快速入門:使用 Azure 入口網站建立虛擬網路Quickstart: Create a virtual network using the Azure portal

虛擬網路是私人網路在 Azure 中的基本建置組塊。A virtual network is the fundamental building block for your private network in Azure. 它可讓 Azure 資源 (例如虛擬機器 (VM)) 彼此及與網際網路安全地進行通訊。It enables Azure resources, like virtual machines (VMs), to securely communicate with each other and with the internet. 在此快速入門中,您將了解如何使用 Azure 入口網站建立虛擬網路。In this Quickstart, you will learn how to create a virtual network using the Azure portal. 然後,您可以將兩部 VM 部署至虛擬網路中、在兩部 VM 之間安全地進行通訊,並從網際網路連線到 VM。Then, you can deploy two VMs into the virtual network, securely communicate between the two VMs, and connect to the VMs from the internet.

如果您沒有 Azure 訂用帳戶,請立即建立免費帳戶If you don't have an Azure subscription, create a free account now.

登入 AzureSign in to Azure

登入 Azure 入口網站Sign in to the Azure portal.

建立虛擬網路Create a virtual network

  1. 在畫面的左上方,選取 [建立資源] > [網路] > [虛擬網路] 。On the upper-left side of the screen, select Create a resource > Networking > Virtual network.

  2. 在 [建立虛擬網路] 中,輸入或選取這項資訊:In Create virtual network, enter or select this information:

    設定Setting Value
    名稱Name 輸入 myVirtualNetworkEnter myVirtualNetwork.
    位址空間Address space 輸入 10.1.0.0/16Enter 10.1.0.0/16.
    訂用帳戶Subscription 選取您的訂用帳戶。Select your subscription.
    資源群組Resource group 選取 [新建] ,輸入 myResourceGroup,然後選取 [確定] 。Select Create new, enter myResourceGroup, then select OK.
    位置Location 選取 [美國東部] 。Select East US.
    子網路 - 名稱Subnet - Name 輸入 myVirtualSubnetEnter myVirtualSubnet.
    子網路 - 位址範圍Subnet - Address range 輸入 10.1.0.0/24Enter 10.1.0.0/24.
  3. 將其他項目保留為預設值,然後選取 [建立] 。Leave the rest as default and select Create.

建立虛擬機器Create virtual machines

在虛擬網路內建立兩個 VM:Create two VMs in the virtual network:

建立第一個 VMCreate the first VM

  1. 在畫面的左上方,選取 [建立資源] > [計算] > [Windows Server 2019 Datacenter] 。On the upper-left side of the screen, select Create a resource > Compute > Windows Server 2019 Datacenter.

  2. 在 [建立虛擬機器 - 基本] 中,輸入或選取這項資訊:In Create a virtual machine - Basics, enter or select this information:

    設定Setting Value
    專案詳細資料PROJECT DETAILS
    訂用帳戶Subscription 選取您的訂用帳戶。Select your subscription.
    資源群組Resource group 選取 myResourceGroupSelect myResourceGroup. 您已在上一節中建立此項目。You created this in the previous section.
    執行個體詳細資料INSTANCE DETAILS
    虛擬機器名稱Virtual machine name 輸入 myVm1Enter myVm1.
    區域Region 選取 [美國東部] 。Select East US.
    可用性選項Availability options 保留預設值 [不需要基礎結構備援] 。Leave the default No infrastructure redundancy required.
    映像Image 保留預設值 [Windows Server 2019 Datacenter] 。Leave the default Windows Server 2019 Datacenter.
    大小Size 保留預設值 [標準 DS1 v2] 。Leave the default Standard DS1 v2.
    系統管理員帳戶ADMINISTRATOR ACCOUNT
    使用者名稱Username 輸入您選擇的使用者名稱。Enter a username of your choosing.
    密碼Password 輸入您選擇的密碼。Enter a password of your choosing. 密碼長度至少必須有 12 個字元,而且符合定義的複雜度需求The password must be at least 12 characters long and meet the defined complexity requirements.
    確認密碼Confirm Password 再次輸入密碼。Reenter password.
    輸入連接埠規則INBOUND PORT RULES
    公用輸入連接埠Public inbound ports 保留預設值 [無] 。Leave the default None.
    節省費用SAVE MONEY
    已經有 Windows 授權?Already have a Windows license? 保留預設值 [否] 。Leave the default No.
  3. 選取 [下一步: 磁碟]。Select Next : Disks.

