43
Learn. Connect. Explore. Learn. Connect. Explore.

Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

  • Upload
    others

  • View
    14

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Learn. Connect. Explore.Learn. Connect. Explore.

Page 2: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Nuts & Bolts of Networking in Azure

Pracheta Budhwar

Technology Evangelist, Microsoft India

@prachetab

Page 3: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Agenda

• Must know concepts of networking on Azure

• Scenarios - Most commonly & asked for scenarios

• Recent announcements

• Demos

• Q&A

Page 4: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Customer needs

Availability

Policy

Ecosystem

Global presence

Global connectivity

Scale out

Seamless

Performance

SecurityEnterprise

Grade

HyperScale

Hybrid

Page 5: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

The Big (Network) Picture

Internet Clients

On premises Datacenter

Azure

Virtual Network

Frontend Connectivity

Load-balanced and direct IPs

ACLs & DDoS protection

Traffic Manager & Azure DNS

Virtual Networks

Flexible multi-tier topologies

Backend Connectivity

Secure Internet cross premises

VPN connectivity

ExpressRoute – direct

connectivity

Page 6: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

foo.cloudapp.net VIP

Page 7: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

IP AddressesThere are multiple ways to access a VM by IP address

VIP – Virtual IP address• An internet-facing IP address that is not bound to a specific computer or network interface card.

• The cloud service that the VM sits within is assigned the VIP.

• You can have multiple VMs in a cloud service. They share the same VIP.

DIP – Dynamic IP address• This IP address is dynamically assigned (via DHCP) to your virtual machine by Azure. You rely on

DHCP – Do NOT statically configure your IP address. Even for DCs.

• The IP address lease directly equates to the lifetime of the VM.

• If you create a virtual network, the VM will receive its DIP from that range.

Page 8: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

IP Addresses

Page 9: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Protocols and Endpoints

Page 10: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

DNS Scenarios

SQL Service

SQL Reporting

Service

SQL Analysis Service

AD / DNS

SQL ServiceDomain joined to On-

Premises Network

Azure Virtual Machine(s)

Business Components & Entities

App Logic

UI Process Components

Web Tier

Internet

Persistent VM Role

SharePoint FrontEnd

Persistent VM Role

SharePoint FrontEnd

Persistent VM Role

Search and Indes

SQL Service

Cloud Service

DC DNS

Persistent VM Role

SQL

Persistent VM Role

SQL

Local DNS

SQ

L A

lwaysO

n

Open User Access (Website)

Page 11: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Connecting Cloud Services with VNET

Page 12: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

P2SVPNs

Existing datacenter

S2S VPN

Page 13: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

On-premises

Your datacenter

Hardware VPN or Windows RRAS

Microsoft Azure

Virtual Network

<subnet 1> <subnet 2> <subnet 3>

DNS Server

HA VPN Gateway

• Extend your premises to the cloud securely

• On-ramp for migrating services to the cloud

• Use your on-prem resources in Azure (monitoring, AD, …)

Page 14: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created
Page 15: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Traffic Manager: DNS-based Load Balancing

www.yourapp.com

Performance - Direct to “closest” service based on network latency

Round-robin - Distribute equally across all services

Failover - Direct to “backup” service if primary fails—also included in other policies

Page 16: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Traffic Management Fundamentals

Page 17: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Announcements in last 6 months..

• Internet connectivity• Traffic Manager External Endpoints

• Instance Level Public IP (Preview)

• IP Reservation for VIPs

• Intra-region communication• Internal Load Balancing

• In-Region VNet to VNet

• Cross-premises connectivity• Multiple-Site VPN

• Cross-Region Vnet to Vnet

• ExpressRoute

Page 18: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Before With multi-site Vnet Connectivity

VNet1US West

VNet2East Asia

Page 19: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Before With multi-site and cross-region VNet to VNet

VNet1US West

VNet2East Asia

Page 20: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

WAN

Corp HQ

Branch office 1

Branch office 2

Public internet

Express Route - Customer want Azure on their Network

WAN

Corp HQ

Branch office 1

Branch Office 2

Public internet

Page 21: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Announcements in last 1 week..

Internet connectivity• Reverse DNS (PTR) Support

• Traffic Manager Nested Profiles

• Instance Level Public IP GA

• Source IP-based Affinity

• TCP flow idle connection timeout

Virtual network• Network Security Group

• Public non-RFC1918 IPs in VNet

• ILB for SQL Always On

Cross-premises connectivity• Forced Tunneling for IPsec VPNs

• ExpressRoute Multi-Subscription Circuit Sharing

• ExpressRoute Multi-Circuit VNet

• High Performance VPN gateway

• VPN/ExpressRoute Operation Logs

• IPsec VPN NULL encryption & PFS

Network Virtual Appliance• Multiple NICs per VM

• MAC persistence

Page 22: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Internet Conectivity

Page 23: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Enable richer profiles with greater flexibility for large/complex deployments

Traffic Manager Nested Profiles

Level 2: Route to nearest Region, with cross-region failover within the Geo

Level 3: Load-balance within the region, divert 1% for flighting

US West US East Europe Europe

Cloud Services

Example: Cross-region failover within a Geo, plus in-region flighting

Page 24: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Instance-Level Public IP GA

