Supplement · Microsoft Azure

VNet, connectivity, DNS và private endpoints

Azure networking cần thiết kế đồng thời IP, routing, name resolution, egress, inspection và service exposure.

VNet và topology

VNet/subnet tạo address và routing boundary; NSG lọc L3/L4 nhưng không thay firewall application-aware. Hub-spoke tập trung shared connectivity/inspection; Virtual WAN phù hợp managed transit quy mô lớn. Peering không transitive mặc định.

Hybrid và routing

VPN cung cấp encrypted Internet connectivity; ExpressRoute cung cấp private circuit nhưng encryption cần quyết định riêng. UDR và BGP propagation có thể tạo asymmetric route; effective routes/NIC rules là evidence khi debug.

DNS

Private DNS zone phải được link đúng VNet; hybrid resolution cần Azure DNS Private Resolver hoặc forwarder có rule rõ. DNS split-horizon và negative caching thường gây lỗi tưởng là network ACL.

Private Link và egress

Private endpoint đưa private IP cho PaaS service nhưng không tự disable public access hoặc sửa DNS mọi nơi. Egress cần predictable SNAT, firewall policy và route; kiểm tra port exhaustion, FQDN dependencies và forced tunneling.

Tài liệu: Virtual Network · Network topology · Private Endpoint · DNS Private Resolver
← PolicyCompute →