使用 Azure 网络服务远程进行工作Working remotely using Azure networking services


本文介绍如何利用 Azure 网络服务、Microsoft 网络和 Azure 合作伙伴生态系统远程进行工作,以及如何缓解因 COVID-19(新冠病毒)危机而面临的网络问题。This article describes how you can leverage Azure networking services, Microsoft network, and the Azure partner ecosystem to work remotely and mitigate network issues that you might be facing because of the COVID-19 crisis.

本文将介绍可供组织用来为用户设置远程访问,或者在使用高峰期通过附加容量补充现有解决方案的选项。This article describes the options that are available to organizations to set up remote access for their users or to supplement their existing solutions with additional capacity during periods of peak utilization. 网络架构师面临着以下挑战:Network architects are faced with the following challenges:

  • 解决由于网络使用率提高而导致的问题。Address an increase in network utilization.
  • 为公司和客户的更多员工提供安全可靠的连接。Provide reliable-secure connectivity to more employees of their company and customers.
  • 在全球范围内提供与远程位置的连接。Provide connectivity to remote locations across the globe.

在远程工作者负载高峰期,并非所有网络都会出现拥塞(例如,专用 WAN 和企业核心网络就不会出现拥塞)。Not all networks (for example, private WAN and corporate core networks) experience congestion from peak remote worker load. 通常只有家庭宽带网络以及企业本地网络的 VPN 网关才会报告瓶颈。The bottlenecks are commonly reported only in home broadband networks and VPN gateways of on-premises networks of corporations.

网络规划人员可以通过记住不同的流量类型需要不同的网络处理优先级,以及通过使用某种智能负载重定向/分配方法,来帮助缓解瓶颈并减轻网络拥塞问题。Network planners can help ease the bottlenecks and alleviate the network congestion by keeping in mind that different traffic types need different network treatment priorities and by some smart load redirection/distribution. 例如,医生与患者之间的实时远程医疗交互流量的重要性就很高,对网络延迟/波动的敏感性也很高。For example, real-time tele-medecine traffic of doctor-patient interaction is of high importance and delay/jitter sensitive. 而如果相同的流量用于存储之间的复制,则它对延迟就不敏感。Whereas, replication of the same traffic between storages is not delay sensitive. 对于前一种流量,必须通过服务质量较高的最佳网络路径进行路由;而对于后一种流量,可以接受通过次优路径进行路由。The former traffic must be routed via the most optimal network path with higher quality of service; whereas it is acceptable to route the later traffic via sub-optimal route.

分享我们的最佳做法 - Azure 网络旨在提供弹性和高可用性Sharing our best practices - Azure network is designed for elasticity and high-availability

Azure 已设计为能够承受资源利用率的骤然变化,并可以在使用高峰期提供很大的帮助。Azure is designed to withstand sudden changes in the utilization of the resources and can greatly help during periods of peak utilization. Azure 的网络已设计为提供高可用性,能够承受不同类型的故障:从单一网络要素的故障,到整个区域的故障。Azure's network has been designed for high availability that can withstand different types of failure: from a single network element failure to failure of an entire region.

Azure 网络已设计为符合各种要求,可为不同类型的网络流量(包括针对 Skype 和 Teams、CDN、实时大数据分析、Azure 存储、必应及 Xbox 的延迟敏感型多媒体流量)提供最佳性能。The Azure network is designed to meet the requirements and provide optimal performance for different types of network traffic including delay sensitive multimedia traffic for Skype and Teams, CDN, real-time big data analysis, Azure storage, Bing, and Xbox. 为了针对不同类型的流量提供最佳性能,Azure 网络会将发往其资源的,或者要通过其资源传输的所有流量吸引到尽量靠近流量来源的位置。To provide optimal performance for different types of traffic, the Azure network attracts all the traffic that is destined to- or wanting to transit through- its resources as close as possible to the origin of the traffic.


借助下面所述的 Azure 网络功能可以利用 Azure 网络的流量吸引行为来提供更好的客户网络体验。Using the Azure networking features described below leverages the traffic attraction behavior of the Azure network to provide a better customer networking experience. Azure 网络的流量吸引行为有助于从第一英里/最后一英里的网络(这些网络在使用高峰期可能会遇到拥塞)中尽快减轻流量负担。The traffic attraction behavior of the Azure network helps off loading traffic as soon as possible from the first/last mile networks that may experience congestion during periods of peak utilization.

使员工能够远程工作Enable employees to work remotely

Azure VPN 网关支持点到站点 (P2S) 和站点到站点 (S2S) VPN 连接。Azure VPN gateway supports both Point-to-Site (P2S) and Site-to-Site (S2S) VPN connections. 使用 Azure VPN 网关可以缩放员工的连接,使其能够安全访问 Azure 部署的资源和本地资源。Using the Azure VPN gateway you can scale your employee's connections to securely access both your Azure deployed resources and your on-premises resources. 有关详细信息,请参阅如何使用户能够远程工作For more information, see How to enable users to work remotely.

