教程:使用 Azure 虚拟 WAN 创建 ExpressRoute 关联Tutorial: Create an ExpressRoute association using Azure Virtual WAN

本教程演示如何使用虚拟 WAN 通过 ExpressRoute 线路来连接到 Azure 中的资源。This tutorial shows you how to use Virtual WAN to connect to your resources in Azure over an ExpressRoute circuit. 有关虚拟 WAN 和 虚拟 WAN 资源的详细信息,请参阅虚拟 WAN 概述For more information about Virtual WAN and Virtual WAN resources, see the Virtual WAN Overview.

本教程介绍如何执行下列操作:In this tutorial, you learn how to:

  • 创建虚拟 WANCreate a virtual WAN
  • 创建中心和网关Create a hub and a gateway
  • 将 VNet 连接到中心Connect a VNet to a hub
  • 将线路连接到中心网关Connect a circuit to a hub gateway
  • 测试连接Test connectivity
  • 更改网关大小Change a gateway size
  • 播发默认路由Advertise a default route

准备阶段Before you begin

在开始配置之前,请验证是否符合以下条件:Verify that you have met the following criteria before beginning your configuration:

  • 你拥有一个要连接到的虚拟网络。You have a virtual network that you want to connect to. 确认本地网络的任何子网都不会与要连接到的虚拟网络重叠。Verify that none of the subnets of your on-premises networks overlap with the virtual networks that you want to connect to. 要在 Azure 门户中创建虚拟网络,请参阅快速入门To create a virtual network in the Azure portal, see the Quickstart.

  • 虚拟网络不包含任何虚拟网络网关。Your virtual network does not have any virtual network gateways. 如果虚拟网络包含网关(VPN 或 ExpressRoute),则必须删除所有网关。If your virtual network has a gateway (either VPN or ExpressRoute), you must remove all gateways. 此配置要求将虚拟网络改为连接到虚拟 WAN 中心网关。This configuration requires that virtual networks are connected instead, to the Virtual WAN hub gateway.

  • 获取中心区域的 IP 地址范围。Obtain an IP address range for your hub region. 该中心是虚拟 WAN 创建和使用的虚拟网络。The hub is a virtual network that is created and used by Virtual WAN. 为中心指定的地址范围不能与要连接到的任何现有虚拟网络重叠。The address range that you specify for the hub cannot overlap with any of your existing virtual networks that you connect to. 此外,它也不能与本地连接到的地址范围重叠。It also cannot overlap with your address ranges that you connect to on premises. 如果不熟悉本地网络配置中的 IP 地址范围,则咨询能够提供此类详细信息的人员。If you are unfamiliar with the IP address ranges located in your on-premises network configuration, coordinate with someone who can provide those details for you.

  • ExpressRoute 线路必须是高级线路,才能连接到中心网关。The ExpressRoute circuit must be a Premium circuit in order to connect to the hub gateway.

  • 如果没有 Azure 订阅,请创建一个试用帐户If you don't have an Azure subscription, create a trial account.

创建虚拟 WANCreate a virtual WAN

从浏览器导航到 Azure 门户并使用 Azure 帐户登录。From a browser, navigate to the Azure portal and sign in with your Azure account.

  1. 导航到“虚拟 WAN”页。Navigate to the Virtual WAN page. 在门户中,单击“+创建资源” 。In the portal, click +Create a resource. 在搜索框中键入“虚拟 WAN” ,然后选择 Enter。Type Virtual WAN into the search box and select Enter.

  2. 从结果中选择“虚拟 WAN” 。Select Virtual WAN from the results. 在“虚拟 WAN”页上,单击“创建”以打开“创建 WAN”页 。On the Virtual WAN page, click Create to open the Create WAN page.

  3. 在“创建 WAN”页的“基本信息”选项卡上,填写以下字段 :On the Create WAN page, on the Basics tab, fill in the following fields:

    创建 WAN

    • 订阅 - 选择要使用的订阅。Subscription - Select the subscription that you want to use.
    • 资源组 - 新建资源组或使用现有的资源组。Resource Group - Create new or use existing.
    • 资源组位置 - 从下拉列表中选择资源位置。Resource group location - Choose a resource location from the dropdown. WAN 是一个全局资源,不会驻留在某个特定区域。A WAN is a global resource and does not live in a particular region. 但是,必须选择一个区域才能更轻松地管理和查找所创建的 WAN 资源。However, you must select a region in order to more easily manage and locate the WAN resource that you create.
    • 名称 - 键入要用于称呼 WAN 的名称。Name - Type the name that you want to call your WAN.
    • 类型 - 选择“标准” 。Type - Select Standard. 不能使用基本 SKU 创建 ExpressRoute 网关。You can't create an ExpressRoute gateway using the Basic SKU.
  4. 填写完字段后,单击“审阅 + 创建” 。After you finish filling out the fields, select Review +Create.

  5. 验证通过后,选择“创建”以创建虚拟 WAN 。Once validation passes, select Create to create the virtual WAN.

