快速入門:使用 Azure 入口網站建立虛擬網路Quickstart: Create a virtual network using the Azure portal

在此快速入門中,您將了解如何使用 Azure 入口網站建立虛擬網路。In this quickstart, you learn how to create a virtual network using the Azure portal. 您將部署兩部虛擬機器 (VM)。You deploy two virtual machines (VMs). 接下來,您可以在 VM 之間安全地進行通訊,並從網際網路連線到 VM。Next, you securely communicate between VMs and connect to VMs from the internet. 虛擬網路是私人網路在 Azure 中的基本建置組塊。A virtual network is the fundamental building block for your private network in Azure. 其可讓 Azure 資源 (例如 VM) 安全地彼此通訊,以及與網際網路通訊。It enables Azure resources, like VMs, to securely communicate with each other and with the internet.

必要條件Prerequisites

登入 AzureSign in to Azure

登入 Azure 入口網站Sign in to the Azure portal.

建立虛擬網路Create a virtual network

  1. 從 Azure 入口網站功能表選取 [建立資源]。From the Azure portal menu, select Create a resource. 從 Azure Marketplace 選取 [網路] > [虛擬網路]。From the Azure Marketplace, select Networking > Virtual network.

  2. 在 [建立虛擬網路] 中,輸入或選取這項資訊:In Create virtual network, enter or select this information:

    設定Setting Value
    訂用帳戶Subscription 選取您的訂用帳戶。Select your subscription.
    資源群組Resource group 選取 [新建],輸入 myResourceGroup,然後選取 [確定]。Select Create new, enter myResourceGroup, then select OK.
    名稱Name 輸入 myVirtualNetworkEnter myVirtualNetwork.
    LocationLocation 選取 [美國東部]。Select East US.
  3. 完成時,選取 [下一步:IP 位址],並在 [IPv4 位址空間]中輸入 10.1.0.0/16。Select Next: IP Addresses, and for IPv4 address space, enter 10.1.0.0/16.

  4. 選取 [新增子網路],然後輸入 myVirtualSubnet作為 [子網路名稱],以及輸入 10.1.0.0/24 作為 [子網路位址範圍]。Select Add subnet, then enter myVirtualSubnet for Subnet name and 10.1.0.0/24 for Subnet address range.

  5. 選取 [新增],然後選取 [檢閱 + 建立]。Select Add, then select Review + create. 將其他項目保留為預設值,然後選取 [建立]。Leave the rest as default and select Create.

  6. 在 [建立虛擬網路] 中,選取 [建立]。In Create virtual network, select Create.

建立虛擬機器Create virtual machines

在虛擬網路內建立兩個 VM:Create two VMs in the virtual network:

建立第一個 VMCreate the first VM

  1. 從 Azure 入口網站功能表選取 [建立資源]。From the Azure portal menu, select Create a resource.

  2. 從 Azure Marketplace 選取 [計算] > [Windows Server 2019 資料中心]。From the Azure Marketplace, select Compute > Windows Server 2019 Datacenter. 選取 [建立]。Select Create.

  3. 在 [建立虛擬機器 - 基本] 中,輸入或選取這項資訊:In Create a virtual machine - Basics, enter or select this information:

    設定Setting Value
    專案詳細資料Project details
    訂用帳戶Subscription 選取您的訂用帳戶。Select your subscription.
    資源群組Resource group 選取 myResourceGroupSelect myResourceGroup. 您已在上一節中建立此資源群組。You created this resource group in the previous section.
    執行個體詳細資料Instance details
    虛擬機器名稱Virtual machine name 輸入 myVm1Enter myVm1.
    區域Region 選取 [美國東部]。Select East US.
    可用性選項Availability options 預設值為 [不需要基礎結構備援]。Default to No infrastructure redundancy required.
    映像Image 預設值為 [Windows Server 2019 Datacenter]。Default to Windows Server 2019 Datacenter.
    大小Size 預設值為 [標準 DS1 v2]。Default to Standard DS1 v2.
    系統管理員帳戶Administrator account
    使用者名稱Username 輸入您選擇的使用者名稱。Enter a username of your choosing.
    密碼Password 輸入您選擇的密碼。Enter a password of your choosing. 密碼長度至少必須有 12 個字元,而且符合定義的複雜度需求The password must be at least 12 characters long and meet the defined complexity requirements.
    確認密碼Confirm Password 重新輸入密碼。Re-enter password.
    輸入連接埠規則Inbound port rules
    公用輸入連接埠Public inbound ports 選取 [允許選取的連接埠]。Select Allow selected ports.
    選取輸入連接埠Select inbound ports 輸入 HTTP (80)和 RDP (3389)。Enter HTTP (80) and RDP (3389).
    節省費用Save money
    已經有 Windows 授權?Already have a Windows license? 預設值為 [否]。Default to No.
  4. 完成時,選取 [下一步:磁碟]。Select Next: Disks.

