際際滷

際際滷Share a Scribd company logo
/build/2014 Azure
インフラエンジニア鬚吋▲奪廛禰`ト
Japan Windows Azure User Group
@kekekekenta
2014定4埖12晩
? 云Y創はChannel9で巷_されている秤鵑鬚發箸没撹されています。
また、哂Zのw侭がたくさんありますがご阻覚ください。
C http://channel9.msdn.com/Events/Build/2014
はじめに
2
Build 2014 Azure インフラエンジニア鬚吋▲奪廛禰`ト
Public Endpoint ACL(Access Control
Lists)
4
IP: 101. 121.---.255
IP: 127.255. ---.---
? Inboundトラフィックのアクセスコントロ`ルができる。Outbound
トラフィックは畠アクセスがS辛されている。
∀襯優奪肇鍠`クVirtual Networks
Azure
床議∀IPアドレスStatic Virtual Network IP
Addresses
New-AzureVMConfig -Name ^mydns ̄ `
-ImageName $img -InstanceSize Small |
Set-AzureSubnet -SubNetNames $subnet |
Add-AzureProvisioningConfig -Windows `
-AdminUsername $adm -Password $pwd |
Set-AzureStaticVNetIP -IPAddress
"10.0.0.8" |
New-AzureVM -ServiceName $svc -VNetName
$vnet
Build 2014 Azure インフラエンジニア鬚吋▲奪廛禰`ト
Microsoft Azureが戻工する俊A
オンプレミス
デ`タセンタ
ファイアウォ`ル
の坪箸亡耡擇垢
コンピュ`タ
Route-based
VPN
Azure
Virtual Network
<subnet 1> <subnet 2> <subnet 3>
DNS
Server
VPN
Gateway
Point-to-Site VPNs
Virtual Networks & P2S 俊A
? ファイアウォ`ルの坪箸らも俊A辛
嬬
? VPNソフトウェアの弖紗インスト`ル
が駅勣ない
? gに聞うことができる。セットアッ
プもg
? プロトタイピングや_k、デモに宴旋
? P2S と S2S の慌贋
P2S
VPNs
Active
Directory
SharePoint SQL
Server
Azure
Existing
Datacenter
S2S
VPN
On-premises
Your datacenter
Hardware VPN or
Windows RRAS
Azure
Virtual Network
<subnet 1> <subnet 2> <subnet 3>
DNS
Server
VPN
Gateway
Site-to-Site 俊A
? オンプレミスのネットワ`クをクラウドに辛嬬
? On-ramp for migrating services to the cloud
? オンプレミスのリソ`スをAzureで聞喘
粥噛顎姻艶に閣永鰻俊Aするには
Cloud on your WAN
? Avoidsrisks fromexposureto Internet
? Avoidscomplexityand addedcosts
? Provideslower latency, higherbandwidthand
greateravailability
Public cloud
WAN
Customer DC
Customer site 1
Customer site 2
Public
internet
もっと芦畠に
IPsec VPN over Internet
? Greaternetworkingcosts and latencysince data is hair
pinnedthrougha customerdata center
? Data travels over the openInternetto connectto cloud
? Bandwidthis limited
Public cloud
WAN
Customer DC
Customer site 1
Customer site 2
Public
internet
ExpressRouteとは
ExpressRoute は、AzureとM
のデ`タセンタgのネットワ`
クを喘の指で俊Aし、互ス
ル`プットで宥佚できるC嬬を
戻工します。
ExpressRouteによる俊A
∀襯優奪肇鍠`ク貧
の Azure Compute
Azure
Edge
Connectivity
Provider
Infrastructure
┣凌治VPN俊Aの栽
∀襯優奪肇鍠`ク貧
の Azure Compute
Azure
Gateway
VPN
Public and Private peering
Internet
Virtual Network and ExpressRoute
Public
internet
Public
internet
Public
internet
ExpressRoute パ`トナ`┗叡廝
Public
internet
Public
internet
ExpressRoute PowerShell Commandlets
ExpressRoute commandlets Description
Get-AzureDedicatedCircuitServiceProvider Lists all ExpressRoute service providers including carriers and internet exchange points offering
connectivity across all regions in Windows Azure.
Get-AzureDedicatedCircuit Lists all ExpressRoute circuits and details of each circuit.
Get-AzureDedicatedCircuitLink Lists the link state of a particular virtual network and an ExpressRoute circuit.
New-AzureDedicatedCircuit Creates a new ExpressRoute circuit in a Windows Azure subscription.
New-AzureDedicatedCircuitLink Creates a link between an ExpressRoute circuit and a virtual network in the current Windows
Azure subscription.
Remove-AzureDedicatedCircuit Removes an ExpressRoute circuit.
Remove-AzureDedicatedCircuitLink Removes the link between a Virtual Network and an ExpressRoute circuit.
BGP Configuration commandlets Description
Get-AzureBGPPeering Returns an object with bgp configuration information of an ExpressRoute circuit.
New-AzureBGPPeering Creates a new BGP peering configuration for an ExpressRoute circuit.
Remove-AzureBGPPeering Removes the routing configuration for an ExpressRoute circuit.
Set-AzureBGPPeering Updates a BGP peering configuration for an ExpressRoute circuit.
ExpressRoute ロケ`ション
ExpressRoute 鯉┗叡廚鯉のため歌深に
1Gbps Port + 15 TB included egress
10Gbps Port + 250 TB included egress
Summary
? Use Traffic Manager to build highly available services
? Use Virtual Network to create virtual private networks in Azure and extend your premises to Azure
? Use Point-to-site connectivity to simplify prototyping and dev / test / lab scenarios
? Use ExpressRoute for Enterprise grade connectivity to Azure
New features
? Traffic Manager, traffic manager for websites
? Static private IPv4 addresses for VMs
? Migrate VMs from one subnet to another without having to redeploy them
? Point-to-site and dynamic routing generally available
? New VPN device vendors validated
? ExpressRoute in preview
サマリ
Build 2014 Azure インフラエンジニア鬚吋▲奪廛禰`ト
Microsoft Azure のオ`トメ`ション
Azure Templates can:
? Ensure Idempotency
? Simplify Orchestration
? Simplify Roll-back
? Provide Cross-Resource Configuration
and Update Support
Azure Templates are:
? Source file, checked-in
? Specifies resources and dependencies
(VMs, WebSites, DBs) and connections
(config, LB sets)
? Parametized input/output
Instantiation of repeatable config.
Configuration ? Resource Group
Resource Manager
SQL - A Website
Virtual
Machines
SQL-A
Website
[SQL CONFIG] VM (2x)
DEPENDS ON SQLDEPENDS ON SQL
SQLCONFIG
∀襯泪轡鵑撹徭啝
27
? VMM Agent
? DSC (in-VM PowerShell)
? Chef
? Puppet
PuppetForge: 喘吭されているオ`トメ`ションソ
リュ`ション
Virtual & Cloud Infrastructure
Applications
Network & Storage Devices
Operating System Resources
NTP SUDO LDAP
RPM SSH USERS
THANK YOU!
29

More Related Content

Build 2014 Azure インフラエンジニア鬚吋▲奪廛禰`ト