Presentation is loading. Please wait.

Presentation is loading. Please wait.

Windows ® Azure ™ Platform. Network Architecture Packet Filtering Built-In Firewalls Connect Service SSL WCF Security Agenda.

Similar presentations


Presentation on theme: "Windows ® Azure ™ Platform. Network Architecture Packet Filtering Built-In Firewalls Connect Service SSL WCF Security Agenda."— Presentation transcript:

1 Windows ® Azure ™ Platform

2 Network Architecture Packet Filtering Built-In Firewalls Connect Service SSL WCF Security Agenda

3 Windows ® Azure ™ Platform Compute Network (Main VLAN) Device Network Fabric Controller

4 Windows ® Azure ™ Platform TOR LB Agg PDU LB Agg LB Agg Racks Data center Routers Aggregation Routers and Load Balancers TOR PDU TOR PDU TOR PDU TOR PDU TOR PDU TOR PDU TOR PDU TOR PDU ……… Top of Rack Switches Power Distribution Units Nodes Main VLAN Compute Network (Main VLAN)

5 Windows ® Azure ™ Platform Network connectivity is restricted using the host firewall Packet Filtering is performed on all traffic The FC host agent ensures that the VM can only access IP addresses assigned to VMs of the same service. Also allows access to Internet addresses Hyper-V based hypervisor Hypervisor Network/Disk

6 Windows ® Azure ™ Platform

7

8

9 Windows Azure VM Web Role Worker Role Worker Role... Port 80Port 80 Port 8080Port 8080 Port 10000Port 10000 HTTP TCP.........

10 Windows ® Azure ™ Platform

11 Internet

12 Windows ® Azure ™ Platform Windows Azure

13 Windows ® Azure ™ Platform SSTP (HTTPS Encapsulation) Internet On- premises Server Windows Azure Connect Relay Windows Azure Roles IPv6 with IPsec Transport Mode

14 Windows ® Azure ™ Platform netsh advfirewall firewall add rule name="ICMPv6" dir=in action=allow enable=yes protocol=icmpv6

15 Windows ® Azure ™ Platform Worker Role Web Role

16 Windows ® Azure ™ Platform Channel TypeMotivation Client-to-Role Business activities may contain sensitive data. Prevents man-in-the-middle attacks Administration Both Windows Azure and the developer authenticate each other. Allow administration outside the portal. Client-to-Blob SAS allows access for users to whom the URL was provided. SSL prevents other people from looking at the data. Client-to-SQL Azure Protect connection information. The database usually contains sensitive information. Role-to-StorageUnnecessary, as this channel is trusted.

17 Windows ® Azure ™ Platform

18 Windows ® Azure ™ Platform <add name="MySqlAzureDB" connectionString="Server=tcp:ServerName.database.windows.net; Database=Pubs;User ID=user@server;Password=myPassword; Encrypt=True;TrustServerCertificate=False"/>

19 Windows ® Azure ™ Platform

20 CachingCaching AccessControlAccessControl Service Bus Web Service

21 Windows ® Azure ™ Platform

22

23 © 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows Azure, SQL Azure and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.


Download ppt "Windows ® Azure ™ Platform. Network Architecture Packet Filtering Built-In Firewalls Connect Service SSL WCF Security Agenda."

Similar presentations


Ads by Google