แก้ไข

Choose a secure network topology

A network topology defines the basic routing and traffic flow architecture for your workload. However, you must consider security with the network topology. To simplify the initial decision to formulate a direction, there are some simple paths that can be used to help define the secure topology. This includes whether the workload is a globally distributed workload or a single region-based workload. You also must consider plans to use third-party network virtual appliances (NVA’s) to handle both routing and security.

Azure Virtual WAN is a networking service that brings many networking, security, and routing functionalities together to provide a single operational interface.

Azure Virtual Network Manager is a management service that enables you to group, configure, deploy, and manage virtual networks globally across subscriptions. Security admin rules can be applied to the virtual network to control access to the network and the resources within the network.

Decision tree

The following decision tree helps you choose a network topology that meets your security requirements. It works through the considerations described earlier in this article, such as whether your workload spans multiple regions and whether you plan to use network virtual appliances for routing and security.

Use the resulting topology as an initial direction for your architecture. Because routing and security requirements differ for every workload, evaluate the recommendation in more detail before you commit to a topology.

Secure network topology decision tree.

Next steps