您现在访问的是微软AZURE全球版技术文档网站,若需要访问由世纪互联运营的MICROSOFT AZURE中国区技术文档网站,请访问 https://docs.azure.cn.

快速入门-配置私有云环境Quickstart - Configure a Private Cloud environment

本文介绍如何创建 CloudSimple 私有云并设置私有云环境。In this article, learn how to create a CloudSimple Private Cloud and set up your Private Cloud environment.

在开始之前Before you begin

查看 网络必备组件Review Networking Prerequisites.

登录 AzureSign in to Azure

https://portal.azure.com 中登录 Azure 门户。Sign in to the Azure portal at https://portal.azure.com.

创建私有云Create a Private Cloud

私有云是支持 ESXi 主机、vCenter、vSAN 和 NSX 的独立 VMware 堆栈。A Private Cloud is an isolated VMware stack that supports ESXi hosts, vCenter, vSAN, and NSX.

私有云通过 CloudSimple 门户进行管理。Private Clouds are managed through the CloudSimple portal. 它们在自己的管理域中具有自己的 vCenter 服务器。They have their own vCenter server in its own management domain. 堆栈在专用节点和隔离的裸机硬件节点上运行。The stack runs on dedicated nodes and isolated bare metal hardware nodes.

  1. 选择“所有服务”。Select All services.

  2. 搜索 " CloudSimple Services"。Search for CloudSimple Services.

  3. 选择要在其上创建私有云的 CloudSimple 服务。Select the CloudSimple service on which you want to create your Private Cloud.

  4. 从 " 概述" 中,单击 " 创建私有云 " 以打开 CloudSimple 门户的新浏览器选项卡。From Overview, click Create Private Cloud to open a new browser tab for CloudSimple portal. 如果系统提示,请用 Azure 登录凭据登录。If prompted, sign in with your Azure sign in credentials.

    从 Azure 创建私有云

  5. 在 CloudSimple 门户中,提供私有云的名称。In the CloudSimple portal, provide a name for your Private Cloud.

  6. 选择私有云的 位置Select the Location of your Private Cloud.

  7. 选择 " 节点类型",与在 Azure 上预配的类型一致。Select Node type, consistent with what you provisioned on Azure.

  8. 指定 节点计数Specify Node count. 至少需要三个节点才能创建私有云。At least three nodes are required to create a Private Cloud.

    创建私有云-基本信息

  9. 单击 " 下一步:高级选项"。Click Next: Advanced options.

  10. 输入 vSphere/vSAN 子网的 CIDR 范围。Enter the CIDR range for vSphere/vSAN subnets. 请确保 CIDR 范围不与任何本地或其他 Azure 子网 (虚拟网络) 或网关子网重叠。Make sure that the CIDR range doesn't overlap with any of your on-premises or other Azure subnets (virtual networks) or with the gateway subnet.

    CIDR 范围选项: /24、/23、/22 或/21。CIDR range options: /24, /23, /22, or /21. A/24 CIDR 范围最多支持26个节点,/23 个 CIDR 范围最多支持58个节点,并且/22 和/21 CIDR 范围支持64节点 (私有云) 中的最大节点数。A /24 CIDR range supports up to 26 nodes, a /23 CIDR range supports up to 58 nodes, and a /22 and /21 CIDR range supports 64 nodes (the maximum number of nodes in a Private Cloud). 若要了解详细信息、Vlan 和子网,请参阅 vlan 和子网概述To learn more and VLANs and subnets, see VLANs and subnets overview.

    重要

    VSphere/vSAN CIDR 范围中的 IP 地址保留供私有云基础结构使用。IP addresses in the vSphere/vSAN CIDR range are reserved for use by the Private Cloud infrastructure. 请勿在任何虚拟机上使用此范围内的 IP 地址。Don't use the IP address in this range on any virtual machine.

  11. 单击 " 下一步":查看和创建Click Next: Review and create.

  12. 查看设置。Review the settings. 如果需要更改任何设置,请单击 " 上一步"。If you need to change any settings, click Previous.

  13. 单击“创建”。Click Create.

