什么是 VPN 网关?What is VPN Gateway?

VPN 网关是特定类型的虚拟网关,用于跨公共 Internet 在 Azure 虚拟网络和本地位置之间发送加密的流量。A VPN gateway is a specific type of virtual network gateway that is used to send encrypted traffic between an Azure virtual network and an on-premises location over the public Internet. 也可使用 VPN 网关在基于 Microsoft 网络的 Azure 虚拟网络之间发送加密流量。You can also use a VPN gateway to send encrypted traffic between Azure virtual networks over the Microsoft network. 每个虚拟网络只能有一个 VPN 网关。Each virtual network can have only one VPN gateway. 但是,可以创建连接到相同 VPN 网关的多个连接。However, you can create multiple connections to the same VPN gateway. 与同一个 VPN 网关建立多个连接时,所有 VPN 隧道共享可用的网关带宽。When you create multiple connections to the same VPN gateway, all VPN tunnels share the available gateway bandwidth.

什么是虚拟网关?What is a virtual network gateway?

虚拟网络网关由两个或多个 VM 组成,这些 VM 部署到所创建的名为“网关子网”的特定子网。A virtual network gateway is composed of two or more VMs that are deployed to a specific subnet you create called the gateway subnet. 虚拟网络网关 VM 包含路由表,并运行特定的网关服务。Virtual network gateway VMs contain routing tables and run specific gateway services. 这些 VM 是在创建虚拟网络网关时创建的。These VMs are created when you create the virtual network gateway. 不能直接配置属于虚拟网络网关的 VM。You can't directly configure the VMs that are part of the virtual network gateway.

配置虚拟网络网关时,将配置用于指定网关类型的设置。When you configure a virtual network gateway, you configure a setting that specifies the gateway type. 网关类型确定如何使用虚拟网络网关以及网关所采取的操作。The gateway type determines how the virtual network gateway will be used and the actions that the gateway takes. 网关类型“Vpn”指定创建的虚拟网关类型为“VPN 网关”。The gateway type 'Vpn' specifies that the type of virtual network gateway created is a 'VPN gateway'. 这将它与使用其他网关类型的 ExpressRoute 网关区分开来。This distinguishes it from an ExpressRoute gateway, which uses a different gateway type. 一个虚拟网络可以有两个虚拟网络网关:一个 VPN 网关和一个 ExpressRoute 网关。A virtual network can have two virtual network gateways; one VPN gateway and one ExpressRoute gateway. 有关详细信息,请参阅网关类型For more information, see Gateway types.

创建虚拟网关可能需要多达 45 分钟才能完成。Creating a virtual network gateway can take up to 45 minutes to complete. 创建虚拟网关时,会将网关 VM 部署到网关子网,并使用指定的设置进行配置。When you create a virtual network gateway, gateway VMs are deployed to the gateway subnet and configured with the settings that you specify. 在创建 VPN 网关以后,即在一个 VPN 网关和另一个 VPN 网关之间(VNet 到 VNet)创建 IPsec/IKE VPN 隧道连接,或者在 VPN 网关和本地 VPN 设备(站点到站点)之间创建跨界 IPsec/IKE VPN 隧道连接。After you create a VPN gateway, you can create an IPsec/IKE VPN tunnel connection between that VPN gateway and another VPN gateway (VNet-to-VNet), or create a cross-premises IPsec/IKE VPN tunnel connection between the VPN gateway and an on-premises VPN device (Site-to-Site). 也可创建点到站点 VPN 连接(基于 OpenVPN、IKEv2 或 SSTP 的 VPN),以便从远程位置(例如从会议室或家)连接到虚拟网络。You can also create a Point-to-Site VPN connection (VPN over OpenVPN, IKEv2, or SSTP), which lets you connect to your virtual network from a remote location, such as from a conference or from home.

配置 VPN 网关Configuring a VPN Gateway

VPN 网关连接依赖于使用特定设置配置的多个资源。A VPN gateway connection relies on multiple resources that are configured with specific settings. 大多数资源可以单独配置,虽然某些资源必须按特定顺序配置。Most of the resources can be configured separately, although some resources must be configured in a certain order.

