MCP/MCTS
Radu
Vunvulea
Technology
enthusiastic
Azure MVP
Blogger
Speaker
Open
minded
Geek
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
!
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
DBDB
Storage
Storage
Storage
VM
Storage
VM
VM
Backup
Audit
Security
Center
Monitor
ing
VM
VM
VM
Subnet
Subnet
Virtual
Appliance
IN & OUT 53 DNS traffic cannonical port Allowed
IN 3389 Remote Desktop
Connection
Allowed
IN All Traffic from internet to our
firewall (Virtual Appliance -
NGFW)
Allowed
OUT* 1688 VM Licence check Allowed
OUT All Traffic from VNET to
internet
Denied
IN** 168.63.129.16 Unique IP used by Azure
for DHCP, DNS, Azure Load
Balance
Allow
VNET | Subnet | UDR | IP FW | NGS | Site-to-Site VPN | Point-to-Site VPN | Express Route
Questions
Answers
{
“name” : “Radu Vunvulea,
“blog” : “vunvulearadu.blogspot.com”,
“email” : ”vunvulear@outlook.com”,
“socialMedia” :
{
“twitter” : “@RaduVunvulea”,
“fb” : “radu.vunvulea”
}
}
https://github.com/Microsoft/azure-
docs/blob/master/articles/best-practices-network-
security.md
{
“name” : “Radu Vunvulea,
“blog” : “vunvulearadu.blogspot.com”,
“email” : ”vunvulear@outlook.com”,
“socialMedia” :
{
“twitter” : “@RaduVunvulea”,
“fb” : “radu.vunvulea”
}
}

Network isolated inside a cloud environment Radu Vunvulea DevTalks 2017 Cluj Romania