SlideShare a Scribd company logo
Agenda
Network infrastructure
Four pillars of Azure Networking
Multi-access edge compute tech preview
Our mission
To provide the most secure, trusted, reliable
and performant network for your
workloads, delivered and managed from
the Intelligent Cloud to the Intelligent Edge
Microsoft global network
54 Azure
regions 130k+ miles of fiber +
subsea cables 160+edge
sites 500+network
partners 20k+peering
connections
Region
Edge
Network
Connecting Azure regions to the global network
Edge
Enterprise peering
P R I V A T E
Internet peering
P U B L I C
Microsoft Wide Area Network
Regional Gateways
Availability Zone
D C
D C D C
Availability Zone
D C
D C D C
Availability Zone
D C
D C D C
Azure Region
Microsoft Global Network (WAN)
The Azure Network Edge
Traffic to and between DCs
WAN
core routers
Azure
ExpressRoute
Azure Front Door,
CDN, WAF
Azure Network Edge
Internet and private network
Modernizing your
network
Azure
Networking
services
Azure Peering Service
Monitoring
Peering service platform
Operational
insights
MS Peering
partner
Internet
Customer
Enterprise grade
Internet connectivity
User telemetry RADAR
Connectivity partners
•
•
•
Telemetry platform
•
•
•
Route Anomalies Detection and
Auto Remediation (RADAR)