私有云预配过程开始。Private Cloud provisioning process starts. 预配私有云可能需要长达两个小时。It can take up to two hours for the Private Cloud to be provisioned.

启动 CloudSimple 门户Launch CloudSimple portal

可以从 Azure 门户访问 CloudSimple 门户。You can access the CloudSimple portal from Azure portal. 将使用单一 Sign-On (SSO) ,通过 Azure 登录凭据启动 CloudSimple 门户。The CloudSimple portal will be launched with your Azure sign in credentials using Single Sign-On (SSO). 若要访问 CloudSimple 门户,需要授权 CloudSimple Service 授权 应用程序。Accessing the CloudSimple portal requires you to authorize the CloudSimple Service Authorization application. 有关授予权限的详细信息,请参阅 同意 CloudSimple 服务授权应用程序For more information on granting permissions, see Consent to CloudSimple Service Authorization application.

  1. 选择“所有服务”。Select All services.

  2. 搜索 " CloudSimple Services"。Search for CloudSimple Services.

  3. 选择要在其上创建私有云的 CloudSimple 服务。Select the CloudSimple service on which you want to create your Private Cloud.

  4. 从 "概述" 中,单击 "前往 CloudSimple 门户" ,打开 CloudSimple 门户的新浏览器选项卡。From overview, click Go to the CloudSimple portal to open a new browser tab for CloudSimple portal. 如果系统提示,请用 Azure 登录凭据登录。If prompted, sign in with your Azure sign in credentials.

    启动 CloudSimple 门户

创建点到站点 VPNCreate Point-to-Site VPN

点到站点 VPN 连接是从计算机连接到私有云的最简单方法。A Point-to-Site VPN connection is the simplest way to connect to your Private Cloud from your computer. 如果要远程连接到私有云,请使用点到站点 VPN 连接。Use Point-to-Site VPN connection if you're connecting to the Private Cloud remotely. 若要快速访问私有云,请遵循以下步骤。For quick access to your Private Cloud, follow the steps below. 可以使用 站点到站点 VPNAzure ExpressRoute来访问本地网络中的 CloudSimple 区域。Access to the CloudSimple region from your on-premises network can be done using Site-to-Site VPN or Azure ExpressRoute.

创建网关Create gateway

  1. 启动 CloudSimple 门户,然后选择 " 网络"。Launch CloudSimple portal and select Network.

  2. 选择 VPN 网关Select VPN Gateway.

  3. 单击 " 新建 VPN 网关"。Click New VPN Gateway.

    创建 VPN 网关

  4. 对于 " 网关配置",请指定以下设置,然后单击 " 下一步"。For Gateway configuration, specify the following settings and click Next.

    • 选择 点到站点 VPN 作为网关类型。Select Point-to-Site VPN as the gateway type.
    • 输入名称以标识网关。Enter a name to identify the gateway.
    • 选择要在其中部署 CloudSimple 服务的 Azure 位置。Select the Azure location where your CloudSimple service is deployed.
    • 为点到站点网关指定客户端子网。Specify the client subnet for the Point-to-Site gateway. 当你连接时,将从此子网中指定 DHCP 地址。DHCP addresses will be given from this subnet when you connect.
  5. 对于 " 连接/用户",指定以下设置,然后单击 " 下一步"。For Connection/User, specify the following settings and click Next.

    • 若要自动允许当前和未来的所有用户通过此点到站点网关访问私有云,请选择 " 自动添加所有用户"。To automatically allow all current and future users to access the Private Cloud through this Point-to-Site gateway, select Automatically add all users. 如果选择此选项,则会自动选择 "用户" 列表中的所有用户。When you select this option, all users in the User list are automatically selected. 您可以通过取消选择列表中的单个用户来覆盖 "自动" 选项。You can override the automatic option by deselecting individual users in the list.
    • 若要仅选择单个用户,请单击 "用户" 列表中的复选框。To select only individual users, click the check boxes in the User list.
  6. 通过 "Vlan/子网" 部分,可以为网关和连接指定管理和用户 Vlan/子网。The VLANs/Subnets section allows you to specify management and user VLANs/subnets for the gateway and connections.

