教學課程:使用 Azure 入口網站以路由表路由傳送網路流量Tutorial: Route network traffic with a route table using the Azure portal

根據預設,Azure 會路由虛擬網路內所有子網路之間的流量。Azure routes traffic between all subnets within a virtual network, by default. 您可以建立您自己的路由,以覆寫 Azure 的預設路由。You can create your own routes to override Azure's default routing. 舉例來說,當您想要通過網路虛擬設備 (NVA) 路由傳送子網路之間的流量時,自訂路由便很有用。Custom routes are helpful when, for example, you want to route traffic between subnets through a network virtual appliance (NVA). 在本教學課程中,您會了解如何:In this tutorial, you learn how to:

  • 建立會路由傳送流量的 NVACreate an NVA that routes traffic
  • 建立路由表Create a route table
  • 建立路由Create a route
  • 建立路由表與子網路的關聯Associate a route table to a subnet
  • 將虛擬機器 (VM) 部署到不同子網路Deploy virtual machines (VM) into different subnets
  • 透過 NVA 從一個子網路將流量路由傳送到另一個子網路Route traffic from one subnet to another through an NVA

本教學課程會使用 Azure 入口網站This tutorial uses the Azure portal. 您也可以使用 Azure CLIAzure PowerShellYou can also use Azure CLI or Azure PowerShell.

必要條件Prerequisites

開始之前,您需要具有有效訂用帳戶的 Azure 帳戶。Before you begin, you require an Azure account with an active subscription. 如果您沒有帳戶,可以 免費建立一個帳戶If you do not have one, you can create an account for free.

必要條件Prerequisites

  • Azure 訂用帳戶。An Azure subscription.

登入 AzureSign in to Azure

https://portal.azure.com 登入 Azure 入口網站。Sign in to the Azure portal at https://portal.azure.com.

建立虛擬網路Create a virtual network

  1. 從 Azure 入口網站功能表選取 [建立資源]。From the Azure portal menu, select Create a resource. 從 Azure Marketplace 的 [搜尋] 方塊中,選取 [網路 > 虛擬網路] 或 [搜尋 虛擬網路]。From the Azure Marketplace, select Networking > Virtual network, or search for Virtual Network in the search box.

  2. 選取 [建立] 。Select Create.

  3. 在 [建立虛擬網路] 中,輸入或選取這項資訊:In Create virtual network, enter or select this information:

    設定Setting Value
    訂用帳戶Subscription 選取您的訂用帳戶。Select your subscription.
    資源群組Resource group 選取 [ 建立新 的],輸入 myResourceGroupSelect Create new, enter myResourceGroup.
    選取 [確定]。Select OK.
    名稱Name 輸入 myVirtualNetworkEnter myVirtualNetwork.
    LocationLocation 選取 (us) 美國東部Select (US) East US.
  4. 選取 [ IP 位址 ] 索引標籤,或選取頁面底部的 [ 下一步: IP 位址 ] 按鈕。Select the IP Addresses tab, or select the Next: IP Addresses button at the bottom of the page.

  5. 在 [ IPv4 位址空間] 中,選取現有的位址空間,並將其變更為 10.0.0.0/16In IPv4 address space, select the existing address space and change it to 10.0.0.0/16.

  6. 選取 [ + 新增子網],然後輸入 公用 的子網 名稱10.0.0.0/24 代表 子網位址範圍Select + Add subnet, then enter Public for Subnet name and 10.0.0.0/24 for Subnet address range.

  7. 選取 [新增]。Select Add.

  8. 選取 [ + 新增子網],然後針對子網 位址範圍 輸入 私人子網名稱10.0.1.0/24Select + Add subnet, then enter Private for Subnet name and 10.0.1.0/24 for Subnet address range.

  9. 選取 [新增]。Select Add.

  10. 選取 [ + 新增子網],然後針對子網 位址範圍 輸入 DMZ 作為 子網名稱,並輸入 10.0.2.0/24Select + Add subnet, then enter DMZ for Subnet name and 10.0.2.0/24 for Subnet address range.

  11. 選取 [新增]。Select Add.

  12. 選取 [ 安全性 ] 索引標籤,或選取頁面底部的 [ 下一步:安全性 ] 按鈕。Select the Security tab, or select the Next: Security button at the bottom of the page.

