快速入门:使用 Azure 门户创建虚拟网络Quickstart: Create a virtual network using the Azure portal

虚拟网络是 Azure 中专用网络的基本构建块。A virtual network is the fundamental building block for your private network in Azure. 它能让 Azure 资源(例如虚拟机 (VM))彼此之间安全地通信以及与 Internet 进行通信。It enables Azure resources, like virtual machines (VMs), to securely communicate with each other and with the internet. 本快速入门介绍如何使用 Azure 门户创建虚拟网络。In this Quickstart, you will learn how to create a virtual network using the Azure portal. 然后,你可以将两个 VM 部署到虚拟网络,在两个 VM 之间安全地进行通信,并通过 Internet 连接到 VM。Then, you can deploy two VMs into the virtual network, securely communicate between the two VMs, and connect to the VMs from the internet.

如果还没有 Azure 订阅,请现在就创建一个试用帐户If you don't have an Azure subscription, create a trial account now.

登录 AzureSign in to Azure

登录到 Azure 门户Sign in to the Azure portal.

创建虚拟网络Create a virtual network

  1. 在 Azure 门户菜单中,选择“创建资源” 。From the Azure portal menu, select Create a resource.

  2. 在 Azure 市场中,选择“网络” > “虚拟网络” 。From the Azure Marketplace, select Networking > Virtual network.

  3. 在“创建虚拟网络” 中,输入或选择以下信息:In Create virtual network, enter or select this information:

    设置Setting Value
    NameName 输入 myVirtualNetwork 。Enter myVirtualNetwork.
    地址空间Address space 输入 10.1.0.0/16 。Enter 10.1.0.0/16.
    订阅Subscription 选择订阅。Select your subscription.
    资源组Resource group 选择“新建”,输入 myResourceGroup,然后选择“确定” 。Select Create new, enter myResourceGroup, then select OK.
    位置Location 选择“中国东部”。 Select China East.
    子网 - 名称Subnet - Name 输入 myVirtualSubnet 。Enter myVirtualSubnet.
    子网 - 地址范围Subnet - Address range 输入 10.1.0.0/24 。Enter 10.1.0.0/24.
  4. 将其余的设置保留默认值,然后选择“创建” 。Leave the rest as default and select Create.

创建虚拟机Create virtual machines

在虚拟网络中创建两个 VM:Create two VMs in the virtual network:

创建第一个 VMCreate the first VM

  1. 在 Azure 门户菜单中,选择“创建资源” 。From the Azure portal menu, select Create a resource.

  2. 在 Azure 市场中,在“新建” 页的“搜索市场” 筛选框中,键入“Windows Server 2019 Datacenter” ,然后单击 Enter 键并在搜索结果中选择“Windows Server 2019 Datacenter” 。From the Azure Marketplace, type Windows Server 2019 Datacenter in the Search the Marketplace filter box of New page, then click the Enter key and select Windows Server 2019 Datacenter in search result.

  3. 在“创建虚拟机 - 基本信息” 中,输入或选择以下信息:In Create a virtual machine - Basics, enter or select this information:

    设置Setting ValueValue
    项目详细信息PROJECT DETAILS
    订阅Subscription 选择订阅。Select your subscription.
    资源组Resource group 选择“myResourceGroup”。 Select myResourceGroup. 已在上一部分创建此内容。You created this in the previous section.
    实例详细信息INSTANCE DETAILS
    虚拟机名称Virtual machine name 输入 myVm1 。Enter myVm1.
    区域Region 选择“中国东部”。 Select China East.
    可用性选项Availability options 保留默认值“不需要基础结构冗余” 。Leave the default No infrastructure redundancy required.
    映像Image 保留默认值“Microsoft Windows Server 2019 Datacenter” 。Leave the default Windows Server 2019 Datacenter.
    大小Size 保留默认值“标准 DS1 v2” 。Leave the default Standard DS1 v2.
    管理员帐户ADMINISTRATOR ACCOUNT
    用户名Username 输入所选用户名。Enter a username of your choosing.
    密码Password 输入所选密码。Enter a password of your choosing. 密码必须至少 12 个字符长,且符合定义的复杂性要求The password must be at least 12 characters long and meet the defined complexity requirements.
    确认密码Confirm Password 重新输入密码。Reenter password.
    入站端口规则INBOUND PORT RULES
    公共入站端口Public inbound ports 保留默认值“无” 。Leave the default None.
    节省资金SAVE MONEY
    已有 Windows 许可证?Already have a Windows license? 保留默认值“否” 。Leave the default No.
  4. 选择“下一步:磁盘”Select Next : Disks.

