跨多个 ISP 链接进行 Azure 路径选择Azure path selection across multiple ISP links

Azure 虚拟 WAN 为用户提供了在 VPN 站点中包含链接信息的功能,使 VPN/SD-WAN 设备解决方案能够对特定于分支的策略进行编程,引导流量跨不同链接流入 Azure。Azure Virtual WAN provides a user the capability to include link information in a VPN Site, enabling scenarios where the VPN/SD-WAN device solution can program branch-specific policies to steer traffic across various links into Azure. 这称为 Azure 路径选择This is called Azure path selection .

体系结构Architecture

为了理解 Azure 路径选择的工作原理,让我们以虚拟 WAN VPN 站点和站点到站点连接为例。To understand how Azure path selection works, let's use the example of a Virtual WAN VPN site and a site-to-site connection.

VPN 站点表示包含公共 IP、设备型号和名称等信息的本地 SD-WAN/VPN 设备。实际的本地 VPN 站点可能有多个 ISP 链接,这些链接也可以包含在虚拟 WAN VPN 站点信息中。A VPN site represents the on-premises SD-WAN/VPN device with information such as public IP, device model and name, etc. The actual on-premises VPN site may have multiple ISP links that can also be included in Virtual WAN VPN site information. 这使你可以在 Azure 中查看链接信息。This allows you to view the link information in Azure.

进入虚拟 WAN 的 VPN 的站点到站点 IPsec 连接在虚拟中心内的 VPN 网关实例上终止。A site-to-site IPsec connection coming into a Virtual WAN's VPN terminates on the VPN gateway instances inside a virtual hub. 站点到站点连接表示 VPN 站点与 Azure VPN 网关之间的连接。A site-to-site connection represents the connectivity between the VPN site and the Azure VPN gateway. 它由一个或多个链接连接组成。It consists of one or more link connections. 每个链接连接都由两个隧道组成,每个隧道都在 Azure 虚拟 WAN VPN 网关的唯一实例上终止。Each link connection consists of two tunnels with each tunnel terminating on a unique instance of the Azure Virtual WAN VPN gateway. 站点到站点连接最多可以设置四个链接连接,这使站点到站点连接中最多可以有八个隧道。Up to four link connections can be set up in the site-to-site connection, which makes it possible to have up to eight tunnels within a site-to-site connection. Azure 支持多达 2000 个隧道,这些隧道在单个虚拟 WAN VPN 网关内终止。Azure supports up to 2000 tunnels terminating inside a single Virtual WAN VPN gateway.

多链接关系图

此图显示了在连接到 Azure 虚拟 WAN 的站点中的多链接。This figure shows multi-link at a site connecting to Azure Virtual WAN. 在此图中:In this diagram:

  • 本地分支(VPN/SD-WAN 设备)有两个 ISP 链接。There are two ISP links at the on-premises branch (VPN/SD-WAN device). 每个 ISP 链接对应于一个链接连接。Each ISP link corresponds to a link connection.

  • 假定本地客户管理器 VPN/SD-WAN 设备支持 IKEv1 或 IKEv2 IPsec。It assumed that the on-premises customer-manager VPN/SD-WAN device supports IKEv1 or IKEv2 IPsec.

  • 每个 Azure 站点到站点虚拟 WAN 连接均由其自身内部的链接连接组成。Each Azure site-to-site Virtual WAN connection is composed of link connections within itself. 一个连接最多支持四个链接连接。A connection supports up to four link connections. Azure 会针对虚拟 WAN 连接收取连接单元费用。Azure charges a connection unit fee for the Virtual WAN connection. 链接连接不会产生任何费用。There is no charge for the link connections.

  • 而每个链接连接由两个 IPsec 隧道组成,这些隧道可以在虚拟 WAN VPN 网关的两个不同实例上终止。Each link connection, in turn, consists of two IPsec tunnels that can terminate on two different instances of the Virtual WAN VPN gateway. 网关设置为主动 - 主动网关,以提高复原能力。The gateways are set up as active-active gateways for resiliency. 每个链接连接需要有一个唯一的 IP 地址和 BGP 对等 IP。Each link connection is required to have a unique IP address and BGP Peering IP. 在图中,隧道 0 可以在实例 0 上终止,隧道 1 可以在实例 1 上终止。In the diagram, Tunnel 0 can terminate on instance 0, and Tunnel 1 can terminate on instance 1.

  • 提供路径选择的分支设备可以在分支管理解决方案中启用适当的策略,以引导流量跨不同链接流入 Azure。Branch devices that provide path selection can enable appropriate policy in the branch management solution to steer traffic across multiple links to Azure. 例如,ISP 1 链接可用于更高优先级的流量,ISP 2 链接可以用作备份。For example, the ISP 1 link can be used for higher priority traffic and the ISP 2 link can be used as backup.

  • 需要注意的是,虚拟中心 VPN 在所有终止隧道中使用 ECMP(等价多路径路由)。It is important to note that Virtual HUB VPN uses ECMP (equal cost multi-path routing) across all terminating tunnels.

后续步骤Next steps

请参阅 Azure 常见问题解答See the Azure FAQ.