Book Image

Hands-On Networking with Azure

By : Mohamed Waly
Book Image

Hands-On Networking with Azure

By: Mohamed Waly

Overview of this book

Microsoft Azure networking is one of the most valuable and important offerings in Azure. No matter what solution you are building for the cloud, you'll fi nd a compelling use for it. This book will get you up to speed quickly on Microsoft Azure Networking by teaching you how to use different networking services. By reading this book, you will develop a strong networking foundation for Azure virtual machines and for expanding your on-premise environment to Azure. Hands-On Networking with Azure starts with an introduction to Microsoft Azure networking and creating Azure Virtual Networks with subnets of different types within them. The book helps you understand the architecture of Azure networks. You will then learn the best practices for designing both Windows- and Linux-based Azure VM networks. You will also learn to expand your networks into Azure and how to use Azure DNS. Moreover, you will master best practices for dealing with Azure Load Balancer and the solutions they offer in different scenarios. Finally, we will demonstrate how the Azure Application Gateway works, offering various layer-7 load balancing capabilities for applications. By the end of this book, you will be able to architect your networking solutions for Azure.
Table of Contents (15 chapters)
Title Page
Dedication
Packt Upsell
Contributors
Preface
Index

Securing Azure VNet


The most common question that anyone asks when they buy a service is, can it be secured? The answer to that question in this case is, absolutely yes.

Besides the security Microsoft provides for Azure from its side, there is some configuration that you can do from your side to increase the level of security to your virtual network.

For a higher level of security, you can use the following:

  • NSG: It is like a firewall that controls the inbound and outbound traffic by specifying which traffic is allowed to flow to/from the NIC/subnet
  • Distributed denial of service (DDoS) protection: It is used to prevent DDoS attacks and at the time of writing is in preview

NSG

NSG controls the flow of traffic by specifying which traffic is allowed to enter or exit the network.

Creating NSG

Creating an NSG is a pretty straightforward process. To do it, you need to follow these steps:

  1. Navigate to Azure portal, and search for network security groups, as shown in the following screenshot:

Figure 2.13:...