  5. 在“创建虚拟机 - 磁盘”中,保留默认设置,然后选择“下一步:网络”In Create a virtual machine - Disks, leave the defaults and select Next : Networking.

  6. 在“创建虚拟机 - 基本信息” 中,选择以下信息:In Create a virtual machine - Networking, select this information:

    设置Setting Value
    虚拟网络Virtual network 保留默认值“myVirtualNetwork” 。Leave the default myVirtualNetwork.
    子网Subnet 保留默认值“myVirtualSubnet (10.1.0.0/24)” 。Leave the default myVirtualSubnet (10.1.0.0/24).
    公共 IPPublic IP 保留默认值“(new) myVm-ip” 。Leave the default (new) myVm-ip.
    公共入站端口Public inbound ports 选择“允许所选端口” 。Select Allow selected ports.
    选择入站端口Select inbound ports 选择 HTTP 和 RDP 。Select HTTP and RDP.
  7. 选择“下一步:管理”Select Next : Management.

  8. 在“创建虚拟机 - 管理”中,为“诊断存储帐户”选择“新建” 。In Create a virtual machine - Management, for Diagnostics storage account, select Create New.

  9. 在“创建存储帐户”中,输入或选择以下信息 :In Create storage account, enter or select this information:

    设置Setting Value
    NameName 输入 myvmstorageaccount 。Enter myvmstorageaccount. 如果此名称已被使用,请创建唯一的名称。If this name is taken, create a unique name.
    帐户类型Account kind 保留默认值“存储(常规用途 v1)” 。Leave the default Storage (general purpose v1).
    性能Performance 保留默认值“标准” 。Leave the default Standard.
    复制Replication 保留默认值“本地冗余存储(LRS)” 。Leave the default Locally-redundant storage (LRS).
  10. 选择“确定” Select OK

  11. 选择“查看 + 创建” 。Select Review + create. 随后你会转到“查看 + 创建”页,Azure 将在此页面验证配置 。You're taken to the Review + create page where Azure validates your configuration.

  12. 看到“验证通过”消息时,选择“创建” 。When you see the Validation passed message, select Create.

创建第二个 VMCreate the second VM

  1. 完成前面的步骤 1 和 9。Complete steps 1 and 9 from above.

    Note

    在步骤 2 中,对于“虚拟机名称”,请输入 myVm2 。In step 2, for the Virtual machine name, enter myVm2.

    在步骤 7 中,对于“诊断存储帐户”,请确保选择 myvmstorageaccount 。In step 7, for Diagnosis storage account, make sure you select myvmstorageaccount.

  2. 选择“查看 + 创建” 。Select Review + create. 随后你会转到“查看 + 创建”页,Azure 将验证配置 。You're taken to the Review + create page and Azure validates your configuration.

  3. 看到“验证通过”消息时,选择“创建” 。When you see the Validation passed message, select Create.

从 Internet 连接到 VMConnect to a VM from the internet

创建 myVm1 后,连接到 Internet 。After you've created myVm1, connect to the internet.

  1. 在门户的搜索栏中,输入 myVm1 。In the portal's search bar, enter myVm1.

  2. 选择“连接”按钮。 Select the Connect button.

    连接到虚拟机

    选择“连接”按钮后,“连接到虚拟机”随即打开 。After selecting the Connect button, Connect to virtual machine opens.

  3. 选择“下载 RDP 文件” 。Select Download RDP File. Azure 创建远程桌面协议 (.rdp) 文件,并下载到计算机 。Azure creates a Remote Desktop Protocol (.rdp) file and downloads it to your computer.

  4. 打开下载的 .rdp 文件。Open the downloaded .rdp file.

    1. 出现提示时,选择“连接” 。If prompted, select Connect.

    2. 输入在创建 VM 时指定的用户名和密码。Enter the username and password you specified when creating the VM.