  4. 在 [建立虛擬機器 - 磁碟] ,保留預設值並選取 [下一步: 網路功能]。In Create a virtual machine - Disks, leave the defaults and select Next : Networking.

  5. 在 [建立虛擬機器 - 網路功能] 中,選取這項資訊:In Create a virtual machine - Networking, select this information:

    設定Setting Value
    虛擬網路Virtual network 保留預設值 [myVirtualNetwork] 。Leave the default myVirtualNetwork.
    子網路Subnet 保留預設值 [myVirtualSubnet (10.1.0.0/24)] 。Leave the default myVirtualSubnet (10.1.0.0/24).
    公用 IPPublic IP 保留預設值 [(new) myVm-ip] 。Leave the default (new) myVm-ip.
    公用輸入連接埠Public inbound ports 選取 [允許選取的連接埠] 。Select Allow selected ports.
    選取輸入連接埠Select inbound ports 選取 [HTTP] 和 [RDP] 。Select HTTP and RDP.
  6. 選取 [下一步: 管理]。Select Next : Management.

  7. 在 [建立虛擬機器 - 管理] 中,針對 [診斷儲存體帳戶] ,選取 [新建] 。In Create a virtual machine - Management, for Diagnostics storage account, select Create New.

  8. 在 [建立儲存體帳戶] 中,輸入或選取這項資訊:In Create storage account, enter or select this information:

    設定Setting Value
    名稱Name 輸入 myvmstorageaccountEnter myvmstorageaccount. 如果此名稱已被使用,請建立唯一名稱。If this name is taken, create a unique name.
    帳戶類型Account kind 保留預設值 [儲存體 (一般用途 v1)] 。Leave the default Storage (general purpose v1).
    效能Performance 保留預設值 [標準] 。Leave the default Standard.
    複寫Replication 保留預設值 [本地備援儲存體 (LRS)] 。Leave the default Locally-redundant storage (LRS).
  9. 選取 [確定] Select OK

  10. 選取 [檢閱 + 建立] 。Select Review + create. 您會移至 [檢閱 + 建立] 頁面,其中 Azure 會驗證您的設定。You're taken to the Review + create page where Azure validates your configuration.

  11. 當您看到 [驗證成功] 訊息時,請選取 [建立] 。When you see the Validation passed message, select Create.

建立第二部 VMCreate the second VM

  1. 完成上述的步驟 1 到 9。Complete steps 1 and 9 from above.

    注意

    在步驟 2 中,針對 [虛擬機器名稱] 輸入 myVm2In step 2, for the Virtual machine name, enter myVm2.

    在步驟 7 中,針對 [診斷儲存體帳戶] ,務必選取 [myvmstorageaccount] 。In step 7, for Diagnosis storage account, make sure you select myvmstorageaccount.

  2. 選取 [檢閱 + 建立] 。Select Review + create. 您會移至 [檢閱 + 建立] 頁面,且 Azure 會驗證您的設定。You're taken to the Review + create page and Azure validates your configuration.

  3. 當您看到 [驗證成功] 訊息時,請選取 [建立] 。When you see the Validation passed message, select Create.

從網際網路連線至 VMConnect to a VM from the internet

在您建立 myVm1 之後,請連線到網際網路。After you've created myVm1, connect to the internet.

  1. 在入口網站的搜尋列中,輸入 myVm1In the portal's search bar, enter myVm1.

  2. 選取 [連線] 按鈕。Select the Connect button.

    連接到虛擬機器

    選取 [連線] 按鈕之後,隨即會開啟 [連線至虛擬機器] 。After selecting the Connect button, Connect to virtual machine opens.

  3. 選取 [下載 RDP 檔案] 。Select Download RDP File. Azure 會建立一個「遠端桌面通訊協定」( .rdp) 檔案,並下載至您的電腦。Azure creates a Remote Desktop Protocol (.rdp) file and downloads it to your computer.

  4. 開啟下載的 .rdp 檔案。Open the downloaded .rdp file.

    1. 如果出現提示,請選取 [連接] 。If prompted, select Connect.

    2. 輸入您在建立 VM 時指定的使用者名稱和密碼。Enter the username and password you specified when creating the VM.