  13. 在 [BastionHost] 底下,選取 [啟用]。Under BastionHost, select Enable. 輸入此資訊:Enter this information:

    設定Setting Value
    Bastion 名稱Bastion name 輸入 myBastionHostEnter myBastionHost
    AzureBastionSubnet 位址空間AzureBastionSubnet address space 輸入 10.0.3.0/24Enter 10.0.3.0/24
    公用 IP 位址Public IP Address 選取 [建立新的]。Select Create new.
    在 [名稱] 中,輸入 myBastionIP。For Name, enter myBastionIP.
    選取 [確定]。Select OK.
  14. 選取 [檢閱 + 建立] 索引標籤,或選取 [檢閱 + 建立] 按鈕。Select the Review + create tab or select the Review + create button.

  15. 選取 [建立] 。Select Create.

建立 NVACreate an NVA

網路虛擬設備 (NVA) 是可協助路由和防火牆最佳化等網路功能的虛擬機器。Network virtual appliances (NVAs) are virtual machines that help with network functions, such as routing and firewall optimization. 本教學課程假設您使用的是 Windows Server 2019 DatacenterThis tutorial assumes you're using Windows Server 2019 Datacenter. 如果您想要,您可以選取不同的作業系統。You can select a different operating system if you want.

  1. 在入口網站的左上角,選取 [建立資源] > [計算] > [虛擬機器]。On the upper-left side of the portal, select Create a resource > Compute > Virtual machine.

  2. 在 [建立虛擬機器] 中,輸入或選取 [基本資訊] 索引標籤中的值:In Create a virtual machine, type or select the values in the Basics tab:

    設定Setting Value
    專案詳細資料Project Details
    訂用帳戶Subscription 選取您的 Azure 訂用帳戶Select your Azure subscription
    資源群組Resource Group 選取 myResourceGroupSelect myResourceGroup
    執行個體詳細資料Instance details
    虛擬機器名稱Virtual machine name 輸入 myVMNVAEnter myVMNVA
    區域Region 選取 (美國) 美國東部Select (US) East US
    可用性選項Availability Options 選取 [不需要基礎結構備援]Select No infrastructure redundancy required
    映像Image 選取 [Windows Server 2019 Datacenter]Select Windows Server 2019 Datacenter
    Azure Spot 執行個體Azure Spot instance 選取 [否]Select No
    大小Size 選擇 VM 大小或接受預設設定Choose VM size or take default setting
    系統管理員帳戶Administrator account
    使用者名稱Username 輸入使用者名稱Enter a username
    密碼Password 輸入密碼Enter a password
    確認密碼Confirm password 再次輸入密碼Reenter password
    輸入連接埠規則Inbound port rules
    公用輸入連接埠Public inbound ports 選取 [無]。Select None.
  3. 選取 [網路] 索引標籤,或選取 [下一步:磁碟] ,然後選取 [下一步:網路]Select the Networking tab, or select Next: Disks, then Next: Networking.

  4. 在 [網路功能] 索引標籤中,選取或輸入:In the Networking tab, select or enter:

    設定Setting Value
    網路介面Network interface
    虛擬網路Virtual network 選取 [ myVirtualNetwork]。Select myVirtualNetwork.
    子網路Subnet 選取 DMZSelect DMZ
    公用 IPPublic IP 選取 [無]Select None
    NIC 網路安全性群組NIC network security group 選取 [基本]Select Basic
    公用輸入埠網路Public inbound ports network 選取 [無]。Select None.
  5. 選取 [ 審核 + 建立 ] 索引標籤,或選取頁面底部的 [藍色 審核] + [建立 ] 按鈕。Select the Review + create tab, or select the blue Review + create button at the bottom of the page.

  6. 檢閱設定,然後選取 [建立]。Review the settings, and then select Create.

建立路由表Create a route table

  1. Azure 入口網站功能表或 [首頁] 頁面,選取 [建立資源]。On the Azure portal menu or from the Home page, select Create a resource.

  2. 在搜尋方塊中,輸入「路由表」。In the search box, enter Route table. 當搜尋結果中出現 路由表 出時加以選取。When Route table appears in the search results, select it.

  3. 在 [路由表] 頁面中,選取 [建立]。In the Route table page, select Create.