设计Design

必须知道,VPN 网关连接可以使用不同的配置。It's important to know that there are different configurations available for VPN gateway connections. 必须确定哪种配置最适合自己的需要。You need to determine which configuration best fits your needs. 例如,点到站点、站点到站点以及共存的 ExpressRoute/站点到站点连接都有不同的说明和配置要求。For example, Point-to-Site, Site-to-Site, and coexisting ExpressRoute/Site-to-Site connections all have different instructions and configuration requirements. 要了解设计和查看连接拓扑图,请参阅设计For information about design and to view connection topology diagrams, see Design.

规划表Planning table

下表可帮助选择最适合解决方案的连接选项。The following table can help you decide the best connectivity option for your solution.

点到站点Point-to-Site 站点到站点Site-to-Site ExpressRouteExpressRoute
Azure 支持的服务Azure Supported Services 云服务和虚拟机Cloud Services and Virtual Machines 云服务和虚拟机Cloud Services and Virtual Machines 服务列表Services list
典型带宽Typical Bandwidths 基于网关 SKUBased on the gateway SKU 通常 < 1 Gbps(总计)Typically < 1 Gbps aggregate 50 Mbps、100 Mbps、200 Mbps、500 Mbps、1 Gbps、2 Gbps、5 Gbps、10 Gbps50 Mbps, 100 Mbps, 200 Mbps, 500 Mbps, 1 Gbps, 2 Gbps, 5 Gbps, 10 Gbps
支持的协议Protocols Supported 安全套接字隧道协议 (SSTP)、OpenVPN 和 IPsecSecure Sockets Tunneling Protocol (SSTP), OpenVPN and IPsec IPsecIPsec 通过 VLAN、NSP 的 VPN 技术(MPLS、VPLS...)直接连接Direct connection over VLANs, NSP's VPN technologies (MPLS, VPLS,...)
路由Routing 基于路由(动态)RouteBased (dynamic) 支持基于策略(静态路由)和基于路由(动态路由 VPN)We support PolicyBased (static routing) and RouteBased (dynamic routing VPN) BGPBGP
连接复原能力Connection resiliency 主动-被动active-passive 主动-被动或主动-主动active-passive or active-active 主动-主动active-active
典型用例Typical use case 云服务和虚拟机的原型设计、开发/测试/实验方案Prototyping, dev / test / lab scenarios for cloud services and virtual machines 云服务和虚拟机的开发/测试/实验方案和小规模生产工作负荷Dev / test / lab scenarios and small scale production workloads for cloud services and virtual machines 访问所有 Azure 服务(已验证列表)、企业级和任务关键型工作负荷、备份、大数据、Azure 即 DR 站点Access to all Azure services (validated list), Enterprise-class and mission critical workloads, Backup, Big Data, Azure as a DR site
SLASLA SLASLA SLASLA SLASLA
定价Pricing 定价Pricing 定价Pricing 定价Pricing
技术文档Technical Documentation VPN 网关文档VPN Gateway Documentation VPN 网关文档VPN Gateway Documentation ExpressRoute 文档ExpressRoute Documentation
常见问题FAQ VPN 网关常见问题VPN Gateway FAQ VPN 网关常见问题VPN Gateway FAQ ExpressRoute 常见问题ExpressRoute FAQ

设置Settings

为每个资源选择的设置对于成功创建连接至关重要。The settings that you chose for each resource are critical to creating a successful connection. 有关 VPN 网关的各个资源和设置的信息,请参阅 关于 VPN 网关设置For information about individual resources and settings for VPN Gateway, see About VPN Gateway settings. 本文包含的信息有助于了解网关类型、网关 SKU、VPN 类型、连接类型、网关子网、本地网关,以及可能需要考虑的其他各项资源设置。The article contains information to help you understand gateway types, gateway SKUs, VPN types, connection types, gateway subnets, local network gateways, and various other resource settings that you may want to consider.

