Azure Private Link 介绍

Azure Private Link enables you to access Azure PaaS Services (for example, Azure Storage and SQL Database) and Azure hosted customer-owned/partner services over a private endpoint in your virtual network.

Traffic between your virtual network and the service travels the Microsoft backbone network. Exposing your service to the public internet is no longer necessary. You can create your own private link service in your virtual network and deliver it to your customers. Setup and consumption using Azure Private Link is consistent across Azure PaaS, customer-owned, and shared partner services.

Azure Private Link使您能够通过虚拟网络中的专用端点访问Azure PaaS服务(例如,Azure存储和SQL数据库)和Azure托管的客户拥有/合作伙伴服务。

虚拟网络和服务之间的流量通过Microsoft骨干网络传输。不再需要将您的服务公开到公共网络。您可以在虚拟网络中创建自己的专用链接服务,并将其交付给客户。使用Azure Private Link的设置和使用在Azure PaaS、客户拥有和共享合作伙伴服务中保持一致。

 Important

Azure Private Link is now generally available. Both Private Endpoint and Private Link service (service behind standard load balancer) are generally available. Different Azure PaaS will onboard to Azure Private Link at different schedules. See Private Link availability for an accurate status of Azure PaaS on Private Link. For known limitations, see Private Endpoint and Private Link Service.

Key benefits

Azure Private Link provides the following benefits:

  • Privately access services on the Azure platform: Connect your virtual network using private endpoints to all services that can be used as application components in Azure. Service providers can render their services in their own virtual network and consumers can access those services in their local virtual network. The Private Link platform will handle the connectivity between the consumer and services over the Azure backbone network.

  • On-premises and peered networks: Access services running in Azure from on-premises over ExpressRoute private peering, VPN tunnels, and peered virtual networks using private endpoints. There's no need to configure ExpressRoute Microsoft peering or traverse the internet to reach the service. Private Link provides a secure way to migrate workloads to Azure.

  • Protection against data leakage: A private endpoint is mapped to an instance of a PaaS resource instead of the entire service. Consumers can only connect to the specific resource. Access to any other resource in the service is blocked. This mechanism provides protection against data leakage risks.

  • Global reach: Connect privately to services running in other regions. The consumer's virtual network could be in region A and it can connect to services behind Private Link in region B.

  • Extend to your own services: Enable the same experience and functionality to render your service privately to consumers in Azure. By placing your service behind a standard Azure Load Balancer, you can enable it for Private Link. The consumer can then connect directly to your service using a private endpoint in their own virtual network. You can manage the connection requests using an approval call flow. Azure Private Link works for consumers and services belonging to different Azure Active Directory tenants.

Azure Private Link提供以下好处:

私有访问Azure平台上的服务:使用私有端点将您的虚拟网络连接到可以用作Azure中应用程序组件的所有服务。服务提供商可以在其自己的虚拟网络中提供其服务,而消费者可以在其本地虚拟网络中访问这些服务。Private Link平台将通过Azure骨干网络处理消费者和服务之间的连接。

本地和对等网络:通过ExpressRoute专用对等、VPN隧道和使用专用端点的对等虚拟网络从本地访问Azure中运行的服务。无需配置ExpressRoute Microsoft对等网络或通过互联网访问服务。Private Link提供了一种将工作负载迁移到Azure的安全方法。

防止数据泄漏:私有端点映射到PaaS资源的实例,而不是整个服务。消费者只能连接到特定资源。对服务中任何其他资源的访问被阻止。该机制可防止数据泄漏风险。

全球覆盖:私人连接到其他地区的服务。消费者的虚拟网络可以在区域A中,并且它可以连接到区域B中的专用链路之后的服务。

扩展到您自己的服务:启用相同的体验和功能,以便在Azure中向消费者私下提供您的服务。通过将您的服务置于标准Azure负载平衡器之后,您可以为专用链接启用它。然后,使用者可以使用自己的虚拟网络中的专用端点直接连接到您的服务。您可以使用批准呼叫流管理连接请求。Azure Private Link适用于属于不同Azure Active Directory租户的消费者和服务。

 Note

Azure Private Link, along with Azure Virtual Network, span across Azure Availability Zones and are therefore zone resilient. To provide high availability for the Azure resource using a private endpoint, ensure that resource is zone resilient.

Availability

For information on Azure services that support Private Link, see Azure Private Link availability.

For the most up-to-date notifications, check the Azure Private Link updates page.

Logging and monitoring

Azure Private Link has integration with Azure Monitor. This combination allows:

  • Archival of logs to a storage account.
  • Streaming of events to your Event Hub.
  • Azure Monitor logging.

You can access the following information on Azure Monitor:

  • Private endpoint:

    • Data processed by the Private Endpoint  (IN/OUT)
  • Private Link service:

    • Data processed by the Private Link service (IN/OUT)
    • NAT port availability

Pricing

For pricing details, see Azure Private Link pricing.

FAQs

For FAQs, see Azure Private Link FAQs.

Limits

For limits, see Azure Private Link limits.

Service Level Agreement

For SLA, see SLA for Azure Private Link

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值