使用 PowerShell 创建基于路由的 VPN 网关Create a route-based VPN gateway using PowerShell

本文可帮助你使用 PowerShell 快速创建基于路由的 Azure VPN 网关。This article helps you quickly create a route-based Azure VPN gateway using PowerShell. 创建与本地网络的 VPN 连接时使用 VPN 网关。A VPN gateway is used when creating a VPN connection to your on-premises network. 还可以使用 VPN 网关连接 VNet。You can also use a VPN gateway to connect VNets.

准备阶段Before you begin

本文中的步骤将创建 VNet、子网、网关子网和基于路由的 VPN 网关(虚拟网络网关)。The steps in this article will create a VNet, a subnet, a gateway subnet, and a route-based VPN gateway (virtual network gateway). 完成网关创建后,可以创建连接。Once the gateway creation has completed, you can then create connections. 执行这些步骤需要 Azure 订阅。These steps require an Azure subscription. 如果没有 Azure 订阅,可在开始前创建一个试用帐户If you don't have an Azure subscription, create a Trial before you begin.

使用 Azure PowerShellWorking with Azure PowerShell

可以在计算机本地安装并运行 Azure PowerShell cmdlet。You can install and run the Azure PowerShell cmdlets locally on your computer. PowerShell cmdlet 经常更新。PowerShell cmdlets are updated frequently. 如果尚未安装最新版本,说明中指定的值可能会导致出错。If you have not installed the latest version, the values specified in the instructions may fail. 若要查找计算机上安装的 Azure PowerShell 的版本,请使用 Get-Module -ListAvailable Az cmdlet。To find the versions of Azure PowerShell installed on your computer, use the Get-Module -ListAvailable Az cmdlet. 若要进行安装或更新,请参阅安装 Azure PowerShell 模块To install or update, see Install the Azure PowerShell module.

创建资源组Create a resource group

使用 New-AzResourceGroup 创建 Azure 资源组。Create an Azure resource group with New-AzResourceGroup. 资源组是在其中部署和管理 Azure 资源的逻辑容器。A resource group is a logical container into which Azure resources are deployed and managed. 创建资源组。Create a resource group. 使用提升的权限打开 PowerShell 控制台,并使用 Connect-AzAccount -Environment AzureChinaCloud 命令连接到 Azure。Open your PowerShell console with elevated privileges and connect to Azure using the Connect-AzAccount -Environment AzureChinaCloud command.

New-AzResourceGroup -Name TestRG1 -Location ChinaNorth

创建虚拟网络Create a virtual network

使用 New-AzVirtualNetwork 创建虚拟网络。Create a virtual network with New-AzVirtualNetwork. 以下示例在“ChinaNorth”位置创建一个名为“VNet1”的虚拟网络 :The following example creates a virtual network named VNet1 in the ChinaNorth location:

$virtualNetwork = New-AzVirtualNetwork `
  -ResourceGroupName TestRG1 `
  -Location ChinaNorth `
  -Name VNet1 `
  -AddressPrefix 10.1.0.0/16

使用 New-AzVirtualNetworkSubnetConfig cmdlet 创建子网配置。Create a subnet configuration using the New-AzVirtualNetworkSubnetConfig cmdlet.

$subnetConfig = Add-AzVirtualNetworkSubnetConfig `
  -Name Frontend `
  -AddressPrefix 10.1.0.0/24 `
  -VirtualNetwork $virtualNetwork

使用 Set-AzVirtualNetwork cmdlet 设置虚拟网络的子网配置。Set the subnet configuration for the virtual network using the Set-AzVirtualNetwork cmdlet.

$virtualNetwork | Set-AzVirtualNetwork

添加网关子网Add a gateway subnet

网关子网包含虚拟网络网关服务使用的保留 IP 地址。The gateway subnet contains the reserved IP addresses that the virtual network gateway services use. 使用下面的示例添加网关子网:Use the following examples to add a gateway subnet:

为 VNet 设置变量。Set a variable for your VNet.

$vnet = Get-AzVirtualNetwork -ResourceGroupName TestRG1 -Name VNet1

使用 Add-AzVirtualNetworkSubnetConfig cmdlet 创建网关子网。Create the gateway subnet using the Add-AzVirtualNetworkSubnetConfig cmdlet.

Add-AzVirtualNetworkSubnetConfig -Name 'GatewaySubnet' -AddressPrefix 10.1.255.0/27 -VirtualNetwork $vnet

使用 Set-AzVirtualNetwork cmdlet 设置虚拟网络的子网配置。Set the subnet configuration for the virtual network using the Set-AzVirtualNetwork cmdlet.

$vnet | Set-AzVirtualNetwork

请求公共 IP 地址Request a public IP address

VPN 网关必须具有动态分配的公共 IP 地址。A VPN gateway must have a dynamically allocated public IP address. 创建与 VPN 网关的连接时,这是你指定的 IP 地址。When you create a connection to a VPN gateway, this is the IP address that you specify. 使用下面的示例请求一个公共 IP 地址:Use the following example to request a public IP address:

$gwpip= New-AzPublicIpAddress -Name VNet1GWIP -ResourceGroupName TestRG1 -Location 'China North' -AllocationMethod Dynamic

创建网关 IP 地址配置Create the gateway IP address configuration

网关配置定义要使用的子网和公共 IP 地址。The gateway configuration defines the subnet and the public IP address to use. 使用以下示例创建网关配置:Use the following example to create your gateway configuration:

$vnet = Get-AzVirtualNetwork -Name VNet1 -ResourceGroupName TestRG1
$subnet = Get-AzVirtualNetworkSubnetConfig -Name 'GatewaySubnet' -VirtualNetwork $vnet
$gwipconfig = New-AzVirtualNetworkGatewayIpConfig -Name gwipconfig1 -SubnetId $subnet.Id -PublicIpAddressId $gwpip.Id

创建 VPN 网关Create the VPN gateway

创建 VPN 网关可能需要 45 分钟或更长时间。A VPN gateway can take 45 minutes or more to create. 完成创建网关后,可以创建虚拟网络与另一个 VNet 之间的连接。Once the gateway has completed, you can create a connection between your virtual network and another VNet. 或者,创建虚拟网络与本地位置之间的连接。Or, create a connection between your virtual network and an on-premises location. 使用 New-AzVirtualNetworkGateway cmdlet 创建 VPN 网关。Create a VPN gateway using the New-AzVirtualNetworkGateway cmdlet.

New-AzVirtualNetworkGateway -Name VNet1GW -ResourceGroupName TestRG1 `
-Location 'China North' -IpConfigurations $gwipconfig -GatewayType Vpn `
-VpnType RouteBased -GatewaySku VpnGw1

查看 VPN 网关View the VPN gateway

可使用 Get-AzVirtualNetworkGateway cmdlet 查看 VPN 网关。You can view the VPN gateway using the Get-AzVirtualNetworkGateway cmdlet.

Get-AzVirtualNetworkGateway -Name Vnet1GW -ResourceGroup TestRG1

输出将类似于以下示例:The output will look similar to this example:

Name                   : VNet1GW
ResourceGroupName      : TestRG1
Location               : chinanorth
Id                     : /subscriptions/<subscription ID>/resourceGroups/TestRG1/provide
                         rs/Microsoft.Network/virtualNetworkGateways/VNet1GW
Etag                   : W/"0952d-9da8-4d7d-a8ed-28c8ca0413"
ResourceGuid           : dc6ce1de-2c4494-9d0b-20b03ac595
ProvisioningState      : Succeeded
Tags                   :
IpConfigurations       : [
                           {
                             "PrivateIpAllocationMethod": "Dynamic",
                             "Subnet": {
                               "Id": "/subscriptions/<subscription ID>/resourceGroups/Te
                         stRG1/providers/Microsoft.Network/virtualNetworks/VNet1/subnets/GatewaySubnet"
                             },
                             "PublicIpAddress": {
                               "Id": "/subscriptions/<subscription ID>/resourceGroups/Te
                         stRG1/providers/Microsoft.Network/publicIPAddresses/VNet1GWIP"
                             },
                             "Name": "default",
                             "Etag": "W/\"0952d-9da8-4d7d-a8ed-28c8ca0413\"",
                             "Id": "/subscriptions/<subscription ID>/resourceGroups/Test
                         RG1/providers/Microsoft.Network/virtualNetworkGateways/VNet1GW/ipConfigurations/de
                         fault"
                           }
                         ]
GatewayType            : Vpn
VpnType                : RouteBased
EnableBgp              : False
ActiveActive           : False
GatewayDefaultSite     : null
Sku                    : {
                           "Capacity": 2,
                           "Name": "VpnGw1",
                           "Tier": "VpnGw1"
                         }
VpnClientConfiguration : null
BgpSettings            : {
     

查看公共 IP 地址View the public IP address

若要查看 VPN 网关的公共 IP 地址,请使用 Get-AzPublicIpAddress cmdlet。To view the public IP address for your VPN gateway, use the Get-AzPublicIpAddress cmdlet.

Get-AzPublicIpAddress -Name VNet1GWIP -ResourceGroupName TestRG1

在此示例响应中,IpAddress 值是公共 IP 地址。In the example response, the IpAddress value is the public IP address.

Name                     : VNet1GWIP
ResourceGroupName        : TestRG1
Location                 : chinanorth
Id                       : /subscriptions/<subscription ID>/resourceGroups/TestRG1/provi
                           ders/Microsoft.Network/publicIPAddresses/VNet1GWIP
Etag                     : W/"5001666a-bc2a-484b-bcf5-ad488dabd8ca"
ResourceGuid             : 3c7c481e-9828-4dae-abdc-f95b383
ProvisioningState        : Succeeded
Tags                     :
PublicIpAllocationMethod : Dynamic
IpAddress                : 13.90.153.3
PublicIpAddressVersion   : IPv4
IdleTimeoutInMinutes     : 4
IpConfiguration          : {
                             "Id": "/subscriptions/<subscription ID>/resourceGroups/Test
                           RG1/providers/Microsoft.Network/virtualNetworkGateways/VNet1GW/ipConfigurations/
                           default"
                           }
DnsSettings              : null
Zones                    : {}
Sku                      : {
                             "Name": "Basic"
                           }
IpTags                   : {}

清理资源Clean up resources

如果不再需要所创建的资源,请使用 Remove-AzResourceGroup 命令删除资源组。When you no longer need the resources you created, use the Remove-AzResourceGroup command to delete the resource group. 这将删除资源组及其包含的所有资源。This will delete the resource group and all of the resources it contains.

Remove-AzResourceGroup -Name TestRG1

后续步骤Next steps

完成创建网关后,可以创建虚拟网络与另一个 VNet 之间的连接。Once the gateway has finished creating, you can create a connection between your virtual network and another VNet. 或者,创建虚拟网络与本地位置之间的连接。Or, create a connection between your virtual network and an on-premises location.