什么是安全虚拟中心?What is a secured virtual hub?

虚拟中心是 Microsoft 托管的虚拟网络,支持来自其他资源的连接。A virtual hub is a Microsoft-managed virtual network that enables connectivity from other resources. 在 Azure 门户中基于虚拟 WAN 创建虚拟中心时,还将创建一个虚拟中心 VNet 和网关(可选)作为其组件。When a virtual hub is created from a Virtual WAN in the Azure portal, a virtual hub VNet and gateways (optional) are created as its components.

安全虚拟中心是一个 Azure 虚拟 WAN 中心,其中包含通过 Azure 防火墙管理器配置的关联的安全和路由策略。A secured virtual hub is an Azure Virtual WAN Hub with associated security and routing policies configured by Azure Firewall Manager. 使用安全虚拟中心,可通过本机安全服务轻松创建中心辐射型可传递体系结构,实现流量管理和保护。Use secured virtual hubs to easily create hub-and-spoke and transitive architectures with native security services for traffic governance and protection.

可以使用安全虚拟中心来筛选虚拟网络 (V2V) 之间的流量、虚拟网络与分支机构 (B2V) 之间的流量以及流向 Internet (B2I/V2I) 的流量。You can use a secured virtual hub to filter traffic between virtual networks (V2V), virtual networks and branch offices (B2V) and traffic to the Internet (B2I/V2I). 安全虚拟中心提供自动路由。A secured virtual hub provides automated routing. 因此,无需配置自己的 UDR(用户定义的路由)即可通过防火墙路由流量。There's no need to configure your own UDRs (user defined routes) to route traffic through your firewall.

你可以选择用于保护和管理网络流量的所需安全提供程序,包括 Azure 防火墙和/或第三方安全即服务 (SECaaS) 提供程序。You can choose the required security providers to protect and govern your network traffic, including Azure Firewall, third-party security as a service (SECaaS) providers, or both. 目前,安全中心不支持分支到分支 (B2B) 的筛选和跨多个中心进行的筛选。Currently, a secured hub doesn�t support Branch to Branch (B2B) filtering and filtering across multiple hubs. 有关详细信息,请参阅什么是 Azure 防火墙管理器?To learn more, see What is Azure Firewall Manager?.

创建安全虚拟中心Create a secured virtual hub

使用 Azure 门户中的防火墙管理器,可以创建新的安全虚拟中心,也可使用 Azure 虚拟 WAN 转换之前创建的现有虚拟中心。Using Firewall Manager in the Azure portal, you can either create a new secured virtual hub, or convert an existing virtual hub that you previously created using Azure Virtual WAN.

后续步骤Next steps

要创建安全虚拟中心并使用它来保护和管理中心和分支网络,请参阅教程:在 Azure 门户中使用 Azure 防火墙管理器保护云网络To create a secured virtual hub and use it to secure and govern a hub and spoke network, see Tutorial: Secure your cloud network with Azure Firewall Manager using the Azure portal.