Delivering optimal public Internet
connectivity to Microsoft Cloud
PREVIEW
BRK2144 | 11/05 (3:30 - 4:15 PM) | Selecting the correct network connectivity service for your workloads
Azure Virtual WAN
Region 2
Region 1
Region 3
Datacenter
Point-to-site VPN
ExpressRoute
VNet
VNet
VNet
Corp HQ
Branch Branch Branch Branch
VNet
• ExpressRoute Integration
• Point to site VPN Integration
• Path selection from branch
GA
PREVIEW
• Hub/Any-to-any connectivity
• Azure Firewall integration
Provides optimized and automated
branch connectivity to, and
through Azure
BRK3138 | 11/06 (9:15 - 10 AM) | Global transit network architectures with Azure Virtual WAN
ExpressRoute
Fast Path
• Improved throughput, packets/sec, connections/sec,
number of flows
ExpressRoute Site
Customer
Cage
Microsoft
Cage
GA
PREVIEW
MACsec encryption
• Secures physical links at ExpressRoute sites
• Bring-your-own-key, store keys in Azure Key Vault
• Available on ER Direct
ExpressRoute Local
• No egress charges from Azure to local ER site
Continued expansion of ER locations
BRK3172 | 11/06 (3:30 – 4:15 PM) | Advanced networking best practices with Azure ExpressRoute
MACsec
SKUs
Aggregate
throughput
P2S
connections
IKEv1/v2
VpnGw1 650 Mbps 250 IKEv1+IKEv2
VpnGw2 1 Gbps 500 IKEv1+IKEv2
VpnGw3 2.5 Gbps 1000 IKEv1+IKEv2
VpnGw4 5 Gbps 5,000 IKEv1+IKEv2
VpnGw5 10 Gbps 10,000 IKEv1+IKEv2
VPN
PREVIEW
PREVIEWAAD auth + MFA
Azure VPN Client (Windows App)
• OpenVPN protocol
• Native AAD authentication with MFA
• Client-side Diagnostics, Logs, & Metrics
High throughput VPN – 10Gbps
• New Azure VPN gateways – VpnGw3/4/5
• Up to 10 Gbps aggregate
• Up to 10,000 P2S connections
IKEv1 + IKEv2 on VpnGw1-5
• IKEv1 on new VpnGw SKUs (1 ~ 5)
• Multiple IKEv1 S2S tunnels
• IKEv1 and IKEv2 on the same VPN gateway
VPN gateway packet capture
• With 5-tuple packet filter
• ETW or PCAP formats
Custom IKE traffic selectors
PREVIEW
GA
GA
COMING SOON
BRK2144 | 11/05 (3:30 - 4:15 PM) | Selecting the correct network connectivity service for your workloads
IPv6 in Azure VNETs
THR3111 | 11/05 (4:20 - 4:40 PM) | GA launch of IPv6 for Azure VNETs
"We've grown to value and trust the stability and
reliability of IPv6 connectivity in Azure. As we look to
expand our cloud-based portfolio and offer additional
services for the 65 million endpoints we manage
globally, IPv6 capability is a key enabler for adapting
our IoT framework to the cloud.”
Greg Richards, SVP, Technology & Research, Itron
Native IPv6 all the way to the VMs
Private IPv6 addresses for VMs and NICs
Dual stacked IPv4/IPv6 VMs for max flexibility
GA
Internet
IPv6 User-
Defined
Routes
IPv6
NSG
Rules
IPv6
Load
Balancer
IPv6
IPv6
IPv4
Windows VM
Front-End
Subnet
IPv6
NSG
RulesApplication
Subnet
DDoS Protection
IPv6
IPv4
Linux VM
Azure Virtual Network Dual Stacked (IPv4+IPv6)
Azure
Networking
services
Modernizing your
network
Achieving Zero Trust with Azure Networking
Cloud-native network security services
Defense-in-depth
+
Software Defined Network (SDN)
Virtual
Networks
Network
Security Groups
User Defined
Routes
Load
Balancer
Azure
Firewall
Azure DDoS
Protection
Azure Web
Application Firewall
Azure
Private Link
Azure Private Link
Highly secure and private connectivity to Azure services
Private access from VNets,
peered VNets and
on-premises
In-built Data
Exfiltration Protection
Predictable private IP
addresses for PaaS
resources
Unified experience across
PaaS, Customer Owned
and marketplace Services
Private Link for Azure Storage, SQL DB and data exfiltration protection
PREVIEW
BRK3168 | 11/07 (9:15 - 10 AM) | Delivering services privately in your VNet with Azure Private Link
Azure PaaS and
marketplace services
ER Gateway
Private
endpoint
10.0.0.5
Deny Internet
On-premises
Virtual Network (10.0.0.0/16)
Private
Link
Storage SQL DWSQL Marketplace
Azure Firewall Manager
Central deployment and configuration
•
•
Automated routing
•
Advanced security with 3rd party SECaaS
•
•
PREVIEW
Virtual Network support, Split routing
•
•
ROADMAP
Central network security policy and route management
for globally distributed, software-defined perimeters
Global admin
Global policy
Azure region 1 Azure region N
Azure
Firewall
Secured
vHub
Azure
Firewall
Secured
vHub
Local admin
HQ/
branch
Virtual WAN
ER/VPN
Datacenter
Virtual WAN
ER/VPN
End-user
devices
VPN
VNet
3rd party
partners
3rd party
partners
Azure Firewall Manager
Trusted security partners
Use Azure as your Secured Internet Edge
Use best-in-breed third-
party Security-as-a-
Service (SECaaS)
partners with Azure
Firewall Manager
Protect VNet-to-
Internet or Branch-to-
Internet user traffic
Combine with Azure
Firewall for layered
security
Breakout Office 365
traffic directly at branch;
filter rest of Internet
traffic using SECaaS on
Azure
BRK3170 | 11/07 (3:30 - 4:15 PM) | Building and Managing distributed micro-perimeters with Azure Firewall
AVAILABLE IN PREVIEW COMING SOON
BRK3185 | 11/06 (2:15 - 3 PM) | Securing your cloud perimeter with Azure Network Security
Azure Bastion
Secure and seamless RDP and SSH access to your
virtual machines
GA
RDP/SSH to your workload using HTML5 standards-
based web-browser, directly in Azure Portal
Resources can be accessed without public IP
addresses
Supported Azure resources include VMs, VM Scale
Sets, Dev-Test Labs
Azure Portal
Remote Protocol
(RDP, SSH, et al)
SSL
443,
Internet
AzureBastionSubnet
Port: 3389/22
“AzureBastionSubnet”
Target VM Subnet(s)
Private IP
Azure VM
Azure VM
Azure VM
Customer’s Virtual Network
SSL
Azure Bastion
Azure WAF
BRK3171 | 11/08 (9:15 - 10 AM) | Using Azure Web Application Firewall to protect your web applications and web APIs
Azure Global WAF
(Front Door)
Azure Regional WAF
(Application Gateway)
Uniform policy
WAF policy
PaaS, IaaS and on-premises backends
OWASP rules
Bot management
Custom rules
Microsoft threat intelligence
•
•
Site and URI path specific WAF policies

