinguishes conversations by transport-layer port numbers.
Example: place NAT Gateway in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.13 Availability Zones
Availability Zones is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Availability Zones in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.14 Regions
Regions is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Regions in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.15 Multicloud
Multicloud is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Multicloud in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.16 SD-WAN Integration
SD-WAN uses centralized policy and an overlay to steer application traffic across multiple WAN transports according to availability, latency, loss, jitter, and business intent.
Example: place SD-WAN Integration in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.17 Application-Aware Routing
Application-Aware Routing affects how Layer 3 devices choose a path toward destination networks. Correct routing depends on the destination prefix, route source, next hop or exit interface, route preference, metric, and reachability of the next step.
Example: a router receives a packet for 10.20.30.40 and has several matching routes. It selects the most specific matching prefix, then forwards toward the route's next hop or exit interface if that path is usable.
What to check
- Check the destination prefix and the most-specific matching route.
- Verify next-hop reachability, route source, preference, metric, and return path.
- Confirm that ACLs, NAT, VPN policy, or upstream routing are not blocking an otherwise-correct route.
39.18 SASE
SASE combines wide-area connectivity with cloud-delivered security services so access policy can follow users, devices, applications, and locations.
Example: place SASE in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.19 SSE
SSE is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place SSE in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.20 ZTNA
ZTNA is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place ZTNA in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.21 Identity-Aware Access
Identity-Aware Access is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Identity-Aware Access in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.22 Edge Computing
Edge Computing is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Edge Computing in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.23 CDN
CDN is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place CDN in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.24 Cloud Load Balancer
Cloud Load Balancer is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Cloud Load Balancer in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.25 Autoscaling
Autoscaling is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Autoscaling in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.26 Cloud Monitoring
Cloud Monitoring is one of the core topics in Cloud Connectivity, Hybrid Networking, SASE, and Edge. Understand what the term represents, where it operates in the network, what information it uses, and what observable behavior confirms that it is working correctly.
Example: place Cloud Monitoring in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
39.27 Cloud VPN Troubleshooting
A VPN creates a protected logical connection across an untrusted or shared network. The design must define endpoints, authentication, encryption, routing, and failure behavior.
Example: two sites can reach the public internet but cannot pass private traffic through the secure tunnel. Check peer reachability, negotiation state, authentication, encryption proposals, interesting traffic, NAT interaction, routes, and policy.
What to check
- Confirm the symptom and determine whether the problem affects one host, one segment, one site, or many sites.
- Compare actual configuration and measurements with the intended design, baseline, or documentation.
- Change one variable at a time, verify the result, and document both the cause and the final fix.
39.28 Overlapping Cloud Networks
Ping is a basic reachability and round-trip-time test. A failed ping does not always prove the destination is down because policy may block ICMP.
Example: ping the local loopback, local interface, default gateway, remote IP, and finally a hostname. The first failed step helps narrow the fault domain, but remember that ICMP filtering can produce false negatives.
What to check
- Identify which OSI/TCP-IP layer and device type are primarily responsible.
- Check configuration, interface or service state, counters, logs, and a simple end-to-end test.
- Verify both normal operation and one realistic failure case so you understand what changes when the feature breaks.
Command or data example
ping 192.0.2.1
39.29 Cloud Latency
Latency is the time required for traffic to travel between endpoints. Propagation, serialization, queueing, processing, and path choice can all contribute.
Example: place Cloud Latency in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Confirm the symptom and determine whether the problem affects one host, one segment, one site, or many sites.
- Compare actual configuration and measurements with the intended design, baseline, or documentation.
- Change one variable at a time, verify the result, and document both the cause and the final fix.
39.30 Hybrid Network Troubleshooting
Hybrid Network Troubleshooting is a troubleshooting condition. The useful approach is to confirm symptoms, determine scope, identify the relevant layer, compare actual values with the intended design, test one theory at a time, and verify service after the fix.
Example: place Hybrid Network Troubleshooting in a small office network containing clients, switches, a router, wireless access, DNS/DHCP services, and an internet connection. Identify which device or layer owns the function and what evidence you would inspect to verify it.
What to check
- Confirm the symptom and determine whether the problem affects one host, one segment, one site, or many sites.
- Compare actual configuration and measurements with the intended design, baseline, or documentation.
- Change one variable at a time, verify the result, and document both the cause and the final fix.