查看虚拟中心的有效路由View effective routes of a virtual hub

可以在 Azure 门户中查看虚拟 WAN 中心的所有路由。You can view all the routes of your Virtual WAN hub in the Azure portal. 若要查看路由,请导航到虚拟中心,然后选择“路由”>“查看有效路由” 。To view the routes, navigate to the virtual hub, then select Routing -> View Effective Routes.

了解路由Understanding routes

以下示例可帮助你更好地了解虚拟 WAN 路由的显示方式。The following example can help you better understand how Virtual WAN routing appears.

在此示例中,我们有一个具有三个中心的虚拟 WAN。In this example, we have a virtual WAN with three hubs. 第一个中心在“中国东部”区域,第二个中心在“中国北部”区域,第三个中心在“中国北部 2”区域。The first hub is in the China East region, second hub is in the China North region, and the third hub is in the China North 2 region. 在虚拟 WAN 中,所有中心都是互联的。In a virtual WAN, all hubs are interconnected. 在此示例中,我们假设“中国东部”和“中国北部”中心与本地分支(辐射)和 Azure 虚拟网络(辐射)之间都有连接。In this example, we will assume that the China East and China North hubs have connections from on-premises branches (spokes) and Azure virtual networks (spokes).

包含网络虚拟设备 (10.4.0.6) 的 Azure VNet 辐射 (10.4.0.0/16) 进一步对等互连到一个 VNet (10.5.0.0/16)。An Azure VNet spoke (10.4.0.0/16) with a Network Virtual Appliance (10.4.0.6) is further peered to a VNet (10.5.0.0/16). 有关中心路由表的详细信息,请参阅本文下文中的其他信息See Additional information later in this article for more information about the hub route table.

在此示例中,我们还假设“中国北部 2 分支 1”连接到“中国东部”中心以及“中国北部”中心。In this example, we also assume that the China North 2 Branch 1 is connected to China East hub, as well as to the China North hub. “中国东部”中的一个 ExpressRoute 线路将分支 2 连接到“中国东部”中心。An ExpressRoute circuit in China East connects Branch 2 to the China East hub.

示意图

查看有效路由View effective routes

当你在门户中选择“查看有效路由”时,它将为“中国东部”中心生成中心路由表中显示的输出。When you select 'View Effective Routes' in the portal, it produces the output shown in the Hub route table for the China East Hub.

如下所示,第一行表示,由于 VPN“下一跃点类型” 连接(“下一跃点”VPN 网关实例 0 的 IP 为 10.1.0.6、实例 1 的 IP 为 10.1.0.7),“中国东部”中心已获知了 10.20.1.0/24(分支 1)的路由。To put this in perspective, the first line implies that the China East hub has learned the route of 10.20.1.0/24 (Branch 1) due to the VPN Next hop type connection ('Next hop' VPN Gateway Instance0 IP 10.1.0.6, Instance1 IP 10.1.0.7). “路由原点” 指向资源 ID。Route Origin points to the resource ID. “AS 路径” 表示分支 1 的 AS 路径。AS Path indicates the AS Path for Branch 1.

中心路由表Hub route table

可以使用表底部的滚动条查看“AS 路径”。Use the scroll bar at the bottom of the table to view the "AS Path".

