Azure solution: deployment of the best hybrid network architecture of Azure and On Premise Network

51CTO blog address: https://blog.51cto.com/14669127blog
garden blog address: https://www.cnblogs.com/Nancy1983

More and more companies will consider migrating most of their local resources to Azure. However, some small data centers must be kept locally before they can be integrated into the Azure network. Therefore, the priority is to use a hybrid network architecture to ensure that you can access local and based Cloud resources.
In order to meet this demand, we need to consider generating a network integration plan for Azure, which includes the selection of the best hybrid network options available in Azure, which must meet the organization's requirements for hybrid connections. Although many reference architectures can be used when designing a hybrid network, the more popular architecture is Site to Site Configuration. The following figure is a simplified reference architecture that illustrates how to connect the local network to the Azure platform. The Internet connection uses IPsec ** * Tunnel.

Azure solution: deployment of the best hybrid network architecture of Azure and On Premise Network

The architecture has the following components:

  • On Premise Network: Represents the local active directory and any data and resources
  • When the gateway uses a public connection, it is responsible for sending encrypted traffic to the virtual IP address.
  • Azure Virtual Network: Contains all cloud applications and any Azure *** gateway components
  • The Azure VPN gateway provides an encrypted connection between the Azure virtual network and the local network, which is composed of Virtual Network Gateway, Local Network Gateway, Connection and Gateway Subnet
  • Cloud Application is an application provided through Azure
  • Internal Load Balancer: Route cloud traffic to the correct cloud-based application or resource.

The advantages of using this architecture are:

  • Simplified configuration and maintenance
  • Having a VPN gateway helps ensure that all data and traffic are encrypted between the internal gateway and the Azure gateway
  • The architecture can be extended to meet the network needs of the organization

Note: This architecture is not suitable for all situations, because it uses an existing Internet connection as a link between two gateways, bandwidth limitations may cause delays due to reuse of existing infrastructure

Guess you like

Origin blog.51cto.com/14669127/2642345