  4. 在 [基本] 索引標籤中的 [建立路由表] 中,輸入或選取下列資訊:In Create route table in the Basics tab, enter or select the following information:

    設定Setting Value
    專案詳細資料Project details
    訂用帳戶Subscription 選取您的訂用帳戶。Select your subscription.
    資源群組Resource group 選取 myResourceGroupSelect myResourceGroup.
    執行個體詳細資料Instance details
    區域Region 選取 [美國東部] 。Select East US.
    NameName 輸入 myRouteTablePublicEnter myRouteTablePublic.
    傳播閘道路由Propagate gateway routes 選取 [是] 。Select Yes.

    建立路由表,Azure 入口網站。

  5. 選取 [ 審核 + 建立 ] 索引標籤,或選取頁面底部的 [藍色 審核] + [建立 ] 按鈕。Select the Review + create tab, or select the blue Review + create button at the bottom of the page.

建立路由Create a route

  1. 移至 Azure 入口網站,以管理您的路由表。Go to the Azure portal to manage your route table. 搜尋並選取 [路由表]。Search for and select Route tables.

  2. 選取路由表 myRouteTablePublic 的名稱。Select the name of your route table myRouteTablePublic.

  3. 在 [ myRouteTablePublic ] 頁面的 [ 設定 ] 區段中,選取 [ 路由]。In the myRouteTablePublic page, in the Settings section, select Routes.

  4. 在 [路由] 頁面中,選取 [ + 新增 ] 按鈕。In the routes page, select the + Add button.

  5. 在 [新增路由] 中,輸入或選取這項資訊:In Add route, enter or select this information:

    設定Setting Value
    路由名稱Route name 輸入 ToPrivateSubnetEnter ToPrivateSubnet
    位址首碼Address prefix 輸入 10.0.1.0/24 (稍早建立之 私人 子網的位址範圍) Enter 10.0.1.0/24 (The address range of the Private subnet created earlier)
    下一個躍點類型Next hop type 選取 [ 虛擬裝置]。Select Virtual appliance.
    下一個躍點位址Next hop address 輸入 10.0.2.4 (DMZ 子網位址範圍內的位址) Enter 10.0.2.4 (An address within the address range of the DMZ subnet)
  6. 選取 [確定]。Select OK.

建立路由表與子網路的關聯Associate a route table to a subnet

  1. 移至 Azure 入口網站,以管理您的虛擬網路。Go to the Azure portal to manage your virtual network. 搜尋並選取 [虛擬網路]。Search for and select Virtual networks.

  2. 選取您虛擬網路 myVirtualNetwork 的名稱。Select the name of your virtual network myVirtualNetwork.

  3. 在 [ myVirtualNetwork ] 頁面的 [ 設定 ] 區段中,選取 [ 子網]。In the myVirtualNetwork page, in the Settings section, select Subnets.

  4. 在虛擬網路的子網清單中,選取 [ 公用]。In the virtual network's subnet list, select Public.

  5. 在 [ 路由表] 中,選擇您建立的路由表 myRouteTablePublicIn Route table, choose the route table you created myRouteTablePublic.

  6. 選取 [ 儲存 ],將您的路由表與 公用 子網產生關聯。Select Save to associate your route table to the Public subnet.

    關聯路由表、子網清單、虛擬網路 Azure 入口網站。

開啟 IP 轉送Turn on IP forwarding

接下來,為新的 NVA 虛擬機器 myVMNVA 開啟 IP 轉送。Next, turn on IP forwarding for your new NVA virtual machine, myVMNVA. 當 Azure 將網路流量傳送至 myVMNVA 時,如果流量的目的地是不同的 ip 位址,則 IP 轉送會將流量傳送到正確的位置。When Azure sends network traffic to myVMNVA, if the traffic is destined for a different IP address, IP forwarding sends the traffic to the correct location.

  1. 移至 Azure 入口網站,以管理您的 VM。Go to the Azure portal to manage your VM. 搜尋並選取 [虛擬機器]。Search for and select Virtual machines.

  2. 選取虛擬機器 myVMNVA 的名稱。Select the name of your virtual machine myVMNVA.

  3. 在 [ myVMNVA 總覽] 頁面的 [ 設定] 中,選取 [ 網路]。In the myVMNVA overview page, in Settings, select Networking.

