ESLZ NetworkDeepDive AAC
ESLZ NetworkDeepDive AAC
ESLZ NetworkDeepDive AAC
©Microsoft Corporation
Azure
Metropolis
Using an analogy, this is similar to
how city utilities such as water, gas,
and electricity are accessible before
new houses are constructed. In this
context, the network, IAM, policies,
management, and monitoring are
shared 'utility' services that must be
readily available to help streamline
the application migration process.
Enterprise-scale?
Subscription Democratisation
Management Group
Enterprise Enrolment Identity & Access
& Subscription
& Azure AD Tenants Management
Organisation
©Microsoft Corporation
Azure
All foundations are NOT created equal
©Microsoft Corporation
Azure
Enterprise-scale
landing zone(s)
The principle purpose of the
“Landing Zone” is therefore to
ensure that when an application
or workload lands on Azure, the
required “plumbing” is already in
place, providing greater agility
and compliance with enterprise
security and governance
requirements.
Network Topology
& Connectivity
IP Addressing
• No IP address overlap, no public IP’s internal
• Size not to big, not to small, purpose driven
• Usage of private IP addresses (RFC1918)
Example - DNS resolution flow when a VM in a VNET tries to resolve private endpoint:
Network
Topology &
Connectivity
DNS
technologies and topology
Network approaches for Azure deployments
Topology &
Connectivity
Define an Azure
Networking
Topology
Network Virtual WAN Global Transit Network
Topology &
Connectivity
Virtual WAN
Network Enterprise-Scale with Azure Virtual WAN
Topology &
Connectivity
Virtual WAN
Traditional
Hub and Spoke
Network Enterprise-Scale with Hub & Spoke
Topology &
Connectivity
Traditional
Hub and Spoke
Enterprise-Scale/README.md at main · Azure/Enterprise-Scale · GitHub
Azure Route Server (ARS) enables network appliances to exchange
route information with Azure virtual networks dynamically.
Network
Topology & Azure Route Server supports Azure ExpressRoute and VPN
gateways to automatically take the latest route information from
Connectivity Azure Route Server instead of manually talking to each network.
Internet
Connectivity
Network
Topology &
Connectivity
Connectivity to
Azure PaaS PaaS
services
Azure Private Endpoint & Private Link
Network
Topology &
Connectivity
Connectivity to
Azure PaaS
▪ Enterprise-scale design principles and
Network implementation can be adopted by all customers,
Topology & no matter what size and history their Azure estate.
Connectivity ▪ Reference implementations enable security,
monitoring, networking, and any other plumbing
needed for landing zones autonomously through
policy enforcement.
Reference
Implementation
Q&A
©Microsoft Corporation
Azure