Geo filtering on regional WAF

PREVIEW
Unified WAF offering
•
Web Application Firewall
Azure
Networking
services
Modernizing your
network
BRK3169 | 11/07 (2:15 - 3 PM) | Deliver highly available and secure web applications with Azure Application Gateway and WAF
Application Gateway
Azure Kubernetes Services (AKS) Ingress Controller
•
•
Azure Key Vault integration
•
Enhanced Metrics
•
GA
Wildcard listener
•
COMING SOON
Application
Gateway
Azure ARM
Azure Key Vault
Azure Kubernetes
Services (AKS)
AKS API
server
AG Ingress
Controller
Pods
Application Gateway routing rules
Application Delivery Controller
BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge
Azure Front Door
Global entry point for high performance, high
availability web applications
GA
Single or multi-region app and API acceleration

Load balancing at the Edge and fast-failover

Integrated SSL, WAF and DDoS

Single region apps
Network Edge POP
Azure region
www.contoso.com
Global
Network
/*
/search/*
Accelerate
Multi-region apps
Network Edge POP
Azure region 1
www.contoso.com
Global
Network
Accelerate
Azure region 2
Failover
Azure CDN
Cost efficient, reliable global content distribution
GA
Reduced Azure egress pricing
•
PREVIEW
Easy to use and highly customizable rules engine
•
•
Azure Region
On-premise/external
Media services
Storage
App service
Edge delivery partners
www.contoso.com
vod.contoso.com
API
Mobile
Media
IoT
Updates
Files
BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge
Azure
Networking
services
Modernizing your
network
Internet Analyzer
Easily measure and compare end user
experience for your application
Cloud migration
Measure the impact of moving the web app to cloud
PREVIEW
CDN and app acceleration
Measure the performance impact of Front Door and CDN
Perform A/B measurements
Measure end user performance of two versions of app
or impact of multiple region deployments
Your real end users,
your customers around the globe
2
Configure your
tests
3
Get your global
perf scorecards
1 Deploy internet
analyzer client
Delivered with
your app
Your current
application
architecture
“What-if”
application
architecture
The
internet
A C T I V E
P E R F O R M A N C E
M E A S U R E M E N T S
Test
configuration
Measurement data
BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge
Azure monitor for networks
Traffic analytics – accelerated processing
 From hours to minutes, faster insights into application and
network activity
GA
Enhanced troubleshooting
• Improved connectivity checks for load balancers, global peering,
cross region connectivity, User Defined Routes, NVAs, ExpressRoute
Monitoring and troubleshooting for cloud and
hybrid networks
Network insights
• Single health console for the entire cloud network
• No agent/configuration required
PREVIEW
Brk30176 enterprise class networking in azure

More Related Content

What's hot

AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
Amazon Web Services
 
Bct Aws-VPC-Training
Bct Aws-VPC-TrainingBct Aws-VPC-Training
Bct Aws-VPC-Training
Kimberly Macias
 
ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...
ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...
ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...
Amazon Web Services
 
(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014
(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014
(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014
Amazon Web Services
 
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation FirewallCisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
Cisco Canada
 
CCI2018 - Azure Network - Security Best Practices
CCI2018 - Azure Network - Security Best PracticesCCI2018 - Azure Network - Security Best Practices
CCI2018 - Azure Network - Security Best Practices
walk2talk srl
 
Putting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation FirewallPutting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation Firewall
Cisco Canada
 
Understanding Azure Networking Services
Understanding Azure Networking ServicesUnderstanding Azure Networking Services
Understanding Azure Networking Services
InCycleSoftware
 