部署工具Deployment tools

开始时可以使用一个配置工具(如 Azure 门户)创建和配置资源。You can start out creating and configuring resources using one configuration tool, such as the Azure portal. 可在以后切换到另一个工具(如 PowerShell)来配置其他资源或修改现有资源(如果适用)。You can later decide to switch to another tool, such as PowerShell, to configure additional resources, or modify existing resources when applicable. 目前,无法在 Azure 门户中配置每个资源和资源设置。Currently, you can't configure every resource and resource setting in the Azure portal. 每个连接拓扑的文章中的说明指定了何时需要特定配置工具。The instructions in the articles for each connection topology specify when a specific configuration tool is needed.

网关 SKUGateway SKUs

创建虚拟网络网关时,需指定要使用的网关 SKU。When you create a virtual network gateway, you specify the gateway SKU that you want to use. 请根据工作负荷、吞吐量、功能和 SLA 的类型,选择满足需求的 SKU。Select the SKU that satisfies your requirements based on the types of workloads, throughputs, features, and SLAs.

按隧道、连接和吞吐量列出的网关 SKUGateway SKUs by tunnel, connection, and throughput

SKUSKU S2S/VNet 到 VNet
隧道
S2S/VNet-to-VNet
Tunnels
P2S
SSTP 连接
P2S
SSTP Connections
P2S
IKEv2/OpenVPN 连接
P2S
IKEv2/OpenVPN Connections
聚合
吞吐量基准
Aggregate
Throughput Benchmark
BGPBGP
基本Basic 最大Max. 10 个10 最大Max. 128128 不支持Not Supported 100 Mbps100 Mbps 不支持Not Supported
VpnGw1VpnGw1 最大Max. 30*30* 最大Max. 128128 最大Max. 250250 650 Mbps650 Mbps 支持Supported
VpnGw2VpnGw2 最大Max. 30*30* 最大Max. 128128 最大Max. 500500 1 Gbps1 Gbps 支持Supported
VpnGw3VpnGw3 最大Max. 30*30* 最大Max. 128128 最大Max. 10001000 1.25 Gbps1.25 Gbps 支持Supported

(*) 如果需要 30 个以上 S2S VPN 隧道,请使用虚拟 WAN(*) Use Virtual WAN if you need more than 30 S2S VPN tunnels.

  • 允许调整 VpnGw SKU 的大小,但基本 SKU 的大小调整除外。The resizing of VpnGw SKUs is allowed except resizing of the Basic SKU. 基本 SKU 是旧版 SKU,并且具有功能限制。The Basic SKU is a legacy SKU and has feature limitations. 若要从基本 SKU 移到其他 VpnGw SKU,必须删除基本 SKU VPN 网关,并使用所需 SKU 大小创建新网关。In order to move from Basic to another VpnGw SKU, you must delete the Basic SKU VPN gateway and create a new gateway with the desired SKU size.

  • 这些连接限制是独立的。These connection limits are separate. 例如,在 VpnGw1 SKU 上可以有 128 个 SSTP 连接,还可以有 250 个 IKEv2 连接。For example, you can have 128 SSTP connections and also 250 IKEv2 connections on a VpnGw1 SKU.

  • 可在 定价 页上找到定价信息。Pricing information can be found on the Pricing page.

  • 可在 SLA 页上查看 SLA(服务级别协议)信息。SLA (Service Level Agreement) information can be found on the SLA page.

  • 在单个隧道中,最多可以达到 1 Gbps 的吞吐量。On a single tunnel a maximum of 1 Gbps throughput can be achieved. 上表中的聚合吞吐量基准基于对通过单个网关聚合的多个隧道的测量。Aggregate Throughput Benchmark in the above table is based on measurements of multiple tunnels aggregated through a single gateway. 适用于 VPN 网关的聚合吞吐量基准组合了 S2S 和 P2S。The Aggregate Throughput Benchmark for a VPN Gateway is S2S + P2S combined. 如果有大量的 P2S 连接,则可能会对 S2S 连接造成负面影响,因为存在吞吐量限制。If you have a lot of P2S connections, it can negatively impact a S2S connection due to throughput limitations. 受 Internet 流量情况和应用程序行为影响,无法保证聚合吞吐量基准。The Aggregate Throughput Benchmark is not a guaranteed throughput due to Internet traffic conditions and your application behaviors.

