Azure Networking Fundamentals
Azure Networking Fundamentals
A Practical Guide to Understand How to Build a Virtual Datacenter into the Azure Cloud
About the Book
Chapter 1 - Azure Virtual Network (VNet): This chapter starts by introducing Azure Geographies, Regions, and Availability Zones. Then it discusses Subscriptions and Resources Groups. After these basic Azure building block introductions, this chapter focuses on Virtual Networks (VNet). It shows how to create VNet using Azure Portal and Azure Resource Manager tool ARM. This chapter also explains how we can use tags to give informative descriptions to our resources.
Chapter 2 – Network Security Group (NSG): This chapter introduces three NSG scenarios. The first section explains the NSG to NIC association. The second section describes the NSG-Subnet association. The last part of the chapter introduces an Application Security Group (ASG), which we are using to form a logical VM group.
Chapter 3 – Internet Access with VM-Specific Public IP: We can assign a Public IP address, an Instance Level Public IP (ILPIP) to Azure resources using either the Static or Dynamic method. Each VMs has an implicit, default outbound access to the Internet because Azure assigns a default Outbound Access IP address (OPIP) dynamically. The OPIP address is not owned by customers and they may change. Microsoft recommends disabling the default outbound access. The recommended method is using a NAT Gateway or Firewall.
Chapter 4 - Virtual Network NAT Service - NAT Gateway: This chapter explains how VMs without ILPIP can use Azure Virtual Network NAT service provided by the Azure NAT Gateway for the Internet connection. NAT GW is a managed distributed service, which allows an egress-only Internet connection from VMs using either TCP or UDP transport layer protocols.
Chapter 5 – Hybrid Cloud – Site-to-Site VPN (S2S VPN): A Hybrid Cloud is a model where we split application-specific workloads across the public and private clouds. This chapter introduces Azure's hybrid cloud solution using Site-to-Site (S2S) Active-Standby VPN connection between Azure and on-prem DC. Azure S2S A/S VPN service includes five Azure resources.
Chapter 6 – Hybrid Cloud – S2S VPN with BGP: This chapter shows how to enable dynamic routing using BGP between on-prem DC and Azure VNet.
Chapter 7 – VNet-to-VNet VPN: This chapter explains how we can use a VPN GW for allowing an Inter-VNet connection.
Chapter 8 – VNet Peering: This chapter introduces an Azure VNet Peering solution. VNet peering creates bidirectional IP connections between peered VNets. VNet peering links can be established within and across Azure regions and between VNets under the different Azure subscriptions or tenants. The unencrypted data path over peer links stays within Azure private infrastructure.
Chapter 9 – Transit VNet – Hub and Spoke: VNet Peering alone is a non-transitive solution, which only allows IP connection between peered VNets. However, we can build a design where we configure one of the VNets as a Hub VNet, which has VNet peering with Spoke VNets. Then, we set up a gateway VGW into the Hub VNet, which routes traffic between multiple Spoke VNets.
Chapter 10 – Hybrid Cloud – Routing Studies: This chapter discusses route propagations between on-prem DC and Azure Virtual Network in a Hybrid Cloud solution.
Chapter 11 – Virtual WAN Part I – S2S VPN and VNet Connection: This chapter introduces Azure Virtual WAN (vWAN) service. It offers a single deployment, management, and monitoring pane for connectivity services such as Inter-VNet, Site-to-Site VPN, and Express Route. In this chapter, we are focusing on S2S VPN and VNet connections.
Chapter 12 - Virtual WAN Part II – VNet Segmentation: VNets and VPN/ExpressRoute connections are associated with vHub’s Default Route Table, which allows both Vnet-to-Vnet and VNet-to-Remote Site IP connectivity. This chapter explains how we can isolate vnet-swe3 from vnet-swe1 and vnet-swe2 using VNet-specific vHub Route Tables (RT), still allowing VNet-to-VPN Site connection.
Chapter 13 - Virtual WAN Part III – Global Transit Network: This chapter introduces a global transit network architecture based on Azure vWAN.