  5. 在 [建立虛擬機器 - 磁碟] 中,保留預設值並選取 [下一步:網路功能]。In Create a virtual machine - Disks, keep the defaults and select Next: Networking.

  6. 在 [建立虛擬機器 - 網路] 中,選取這項資訊:In Create a virtual machine - Networking, select this information:

    設定Setting Value
    虛擬網路Virtual network 預設值為 [myVirtualNetwork]。Default to myVirtualNetwork.
    子網路Subnet 預設值為 [myVirtualSubnet (10.1.0.0/24)]。Default to myVirtualSubnet (10.1.0.0/24).
    公用 IPPublic IP 預設值為 [(新) myVm-ip]。Default to (new) myVm-ip.
    NIC 網路安全性群組NIC network security group 預設值為 [基本]。Default to Basic.
    公用輸入連接埠Public inbound ports 預設值為 [允許選取的連接埠]。Default to Allow selected ports.
    選取輸入連接埠Select inbound ports 預設值為 [HTTP] 和 [RDP]。Default to HTTP and RDP.
  7. 完成時,選取 [下一步:管理]。Select Next: Management.

  8. 在 [建立虛擬機器 - 管理] 中,針對 [診斷儲存體帳戶],選取 [新建]。In Create a virtual machine - Management, for Diagnostics storage account, select Create New.

  9. 在 [建立儲存體帳戶] 中,輸入或選取這項資訊:In Create storage account, enter or select this information:

    設定Setting Value
    名稱Name 輸入 myvmstorageaccountEnter myvmstorageaccount. 如果此名稱已被使用,請建立唯一名稱。If this name is taken, create a unique name.
    帳戶類型Account kind 預設值為 [儲存體 (一般用途 v1)]。Default to Storage (general purpose v1).
    效能Performance 預設值為 [標準]。Default to Standard.
    複寫Replication 預設值為 [本地備援儲存體 (LRS)]。Default to Locally-redundant storage (LRS).
  10. 選取 [確定],選取 [檢閱 + 建立]。Select OK, then select Review + create. 您會移至 [檢閱 + 建立] 頁面,其中 Azure 會驗證您的設定。You're taken to the Review + create page where Azure validates your configuration.

  11. 當您看到 [驗證成功] 訊息時,請選取 [建立]。When you see the Validation passed message, select Create.

建立第二個 VMCreate the second VM

重複上一節中的程序,以建立另一個虛擬機器。Repeat the procedure in the previous section to create another virtual machine.

重要

針對 [虛擬機器名稱] 輸入 myVm2For the Virtual machine name, enter myVm2.

在步驟 7 中,針對 [診斷儲存體帳戶],務必選取 [myvmstorageaccount]。For Diagnosis storage account, make sure you select myvmstorageaccount, instead of creating one.

從網際網路連線至 VMConnect to a VM from the internet

在您建立 myVm1 之後,請連線到網際網路。After you've created myVm1, connect to the internet.

  1. 在 Azure 入口網站中,搜尋並選取 [myVm1]。In the Azure portal, search for and select myVm1.

  2. 依序選取 [連線]和 [RDP]。Select Connect, then RDP.

    連接到虛擬機器

    [連線] 頁面會隨即開啟。The Connect page opens.

  3. 選取 [下載 RDP 檔案]。Select Download RDP File. Azure 會建立一個「遠端桌面通訊協定」( .rdp) 檔案,並下載至您的電腦。Azure creates a Remote Desktop Protocol (.rdp) file and downloads it to your computer.

  4. 開啟 RDP 檔案。Open the RDP file. 如果出現提示,請選取 [連接]。If prompted, select Connect.

  5. 輸入您在建立 VM 時指定的使用者名稱和密碼。Enter the username and password you specified when creating the VM.

    注意

    您可能需要選取 [其他選擇] > [使用不同的帳戶],以指定您在建立 VM 時輸入的認證。You may need to select More choices > Use a different account, to specify the credentials you entered when you created the VM.

  6. 選取 [確定]。Select OK.