(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect
Amazon Web Services
 
AWS Network Topology/Architecture
AWS Network Topology/ArchitectureAWS Network Topology/Architecture
AWS Network Topology/Architecture
wlscaudill
 
Cisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Connect Toronto 2017 - Model-driven TelemetryCisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Canada
 
(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...
(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...
(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...
Amazon Web Services
 
Palo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & CompliancePalo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & Compliance
Amazon Web Services
 
Azure Hub spoke v1.0
Azure Hub spoke v1.0Azure Hub spoke v1.0
Azure Hub spoke v1.0
Sayed Ashraf Kazi
 
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
Amazon Web Services
 
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
Amazon Web Services
 
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel AvivDouble Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Amazon Web Services
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure Networking
Pedro Sousa
 
Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)
Amazon Web Services
 
(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design
Amazon Web Services
 

What's hot (20)

AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
 
Bct Aws-VPC-Training
Bct Aws-VPC-TrainingBct Aws-VPC-Training
Bct Aws-VPC-Training
 
ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...
ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...
ARC206 Extend your Existing Data Center to the cloud with Amazon VPC - AWS re...
 
(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014
(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014
(SDD422) Amazon VPC Deep Dive | AWS re:Invent 2014
 
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation FirewallCisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
Cisco Connect Toronto 2017 - Putting Firepower into the Next Generation Firewall
 
CCI2018 - Azure Network - Security Best Practices
CCI2018 - Azure Network - Security Best PracticesCCI2018 - Azure Network - Security Best Practices
CCI2018 - Azure Network - Security Best Practices
 
Putting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation FirewallPutting Firepower Into The Next Generation Firewall
Putting Firepower Into The Next Generation Firewall
 
Understanding Azure Networking Services
Understanding Azure Networking ServicesUnderstanding Azure Networking Services
Understanding Azure Networking Services
 
(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect
 
AWS Network Topology/Architecture
AWS Network Topology/ArchitectureAWS Network Topology/Architecture
AWS Network Topology/Architecture
 
Cisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Connect Toronto 2017 - Model-driven TelemetryCisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Connect Toronto 2017 - Model-driven Telemetry
 
(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...
(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...
(ENT308) Best Practices for Implementing Hybrid Architecture Solutions | AWS ...
 
Palo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & CompliancePalo Alto Networks: Protection for Security & Compliance
Palo Alto Networks: Protection for Security & Compliance
 
Azure Hub spoke v1.0
Azure Hub spoke v1.0Azure Hub spoke v1.0
Azure Hub spoke v1.0
 
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
 
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
 
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel AvivDouble Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure Networking
 
Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)
 
(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design
 

Similar to Brk30176 enterprise class networking in azure

CCI2019 - Architecting and Implementing Azure Networking
CCI2019 - Architecting and Implementing Azure NetworkingCCI2019 - Architecting and Implementing Azure Networking
CCI2019 - Architecting and Implementing Azure Networking
walk2talk srl
 
Securing your cloud perimeter with azure network security brk3185
Securing your cloud perimeter with azure network security brk3185Securing your cloud perimeter with azure network security brk3185
Securing your cloud perimeter with azure network security brk3185
jtaylor707
 
A Deepdive into Azure Networking
A Deepdive into Azure NetworkingA Deepdive into Azure Networking
A Deepdive into Azure Networking
Karim Vaes
 
Global Azure Bootcamp 2018 - Azure Network Security
Global Azure Bootcamp 2018 - Azure Network SecurityGlobal Azure Bootcamp 2018 - Azure Network Security
Global Azure Bootcamp 2018 - Azure Network Security
Scott Hoag
 
Perth Azure Usergroup Build 2018 updates
Perth Azure Usergroup Build 2018 updatesPerth Azure Usergroup Build 2018 updates
Perth Azure Usergroup Build 2018 updates
Nirmal Thewarathanthri
 
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – BarracudaProtección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Plain Concepts
 
Connect your datacenter to Microsoft Azure
Connect your datacenter to Microsoft AzureConnect your datacenter to Microsoft Azure
Connect your datacenter to Microsoft Azure
K.Mohamed Faizal
 