如果使用安全套接字隧道协议 (SSTP),并发连接数将限制为 128。If you are using Secure Sockets Tunneling Protocol (SSTP), the number of concurrent connections is limited to 128. 若要获得更多的连接,我们建议转换到 OpenVPN 或 IKEv2。To get a higher number of connections, we suggest transitioning to OpenVPN or IKEv2. 有关详细信息,请参阅从 SSTP 转换到 OpenVPN 协议或 IKEv2For more information, see Transition to OpenVPN protocol or IKEv2 from SSTP.

若要聚合大规模 VPN 连接,以支持不同本地全局位置和不同区域性中心辐射型虚拟网络中的资源之间的任意点到任意点连接,并优化多个家庭宽带网络的利用率,可以使用 Azure 虚拟 WAN。For aggregating large-scale VPN connection, to support any-to-any connections between resources in different on-premises global locations, in different regional hub and spoke virtual networks, and to optimize utilization of multiple home broadband networks you can use Azure Virtual WAN. 有关详细信息,请参阅正在奋力满足在家工作的需求?Azure 虚拟 WAN 可以提供帮助For more information, see Struggling to cater to work from home needs? Here is where Azure Virtual WAN can help.

支持远程工作的另一种方式是部署 Azure 虚拟网络中托管的、通过 Azure 防火墙保护的虚拟桌面基础结构 (VDI)。Another way to support a remote workforce is to deploy a Virtual Desktop Infrastructure (VDI) hosted in your Azure virtual network, secured with an Azure Firewall. 例如,Windows 虚拟桌面 (WVD) 是在 Azure 中运行的桌面和应用虚拟化服务。For example, Windows Virtual Desktop (WVD) is a desktop and app virtualization service that runs in Azure. 使用 Windows 虚拟桌面,可以在 Azure 订阅中设置可缩放的灵活环境,而无需运行任何额外的网关服务器。With Windows Virtual Desktop, you can set up a scalable and flexible environment in your Azure subscription without the need to run any additional gateway servers. 你只负责虚拟网络中的 WVD 虚拟机。You are only responsible for the WVD virtual machines in your virtual network. 有关详细信息,请参阅 Azure 防火墙远程工作支持For more information, see Azure Firewall remote work support.

扩展员工的连接以访问全球分布的资源Extend employees' connection to access globally distributed resources

员工可以借助以下 Azure 服务访问全球分布的资源。The following Azure services can help enable employees to access your globally distributed resources. 资源可能位于任何 Azure 区域或本地网络中,甚至可能位于其他公有云或私有云中。Your resources could be in any of the Azure regions, on-premises networks, or even in other public or private clouds.

  • Azure 虚拟网络对等互连 :如果将资源部署在多个 Azure 区域,并且/或者使用多个虚拟网络聚合远程工作员工的连接,则可以使用虚拟网络对等互连在多个 Azure 虚拟网络之间建立连接。Azure virtual network peering: If you deploy your resources in more than one Azure regions and/or if you aggregate the connectivity of remotely working employees using multiple virtual networks, you can establish connectivity between the multiple Azure virtual networks using virtual network peering. 有关详细信息,请参阅虚拟网络对等互连For more information, see Virtual network peering.

  • 基于 Azure VPN 的解决方案 :对于通过 P2S 或 S2S VPN 连接到 Azure 的远程工作员工,你可以通过在本地网络与 Azure VPN 网关之间配置 S2S VPN,来使其能够访问本地网络。Azure VPN-based solution: For your remote employees connected to Azure via P2S or S2S VPN, you can enable access to on-premises networks by configuring S2S VPN between your on-premises networks and Azure VPN gateway. 有关详细信息,请参阅创建站点到站点连接For more information, see Create a Site-to-Site connection.

  • ExpressRoute:使用 ExpressRoute 专用对等互连,可以在 Azure 部署与本地基础结构或共置设施中的基础结构之间启用专用连接。ExpressRoute: Using ExpressRoute private peering you can enable private connectivity between your Azure deployments and on-premises infrastructure or your infrastructure in a co-location facility. 通过 Microsoft 对等互连使用 ExpressRoute 还可以从本地网络访问 Microsoft 中的公共终结点。ExpressRoute, via Microsoft peering, also permits accessing public endpoints in Microsoft from your on-premises network. ExpressRoute 连接不通过公共 Internet 。ExpressRoute connections do not go over the public Internet. 与通过 Internet 建立的典型连接相比,ExpressRoute 提供的连接更安全,可靠性更高,吞吐量更高,并且延迟更低且稳定。They offer secure connectivity, reliability, higher throughput, with lower and consistent latencies than typical connections over the Internet. 有关详细信息,请参阅 ExpressRoute 概述For more information, see ExpressRoute overview. 利用已成为我们 ExpressRoute 合作伙伴生态系统一部分的现有网络提供商,可以帮助减少与 Microsoft 建立高带宽连接所需的时间。Leveraging your existing network provider that is already part of our ExpressRoute partner ecosystem can help reduce the time to get large bandwidth connections to Microsoft.

