Azure ExpressRoute 的安全控制Security controls for Azure ExpressRoute

本文介绍 Azure ExpressRoute 中内置的安全控制。This article documents the security controls built into Azure ExpressRoute.

安全控制是促使 Azure 服务能够防范、检测和响应安全漏洞的一种服务质量或功能。A security control is a quality or feature of an Azure service that contributes to the service's ability to prevent, detect, and respond to security vulnerabilities.

对于每项控制,我们使用“Yes”或“No”来指示它当前是否用于该服务,对于不适用于该服务的控制为“N/A”。For each control, we use "Yes" or "No" to indicate whether it is currently in place for the service, "N/A" for a control that is not applicable to the service. 我们还可能会提供有关属性的更多信息的注释或链接。We might also provide a note or links to more information about an attribute.

网络Network

安全控制Security control Yes/NoYes/No 注释Notes
服务终结点支持Service endpoint support 不适用N/A
VNet 注入支持VNet injection support 不适用N/A
网络隔离和防火墙支持Network isolation and firewalling support Yes 每个客户都包含在自己的路由域中,并通过隧道连接到自己的 VNetEach customer is contained in its own routing domain and tunneled to its own VNet
强制隧道支持Forced tunneling support 不适用N/A 通过边界网关协议 (BGP)。Via Border Gateway Protocol (BGP).

监视和日志记录Monitoring & logging

安全控制Security control Yes/NoYes/No 注释Notes
Azure 监视支持(Log Analytics 等)Azure monitoring support (Log analytics, App insights, etc.) Yes 请参阅 ExpressRoute 监视、指标和警报See ExpressRoute monitoring, metrics, and alerts.
控制和管理平面日志记录和审核Control and management plane logging and audit Yes
数据平面日志记录和审核Data plane logging and audit No

标识Identity

安全控制Security control Yes/NoYes/No 注释Notes
身份验证Authentication Yes 用于 Microsoft 的网关 (GWM)(控制器)的服务帐户;用于开发和操作的实时 (JIT) 访问。Service account for Gateway for Microsoft (GWM) (controller); Just in Time (JIT) access for Dev and OP.
授权Authorization Yes 用于 Microsoft 的网关 (GWM)(控制器)的服务帐户;用于开发和操作的实时 (JIT) 访问。Service account for Gateway for Microsoft (GWM) (controller); Just in Time (JIT) access for Dev and OP.

数据保护Data protection

安全控制Security control Yes/NoYes/No 注释Notes
服务器端静态加密:Microsoft 管理的密钥Server-side encryption at rest: Microsoft-managed keys 不适用N/A ExpressRoute 不存储客户数据。ExpressRoute does not store customer data.
服务器端静态加密:客户管理的密钥 (BYOK)Server-side encryption at rest: customer-managed keys (BYOK) 不适用N/A
列级加密(Azure 数据服务)Column level encryption (Azure Data Services) 不适用N/A
传输中加密(例如 ExpressRoute 加密、VNet 中加密,以及 VNet-VNet 加密)Encryption in transit (such as ExpressRoute encryption, in VNet encryption, and VNet-VNet encryption) No
加密的 API 调用API calls encrypted Yes 通过 Azure 资源管理器和 HTTPS。Through Azure Resource Manager and HTTPS.

配置管理Configuration management

安全控制Security control Yes/NoYes/No 注释Notes
配置管理支持(配置的版本控制等)Configuration management support (versioning of configuration, etc.) Yes 通过网络资源提供程序 (NRP)。Via the Network Resource Provider (NRP).