      注意

      您可能需要選取 [其他選擇] > [使用不同的帳戶] ,以指定您在建立 VM 時輸入的認證。You may need to select More choices > Use a different account, to specify the credentials you entered when you created the VM.

  5. 選取 [確定] 。Select OK.

  6. 您可能會在登入過程中收到憑證警告。You may receive a certificate warning during the sign in process. 如果您收到憑證警告,請選取 [是] 或 [繼續] 。If you receive a certificate warning, select Yes or Continue.

  7. 當 VM 桌面出現之後,將它最小化以回到您的本機桌面。Once the VM desktop appears, minimize it to go back to your local desktop.

虛擬機器之間的通訊Communicate between VMs

  1. myVm1 的遠端桌面中,開啟 PowerShell。In the Remote Desktop of myVm1, open PowerShell.

  2. 輸入 ping myVm2Enter ping myVm2.

    您將收到如下訊息:You'll receive a message similar to this:

    Pinging myVm2.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.clouda
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    
    Ping statistics for 10.1.0.5:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
    

    ping 失敗,因為 ping 使用網際網路控制訊息通訊協定 (ICMP)。The ping fails, because ping uses the Internet Control Message Protocol (ICMP). 根據預設,ICMP 不允許通過 Windows 防火牆。By default, ICMP isn't allowed through the Windows firewall.

  3. 為了讓 myVm2 在稍後的步驟中可以 Ping myVm1,輸入此命令:To allow myVm2 to ping myVm1 in a later step, enter this command:

    New-NetFirewallRule –DisplayName “Allow ICMPv4-In” –Protocol ICMPv4
    

    此命令可讓 ICMP 連入流量通過 Windows 防火牆:This command allows ICMP inbound through the Windows firewall:

  4. 關閉對 myVm1 的遠端桌面連線。Close the remote desktop connection to myVm1.

  5. 再次完成從網際網路連線至 VM 中的步驟,但連線至 myVm2Complete the steps in Connect to a VM from the internet again, but connect to myVm2.

  6. 從命令提示字元,輸入 ping myvm1From a command prompt, enter ping myvm1.

    您會收到類似此訊息:You'll get back something like this message:

    Pinging myVm1.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.cloudapp.net [10.1.0.4] with 32 bytes of data:
    Reply from 10.1.0.4: bytes=32 time=1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    
    Ping statistics for 10.1.0.4:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 1ms, Average = 0ms
    

    您會從 myVm1 收到回覆,因為您在步驟 3 中允許 ICMP 通過 myVm1 VM 上的 Windows 防火牆。You receive replies from myVm1, because you allowed ICMP through the Windows firewall on the myVm1 VM in step 3.

  7. 關閉對 myVm2 的遠端桌面連線。Close the remote desktop connection to myVm2.

清除資源Clean up resources

當您完成使用虛擬網路與 VM 時,可以刪除資源群組以及其包含的所有資源:When you're done using the virtual network and the VMs, delete the resource group and all of the resources it contains:

  1. 在入口網站頂端的 [搜尋] 方塊中輸入 myResourceGroup,然後從搜尋結果中選取 [myResourceGroup] 。Enter myResourceGroup in the Search box at the top of the portal and select myResourceGroup from the search results.

  2. 選取 [刪除資源群組] 。Select Delete resource group.

  3. 針對 [輸入資源群組名稱] 輸入 myResourceGroup,然後選取 [刪除] 。Enter myResourceGroup for TYPE THE RESOURCE GROUP NAME and select Delete.

後續步驟Next steps

在此快速入門中,您建立了一個預設的虛擬網路與兩部 VM。In this Quickstart, you created a default virtual network and two VMs. 您從網際網路連線到其中一部 VM,然後在兩部 VM 之間安全地進行通訊。You connected to one VM from the internet and securely communicated between the two VMs. 若要深入了解虛擬網路設定,請參閱管理虛擬網路To learn more about virtual network settings, see Manage a virtual network.

根據預設,Azure 允許 VM 之間進行無限制的安全通訊。By default, Azure allows unrestricted secure communication between VMs. 相對地,它只允許從網際網路連線到 Windows VM 的輸入遠端桌面連線。Conversely, it only allows inbound remote desktop connections to Windows VMs from the internet. 若要深入了解設定不同類型的 VM 網路通訊,請移至篩選網路流量教學課程。To learn more about configuring different types of VM network communications, go to the Filter network traffic tutorial.