    • 自动添加选项设置此网关的全局策略。The Automatically add options set the global policy for this gateway. 这些设置将应用于当前的网关。The settings apply to the current gateway. 这些设置可在 " 选择 " 区域中被覆盖。The settings can be overridden in the Select area.
    • 选择 " 添加私有云的管理 vlan/子网"。Select Add management VLANs/Subnets of Private Clouds.
    • 若要添加所有用户定义的 Vlan/子网,请单击 " 添加用户定义的 vlan/子网"。To add all user-defined VLANs/subnets, click Add user-defined VLANs/Subnets.
    • " 选择 设置" 在 " 自动添加" 下覆盖全局设置。The Select settings override the global settings under Automatically add.
  7. 单击 " 下一步 " 查看设置。Click Next to review the settings. 单击 "编辑" 图标进行任何更改。Click the Edit icons to make any changes.

  8. 单击 " 创建 ",创建 VPN 网关。Click Create to create the VPN gateway.

使用点到站点 VPN 连接到 CloudSimpleConnect to CloudSimple using Point-to-Site VPN

从计算机连接到 CloudSimple 时需要 VPN 客户端。VPN client is needed for connecting to CloudSimple from your computer. 下载适用于 Windows 的 OpenVPN client 或用于 MACOS 和 OS X 的 ViscosityDownload OpenVPN client for Windows or Viscosity for macOS and OS X.

  1. 启动 CloudSimple 门户,然后选择 " 网络"。Launch CloudSimple portal and select Network.

  2. 选择 VPN 网关Select VPN Gateway.

  3. 在 VPN 网关列表中,单击 "点到站点 VPN 网关"。From the list of VPN gateways, click the Point-to-Site VPN gateway.

  4. 选择“用户”。Select Users.

  5. 单击 " 下载我的 VPN 配置"Click Download my VPN configuration.

    下载 VPN 配置

  6. 导入 VPN 客户端上的配置。Import the configuration on your VPN client.

  7. 连接到 CloudSimple。Connect to CloudSimple.

为工作负荷 Vm 创建 VLANCreate a VLAN for your workload VMs

创建私有云之后,创建一个 VLAN,你将在其中部署工作负荷/应用程序 Vm。After creating a Private Cloud, create a VLAN where you'll deploy your workload/application VMs.

  1. 在 CloudSimple 门户中,选择 " 网络"。In the CloudSimple portal, select Network.

  2. 单击 " VLAN/子网"。Click VLAN/Subnets.

  3. 单击 " 创建 VLAN/子网"。Click Create VLAN/Subnet.

    创建 VLAN/子网

  4. 选择新 VLAN/子网的 私有云Select the Private Cloud for the new VLAN/subnet.

  5. 从列表中选择一个 VLAN ID。Select a VLAN ID from the list.

  6. 输入子网名称以标识子网。Enter a subnet name to identify the subnet.

  7. 指定子网 CIDR 范围和掩码。Specify the subnet CIDR range and mask. 此范围不得与任何现有子网重叠。This range must not overlap with any existing subnets.

  8. 单击“提交” 。Click Submit.

    创建 VLAN/子网详细信息

将创建 VLAN/子网。The VLAN/subnet will be created. 你现在可以使用此 VLAN ID 在私有云 vCenter 上创建分布式端口组。You can now use this VLAN ID to create a distributed port group on your Private Cloud vCenter.

将环境连接到 Azure 虚拟网络Connect your environment to an Azure virtual network

CloudSimple 为你的私有云提供了 ExpressRoute 线路。CloudSimple provides you with an ExpressRoute circuit for your Private Cloud. 可以将 Azure 上的虚拟网络连接到 ExpressRoute 线路。You can connect your virtual network on Azure to the ExpressRoute circuit. 有关设置连接的完整详细信息,请遵循 使用 ExpressRoute 的 Azure 虚拟网络连接中的步骤。For full details on setting up the connection, follow the steps in Azure Virtual Network Connection using ExpressRoute.

