In this lesson, I provide examples of how Azure Virtual Networking components working together to create networks and how those networks connect together. This is the first and second in a series of lesson on Azure Virtual Networking.
3. Azure Classic vs Azure Resource Manager
Tenminute.tech
In this lesson we will be using the Azure Resource Manager
4. What is AzureVirtual Network?
Tenminute.tech
• AzureVirtual Network enables Azure resources to
communicate with each other and the internet
• A virtual network isolates your resources from others'
resources in the Azure cloud
• You can connect virtual networks to other virtual
networks, or to your on-premises network
5. AzureVirtual Network capabilities
• Isolation
• Internet communication
• Azure resource communication
• Virtual network connectivity
• On-premises connectivity
• Traffic filtering
• Routing
Tenminute.tech
6. Network isolation and segmentation
• Virtual networks are isolated from one another
•You can create separate virtual networks for development,
testing, and production that use the same CIDR address
blocks
•You can create multiple virtual and connect the networks
together
•You can segment a virtual network into multiple subnets
•Azure provides internal name resolution for resources
deployed in a virtual network
•If necessary, you can configure a virtual network to use your
own DNS servers
Tenminute.tech
7. Internet communication
• By default Resources, such as virtual machines
deployed in a virtual network, have access to the
Internet
• You can also enable inbound access to specific
resources, as needed
Tenminute.tech
8. Azure resource communication
•Azure resources deployed in a virtual network can
communicate with each other using private IP addresses
even if the resources are deployed in different subnets
•Azure provides default routing between subnets,
connected virtual networks, and on-premises networks,
so you don't have to configure and manage routes
•If desired, you can customize Azure's routing
Tenminute.tech
9. Virtual network connectivity
•Virtual networks can be connected to each other,
enabling resources in any virtual network to
communicate with resources in any other virtual
network
Tenminute.tech
10. On-premises connectivity
•A virtual network can be connected to an on-premises
network, enabling resources to communicate between
each other
• Point-to-site virtual private network (VPN):
• Site-to-siteVPN:
• Azure ExpressRoute:
Tenminute.tech
11. Traffic filtering
•You can filter network traffic to and from resources in a
virtual network by source IP address and port,
destination IP address and port, and protocol
Tenminute.tech
12. Routing
• You can optionally override Azure's default routing by
configuring your own routes, or by propagating BGP
routes through a network gateway
Tenminute.tech
13. IP address types and allocation methods in Azure
• You can assign IP addresses to Azure resources to
communicate with other Azure resources, your on-
premises network, and the Internet
• There are two types of IP addresses you can use in
Azure:
•Public IP addresses
•Private IP addresses
Tenminute.tech
14. Public IP addresses
• Public IP addresses allow Internet resources to communicate inbound
to Azure resources
• The address is dedicated to the resource, until it is unassigned by you
• In Azure Resource Manager, a public IP address is a resource that has its
own properties
• Some of the resources you can associate a public IP address resource
with are:
• Virtual machine network interfaces
• Internet-facing load balancers
• VPN gateways
• Application gateways
Tenminute.tech
15. Private IP addresses
• Private IP addresses allowAzure resources to communicate
with other resources in a virtual network or an on-premises
network through aVPN gateway or ExpressRoute circuit,
without using an Internet-reachable IP address
• In the Azure Resource Manager deployment model, a private
IP address is associated to the following types of Azure
resources:
• Virtual machine network interfaces
• Internal load balancers (ILBs)
• Application gateways
Tenminute.tech
16. IP address allocation
• There are two methods in which a IP address are
allocated:
• Dynamic: Azure assigns the next available unassigned
or unreserved IP address in the subnet's address range
• Static:You select and assign any unassigned or
unreserved IP address in the subnet's address range
Tenminute.tech
17. DHCP
•DHCP is controlled by Azure
•For those you who want to try to set up DHCP on an
Azure virtual machine, you're going to be very surprised
when you realize that the role isn't even available to you
•And also, keep in mind, the IP address lease, is for the
lifetime of the virtual machine, until you restart, stop or
deallocate theVM
Tenminute.tech
18. Azure-provided name resolution
•Azure provides internal name resolution forVMs and role
instances that reside within the same virtual network or cloud
service
•VMs/instances in a Cloud Service share the same DNS suffix
• DNS names can be assigned to both NICs andVMs
•You can roll your own DNS if required
Tenminute.tech