VMworld 2013: Virtualized Network Services Model with VMware NSX
VMworld 2013: Virtualized Network Services Model with VMware NSX VMworld 2013: Virtualized Network Services Model with VMware NSX
VMworld 2013: Virtualized Network Services Model with VMware NSX
VMworld
 
Getting Started on AWS
Getting Started on AWS Getting Started on AWS
Getting Started on AWS
Amazon Web Services
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
nvirters
 
Building Intelligent Cloud with Microsoft Azure
Building Intelligent Cloud with Microsoft AzureBuilding Intelligent Cloud with Microsoft Azure
Building Intelligent Cloud with Microsoft Azure
WinWire Technologies Inc
 
Introduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best PracticesIntroduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best Practices
Gary Silverman
 
Azure Express Route
Azure Express RouteAzure Express Route
Azure Express Route
Mustafa
 
Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...
Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...
Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...
SkillFactory
 
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
Amazon Web Services
 
Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...
Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...
Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...
David J Rosenthal
 
Microsoft Azure : Hey ITPRo's Meet Azure .. .again!
Microsoft Azure : Hey ITPRo's Meet Azure .. .again!Microsoft Azure : Hey ITPRo's Meet Azure .. .again!
Microsoft Azure : Hey ITPRo's Meet Azure .. .again!
Mike Martin
 
azure track -03- it pros meet azure - again
azure track -03- it pros meet azure - againazure track -03- it pros meet azure - again
azure track -03- it pros meet azure - again
ITProceed
 
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
Amazon Web Services
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
Amazon Web Services
 

Similar to Brk30176 enterprise class networking in azure (20)

CCI2019 - Architecting and Implementing Azure Networking
CCI2019 - Architecting and Implementing Azure NetworkingCCI2019 - Architecting and Implementing Azure Networking
CCI2019 - Architecting and Implementing Azure Networking
 
Securing your cloud perimeter with azure network security brk3185
Securing your cloud perimeter with azure network security brk3185Securing your cloud perimeter with azure network security brk3185
Securing your cloud perimeter with azure network security brk3185
 
A Deepdive into Azure Networking
A Deepdive into Azure NetworkingA Deepdive into Azure Networking
A Deepdive into Azure Networking
 
Global Azure Bootcamp 2018 - Azure Network Security
Global Azure Bootcamp 2018 - Azure Network SecurityGlobal Azure Bootcamp 2018 - Azure Network Security
Global Azure Bootcamp 2018 - Azure Network Security
 
Perth Azure Usergroup Build 2018 updates
Perth Azure Usergroup Build 2018 updatesPerth Azure Usergroup Build 2018 updates
Perth Azure Usergroup Build 2018 updates
 
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – BarracudaProtección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
Protección y acceso a tu información y aplicaciones en Azure y O365 – Barracuda
 
Connect your datacenter to Microsoft Azure
Connect your datacenter to Microsoft AzureConnect your datacenter to Microsoft Azure
Connect your datacenter to Microsoft Azure
 
VMworld 2013: Virtualized Network Services Model with VMware NSX
VMworld 2013: Virtualized Network Services Model with VMware NSX VMworld 2013: Virtualized Network Services Model with VMware NSX
VMworld 2013: Virtualized Network Services Model with VMware NSX
 
Getting Started on AWS
Getting Started on AWS Getting Started on AWS
Getting Started on AWS
 
Banv meetup-contrail
Banv meetup-contrailBanv meetup-contrail
Banv meetup-contrail
 
Building Intelligent Cloud with Microsoft Azure
Building Intelligent Cloud with Microsoft AzureBuilding Intelligent Cloud with Microsoft Azure
Building Intelligent Cloud with Microsoft Azure
 
Introduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best PracticesIntroduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best Practices
 
Azure Express Route
Azure Express RouteAzure Express Route
Azure Express Route
 
Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...
Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...
Конференция Brocade. 3. Повышение гибкости и эффективности применения баланси...
 
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
DEM08 Use Cisco Cloud Connect to Securely Extend Private Network to AWS and M...
 
Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...
Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...
Latest Microsoft Azure Solutions and Announcements - Presented by atidan june...
 
Microsoft Azure : Hey ITPRo's Meet Azure .. .again!
Microsoft Azure : Hey ITPRo's Meet Azure .. .again!Microsoft Azure : Hey ITPRo's Meet Azure .. .again!
Microsoft Azure : Hey ITPRo's Meet Azure .. .again!
 
azure track -03- it pros meet azure - again
azure track -03- it pros meet azure - againazure track -03- it pros meet azure - again
azure track -03- it pros meet azure - again
 
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 

Recently uploaded

Uni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdfUni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems S.M.S.A.
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
Aftab Hussain
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
Zilliz
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Zilliz
 
Large Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial ApplicationsLarge Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial Applications
Rohit Gautam
 
“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”
Claudio Di Ciccio
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Speck&Tech
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
DianaGray10
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
KAMESHS29
 
Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...
Zilliz
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
mikeeftimakis1
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
SOFTTECHHUB
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
James Anderson
 

Recently uploaded (20)

Uni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdfUni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdf
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 
Removing Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software FuzzingRemoving Uninteresting Bytes in Software Fuzzing
Removing Uninteresting Bytes in Software Fuzzing
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
Introducing Milvus Lite: Easy-to-Install, Easy-to-Use vector database for you...
 
Large Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial ApplicationsLarge Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial Applications
 
“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”“I’m still / I’m still / Chaining from the Block”
“I’m still / I’m still / Chaining from the Block”
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
 
Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...Building RAG with self-deployed Milvus vector database and Snowpark Container...
Building RAG with self-deployed Milvus vector database and Snowpark Container...
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
Goodbye Windows 11: Make Way for Nitrux Linux 3.5.0!
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
 