创建虚拟中心和网关Create a virtual hub and gateway

虚拟中心是虚拟 WAN 创建和使用的虚拟网络。A virtual hub is a virtual network that is created and used by Virtual WAN. 它可以包含各种网关,如 VPN 和 ExpressRoute。It can contain various gateways, such as VPN and ExpressRoute. 在本部分中,将为虚拟中心创建 ExpressRoute 网关。In this section, you will create an ExpressRoute gateway for your virtual hub. 你可以在创建新虚拟中心时创建网关,或者可以通过编辑现有中心,在现有中心创建网关。You can either create the gateway when you create a new virtual hub, or you can create the gateway in an existing hub by editing it.

ExpressRoute 网关以 2 Gbps 为单位进行预配。ExpressRoute gateways are provisioned in units of 2 Gbps. 1 个缩放单元= 2 Gbps,最多支持 10 个缩放单元 = 20 Gbps。1 scale unit = 2 Gbps with support up to 10 scale units = 20 Gbps. 完全创建虚拟中心和网关大约需要 30 分钟。It takes about 30 minutes for a virtual hub and gateway to fully create.

创建新的虚拟中心和网关To create a new virtual hub and a gateway

创建新的虚拟中心。Create a new virtual hub. 创建中心后,即使你没有附加任何站点,也会对该中心收取费用。Once a hub is created, you'll be charged for the hub, even if you don't attach any sites.

  1. 找到创建的虚拟 WAN。Locate the Virtual WAN that you created. 在虚拟 WAN 页上的“连接”部分下,选择“中心” 。On the Virtual WAN page, under the Connectivity section, select Hubs.

  2. 在“中心”页上,选择“+ 新建中心”以打开“创建虚拟中心”页 。On the Hubs page, select +New Hub to open the Create virtual hub page.

  3. 在“创建虚拟中心”页上的“基本”选项卡上,请填写以下字段 :On the Create virtual hub page Basics tab, complete the following fields:

    基础知识Basics

    项目详细信息Project details

    • 区域(之前称为位置)Region (previously referred to as Location)
    • 名称Name
    • 中心专用地址空间。Hub private address space. 用于创建中心的最小地址空间是 /24,这表示在创建过程中从 /25 到 /32 的任何范围都将产生错误。The minimum address space is /24 to create a hub, which implies anything range from /25 to /32 will produce an error during creation.
  4. 选择“ExpressRoute 选项卡” 。Select the ExpressRoute tab.

  5. 在“ExpressRoute 选项卡”上,填写以下字段 :On the ExpressRoute tab, complete the following fields:

    ExpressRouteExpressRoute

    • 选择“是”以创建“ExpressRoute”网关 。Select Yes to create an ExpressRoute gateway.
    • 从下拉列表中选择“网关缩放单元” 。Select the Gateway scale units value from the dropdown.
  6. 选择“查看 + 创建”以进行验证 。Select Review + Create to validate.

  7. 选择“创建”以创建中心 。Select Create to create the hub. 30 分钟后,“刷新”以在“中心”页上查看该中心 。After 30 minutes, Refresh to view the hub on the Hubs page. 选择“转到资源”导航到资源 。Select Go to resource to navigate to the resource.

在现有的中心内创建网关To create a gateway in an existing hub

还可以通过编辑现有中心,在现有中心创建网关。You can also create a gateway in an existing hub by editing it.

  1. 导航到要编辑的虚拟中心,然后选择它。Navigate to the virtual hub that you want to edit and select it.

  2. 在“编辑虚拟中心”页上,选中“包括 ExpressRoute 网关”复选框 。On the Edit virtual hub page, select the checkbox Include ExpressRoute gateway.

  3. 选择“确认”以确认所做的更改 。Select Confirm to confirm your changes. 完全创建中心和中心资源大约需要 30 分钟。It takes about 30 minutes for the hub and hub resources to fully create.

    现有中心existing hub

查看网关To view a gateway

创建 ExpressRoute 网关后,可以查看网关详细信息。Once you have created an ExpressRoute gateway, you can view gateway details. 导航到中心,选择“ExpressRoute”,然后查看网关 。Navigate to the hub, select ExpressRoute, and view the gateway.

查看网关View gateway

将 VNet 连接到中心Connect your VNet to the hub

此步骤在中心与 VNet 之间创建对等互连。In this section, you create the peering connection between your hub and a VNet. 针对要连接的每个 VNet 重复这些步骤。Repeat these steps for each VNet that you want to connect.

  1. 在虚拟 WAN 的页面上,单击“虚拟网络连接”。 On the page for your virtual WAN, click Virtual network connection.

  2. 在虚拟网络连接页上,单击“+添加连接”。 On the virtual network connection page, click +Add connection.