PrefixPrefix 下一跃点类型Next hop type 下一跃点Next hop 路由原点Route Origin AS 路径AS Path
10.20.1.0/2410.20.1.0/24 VPNVPN 10.1.0.6、10.1.0.710.1.0.6, 10.1.0.7 /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/vpnGateways/343a19aa6ac74e4d81f05ccccf1536cf-chinaeast-gw/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/vpnGateways/343a19aa6ac74e4d81f05ccccf1536cf-chinaeast-gw 2000020000
10.21.1.0/2410.21.1.0/24 ExpressRouteExpressRoute 10.1.0.10、10.1.0.1110.1.0.10, 10.1.0.11 /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/expressRouteGateways/4444a6ac74e4d85555-chinaeast-gw/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/expressRouteGateways/4444a6ac74e4d85555-chinaeast-gw 2100021000
10.23.1.0/2410.23.1.0/24 VPNVPN 10.1.0.6、10.1.0.710.1.0.6, 10.1.0.7 /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/vpnGateways/343a19aa6ac74e4d81f05ccccf1536cf-chinaeast-gw/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/vpnGateways/343a19aa6ac74e4d81f05ccccf1536cf-chinaeast-gw 2300023000
10.4.0.0/1610.4.0.0/16 虚拟网络连接Virtual Network Connection 在链路上On-link
10.5.0.0/1610.5.0.0/16 IP 地址IP Address 10.4.0.610.4.0.6 /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/easthub_1/routeTables/table_1/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/easthub_1/routeTables/table_1
0.0.0.0/00.0.0.0/0 IP 地址IP Address <Azure Firewall IP> /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/easthub_1/routeTables/table_1/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/easthub_1/routeTables/table_1
10.22.1.0/1610.22.1.0/16 远程中心Remote Hub 10.8.0.6、10.8.0.710.8.0.6, 10.8.0.7 /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/northhub_/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/northhub_ 4848-220004848-22000
10.9.0.0/1610.9.0.0/16 远程中心Remote Hub 在链路上On-link /subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/northhub_1/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.Network/virtualHubs/northhub_1

备注

在示例拓扑中,如果“中国东部”和“中国北部”中心没有相互通信,则所获知的路由 (10.9.0.0/16) 将不存在。If the China East and the China North hubs were not communicating with each other in the example topology, the route learned (10.9.0.0/16) would not exist. 中心仅播发直接连接到它们的网络。Hubs only advertise networks that are directly connected to them.

其他信息Additional information

关于中心路由表About the hub route table

可以创建一个虚拟中心路由,并将该路由应用于虚拟中心路由表。You can create a virtual hub route and apply the route to the virtual hub route table. 可以将多个路由应用于虚拟中心路由表。You can apply multiple routes to the virtual hub route table. 这允许你通过 IP 地址(通常是辐射 VNet 中的网络虚拟设备 (NVA))设置目标 VNet 的路由。This lets you set a route for destination VNet via an IP address (typically the Network Virtual Appliance (NVA) in a spoke VNet). 有关 NVA 的详细信息,请参阅将流量从虚拟中心路由到 NVAFor more information about NVAs, see Route traffic from a virtual hub to an NVA.

关于默认路由 (0.0.0.0/0)About default route (0.0.0.0/0)

虚拟中心能够将获知的默认路由传播到虚拟网络、站点到站点 VPN 和 ExpressRoute 连接,前提是连接上的此标志设置为“已启用”。A virtual hub has the ability to propagate a learned default route to a virtual network, a site-to-site VPN, and an ExpressRoute connection if the flag is 'Enabled' on the connection. 当你编辑虚拟网络连接、VPN 连接或 ExpressRoute 连接时,将显示此标志。This flag is visible when you edit a virtual network connection, a VPN connection, or an ExpressRoute connection. 默认情况下,“EnableInternetSecurity”在中心 VNet、ExpressRoute 和 VPN 连接上始终为 false。'EnableInternetSecurity' is always false by default on Hub VNet, ExpressRoute, and VPN connections.

默认路由并非源自虚拟 WAN 中心。The default route does not originate in the virtual WAN hub. 当虚拟 WAN 中心由于在中心部署防火墙而获知了默认路由或另一个已连接的站点已启用强制隧道时,将会传播默认路由。The default route is propagated if it is already learned by the virtual WAN hub as a result of deploying a firewall in the hub, or if another connected site has forced tunneling enabled.

后续步骤Next steps

有关虚拟 WAN 的详细信息,请参阅虚拟 WAN 概述For more information about Virtual WAN, see the Virtual WAN Overview.