Azure Public IP 路由偏好教戰手冊Phil Huang Sr. Cloud Solution Architect2022/12/20以建立 Azure S2S VPN 為例
View Slide
Azure S2S VPN 建立方案選擇Azure Virtual Network GatewaysPublic IP via MicrosoftPublic IP via Internet
First public IP addressAzure Virtual Network Gateways• First public IP address 為該 Virtual Network Gateway 主要連線方式,故選擇適合的 Public IP 於此使用相當重要
Routing PreferenceAzure Public IP AddressesV.S.Choose Microsoft network? Choose Internet?
Hot / Cold Potato RoutingAzure Public IP 路由偏好指南
Azure 路由喜好設定熱馬鈴薯路由 (Hot potato routing) v.s. 冷馬鈴薯路由 (Cold potato routing)PoP: Point of Presence, 網路服務提供點Ref: https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/routing-preference-overviewCold potato routingHot potato routing
Azure Public IP 路由偏好常見問題Q&A• Q1: 於 Azure 上的 Public IP 路由偏好選擇有什麼差異?• Q2: 是不是一律路由選擇偏好 Microsoft 一定就是最好的?• Q3: 要如何挑選區域及進行自我檢測呢?
Azure Public IP 路由偏好常見問題Q&A• Q1: 於 Azure 上的 Public IP 路由偏好選擇有什麼差異?• A1: 路由路徑會不一樣,詳請後述• Q2: 是不是一律路由選擇偏好 Microsoft 一定就是最好的?• A2: 不一定,有可能選 Internet 反而比較快,而 Microsoft network 比較慢,需實測為主• Q3: 要如何挑選區域及進行自我檢測呢?• A4: 採用 Public IP 之前可以先進行自我簡單檢測
Q1: 於 Azure 上的 Public IP 路由偏好選擇有什麼差異?Azure Public IP 路由偏好指南
我家網路我家網路HINET, TaiwanNTT, JapanHINET, TaiwanPCCW, HongKongMicrosoft Backbonehkg31 -> hkg20 -> tyo31Routing Preference: InternetRouting Preference: Microsoft network
Routing Preference: InternetRouting Preference: Microsoft network我家網路我家網路HINET, TaiwanHINET, TaiwanMicrosoft Backbonetyo30 -> osa31PCCW, HongKong
Routing Preference: InternetRouting Preference: Microsoft network我家網路我家網路HINET, TaiwanHINET, TaiwanTATA CommunicationsPCCW, HongKongMicrosoft Backbonehkg31 -> sg2
Routing Preference: InternetRouting Preference: Microsoft network我家網路我家網路HINET, TaiwanHINET, TaiwanPCCW, HongKongPCCW, HongKongMicrosoft Backbonehkg31
Q2: 是不是一律路由選擇偏好Microsoft 一定就是最好的?Azure Public IP 路由偏好指南
Avg. 50.8msRouting Preference: InternetRouting Preference: Microsoft networkAvg. 74.0ms
Routing Preference: InternetRouting Preference: Microsoft networkAvg. 53.4msAvg. 55.6ms
Routing Preference: InternetRouting Preference: Microsoft networkAvg. 65.3msAvg. 68.9ms
Routing Preference: InternetRouting Preference: Microsoft networkAvg. 38.1msAvg. 35.8ms
Q3: 要如何挑選區域及進行自我檢測呢?Azure Public IP 路由偏好指南
新增 Public IP addressAllow Internet resource to communicate inbound to Azure resourceBy region
My TracerouteNetwork Diagnostic Tool that combines Ping and Traceroute[localhost]$ mtr -z -b
nitefood / asnASN Lookup Tool and Traceroute ServerRef: https://github.com/nitefood/asn
Invent with purpose.