  • Azure 虚拟 WAN:Azure 虚拟 WAN 可以实现 VPN 连接与 ExpressRoute 线路之间的无缝互操作。Azure Virtual WAN: Azure Virtual WAN allows seamless interoperability between your VPN connections and ExpressRoute circuits. 如前所述,Azure 虚拟 WAN 还支持不同本地全局位置和不同区域性中心辐射型虚拟网络中的资源之间的任意点到任意点连接。As mentioned earlier, Azure Virtual WAN also support any-to-any connections between resources in different on-prem global locations, in different regional hub and spoke virtual networks

缩放与前端资源之间的客户连接Scale customer connectivity to frontend resources

当上网的人越来越多时,许多企业网站遇到的客户流量会增大。During times when more people go online, many corporate websites experience increased customer traffic. Azure 应用程序网关可以帮助应对这种前端工作负荷增大的问题。Azure Application Gateway can help manage this increased frontend workload. 有关详细信息,请参阅应用程序网关高流量支持For more information, see Application Gateway high traffic support.

Microsoft 对多云流量的支持Microsoft support for multi-cloud traffic

对于其他公有云中的部署,Microsoft 可提供全球连接。For your deployments in other public clouds, Microsoft can provide global connectivity. Azure 虚拟 WAN、VPN 或 ExpressRoute 在此方面都可以发挥作用。Azure Virtual WAN, VPN or ExpressRoute can help in this regard. 若要扩展从 Azure 到其他云的连接,可以在两个云之间配置 S2S VPN。To extend connectivity from Azure to other clouds, you can configure S2S VPN between the two clouds. 还可以使用 ExpressRoute 建立从 Azure 到其他公有云的连接。You can also establish connectivity from Azure to other public clouds using ExpressRoute. Oracle 云是 ExpressRoute 合作伙伴生态系统的一部分。Oracle cloud is part of ExpressRoute partner ecosystem. 属于 ExpressRoute 伙伴生态系统的一部分的大多数服务提供商还能提供与其他公有云之间的专用连接。Most service providers that are part of the ExpressRoute partner ecosystem also offer private connectivity to other public clouds. 利用这些服务提供商,可以通过 ExpressRoute 在 Azure 与其他云中的部署之间建立专用连接。Leveraging these service providers, you can establish private connectivity between your deployments in Azure and other clouds via ExpressRoute.

后续步骤Next steps

以下文章介绍了如何使用不同的 Azure 网络功能来缩放用户的连接,以使用户能够远程工作:The following articles discuss how different Azure networking features can be used to scale users to work remotely:

文章Article 说明Description
如何使用户能够远程工作How to enable users to work remotely 查看可用选项,以便为用户设置远程访问权限,或使用组织的额外容量对其现有解决方案进行补充。Review available options to set up remote access for users or to supplement their existing solutions with additional capacity for your organization.
正在奋力满足在家工作的需求?Azure 虚拟 WAN 可以提供帮助Struggling to cater to work from home needs? Here is where Azure Virtual WAN can help 使用 Azure 虚拟 WAN 满足组织的远程连接需求。Use Azure Virtual WAN to address the remote connectivity needs of your organization.
应用程序网关高流量支持Application Gateway high traffic support 使用启用了 Web 应用程序防火墙 (WAF) 的应用程序网关,以一种可缩放且安全的方式管理到 Web 应用程序的流量。Use Application Gateway with Web Application Firewall (WAF) for a scalable and secure way to manage traffic to your web applications.
从 SSTP 转换到 OpenVPN 协议或 IKEv2Transition to OpenVPN protocol or IKEv2 from SSTP 通过转换为 OpenVPN 协议或 IKEv2,克服 SSTP 的 128 个并发连接的限制。Overcome the 128 concurrent connection limit of SSTP by transitioning to OpenVPN protocol or IKEv2.
使用 Azure ExpressRoute 创建混合连接以支持远程用户Using Azure ExpressRoute to create hybrid connectivity to support remote users 使用 ExpressRoute 进行混合连接,使组织中的用户能够远程工作。Use ExpressRoute for hybrid connectivity to enable users in your organization to work remotely.
Azure 防火墙远程工作支持Azure Firewall remote work support 使用 Azure 防火墙保护 Azure 虚拟网络资源。Protect your Azure virtual network resources using Azure Firewall.