• Internet IP assigned to a single VM

• Entire port ranges are accessible

• Support applications with dynamic public ports; e.g., FTP, multi-media

• Ideal for workloads with heavy outbound connections

Instance level public IPs

Internet

VM1 VM2

Cloud service Reserved VIP

LB

Page 25: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Source IP-based Affinity

• All connections from the same Internet client IP to the same backend server• 2-tuple/3-tuple hash

• Scenarios• Applications that require multiple

connections to the same server

• Example: media streaming to establish control and data channel to same backend server

Azure Load Balancer

Page 26: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Increasing Idle Connection Timeout

Configurable connection timeout to VIPs

Idle connection timeout as high as 30 minutes

Better experience for mobile clients connecting to Azure

Client

Idle Connection Timeout increased up to 30 minutes

Traffic to the VIP

Server 1 Server 2

Page 27: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Virtual Network & Security

Page 28: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Network Security Groups (NSG)

• Enables network segmentation & DMZ scenarios

• Access Control List

• Filter conditions with allow/deny

• Individual addresses, address prefixes,

wildcards

• Associate with VMs or subnets

• ACLs can be updated independent of VMs

Virtual Network

On Premises 10.0/16

Backend10.3/16

Mid-tier10.2/16

Frontend10.1/16

VPN GW

Internet

S2SVPNs

Internet

Page 29: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

DMZ in a Virtual Network

NSG

NSG

NSG

NSG

Page 30: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Multiple NICs in Azure VMs

• Multiple NICs enable virtual appliances in Azure

• MAC/IP addresses persist through VM life cycle

• Separate frontend-backend traffic, and management-data planes

Internet

Azure Virtual Machine

NIC2 NIC1 Default

FrontendSubnet

AppSubnet

BackendSubnet

10.2.2.2210.2.3.33 10.2.1.11

VIP: 133.44.55.66

Up to 4 NICs per VM

Page 31: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Bring Your Appliances to the Cloud

• Building blocks• Multiple NICs

• MAC address persistence

• Appliance ecosystem• Barracuda NG Firewall

• Citrix NetScaler

• Riverbed Steelhead, SteelApp, SteelStore

• More to come!

“Azure Certified”

Page 32: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Hybrid Networking Services

Page 33: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Microsoft Azure hybrid offerings

Cloud Customer Segment and workloads

Secure point-to-site connectivity

Developers• POC Efforts• Small scale deployments• Connect from anywhere

Secure site-to-site VPN connectivity

SMB, Enterprises

• Connect to Azure compute

ExpressRoute private connectivity

SMB & Enterprises• Mission critical workloads• Backup/DR, media, HPC• Connect to all Azure services

Page 34: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Forced Tunneling

• “Force” or redirect customer Internet-bound traffic to an on-premises site

• Auditing & inspecting outbound traffic from Azure

• Needed by many scenarios for critical security and IT policy requirements

Virtual Network

Backend10.3/16

Mid-tier10.2/16

Frontend10.1/16

VPN GW

Internet

On Premises

S2SVPNs

Forced Tunneledvia S2S VPN Internet

Page 35: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Gateway Enhancements• High Performance Gateway

• Better throughput

• More S2S tunnels

• Pricing

• $0.49 per gateway hour

• Data transfer & VNet traffic rates unchanged

• No Encryption option• Better throughput for Vnet-to-

Vnet within Azure

• Intra-/Inter-region Vnet-to-Vnettraffic stays within Microsoft networks, not Internet

• PFS Support for IKE• Compliance requirements &

better security

• Operations Logs• Visibility into critical gateway

events

Gateway

SKU

ExpressRoute

Throughput*

S2S

Throughput*

Max

Tunnels

Default 500 Mbps 100 Mbps 10

Performance 1000 Mbps 200 Mbps 30* Subject to traffic conditions and application behavior

Page 36: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created
Page 37: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

US

• Atlanta

• Chicago

• Dallas

• Los Angeles

• New York

• Seattle

• Silicon Valley, CA

• Washington D.C.

EMEA

• Amsterdam

• London, UK

APAC

• Hong Kong

• Singapore

• Sydney

• Tokyo

• AT&T

• British Telecom

• Colt

• Equinix

• Internet Initiative Japan (IIJ)

• Level3

• Orange

• SingTel

• Tata Communications

• Telecity Group

• Telstra

• Verizon

Azure datacenters

ExpressRoute Locations (today)

New Locations and coming soon

Page 38: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

North Europe

WestEurope

London Amsterdam

Page 39: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Sharing ExpressRoute Connections• Share an ExpressRoute circuit across other subscriptions

• Circuit owner must authorize and can revoke

• Owner gets billed for usage Microsoft Azure

ExpressRoute

Marketing

Sales

R&D

IT

Page 40: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Q&A

Page 41: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Follow us online

Facebookfacebook.com/MicrosoftDeveloper.India

twitter.com/msdevindia

Twitter

Twitter: prachetab

Email: [email protected]

Page 42: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created

Your Feedback is Important

OPTION 3: Feedback stations outside the hall

Fill out evaluation of this session and help shape future events.

OPTION 1 OPTION 2

Replace this space with the

actual QR Code

Page 43: Learn. Connect. Explore.... · •Barracuda NG Firewall •Citrix NetScaler •Riverbed Steelhead, SteelApp, SteelStore •More to come! ... PowerPoint Presentation Author: Test Created