方案:任意位置到任意位置Scenario: Any-to-any

使用虚拟 WAN 虚拟中心路由时,有很多可用方案。When working with Virtual WAN virtual hub routing, there are quite a few available scenarios. 在“任意位置到任意位置”方案中,任意分支都可以联系另一个分支。In an Any-to-any scenario, any spoke can reach another spoke. 如果存在多个中心,默认情况下会在标准虚拟 WAN 中启用中心到中心路由(也称为“中心间”)。When multiple hubs exist, hub-to-hub routing (also known as inter-hub) is enabled by default in Standard Virtual WAN. 有关虚拟中心路由的详细信息,请参阅关于虚拟中心路由For more information about virtual hub routing, see About virtual hub routing.

设计Design

为了确定虚拟 WAN 方案中将会需要多少路由表,可以构建一个连接矩阵,其中每个单元格都表示源(行)是否可以与目标(列)通信。In order to figure out how many route tables will be needed in a Virtual WAN scenario, you can build a connectivity matrix, where each cell represents whether a source (row) can communicate to a destination (column).

FromFrom 目标To VNetVNets 分支Branches
VNetVNets 直接Direct 直接Direct
分支Branches 直接Direct 直接Direct

上表中的各单元格描述了虚拟 WAN 连接(流的“源”端,行标题)是否与目标前缀(流的“目标”端,斜体形式的列标题)通信。Each of the cells in the previous table describes whether a Virtual WAN connection (the "From" side of the flow, the row headers) communicates with a destination prefix (the "To" side of the flow, the column headers in italics). 在此方案中,没有防火墙或网络虚拟设备,因此通信直接通过虚拟 WAN 进行(因此在表中使用“直接”一词)。In this scenario there are no firewalls or Network Virtual Appliances, so communication flows directly over Virtual WAN (hence the word "Direct" in the table).

由于来自 VNet 和分支(VPN、ExpressRoute 和用户 VPN)的所有连接都具有相同的连接要求,因此需要单个路由表。Since all connections from both VNets and branches (VPN, ExpressRoute, and User VPN) have the same connectivity requirements, a single route table is required. 这样,所有的连接都将会关联,并将传播到同一个路由表,即 Default 路由表:As a result, all connections will be associated and propagate to the same route table, the Default route table:

  • 虚拟网络:Virtual networks:
    • 关联的路由表:DefaultAssociated route table: Default
    • 传播到路由表:DefaultPropagating to route tables: Default
  • 分支:Branches:
    • 关联的路由表:DefaultAssociated route table: Default
    • 传播到路由表:DefaultPropagating to route tables: Default

有关虚拟中心路由的详细信息,请参阅关于虚拟中心路由For more information about virtual hub routing, see About virtual hub routing.

体系结构Architecture

在图 1 中,所有 VNet 和分支(VPN、ExpressRoute、P2S)都可以相互联系。In Figure 1, all VNets and Branches (VPN, ExpressRoute, P2S) can reach each other. 在虚拟中心,连接的工作方式如下:In a virtual hub, connections work as follows:

  • VPN 连接将 VPN 站点连接到 VPN 网关。A VPN connection connects a VPN site to a VPN gateway.
  • 虚拟网络连接将虚拟网络连接到虚拟中心。A virtual network connection connects a virtual network to a virtual hub. 虚拟中心的路由器提供 VNet 之间的传输功能。The virtual hub's router provides the transit functionality between VNets.
  • ExpressRoute 连接将 ExpressRoute 线路连接到 ExpressRoute 网关。An ExpressRoute connection connects an ExpressRoute circuit to an ExpressRoute gateway.

这些连接(默认在创建时)都会关联到 Default 路由表,除非已将连接的路由配置设置为“无”,或者设置为自定义路由表。These connections (by default at creation) are associated to the Default route table, unless you set up the routing configuration of the connection to either None, or a custom route table. 这些连接也传播路由,默认情况下传播到 Default 路由表。These connections also propagate routes, by default to the Default route table. 这种方式实现了“任意位置到任意位置”方案,其中任何分支(VNet、VPN、ER、P2S)都可以相互联系。This is what enables an any-to-any scenario where any spoke (VNet, VPN, ER, P2S) can reach each other.

图 1Figure 1

图 1

工作流Workflow

对于标准虚拟 WAN,默认情况下会启用此方案。This scenario is enabled by default for Standard Virtual WAN. 如果 WAN 配置中禁用了分支到分支的设置,将会禁止分支之间的连接。If the setting for branch-to-branch are disabled in WAN configuration, that will disallow connectivity between branch spokes. VPN/ExpressRoute/用户 VPN 在虚拟 WAN 中被视为分支VPN/ExpressRoute/User VPN are considered as branch spokes in Virtual WAN

后续步骤Next steps