Chapter 14 – Hybrid Cloud – Express Route: ExpressRoute (ER) is an Azure service that offers a logical circuit between Customer Edge (CE) router(s) and the pair of Microsoft Enterprise Edge (MSEE) devices. MSEEs are in one of the Azure selected Co-locations (Colo) - Carrier Neutral Facilities having a connection straight to the Microsoft Backbone network and ExpressRoute Provider (ERP). We can deploy an ExpressRoute circuit between Customer Edge (CE) and MSEE directly (ExpressRouteDirect) if the CE device is in Colo. If we don’t have existence in Colo, we can use ExpressRoute Provider’s infrastructure as a transport network between on-prem CE and MSEE. In this model, the ERP provides a layer 2 circuit (VLAN) between the CE-facing interface and to MSEE-facing port through its ExpressRoute Provider Edge (ERPE) devices. The ExpressRoute Provider model is the main focus of this chapter.
Chapter 15 – Load Balancer & NAT - Ananta: This chapter introduces Azure’s cloud-scale load-balancing/NAT service Ananta. It consists of three building blocks. Ananta Manager (AM) is a highly available centralized Control Plane. Multiplexer (MUX) pool has a set of MUXs, which offer a Load Balancing service for inbound traffic. Ananta Host Agent (HA) is like a virtual switch within the Hypervisor’s VMSwitch performing NAT functions.
The Leanpub 60-day 100% Happiness Guarantee
Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
80% Royalties. Earn $16 on a $20 book.
We pay 80% royalties. That's not a typo: you earn $16 on a $20 sale. If we sell 5000 non-refunded copies of your book or course for $20, you'll earn $80,000.
(Yes, some authors have already earned much more than that on Leanpub.)
In fact, authors have earned$12,046,757writing, publishing and selling on Leanpub.
Learn more about writing on Leanpub
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
Learn more about Leanpub's ebook formats and where to read them
Top Books
OpenIntro Statistics
David Diez, Christopher Barr, Mine Cetinkaya-Rundel, and OpenIntroA complete foundation for Statistics, also serving as a foundation for Data Science.
Leanpub revenue supports OpenIntro (US-based nonprofit) so we can provide free desk copies to teachers interested in using OpenIntro Statistics in the classroom and expand the project to support free textbooks in other subjects.
More resources: openintro.org.
Mastering STM32 - Second Edition
Carmine NovielloWith more than 1200 microcontrollers, STM32 is probably the most complete ARM Cortex-M platform on the market. This book aims to be the most complete guide around introducing the reader to this exciting MCU portfolio from ST Microelectronics and its official CubeHAL and STM32CubeIDE development environment.
C++20 - The Complete Guide
Nicolai M. JosuttisAll new language and library features of C++20 (for those who know previous C++ versions).
The book presents all new language and library features of C++20. Learn how this impacts day-to-day programming, to benefit in practice, to combine new features, and to avoid all new traps.
Buy early, pay less, free updates.
Other books:
Jetpack Compose internals
Jorge CastilloJetpack Compose is the future of Android UI. Master how it works internally and become a more efficient developer with it. You'll also find it valuable if you are not an Android dev. This book provides all the details to understand how the Compose compiler & runtime work, and how to create a client library using them.
Talking with Tech Leads
Patrick KuaA book for Tech Leads, from Tech Leads. Discover how more than 35 Tech Leads find the delicate balance between the technical and non-technical worlds. Discover the challenges a Tech Lead faces and how to overcome them. You may be surprised by the lessons they have to share.Functional Event-Driven Architecture
Gabriel VolpeExplore the event-driven architecture (EDA) in a purely functional way. Learn to design and develop distributed systems that scale. Identify common design patterns in such systems.
Take your functional programming skills to the next level by joining me in developing a distributed system powered by Apache Pulsar and Fs2 streams, all in Scala 3!