Brk30176 enterprise class networking in azure

  • 1.
  • 2.
  • 3.
  • 4. Agenda Network infrastructure Four pillars of Azure Networking Multi-access edge compute tech preview
  • 5. Our mission To provide the most secure, trusted, reliable and performant network for your workloads, delivered and managed from the Intelligent Cloud to the Intelligent Edge
  • 6.
  • 7. Microsoft global network 54 Azure regions 130k+ miles of fiber + subsea cables 160+edge sites 500+network partners 20k+peering connections Region Edge Network
  • 8.
  • 9. Connecting Azure regions to the global network Edge Enterprise peering P R I V A T E Internet peering P U B L I C Microsoft Wide Area Network Regional Gateways Availability Zone D C D C D C Availability Zone D C D C D C Availability Zone D C D C D C Azure Region
  • 10. Microsoft Global Network (WAN) The Azure Network Edge Traffic to and between DCs WAN core routers Azure ExpressRoute Azure Front Door, CDN, WAF Azure Network Edge Internet and private network
  • 12.
  • 13. Azure Peering Service Monitoring Peering service platform Operational insights MS Peering partner Internet Customer Enterprise grade Internet connectivity User telemetry RADAR Connectivity partners • • • Telemetry platform • • • Route Anomalies Detection and Auto Remediation (RADAR)  Delivering optimal public Internet connectivity to Microsoft Cloud PREVIEW BRK2144 | 11/05 (3:30 - 4:15 PM) | Selecting the correct network connectivity service for your workloads
  • 14. Azure Virtual WAN Region 2 Region 1 Region 3 Datacenter Point-to-site VPN ExpressRoute VNet VNet VNet Corp HQ Branch Branch Branch Branch VNet • ExpressRoute Integration • Point to site VPN Integration • Path selection from branch GA PREVIEW • Hub/Any-to-any connectivity • Azure Firewall integration Provides optimized and automated branch connectivity to, and through Azure BRK3138 | 11/06 (9:15 - 10 AM) | Global transit network architectures with Azure Virtual WAN
  • 15. ExpressRoute Fast Path • Improved throughput, packets/sec, connections/sec, number of flows ExpressRoute Site Customer Cage Microsoft Cage GA PREVIEW MACsec encryption • Secures physical links at ExpressRoute sites • Bring-your-own-key, store keys in Azure Key Vault • Available on ER Direct ExpressRoute Local • No egress charges from Azure to local ER site Continued expansion of ER locations BRK3172 | 11/06 (3:30 – 4:15 PM) | Advanced networking best practices with Azure ExpressRoute MACsec
  • 16. SKUs Aggregate throughput P2S connections IKEv1/v2 VpnGw1 650 Mbps 250 IKEv1+IKEv2 VpnGw2 1 Gbps 500 IKEv1+IKEv2 VpnGw3 2.5 Gbps 1000 IKEv1+IKEv2 VpnGw4 5 Gbps 5,000 IKEv1+IKEv2 VpnGw5 10 Gbps 10,000 IKEv1+IKEv2 VPN PREVIEW PREVIEWAAD auth + MFA Azure VPN Client (Windows App) • OpenVPN protocol • Native AAD authentication with MFA • Client-side Diagnostics, Logs, & Metrics High throughput VPN – 10Gbps • New Azure VPN gateways – VpnGw3/4/5 • Up to 10 Gbps aggregate • Up to 10,000 P2S connections IKEv1 + IKEv2 on VpnGw1-5 • IKEv1 on new VpnGw SKUs (1 ~ 5) • Multiple IKEv1 S2S tunnels • IKEv1 and IKEv2 on the same VPN gateway VPN gateway packet capture • With 5-tuple packet filter • ETW or PCAP formats Custom IKE traffic selectors PREVIEW GA GA COMING SOON BRK2144 | 11/05 (3:30 - 4:15 PM) | Selecting the correct network connectivity service for your workloads
  • 17. IPv6 in Azure VNETs THR3111 | 11/05 (4:20 - 4:40 PM) | GA launch of IPv6 for Azure VNETs "We've grown to value and trust the stability and reliability of IPv6 connectivity in Azure. As we look to expand our cloud-based portfolio and offer additional services for the 65 million endpoints we manage globally, IPv6 capability is a key enabler for adapting our IoT framework to the cloud.” Greg Richards, SVP, Technology & Research, Itron Native IPv6 all the way to the VMs Private IPv6 addresses for VMs and NICs Dual stacked IPv4/IPv6 VMs for max flexibility GA Internet IPv6 User- Defined Routes IPv6 NSG Rules IPv6 Load Balancer IPv6 IPv6 IPv4 Windows VM Front-End Subnet IPv6 NSG RulesApplication Subnet DDoS Protection IPv6 IPv4 Linux VM Azure Virtual Network Dual Stacked (IPv4+IPv6)
  • 19.
  • 20. Achieving Zero Trust with Azure Networking Cloud-native network security services Defense-in-depth + Software Defined Network (SDN) Virtual Networks Network Security Groups User Defined Routes Load Balancer Azure Firewall Azure DDoS Protection Azure Web Application Firewall Azure Private Link
  • 21. Azure Private Link Highly secure and private connectivity to Azure services Private access from VNets, peered VNets and on-premises In-built Data Exfiltration Protection Predictable private IP addresses for PaaS resources Unified experience across PaaS, Customer Owned and marketplace Services Private Link for Azure Storage, SQL DB and data exfiltration protection PREVIEW BRK3168 | 11/07 (9:15 - 10 AM) | Delivering services privately in your VNet with Azure Private Link Azure PaaS and marketplace services ER Gateway Private endpoint 10.0.0.5 Deny Internet On-premises Virtual Network (10.0.0.0/16) Private Link Storage SQL DWSQL Marketplace