      Note

      可能需要选择“更多选择” > “使用其他帐户”,以指定在创建 VM 时输入的凭据 。You may need to select More choices > Use a different account, to specify the credentials you entered when you created the VM.

  5. 选择“确定” 。Select OK.

  6. 在登录过程中可能会收到证书警告。You may receive a certificate warning during the sign in process. 如果收到证书警告,请选择“确定”或“继续” 。If you receive a certificate warning, select Yes or Continue.

  7. VM 桌面出现后,将其最小化以返回到本地桌面。Once the VM desktop appears, minimize it to go back to your local desktop.

VM 之间进行通信Communicate between VMs

  1. 在 myVm1 远程桌面中,打开 PowerShell 。In the Remote Desktop of myVm1, open PowerShell.

  2. 输入 ping myVm2Enter ping myVm2.

    将收到类似于下面的消息:You'll receive a message similar to this:

    Pinging myVm2.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.cloudapp.chinacloudapi.cn
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    
    Ping statistics for 10.1.0.5:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
    

    由于 ping 使用 Internet 控制消息协议 (ICMP),ping 失败。The ping fails, because ping uses the Internet Control Message Protocol (ICMP). 默认情况下,不允许 ICMP 通过 Windows 防火墙。By default, ICMP isn't allowed through the Windows firewall.

  3. 要允许 myVm2 在后面的步骤中对 myVm1 执行 ping 操作 ,请输入以下命令:To allow myVm2 to ping myVm1 in a later step, enter this command:

    New-NetFirewallRule -DisplayName "Allow ICMPv4-In" -Protocol ICMPv4
    

    该命令允许 ICMP 通过 Windows 防火墙入站:This command allows ICMP inbound through the Windows firewall:

  4. 关闭与 myVm1 的远程桌面连接。Close the remote desktop connection to myVm1.

  5. 再次完成从 Internet 连接到 VM 中的步骤,但这次连接到 myVm2Complete the steps in Connect to a VM from the internet again, but connect to myVm2.

  6. 从命令提示符输入 ping myvm1From a command prompt, enter ping myvm1.

    你将看到类似于以下信息的内容:You'll get back something like this message:

    Pinging myVm1.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.chinacloudapp.cn [10.1.0.4] with 32 bytes of data:
    Reply from 10.1.0.4: bytes=32 time=1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    
    Ping statistics for 10.1.0.4:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 1ms, Average = 0ms
    

    将从 myVm1 收到答复,因为在第 3 步中已经允许 ICMP 通过 myVm1 VM 上的 Windows 防火墙 。You receive replies from myVm1, because you allowed ICMP through the Windows firewall on the myVm1 VM in step 3.

  7. 关闭与 myVm2 的远程桌面连接。Close the remote desktop connection to myVm2.

清理资源Clean up resources

使用虚拟网络和 VM 之后,请删除资源组和其包含的所有资源:When you're done using the virtual network and the VMs, delete the resource group and all of the resources it contains:

  1. 在门户顶部的“搜索”框中输入“myResourceGroup”,并从搜索结果中选择“myResourceGroup” 。Enter myResourceGroup in the Search box at the top of the portal and select myResourceGroup from the search results.

  2. 选择“删除资源组” 。Select Delete resource group.

  3. 对于“键入资源组名称”,请输入“myResourceGroup”,然后选择“删除” 。Enter myResourceGroup for TYPE THE RESOURCE GROUP NAME and select Delete.

后续步骤Next steps

在本快速入门中,你创建了默认的虚拟网络和两个 VM。In this Quickstart, you created a default virtual network and two VMs. 从 Internet 连接到了其中一个 VM,并在两个 VM 之间安全地进行了通信。You connected to one VM from the internet and securely communicated between the two VMs. 若要了解有关虚拟网络设置的详细信息,请参阅管理虚拟网络To learn more about virtual network settings, see Manage a virtual network.

默认情况下,Azure 可让 VM 彼此之间进行不受限制的安全通信。By default, Azure allows unrestricted secure communication between VMs. 相反,它只允许从 Internet 到 Windows VM 的入站远程桌面连接。Conversely, it only allows inbound remote desktop connections to Windows VMs from the internet. 要了解有关配置不同类型的 VM 网络通信的详细信息,请转到筛选网络流量教程。To learn more about configuring different types of VM network communications, go to the Filter network traffic tutorial.