Machine Learning Q and AI
Sebastian Raschka, PhDHave you recently completed a machine learning or deep learning course and wondered what to learn next? With 30 questions and answers on key concepts in machine learning and AI, this book provides bite-sized bits of knowledge for your journey to becoming a machine learning expert.
Getting to Know IntelliJ IDEA
Trisha Gee and Helen ScottIf we treat our IDE as a text editor, we are doing ourselves a disservice. Using a combination of tutorials and a questions-and-answers approach, Getting to Know IntelliJ IDEA will help you find ways to use IntelliJ IDEA that enable you to work comfortably and productively as a professional developer.
The Rails 7 Way
Obie Fernandez, Lucas Dohmen, and Tom Henrik AadlandThe Rails™ 7 Way is the comprehensive, authoritative reference guide for professionals delivering production-quality code using modern Ruby on Rails. It illuminates the entire Rails 7 API, its most powerful idioms, design approaches, and libraries. Building on the previous editions, this edition has been heavily refactored and updated.
Ansible for DevOps
Jeff GeerlingAnsible is a simple, but powerful, server and configuration management tool. Learn to use Ansible effectively, whether you manage one server—or thousands.
Top Bundles
- #1
Software Architecture
2 Books
"Software Architecture for Developers" is a practical and pragmatic guide to modern, lightweight software architecture, specifically aimed at developers. You'll learn:The essence of software architecture.Why the software architecture role should include coding, coaching and collaboration.The things that you really need to think about before... - #2
CCIE Service Provider Ultimate Study Bundle
2 Books
Piotr Jablonski, Lukasz Bromirski, and Nick Russo have joined forces to deliver the only CCIE Service Provider training resource you'll ever need. This bundle contains a detailed and challenging collection of workbook labs, plus an extensively detailed technical reference guide. All of us have earned the CCIE Service Provider certification... - #3
Modern C++ Collection
3 Books
Get All about Modern C++C++ Standard Library, including C++20Concurrency with Modern C++, including C++20C++20Each book has about 200 complete code examples. Updates are included. When I update one of the books, you immediately get the updated bundle. You can expect significant updates to each new C++ standard (C++23, C++26, .. ) and also... - #4
Pattern-Oriented Memory Forensics and Malware Detection
2 Books
This training bundle for security engineers and researchers, malware and memory forensics analysts includes two accelerated training courses for Windows memory dump analysis using WinDbg. It is also useful for technical support and escalation engineers who analyze memory dumps from complex software environments and need to check for possible... - #5
1500 QUIZ COMMENTATI (3 libri)
3 Books
Tre libri dei QUIZ MMG Commentati al prezzo di DUE! I QUIZ dei concorsi ufficiali di Medicina Generale relativi agli anni: 2000-2001-2003-2012-2013-2014-2015-2016-2017-2018-2019-2020-2021 +100 inediti Raccolti in unico bundle per aiutarvi nello studio e nella preparazione al concorso. All'interno di ogni libro i quiz sono stati suddivisi per... - #6
Practical FP in Scala + Functional event-driven architecture
2 Books
Practical FP in Scala (A hands-on approach) & Functional event-driven architecture, aka FEDA, (Powered by Scala 3), together as a bundle! The content of PFP in Scala is a requirement to understand FEDA so why not take advantage of this bundle!? - #8
Growing Agile: The Complete Coach's Guide
7 Books
Growing Agile: Coach's Guide Series This bundle provides a collection of training and workshop plans for a variety of agile topics. The series is aimed at agile coaches, trainers and ScrumMasters who often find themselves needing to help teams understand agile concepts. Each book in the series provides the plans, slides, handouts and activity... - #9
Development and Deployment of Multiplayer Online Games, Part ARCH. Architecture (Vol. I-III)
3 Books
What's the Big Idea? The idea behind this book is to summarize the body of knowledge that already exists on multiplayer games but is not available in one single place.And quite a fewof the issues discussed within this series (planned as three nine volumes ~300 pages each), while known in the industry, have not been published at all (except for...