登录到 vCenterSign in to vCenter

你现在可以登录到 vCenter 来设置虚拟机和策略。You can now sign in to vCenter to set up virtual machines and policies.

  1. 若要访问 vCenter,请从 CloudSimple 门户启动。To access vCenter, start from the CloudSimple portal. 在主页上的 " 常见任务" 下,单击 " 启动 vSphere 客户端"。On the Home page, under Common Tasks, click Launch vSphere Client. 选择私有云,然后单击 "在私有云上 启动 VSphere 客户端 "。Select the Private Cloud and then click Launch vSphere Client on the Private Cloud.

    启动 vSphere 客户端

  2. 选择首选的 vSphere 客户端以访问 vCenter,并使用用户名和密码进行登录。Select your preferred vSphere client to access vCenter and sign in with your username and password. 默认值为:The defaults are:

    • 用户名: CloudOwner@cloudsimple.localUser name: CloudOwner@cloudsimple.local
    • 密码:CloudSimple123!Password: CloudSimple123!

下一过程中的 vCenter 屏幕来自 vSphere (HTML5) 客户端。The vCenter screens in the next procedures are from the vSphere (HTML5) client.

更改你的 vCenter 密码Change your vCenter password

CloudSimple 建议你在首次登录到 vCenter 时更改密码。CloudSimple recommends that you change your password the first time you sign in to vCenter.
设置的密码必须满足以下要求:The password you set must meet the following requirements:

  • 最长生存期:密码每365天必须更改一次Maximum lifetime: Password must be changed every 365 days

  • 限制重复使用:用户无法重用前面的五个密码Restrict reuse: Users can't reuse any of the previous five passwords

  • 长度: 8-20 个字符Length: 8 - 20 characters

  • 特殊字符:至少一个特殊字符Special character: At least one special character

  • 字母字符:至少一个大写字符、a-z 和至少一个小写字符 a-zAlphabetic characters: At least one uppercase character, A-Z, and at least one lowercase character, a-z

  • 数字:至少一个数字字符,0-9Numbers: At least one numeric character, 0-9

  • 最大相同的相邻字符:三个Maximum identical adjacent characters: Three

    示例: CC 或 CCC 可作为密码的一部分接受,但 CCCC 不能。Example: CC or CCC is acceptable as a part of the password, but CCCC isn't.

如果设置的密码不符合要求:If you set a password that doesn't meet the requirements:

  • 如果使用 vSphere Flash 客户端,则会报告错误if you use the vSphere Flash Client, it reports an error
  • 如果使用 HTML5 客户端,则不会报告错误。If you use the HTML5 client, it doesn't report an error. 客户端不接受更改,旧密码将继续工作。The client doesn't accept the change and the old password continues to work.

访问 NSX 管理器Access NSX manager

使用默认密码部署了 NSX 管理器。NSX manager is deployed with a default password.

  • 用户名: 管理员User name: admin
  • 密码: CloudSimple123!Password: CloudSimple123!

可以在 CloudSimple portal 上查找 NSX manager (FQDN) 和 IP 地址的完全限定域名。You can find the fully qualified domain name (FQDN) and IP address of NSX manager on CloudSimple portal.

  1. 启动 CloudSimple 门户并选择 " 资源"。Launch CloudSimple portal and select Resources.

  2. 单击要使用的私有云。Click on the Private Cloud, which you want to use.

  3. 选择 vSphere 管理网络Select vSphere management network

  4. 使用 NSX Manager 的 FQDN 或 IP 地址,并使用 web 浏览器进行连接。Use the FQDN or IP address of NSX Manager and connect using a web browser.

    查找 NSX Manager FQDN

创建端口组Create a port group

在 vSphere 中创建分布式端口组:To create a distributed port group in vSphere:

  1. 按照 VSphere 网络指南中的 "添加分布式端口组" 中的说明进行操作。Follow the instructions in "Add a distributed port group" in vSphere Networking Guide.
  2. 设置分布式端口组时,请提供在 为工作负荷 Vm 创建 vlan中创建的 vlan ID。When setting up the distributed port group, provide the VLAN ID created in Create a VLAN for your Workload VMs.

后续步骤Next steps