快速入门:使用 Azure 门户创建虚拟网络Quickstart: Create a virtual network using the Azure portal

本快速入门介绍如何使用 Azure 门户创建虚拟网络。In this quickstart, you learn how to create a virtual network using the Azure portal. 我们部署两个虚拟机 (VM)。You deploy two virtual machines (VMs). 接下来就可以在 VM 之间安全地通信,并通过 Internet 连接到 VM。Next, you securely communicate between VMs and connect to VMs from the internet. 虚拟网络是 Azure 中专用网络的基本构建块。A virtual network is the fundamental building block for your private network in Azure. 它能让 Azure 资源(例如 VM)互相安全通信以及与 Internet 通信。It enables Azure resources, like VMs, to securely communicate with each other and with the internet.

先决条件Prerequisites

登录 AzureSign in to Azure

登录到 Azure 门户Sign in to the Azure portal.

创建虚拟网络Create a virtual network

  1. 在 Azure 门户菜单中,选择“创建资源” 。From the Azure portal menu, select Create a resource. 在 Azure 市场中,选择“网络” > “虚拟网络” 。From the Azure Marketplace, select Networking > Virtual network.

  2. 在“创建虚拟网络” 中,输入或选择以下信息:In Create virtual network, enter or select this information:

    设置Setting Value
    订阅Subscription 选择订阅。Select your subscription.
    资源组Resource group 选择“新建”,输入 myResourceGroup,然后选择“确定” 。Select Create new, enter myResourceGroup, then select OK.
    名称Name 输入 myVirtualNetwork 。Enter myVirtualNetwork.
    位置Location 选择“中国东部”。 Select China East.
  3. 在完成时选择“下一步: IP 地址”,并输入 10.1.0.0/16 作为“IPv4 地址空间”。 Select Next: IP Addresses, and for IPv4 address space, enter 10.1.0.0/16.

  4. 选择“添加子网” ,然后输入 myVirtualSubnet 作为“子网名称” ,输入 10.1.0.0/24 作为“子网地址范围”。 Select Add subnet, then enter myVirtualSubnet for Subnet name and 10.1.0.0/24 for Subnet address range.

  5. 选择“添加”,然后选择“查看 + 创建”。 Select Add, then select Review + create. 将其余的设置保留默认值,然后选择“创建” 。Leave the rest as default and select Create.

  6. 在“创建虚拟网络”中,选择“创建”。 In Create virtual network, select Create.

创建虚拟机Create virtual machines

在虚拟网络中创建两个 VM:Create two VMs in the virtual network:

创建第一个 VMCreate the first VM

  1. 在 Azure 门户菜单中,选择“创建资源” 。From the Azure portal menu, select Create a resource.

  2. 在 Azure 市场中,在“新建” 页的“搜索市场” 筛选框中,键入“Windows Server 2019 Datacenter” ,然后单击 Enter 键并在搜索结果中选择“Windows Server 2019 Datacenter” 。From the Azure Marketplace, type Windows Server 2019 Datacenter in the Search the Marketplace filter box of New page, then click the Enter key and select Windows Server 2019 Datacenter in search result.

  3. 在“创建虚拟机 - 基本信息” 中,输入或选择以下信息:In Create a virtual machine - Basics, enter or select this information:

    设置Setting Value
    项目详细信息Project details
    订阅Subscription 选择订阅。Select your subscription.
    资源组Resource group 选择“myResourceGroup”。 Select myResourceGroup. 我们在上一部分创建了此资源组。You created this resource group in the previous section.
    实例详细信息Instance details
    虚拟机名称Virtual machine name 输入 myVm1 。Enter myVm1.
    区域Region 选择“中国东部”。 Select China East.
    可用性选项Availability options 默认设置为“无需基础结构冗余”。 Default to No infrastructure redundancy required.
    映像Image 默认设置为“Windows Server 2019 Datacenter”。 Default to Windows Server 2019 Datacenter.
    大小Size 默认设置为“标准 DS1 v2” 。Default to Standard DS1 v2.
    管理员帐户Administrator account
    用户名Username 输入所选用户名。Enter a username of your choosing.
    密码Password 输入所选密码。Enter a password of your choosing. 密码必须至少 12 个字符长,且符合定义的复杂性要求The password must be at least 12 characters long and meet the defined complexity requirements.
    确认密码Confirm Password 重新输入密码。Re-enter password.
    入站端口规则Inbound port rules
    公共入站端口Public inbound ports 选择“允许所选端口” 。Select Allow selected ports.
    选择入站端口Select inbound ports 输入 HTTP (80)RDP (3389)Enter HTTP (80) and RDP (3389).
    节省资金Save money
    已有 Windows 许可证?Already have a Windows license? 默认设置为“否” 。Default to No.
  4. 在完成时选择“下一步:磁盘”Select Next: Disks.