为了帮助我们的客户了解使用不同算法的 SKU 的相对性能,我们使用市售 iPerf 和 CTSTraffic 工具来衡量性能。To help our customers understand the relative performance of SKUs using different algorithms, we used publicly available iPerf and CTSTraffic tools to measure performances. 下表列出了 VpnGw SKU 的性能测试结果。The table below lists the results of performance tests for VpnGw SKUs. 可以看到,对 IPsec 加密和完整性使用 GCMAES256 算法时,可获得最佳性能。As you can see, the best performance is obtained when we used GCMAES256 algorithm for both IPsec Encryption and Integrity. 对 IPsec 加密使用 AES256 以及对完整性使用 SHA256 时,可获得平均性能。We got average performance when using AES256 for IPsec Encryption and SHA256 for Integrity. 对 IPsec 加密使用 DES3 以及对完整性使用 SHA256 可获得最低性能。When we used DES3 for IPsec Encryption and SHA256 for Integrity we got lowest performance.

SKUSKU 使用
的算法
Algorithms
used
观察到的
吞吐量
Throughput
observed
观察到的
每秒数据包数
Packets per second
observed
VpnGw1VpnGw1 GCMAES256GCMAES256
AES256 & SHA256AES256 & SHA256
DES3 & SHA256DES3 & SHA256
650 Mbps650 Mbps
500 Mbps500 Mbps
120 Mbps120 Mbps
58,00058,000
50,00050,000
50,00050,000
VpnGw2VpnGw2 GCMAES256GCMAES256
AES256 & SHA256AES256 & SHA256
DES3 & SHA256DES3 & SHA256
1 Gbps1 Gbps
500 Mbps500 Mbps
120 Mbps120 Mbps
90,00090,000
80,00080,000
55,00055,000
VpnGw3VpnGw3 GCMAES256GCMAES256
AES256 & SHA256AES256 & SHA256
DES3 & SHA256DES3 & SHA256
1.25 Gbps1.25 Gbps
550 Mbps550 Mbps
120 Mbps120 Mbps
105,000105,000
90,00090,000
60,00060,000

定价Pricing

支付两项内容:虚拟网络网关的每小时计算成本和虚拟网络网关的出口数据传输。You pay for two things: the hourly compute costs for the virtual network gateway, and the egress data transfer from the virtual network gateway. 可在 定价 页上找到定价信息。Pricing information can be found on the Pricing page.

虚拟网络网关计算成本Virtual network gateway compute costs
每个虚拟网络网关都有每小时计算成本。Each virtual network gateway has an hourly compute cost. 价格基于创建虚拟网络网关时指定的网关 SKU。The price is based on the gateway SKU that you specify when you create a virtual network gateway. 成本与网关本身以及流经网关的数据传输相关。The cost is for the gateway itself and is in addition to the data transfer that flows through the gateway. 主动-主动设置的成本与主动-被动设置的成本相同。Cost of an active-active setup is the same as active-passive.

数据传输成本Data transfer costs
数据传输成本根据源虚拟网络网关的出口流量计算。Data transfer costs are calculated based on egress traffic from the source virtual network gateway.

  • 如果要将流量发送到本地 VPN 设备,以 Internet 出口数据传输率收取费用。If you are sending traffic to your on-premises VPN device, it will be charged with the Internet egress data transfer rate.
  • 如果要在不同区域的虚拟网络之间发送流量,定价因区域而异。If you are sending traffic between virtual networks in different regions, the pricing is based on the region.
  • 如果要仅在属于同一区域的虚拟网络之间发送流量,则没有数据成本。If you are sending traffic only between virtual networks that are in the same region, there are no data costs. 同一区域的 VNet 之间的流量免费。Traffic between VNets in the same region is free.

有关用于 VPN 网关的网关 SKU 的详细信息,请参阅网关 SKUFor more information about gateway SKUs for VPN Gateway, see Gateway SKUs.

常见问题解答FAQ

有关 VPN 网关的常见问题,请参阅 VPN 网关常见问题For frequently asked questions about VPN gateway, see the VPN Gateway FAQ.

后续步骤Next steps