  3. 在“添加连接”页上填写以下字段 :On the Add connection page, fill in the following fields:

    • 连接名称 - 为连接命名。Connection name - Name your connection.
    • 中心 - 选择要与此连接关联的中心。Hubs - Select the hub you want to associate with this connection.
    • 订阅 - 验证订阅。Subscription - Verify the subscription.
    • 虚拟网络 - 选择要连接到此中心的虚拟网络。Virtual network - Select the virtual network you want to connect to this hub. 此虚拟网络不能包含现有的虚拟网络网关(既不能是 VPN 也不能是 ExpressRoute)。The virtual network cannot have an already existing virtual network gateway (neither VPN, nor ExpressRoute).

将线路连接到中心网关Connect your circuit to the hub gateway

创建网关后,就可以将 ExpressRoute 线路连接到该网关。Once the gateway is created, you can connect an ExpressRoute circuit to it. ExpressRoute Global Reach 支持的位置中的 ExpressRoute 高级版线路可以连接到虚拟 WAN ExpressRoute 网关。ExpressRoute Premium circuits that are in ExpressRoute Global Reach-supported locations can connect to a Virtual WAN ExpressRoute gateway.

将线路连接到中心网关To connect the circuit to the hub gateway

在门户中,转到“虚拟中心”->“连接性”->“ExpressRoute”页面 。In the portal, go to the Virtual hub -> Connectivity -> ExpressRoute page. 如果可以在订阅访问 ExpressRoute 线路,将在线路列表中看到要使用的线路。If you have access in your subscription to an ExpressRoute circuit, you will see the circuit you want to use in the list of circuits. 如果没有看到任何线路,但已获得授权密钥和对等线路 URI,则可以兑换并连接线路。If you don't see any circuits, but have been provided with an authorization key and peer circuit URI, you can redeem and connect a circuit. 请参阅通过兑换授权密钥进行连接See To connect by redeeming an authorization key.

  1. 选择线路。Select the circuit.

  2. 选择“连接线路” 。Select Connect circuit(s).

    连接线路connect circuits

通过兑换授权密钥进行连接To connect by redeeming an authorization key

使用提供的授权密钥和线路 URI 进行连接。Use the authorization key and circuit URI you were provided in order to connect.

  1. 在 ExpressRoute 页面上,单击“+ 兑换授权密钥” On the ExpressRoute page, click +Redeem authorization key

    兑换redeem

  2. 在“兑换授权密钥”页上,填写值。On the Redeem authorization key page, fill in the values.

    兑换密钥值redeem key values

  3. 选择“添加”以添加密钥 。Select Add to add the key.

  4. 查看线路。View the circuit. 兑换线路只显示名称(不显示类型、提供程序和其他信息),因为它与用户的订阅不同。A redeemed circuit only shows the name (without the type, provider and other information) because it is in a different subscription than that of the user.

测试连接To test connectivity

建立线路连接后,中心连接状态将指示“此中心”,这意味着已建立通向中心 ExpressRoute 网关的连接。After the circuit connection is established, the hub connection status will indicate 'this hub', implying the connection is established to the hub ExpressRoute gateway. 等待大约 5 分钟,然后再测试 ExpressRoute 线路后面的客户端(例如,先前创建的 VNet 中的 VM)的连接性。Wait approximately 5 minutes before you test connectivity from a client behind your ExpressRoute circuit, for example, a VM in the VNet that you created earlier.

如果你的站点连接到与 ExpressRoute 网关位于同一中心的虚拟 WAN VPN 网关,则可以在 VPN 和 ExpressRoute 终结点之间进行双向连接。If you have sites connected to a Virtual WAN VPN gateway in the same hub as the ExpressRoute gateway, you can have bidirectional connectivity between VPN and ExpressRoute end points. 支持动态路由 (BGP)。Dynamic routing (BGP) is supported. 中心网关的 ASN 是固定的,此时无法编辑。The ASN of the gateways in the hub is fixed and cannot be edited at this time.

更改网关的大小To change the size of a gateway

如果要更改 ExpressRoute 网关的大小,请在中心内找到 ExpressRoute 网关,然后从下拉列表中选择缩放单元。If you want to change the size of your ExpressRoute gateway, locate the ExpressRoute gateway inside the hub, and select the scale units from the dropdown. 保存所做更改。Save your change. 更新中心网关需要大约 30 分钟。It will take approximately 30 minutes to update the hub gateway.

更改网关大小change gateway size

向终结点播发默认路由 0.0.0.0/0To advertise default route 0.0.0.0/0 to endpoints

如果想要 Azure 虚拟中心将默认路由 0.0.0.0/0 播发到 ExpressRoute 终结点,则需要启用“传播默认路由”。If you would like the Azure virtual hub to advertise the default route 0.0.0.0/0 to your ExpressRoute end points, you will need to enable 'Propagate default route'.

  1. 选择“线路”->“…”->“编辑连接” 。Select your Circuit ->…-> Edit connection.

    编辑连接Edit connection

  2. 选择“启用”来传播默认路由 。Select Enable to propagate the default route.

    传播默认路由Propagate default route

后续步骤Next steps

若要详细了解虚拟 WAN,请参阅虚拟 WAN 概述页。To learn more about Virtual WAN, see the Virtual WAN Overview page.