  7. 您可能會在登入時收到憑證警告。You may receive a certificate warning when you sign in. 如果您收到憑證警告,請選取 [是] 或 [繼續]。If you receive a certificate warning, select Yes or Continue.

  8. 當 VM 桌面出現之後,將它最小化以回到您的本機桌面。Once the VM desktop appears, minimize it to go back to your local desktop.

虛擬機器之間的通訊Communicate between VMs

  1. myVm1 的遠端桌面中,開啟 PowerShell。In the Remote Desktop of myVm1, open PowerShell.

  2. 輸入 ping myVm2Enter ping myVm2.

    您將收到類似此輸出的訊息:You'll receive a message similar to this output:

    Pinging myVm2.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.clouda
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    
    Ping statistics for 10.1.0.5:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
    

    ping 失敗,因為 ping 使用網際網路控制訊息通訊協定 (ICMP)。The ping fails, because ping uses the Internet Control Message Protocol (ICMP). 根據預設,ICMP 不允許通過 Windows 防火牆。By default, ICMP isn't allowed through the Windows firewall.

  3. 為了讓 myVm2 在稍後的步驟中可以 Ping myVm1,輸入此命令:To allow myVm2 to ping myVm1 in a later step, enter this command:

    New-NetFirewallRule –DisplayName "Allow ICMPv4-In" –Protocol ICMPv4
    

    此命令可讓 ICMP 連入流量通過 Windows 防火牆:This command allows ICMP inbound through the Windows firewall:

  4. 關閉對 myVm1 的遠端桌面連線。Close the remote desktop connection to myVm1.

  5. 再次完成 從網際網路連線至 VM 中的步驟,但連線至 myVm2Complete the steps in Connect to a VM from the internet again, but connect to myVm2.

  6. 從命令提示字元,輸入 ping myvm1From a command prompt, enter ping myvm1.

    您會收到類似此訊息:You'll get back something like this message:

    Pinging myVm1.0v0zze1s0uiedpvtxz5z0r0cxg.bx.internal.cloudapp.net [10.1.0.4] with 32 bytes of data:
    Reply from 10.1.0.4: bytes=32 time=1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    Reply from 10.1.0.4: bytes=32 time<1ms TTL=128
    
    Ping statistics for 10.1.0.4:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 1ms, Average = 0ms
    

    您會從 myVm1 收到回覆,因為您在步驟 3 中允許 ICMP 通過 myVm1 VM 上的 Windows 防火牆。You receive replies from myVm1, because you allowed ICMP through the Windows firewall on the myVm1 VM in step 3.

  7. 關閉對 myVm2 的遠端桌面連線。Close the remote desktop connection to myVm2.

清除資源Clean up resources

在此快速入門中,您建立了一個預設的虛擬網路和兩個 VM。In this quickstart, you created a default virtual network and two VMs. 您從網際網路連線到其中一部 VM,然後在兩部 VM 之間安全地進行通訊。You connected to one VM from the internet and securely communicated between the two VMs.

當您完成使用虛擬網路與 VM 時,可以刪除資源群組以及其包含的所有資源:When you're done using the virtual network and the VMs, delete the resource group and all of the resources it contains:

  1. 搜尋並選取 [myResourceGroup]。Search for and select myResourceGroup.

  2. 選取 [刪除資源群組]。Select Delete resource group.

  3. 針對 [輸入資源群組名稱] 輸入 myResourceGroup,然後選取 [刪除]。Enter myResourceGroup for TYPE THE RESOURCE GROUP NAME and select Delete.

後續步驟Next steps

若要深入了解虛擬網路設定,請參閱建立、變更或刪除虛擬網路To learn more about virtual network settings, see Create, change, or delete a virtual network.

根據預設,Azure 允許 VM 之間進行安全通訊。By default, Azure allows secure communication between VMs. Azure 只允許從網際網路連線到 Windows VM 的輸入遠端桌面連線。Azure only allows inbound remote desktop connections to Windows VMs from the internet. 若要深入了解 VM 網路通訊的類型,請參閱篩選網路流量To learn more about types of VM network communications, see Filter network traffic.

注意

Azure 服務成本費用。Azure services cost money. Azure 成本管理可協助您設定預算和設定警示以控制費用。Azure Cost Management helps you set budgets and configure alerts to keep spending under control. 使用成本管理來分析、管理和最佳化您的 Azure 成本。Analyze, manage, and optimize your Azure costs with Cost Management. 若要深入了解,請參閱分析成本的快速入門To learn more, see the quickstart on analyzing your costs.