  5. 在“创建虚拟机 - 磁盘”中保留默认值,然后选择“下一步: 网络”In Create a virtual machine - Disks, keep the defaults and select Next: Networking.

  6. 在“创建虚拟机 - 基本信息” 中,选择以下信息:In Create a virtual machine - Networking, select this information:

    设置Setting Value
    虚拟网络Virtual network 默认设置为 myVirtualNetworkDefault to myVirtualNetwork.
    子网Subnet 默认设置为 myVirtualSubnet (10.1.0.0/24)Default to myVirtualSubnet (10.1.0.0/24).
    公共 IPPublic IP 默认设置为“(新) myVm-ip” 。Default to (new) myVm-ip.
    NIC 网络安全组NIC network security group 默认设置为“基本” 。Default to Basic.
    公共入站端口Public inbound ports 默认设置为“允许所选端口” 。Default to Allow selected ports.
    选择入站端口Select inbound ports 默认设置为“HTTP”和“RDP”。 Default to HTTP and RDP.
  7. 在完成时选择“下一步:管理”Select Next: Management.

  8. 在“创建虚拟机 - 管理”中,为“诊断存储帐户”选择“新建” 。In Create a virtual machine - Management, for Diagnostics storage account, select Create New.

  9. 在“创建存储帐户”中,输入或选择以下信息 :In Create storage account, enter or select this information:

    设置Setting Value
    名称Name 输入 myvmstorageaccount 。Enter myvmstorageaccount. 如果此名称已被使用,请创建唯一的名称。If this name is taken, create a unique name.
    帐户类型Account kind 默认设置为“存储(常规用途 v1)”。 Default to Storage (general purpose v1).
    性能Performance 默认设置为“标准” 。Default to Standard.
    复制Replication 默认设置为“本地冗余存储(LRS)”。 Default to Locally-redundant storage (LRS).
  10. 选择“确定”,然后选择“查看 + 创建”。 Select OK, then select Review + create. 随后你会转到“查看 + 创建”页,Azure 将在此页面验证配置 。You're taken to the Review + create page where Azure validates your configuration.

  11. 看到“验证通过”消息时,选择“创建” 。When you see the Validation passed message, select Create.

创建第二个 VMCreate the second VM

重复上一部分的过程,创建另一个虚拟机。Repeat the procedure in the previous section to create another virtual machine.

重要

输入 myVm2 作为“虚拟机名称”。 For the Virtual machine name, enter myVm2.

确保选择 myvmstorageaccount 作为“诊断存储帐户”,而不是创建一个。 。For Diagnosis storage account, make sure you select myvmstorageaccount, instead of creating one.

从 Internet 连接到 VMConnect to a VM from the internet

创建 myVm1 后,连接到 Internet 。After you've created myVm1, connect to the internet.

  1. 在 Azure 门户中,搜索并选择“myVm1”。 In the Azure portal, search for and select myVm1.

  2. 选择“连接”,然后选择“RDP” 。 Select Connect, then RDP.

    连接到虚拟机

    此时会打开“连接”页。 The Connect page opens.

  3. 选择“下载 RDP 文件” 。Select Download RDP File. Azure 会创建远程桌面协议 ( .rdp) 文件,并将其下载到计算机。Azure creates a Remote Desktop Protocol (.rdp) file and downloads it to your computer.

  4. 打开该 RDP 文件。Open the RDP file. 出现提示时,选择“连接” 。If prompted, select Connect.

  5. 输入在创建 VM 时指定的用户名和密码。Enter the username and password you specified when creating the VM.

