Wednesday, March 9, 2022

Create the on-premises virtual machine


This is a virtual machine that you use to connect using Remote Desktop to the public IP address. From there, you then connect to the on-premises server through the firewall.

  1. From the Azure portal home page, select Create a resource.
  2. Under Popular, select Windows Server 2016 Datacenter.
  3. Enter these values for the virtual machine:
    • Resource group - Select existing, and then select FW-Hybrid-Test.
    • Virtual machine name - VM-Onprem.
    • Region - Same region that you're used previously.
    • User name: <type a user name>.
    • Password: <type a user password>.
  4. For Public inbound ports, select Allow selected ports, and then select RDP (3389)
  5. Select Next:Disks.
  6. Accept the defaults and select Next:Networking.
  7. Select VNet-Onprem for virtual network and the subnet is SN-Corp.
  8. Select Next:Management.
  9. For Boot diagnostics, Select Disable.
  10. Select Review+Create, review the settings on the summary page, and then select Create.

 Note

Azure provides a default outbound access IP for VMs that either aren't assigned a public IP address or are in the back-end pool of an internal basic Azure load balancer. The default outbound access IP mechanism provides an outbound IP address that isn't configurable.

For more information, see Default outbound access in Azure.

The default outbound access IP is disabled when either a public IP address is assigned to the VM or the VM is placed in the back-end pool of a standard load balancer, with or without outbound rules. If an Azure Virtual Network network address translation (NAT) gateway resource is assigned to the subnet of the virtual machine, the default outbound access IP is disabled.

VMs that are created by virtual machine scale sets in flexible orchestration mode don't have default outbound access.

For more information about outbound connections in Azure, see Use source network address translation (SNAT) for outbound connections.

Test the firewall


  1. First, note the private IP address for VM-spoke-01 virtual machine.

  2. From the Azure portal, connect to the VM-Onprem virtual machine.

  1. Open a web browser on VM-Onprem, and browse to http://<VM-spoke-01 private IP>.

    You should see the VM-spoke-01 web page: VM-Spoke-01 web page

  2. From the VM-Onprem virtual machine, open a remote desktop to VM-spoke-01 at the private IP address.

    Your connection should succeed, and you should be able to sign in.

So now you've verified that the firewall rules are working:

  • You can browse web server on the spoke virtual network.
  • You can connect to the server on the spoke virtual network using RDP.

Next, change the firewall network rule collection action to Deny to verify that the firewall rules work as expected.

  1. Select the hybrid-test-pol Firewall Policy.
  2. Select Rule Collections.
  3. Select the RCNet01 rule collection.
  4. For Rule collection action, select Deny.
  5. Select Save.

Close any existing remote desktops before testing the changed rules. Now run the tests again. They should all fail this time.

Create the routes

Create a couple routes:

  • A route from the hub gateway subnet to the spoke subnet through the firewall IP address
  • A default route from the spoke subnet through the firewall IP address
  1. From the Azure portal home page, select Create a resource.
  2. In the search text box, type route table and press Enter.
  3. Select Route table.
  4. Select Create.
  5. Select the FW-Hybrid-Test for the resource group.
  6. For Region, select the same location that you used previously.
  7. For the name, type UDR-Hub-Spoke.
  8. Select Review + Create.
  9. Select Create.
  10. After the route table is created, select it to open the route table page.
  11. Select Routes in the left column.
  12. Select Add.
  13. For the route name, type ToSpoke.
  14. For the address prefix, type 10.6.0.0/16.
  15. For next hop type, select Virtual appliance.
  16. For next hop address, type the firewall's private IP address that you noted earlier.
  17. Select OK.

Now associate the route to the subnet.

  1. On the UDR-Hub-Spoke - Routes page, select Subnets.
  2. Select Associate.
  3. Under Virtual network, select VNet-hub.
  4. Under Subnet, select GatewaySubnet.
  5. Select OK.

Now create the default route from the spoke subnet.

