Kako uklopiti oblak u svoju postojeću infrastrukturu? Tomica Kaniški CITUS d.o.o.
Agenda Windows Azure Networking Windows Azure Virtual Machines Windows Azure Backup Windows Azure Hyper-V Recovery Manager
Windows Azure Pricing Calculator
Windows Azure Networking
Secure Site-to-Site Network Connectivity Windows Azure Virtual Network Windows Azure Hybrid and Connectivity Options Data Synchronization SQL Data Sync Application-Layer Connectivity & Messaging Service Bus Secure Machine-to-Machine Network Connectivity Windows Azure Connect
Windows Azure Virtual Network Your “virtual” branch office / datacenter in the cloud Enables customers to extend their Enterprise Networks into Windows Azure Networking on-ramp for migrating existing apps and services to Windows Azure Enables “hybrid” apps that span cloud/premises A protected private virtual network in the cloud Enables customers to setup secure private IPv4 networks fully contained within Windows Azure IP address persistence
Virtual Network Features Customer-managed private virtual networks within Windows Azure “Bring your own IPv4 addresses” Control over placement of Windows Azure Roles within the network Stable IPv4 addresses for VMs Hosted VPN Gateway enables site-to-site connectivity Automated provisioning & management Support existing on-premises VPN devices Use on-premise DNS servers for name resolution Enables customers to use their on-premise DNS servers for name resolution Enables VMs running in Windows Azure to be joined to corporate domains running on-premise (use your on-premise Active Directory)
The „virtual” branch office
Example: Contoso’s Deployment / / / /
Supported VPN Device List PlatformOS FamilyExamples SRX Series RoutersJunOS , 650 J Series RoutersJunOS ISG Series RoutersScreenOS 6.2+SX2 SSG Series RoutersScreenOS CiscoJuniper PlatformOS FamilyExamples ASA 5500 Series (Adaptive Security Appliances) ASA Software , 5550 ASR 1000 Series Aggregation Services Routers IOS XE ISR Series Integrated Services Routers IOS , 2901, 2911 Generic VPN devices must support: IKE v1 AES 128, 256 SHA1, SHA2
Gateway redundancy and availability Only single IPsec tunnel supported per Virtual Network Gateway tenant on Azure side has 2 instances (active-passive mode) Only one public IP(v4) address for tunnel establishment A pair of VPN devices can be a redundant pair using industry standard protocols HSRP VRRP
DEMO Windows Azure Networking (Site-to-Site VPN)
Site-to-Site VPN with MikroTik… (yes, it works )
Windows Azure Virtual Machines
Cloud Cloud First Provisioning Management Portal >_ Scripting (Windows, Linux and Mac) REST API Boot VM from New Disk
Supported Windows Server Applications
Virtual Machine Sizes Compute Instance NameCPU CoresMemoryPrice per hour Extra Small (A0)Shared768 MB$0.02 (~$15/month) Small (A1)11.75 GB$0.09 (~$67/month) Medium (A2)23.5 GB$0.18 (~$134/month) Large (A3)47 GB$0.36 (~$268/month) Extra Large (A4)814 GB$0.72 (~$536/month) A5214 GB$0.40 (~$298/month) A6428 GB$0.80 (~$596/month) A7856 GB$1.60 (~$1,192/month)
VM disk layout (1) OS Disk Persistent SATA Drive C:
VM disk layout (2) Temporary Storage Disk Local (Not Persistent) SATA Drive D:
VM disk layout (3) Data Disk(s) Persistent SCSI Customer Defined Letter
Some tips on BYO Images Sysprep and “Generalize” is expected Do NOT put unattend.xml on the disk Do NOT install the Windows Azure Integration Components!
DEMO Windows Azure Virtual Machines (Portal + App Controller)
Active Directory (on a VM) in Azure? (1) AD is Supported in Windows Azure Virtual Machines Capture/Imaging is not supported with DCs To make a new DC provision a VM and run promote it to be a DC Consider cost and deploy according to requirements Inbound traffic is free, outbound traffic is not Standard Azure outbound traffic costs apply Nominal fee per hour for the gateway itself Can be started and stopped as you see fit (if stopped, VMs are isolated from corporate network ) RODCs will likely prove more cost effective
Active Directory (on a VM) in Azure? (1) Load Balancer Public IP Site to Site VPN Tunnel On Premises Resources Contoso.com Active Directory AD Auth Extranet Active Directory
Windows Azure Backup
Peace of mind – your server is backing up to the cloud! Simple to manage familiar backup tools in Windows Server 2012 R2, Windows Server 2012 R2 Essentials, and the System Center 2012 R2 Data Protection Manager Efficient and flexible incremental backups – only changes to files are transferred to the cloud efficient use of storage, reduced bandwidth usage, offers point-in-time recovery of multiple versions of data configurable data retention policies, data compression and data transfer throttling How-to („a bit out-of-date” ) online-backup-for-windows-server-2012.aspx?wa=wsignin1.0 online-backup-for-windows-server-2012.aspx?wa=wsignin1.0
DEMO Windows Azure Backup
Windows Azure Hyper-V Recovery Manager
SaaS application Hybrid service that allows you to automate and orchestrate your DR solution
DEMO Windows Azure Hyper-V Recovery Manager
Agenda Windows Azure Networking Windows Azure Virtual Machines Windows Azure Backup Windows Azure Hyper-V Recovery Manager
Thank you!