    备注

    可能需要选择“更多选择” > “使用其他帐户”,以指定在创建 VM 时输入的凭据 。You may need to select More choices > Use a different account, to specify the credentials you entered when you created the VM.

  6. 选择“确定” 。Select OK.

  7. 可能会在登录时收到证书警告。You may receive a certificate warning when you sign in. 如果收到证书警告,请选择“确定”或“继续” 。If you receive a certificate warning, select Yes or Continue.

  8. VM 桌面出现后,将其最小化以返回到本地桌面。Once the VM desktop appears, minimize it to go back to your local desktop.

VM 之间进行通信Communicate between VMs

  1. 在 myVm1 远程桌面中,打开 PowerShell 。In the Remote Desktop of myVm1, open PowerShell.

  2. 输入 ping myVm2Enter ping myVm2.

    会收到类似于以下输出的消息:You'll receive a message similar to this output:

    Pinging myVm2.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.cloudapp.chinacloudapi.cn
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    
    Ping statistics for 10.1.0.5:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
    

    由于 ping 使用 Internet 控制消息协议 (ICMP),ping 失败。The ping fails, because ping uses the Internet Control Message Protocol (ICMP). 默认情况下,不允许 ICMP 通过 Windows 防火墙。By default, ICMP isn't allowed through the Windows firewall.

  3. 要允许 myVm2 在后面的步骤中对 myVm1 执行 ping 操作 ,请输入以下命令:To allow myVm2 to ping myVm1 in a later step, enter this command:

    New-NetFirewallRule -DisplayName "Allow ICMPv4-In" -Protocol ICMPv4
    

    该命令允许 ICMP 通过 Windows 防火墙入站:This command allows ICMP inbound through the Windows firewall:

  4. 关闭与 myVm1 的远程桌面连接。Close the remote desktop connection to myVm1.

  5. 再次完成从 Internet 连接到 VM 中的步骤,但这次连接到 myVm2Complete the steps in Connect to a VM from the internet again, but connect to myVm2.

  6. 从命令提示符输入 ping myvm1From a command prompt, enter ping myvm1.

    你将看到类似于以下信息的内容:You'll get back something like this message:

    Pinging myVm1.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.chinacloudapp.cn [10.1.0.4] with 32 bytes of data:
    Reply from 10.1.0.4: bytes=32 time=1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    
    Ping statistics for 10.1.0.4:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 1ms, Average = 0ms
    

    将从 myVm1 收到答复,因为在第 3 步中已经允许 ICMP 通过 myVm1 VM 上的 Windows 防火墙 。You receive replies from myVm1, because you allowed ICMP through the Windows firewall on the myVm1 VM in step 3.

  7. 关闭与 myVm2 的远程桌面连接。Close the remote desktop connection to myVm2.

清理资源Clean up resources

在本快速入门中,你创建了默认的虚拟网络和两个 VM。In this quickstart, you created a default virtual network and two VMs. 从 Internet 连接到了其中一个 VM,并在两个 VM 之间安全地进行了通信。You connected to one VM from the internet and securely communicated between the two VMs.

使用虚拟网络和 VM 之后,请删除资源组和其包含的所有资源:When you're done using the virtual network and the VMs, delete the resource group and all of the resources it contains:

  1. 搜索并选择“myResourceGroup” 。Search for and select myResourceGroup.

  2. 选择“删除资源组” 。Select Delete resource group.

  3. 对于“键入资源组名称”,请输入“myResourceGroup”,然后选择“删除” 。Enter myResourceGroup for TYPE THE RESOURCE GROUP NAME and select Delete.

后续步骤Next steps

若要详细了解虚拟网络设置,请参阅创建、更改或删除虚拟网络To learn more about virtual network settings, see Create, change, or delete a virtual network.

默认情况下,Azure 允许在 VM 之间进行安全通信。By default, Azure allows secure communication between VMs. Azure 只允许从 Internet 到 Windows VM 的入站远程桌面连接。Azure only allows inbound remote desktop connections to Windows VMs from the internet. 若要详细了解 VM 网络通信类型,请参阅筛选网络流量To learn more about types of VM network communications, see Filter network traffic.