  1. From the Azure portal home page, select Create a resource.
  2. In the search text box, type route table and press Enter.
  3. Select Route table.
  4. Select Create.
  5. Select the FW-Hybrid-Test for the resource group.
  6. For Region, select the same location that you used previously.
  7. For the name, type UDR-DG.
  8. For Propagate gateway route, select No.
  9. Select Review + Create.
  10. Select Create.
  11. After the route table is created, select it to open the route table page.
  12. Select Routes in the left column.
  13. Select Add.
  14. For the route name, type ToHub.
  15. For the address prefix, type 0.0.0.0/0.
  16. For next hop type, select Virtual appliance.
  17. For next hop address, type the firewall's private IP address that you noted earlier.
  18. Select OK.

Now associate the route to the subnet.

  1. On the UDR-DG - Routes page, select Subnets.
  2. Select Associate.
  3. Under Virtual network, select VNet-spoke.
  4. Under Subnet, select SN-Workload.
  5. Select OK.

Configure network rules

First, add a network rule to allow web traffic.

  1. From the FW-Hybrid-Test resource group, select the hybrid-test-pol Firewall Policy.
  2. Select Network rules.
  3. Select Add add a rule collection.
  4. For Name, type RCNet01.
  5. For Priority, type 100.
  6. For Rule collection action, select Allow.
  7. Under Rules, for Name, type AllowWeb.
  8. For Source type, select IP address.
  9. For Source, type 192.168.1.0/24.
  10. For Protocol, select TCP.
  11. For Destination Ports, type 80.
  12. For Destination type, select IP address.
  13. For Destination, type 10.6.0.0/16.

Now add a rule to allow RDP traffic.

On the second rule row, type the following information:

  1. Name, type AllowRDP.
  2. For Source type, select IP address.
  3. For Source, type 192.168.1.0/24.
  4. For Protocol, select TCP.
  5. For Destination Ports, type 3389.
  6. For Destination type, select IP address.
  7. For Destination, type 10.6.0.0/16
  8. Select Add.

Configure and deploy the firewall

 

Configure and deploy the firewall

Now deploy the firewall into the firewall hub virtual network.

  1. From the Azure portal home page, select Create a resource.

  2. In the left column, select Networking, and search for and then select Firewall.

  3. On the Create a Firewall page, use the following table to configure the firewall:

    SettingValue
    Subscription<your subscription>
    Resource groupFW-Hybrid-Test
    NameAzFW01
    RegionEast US
    Firewall managementUse a Firewall Policy to manage this firewall
    Firewall policyAdd new:
    hybrid-test-pol
    East US
    Choose a virtual networkUse existing:
    VNet-hub
    Public IP addressAdd new:
    fw-pip.
  4. Select Review + create.

  5. Review the summary, and then select Create to create the firewall.

    This takes a few minutes to deploy.

  6. After deployment completes, go to the FW-Hybrid-Test resource group, and select the AzFW01 firewall.

  7. Note the private IP address. You'll use it later when you create the default route.

Create the on-premises virtual network

 

Create the on-premises virtual network

  1. From the Azure portal home page, select Create a resource.
  2. In Networking, select Virtual network.
  3. For Resource group, select FW-Hybrid-Test.
  4. For Name, type VNet-OnPrem.
  5. For Region, select (US) East US.
  6. Select Next : IP Addresses
  7. For IPv4 address space, delete the default address and type 192.168.0.0/16.
  8. Under Subnet name, select Add subnet.
  9. For Subnet name type SN-Corp.
  10. For Subnet address range, type 192.168.1.0/24.
  11. Select Add.
  12. Select Review + create.
  13. Select Create.

Now create a second subnet for the gateway.

  1. On the VNet-Onprem page, select Subnets.
  2. Select +Subnet.
  3. For Name, type GatewaySubnet.
  4. For Subnet address range type 192.168.2.0/24.
  5. Select OK.

Create the spoke virtual network

 

  1. From the Azure portal home page, select Create a resource.
  2. In Networking, select Virtual network.
  3. For Resource group, select FW-Hybrid-Test.
  4. For Name, type VNet-Spoke.
  5. For Region, select (US) East US.
  6. Select Next: IP Addresses.
  7. For IPv4 address space, delete the default address and type 10.6.0.0/16.
  8. Under Subnet name, select Add subnet.
  9. For Subnet name type SN-Workload.
  10. For Subnet address range, type 10.6.0.0/24.
  11. Select Add.
  12. Select Review + create.
  13. Select Create.