  • 22. Azure Firewall Manager Central deployment and configuration • • Automated routing • Advanced security with 3rd party SECaaS • • PREVIEW Virtual Network support, Split routing • • ROADMAP Central network security policy and route management for globally distributed, software-defined perimeters Global admin Global policy Azure region 1 Azure region N Azure Firewall Secured vHub Azure Firewall Secured vHub Local admin HQ/ branch Virtual WAN ER/VPN Datacenter Virtual WAN ER/VPN End-user devices VPN VNet 3rd party partners 3rd party partners
  • 23. Azure Firewall Manager Trusted security partners Use Azure as your Secured Internet Edge Use best-in-breed third- party Security-as-a- Service (SECaaS) partners with Azure Firewall Manager Protect VNet-to- Internet or Branch-to- Internet user traffic Combine with Azure Firewall for layered security Breakout Office 365 traffic directly at branch; filter rest of Internet traffic using SECaaS on Azure BRK3170 | 11/07 (3:30 - 4:15 PM) | Building and Managing distributed micro-perimeters with Azure Firewall AVAILABLE IN PREVIEW COMING SOON
  • 24. BRK3185 | 11/06 (2:15 - 3 PM) | Securing your cloud perimeter with Azure Network Security Azure Bastion Secure and seamless RDP and SSH access to your virtual machines GA RDP/SSH to your workload using HTML5 standards- based web-browser, directly in Azure Portal Resources can be accessed without public IP addresses Supported Azure resources include VMs, VM Scale Sets, Dev-Test Labs Azure Portal Remote Protocol (RDP, SSH, et al) SSL 443, Internet AzureBastionSubnet Port: 3389/22 “AzureBastionSubnet” Target VM Subnet(s) Private IP Azure VM Azure VM Azure VM Customer’s Virtual Network SSL Azure Bastion
  • 25. Azure WAF BRK3171 | 11/08 (9:15 - 10 AM) | Using Azure Web Application Firewall to protect your web applications and web APIs Azure Global WAF (Front Door) Azure Regional WAF (Application Gateway) Uniform policy WAF policy PaaS, IaaS and on-premises backends OWASP rules Bot management Custom rules Microsoft threat intelligence • • Site and URI path specific WAF policies  Geo filtering on regional WAF  PREVIEW Unified WAF offering • Web Application Firewall
  • 27.
  • 28. BRK3169 | 11/07 (2:15 - 3 PM) | Deliver highly available and secure web applications with Azure Application Gateway and WAF Application Gateway Azure Kubernetes Services (AKS) Ingress Controller • • Azure Key Vault integration • Enhanced Metrics • GA Wildcard listener • COMING SOON Application Gateway Azure ARM Azure Key Vault Azure Kubernetes Services (AKS) AKS API server AG Ingress Controller Pods Application Gateway routing rules Application Delivery Controller
  • 29. BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge Azure Front Door Global entry point for high performance, high availability web applications GA Single or multi-region app and API acceleration  Load balancing at the Edge and fast-failover  Integrated SSL, WAF and DDoS  Single region apps Network Edge POP Azure region www.contoso.com Global Network /* /search/* Accelerate Multi-region apps Network Edge POP Azure region 1 www.contoso.com Global Network Accelerate Azure region 2 Failover
  • 30. Azure CDN Cost efficient, reliable global content distribution GA Reduced Azure egress pricing • PREVIEW Easy to use and highly customizable rules engine • • Azure Region On-premise/external Media services Storage App service Edge delivery partners www.contoso.com vod.contoso.com API Mobile Media IoT Updates Files BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge
  • 32.
  • 33. Internet Analyzer Easily measure and compare end user experience for your application Cloud migration Measure the impact of moving the web app to cloud PREVIEW CDN and app acceleration Measure the performance impact of Front Door and CDN Perform A/B measurements Measure end user performance of two versions of app or impact of multiple region deployments Your real end users, your customers around the globe 2 Configure your tests 3 Get your global perf scorecards 1 Deploy internet analyzer client Delivered with your app Your current application architecture “What-if” application architecture The internet A C T I V E P E R F O R M A N C E M E A S U R E M E N T S Test configuration Measurement data BRK2146 | 11/07 (11:45 AM - 12:30 PM) | Taking applications and content to the edge
  • 34. Azure monitor for networks Traffic analytics – accelerated processing  From hours to minutes, faster insights into application and network activity GA Enhanced troubleshooting • Improved connectivity checks for load balancers, global peering, cross region connectivity, User Defined Routes, NVAs, ExpressRoute Monitoring and troubleshooting for cloud and hybrid networks Network insights • Single health console for the entire cloud network • No agent/configuration required PREVIEW