Professional Documents
Culture Documents
Networking
CDP-B227
Yousef Khalidi
Distinguished Engineer
Microsoft Corporation
Agenda
Internet Connectivity
Traffic Manager & DNS
Internet Connectivity & Load Balancing
ExpressRoute
Customer needs Global presence
Global connectivity
Hyper Scale out
Scale
Seamless
Availability
Enterprise Performance
Policy Hybrid Security
Ecosystem Grade
The Big (Network) Picture Virtual Networks
Azure Flexible multi-tier topologies
Virtual Network
Internet Clients
Frontend Connectivity
Load-balanced and direct IPs
ACLs & DDoS protection Backend Connectivity
Traffic Manager & Azure DNS Secure Internet cross premises
VPN connectivity
ExpressRoute – direct
connectivity
On premises
Datacenter
Previous TechEd NA Announcements
Internet connectivity
Traffic Manager External Endpoints
Instance Level Public IP (Preview)
IP Reservation for VIPs
Intra-region communication
Internal Load Balancing
In-Region VNet to VNet
Cross-premises connectivity
Multiple-Site VPN
Cross-Region Vnet to Vnet
ExpressRoute
N
What’s New for TechEd Europe
EW
Internet connectivity Cross-premises
Reverse DNS (PTR) Support connectivity
Traffic Manager Nested Profiles Forced Tunneling for IPsec VPNs
Instance Level Public IP GA ExpressRoute Multi-Subscription
Source IP-based Affinity Circuit Sharing
TCP flow idle connection timeout ExpressRoute Multi-Circuit VNet
High Performance VPN gateway
Virtual network VPN/ExpressRoute Operation Logs
Network Security Group
IPsec VPN NULL encryption & PFS
Public non-RFC1918 IPs in VNet
ILB for SQL Always On Network Virtual Appliance
Multiple NICs per VM
MAC persistence
Internet
Connectivity
Traffic Manager: DNS-based Load Balancing
EW
Enable richer profiles with greater flexibility for
large/complex deployments
Level 1: Route to user’s
Example: Cross-region nearest Geo (US, EU, ASIA)
failover within a Geo,
plus in-region flighting Level 2: Route to nearest
Region, with cross-region
failover within the Geo
Cloud Services
Instance-Level Public IP GA
G
A
Internet IP assigned to a single VM
Entire port ranges are accessible
Support applications with dynamic Internet
public ports; e.g., FTP, multi-media
Ideal for workloads with heavy
151.2.3.4
outbound connections LB Microsoft Azure
VM1 VM2
N
Source IP-based Affinity
EW
All connections from the Client 1 Client 2 Client 3
VIP
Scenarios Azure Load Balancer
Applications that require multiple
connections to the same server
Example: media streaming to
establish control and data channel
to same backend server VM Server VM Server
Instance 1 Instance 2
N
Increasing Idle Connection Timeout
EW
Configurable connection Client
timeout to VIPs
Idle Connection
Traffic to Timeout
Idle connection timeout as high the VIP increased up to
as 30 minutes 30 minutes
LB
Better experience for mobile
clients connecting to Azure
Server 1 Server 2
Virtual Network &
Security
N
Network Security Groups (NSG)
EW
Enables network On Premises 10.0/16
segmentation & DMZ
scenarios Internet
Access Control List
√
S2S Internet
Filter conditions with allow/deny VPNs √
Individual addresses, address
prefixes, wildcards
√ √
Associate with VMs or VPN
GW
DMZ
Database
DNS Servers
NSG
Load Balancer
Internal
Load
Balancer
NSG
App Servers
NSG NSG
Web Proxy
VIRTUAL NETWORK
Virtual Appliance
Platform &
Ecosystem
N
Multiple NICs in Azure VMs
EW
Up to 4 NICs per VM
Multiple NICs enable virtual
appliances in Azure
Azure Virtual Machine
VIP:
133.44.55.66
Internet
Separate frontend-backend
traffic, and management-data Backend
Subnet
App
Subnet
Frontend
Subnet
Appliance ecosystem
Barracuda NG Firewall
Citrix NetScaler
Riverbed Steelhead, SteelApp,
SteelStore
More to come!
Citrix NetScaler &
Azure
Jason Poole
Director PMM Netscaler
Citrix
Work Anywhere Services Anywhere
App Store
Data Sync & Sharing
Windows Desktops
App Store
Apps Data Data Sync & Sharing
Windows Desktops
Personal
Networking & Cloud Infrastructure
• Developers
Secure point-to-site • POC Efforts
connectivity • Small scale deployments
• Connect from anywhere
• SMB, Enterprises
Secure site-to-site • Connect to Azure compute
VPN connectivity
EW
“Force” or redirect customer On Premises
Internet-bound traffic to an
on-premises site Internet
Forced Tunneled
Auditing & inspecting S2S
via S2S VPN Internet
outbound traffic from Azure
VPNs
EW
High Performance Gateway No Encryption option
Better throughput Better throughput for Vnet-to-
More S2S tunnels Vnet within Azure
Pricing Intra-/Inter-region Vnet-to-Vnet
$0.49 per gateway hour traffic stays within Microsoft
Data transfer & VNet traffic rates networks, not Internet
unchanged
PFS Support for IKE
Compliance requirements &
Gateway SKU ExpressRoute S2S Max better security
Throughput* Throughput* Tunnels
Default 500 Mbps 100 Mbps 10 Operations Logs
Performance 1000 Mbps 200 Mbps 30 Visibility into critical gateway
* Subject to traffic conditions and application behavior events
N
Virtual Network VPN Ecosystem
EW
ExpressRoute
Customers want Azure on their network
Branch Office 2 Branch office 2
Azure Azure
N
EW
Exchange Provider Network Service Provider
Microsoft Microsoft
Public Azure Azure
internet Customer site 3
Customer site 2
WAN
Public
Customer site ExpressRoute internet
partner location Customer site 1
ExpressRoute Locations
Locations
US
• Atlanta
• Chicago
• Dallas
• Los Angeles
• New York
• Seattle
• Silicon Valley, CA
• Washington D.C.
EMEA
• Amsterdam
• London, UK
Partners
• AT&T
APAC • British Telecom
• Hong Kong • Colt
• Singapore • Equinix
• Sydney • Internet Initiative Japan (IIJ)
• Tokyo • Level3
• Orange
• SingTel Azure datacenters
• Tata Communications
• Telecity Group ExpressRoute Locations (today)
• Telstra
New Locations and coming soon
• Verizon
Path Diversity for HA and DR
N
EW
North West
One VNet can be linked to many circuits Europe Europe
N
EW
Share an ExpressRoute circuit across other subscriptions
Circuit owner must authorize and can revoke
Owner gets billed for usage Microsoft Azure
On-premises Network
Storage SQL DB Websites
Proxy /
SQL Farm IIS Servers Interner edge
AD / DNS
IT
Monitoring
AD / DNS ExpressRoute
Exchange
AD / DNS
AD / DNS Sales
AD / DNS
R&D
Marketing
In Summary
Enabling more enterprise scenarios
Expanded partnerships
training http://bit.ly/
(Coming soon) (Coming soon) Azure-MVA
Microsoft Azure Architecting Microsoft
Fundamentals Azure Solutions
Get certified for 1/2 the price at TechEd Europe 2014! http://bit.ly/
TechEd-CertDeal
Please Complete An Evaluation Form
Your input is important!