  4. myVMNVA[網路] 頁面中,選取 [網路介面] 旁的網路介面。In the Networking page of myVMNVA, select the network interface next to Network Interface. 介面名稱的開頭會是 myvmnvaThe name of the interface will begin with myvmnva.

    網路, 網路虛擬設備 (NVA) 虛擬機器 (VM), Azure 入口網站

  5. 在 [網路介面總覽] 頁面的 [設定] 中,選取 [ IP****設定]。In the network interface overview page, in Settings, select IP configurations.

  6. 在 [ ip 設定] 頁面中,將 [ ip 轉送 ] 設定為 [ 啟用],然後選取 [ 儲存]。In the IP configurations page, set IP forwarding to Enabled, then select Save.

    啟用 IP 轉送

建立公用和私人虛擬機器Create public and private virtual machines

在虛擬網路中建立公用 VM 和私人 VM。Create a public VM and a private VM in the virtual network. 您稍後將用它們來檢視 Azure 透過 NVA 將「公用」子網路的流量路由至「私人」子網路。Later, you'll use them to see that Azure routes the Public subnet traffic to the Private subnet through the NVA.

公用 VMPublic VM

  1. 在入口網站的左上角,選取 [建立資源] > [計算] > [虛擬機器]。On the upper-left side of the portal, select Create a resource > Compute > Virtual machine.

  2. 在 [建立虛擬機器] 中,輸入或選取 [基本資訊] 索引標籤中的值:In Create a virtual machine, type or select the values in the Basics tab:

    設定Setting Value
    專案詳細資料Project Details
    訂用帳戶Subscription 選取您的 Azure 訂用帳戶Select your Azure subscription
    資源群組Resource Group 選取 myResourceGroupSelect myResourceGroup
    執行個體詳細資料Instance details
    虛擬機器名稱Virtual machine name 輸入 myVMPublicEnter myVMPublic
    區域Region 選取 (美國) 美國東部Select (US) East US
    可用性選項Availability Options 選取 [不需要基礎結構備援]Select No infrastructure redundancy required
    映像Image 選取 [Windows Server 2019 Datacenter]Select Windows Server 2019 Datacenter
    Azure Spot 執行個體Azure Spot instance 選取 [否]Select No
    大小Size 選擇 VM 大小或接受預設設定Choose VM size or take default setting
    系統管理員帳戶Administrator account
    使用者名稱Username 輸入使用者名稱Enter a username
    密碼Password 輸入密碼Enter a password
    確認密碼Confirm password 再次輸入密碼Reenter password
    輸入連接埠規則Inbound port rules
    公用輸入連接埠Public inbound ports 選取 [無]。Select None.
  3. 選取 [網路] 索引標籤,或選取 [下一步:磁碟] ,然後選取 [下一步:網路]Select the Networking tab, or select Next: Disks, then Next: Networking.

  4. 在 [網路功能] 索引標籤中,選取或輸入:In the Networking tab, select or enter:

    設定Setting Value
    網路介面Network interface
    虛擬網路Virtual network 選取 [ myVirtualNetwork]。Select myVirtualNetwork.
    子網路Subnet 選取 公用Select Public
    公用 IPPublic IP 選取 [無]Select None
    NIC 網路安全性群組NIC network security group 選取 [基本]Select Basic
    公用輸入埠網路Public inbound ports network 選取 [無]。Select None.
  5. 選取 [ 審核 + 建立 ] 索引標籤,或選取頁面底部的 [藍色 審核] + [建立 ] 按鈕。Select the Review + create tab, or select the blue Review + create button at the bottom of the page.

  6. 檢閱設定,然後選取 [建立]。Review the settings, and then select Create.

私人 VMPrivate VM

  1. 在入口網站的左上角,選取 [建立資源] > [計算] > [虛擬機器]。On the upper-left side of the portal, select Create a resource > Compute > Virtual machine.

  2. 在 [建立虛擬機器] 中,輸入或選取 [基本資訊] 索引標籤中的值:In Create a virtual machine, type or select the values in the Basics tab:

    設定Setting Value
    專案詳細資料Project Details
    訂用帳戶Subscription 選取您的 Azure 訂用帳戶Select your Azure subscription
    資源群組Resource Group 選取 myResourceGroupSelect myResourceGroup
    執行個體詳細資料Instance details
    虛擬機器名稱Virtual machine name 輸入 myVMPrivateEnter myVMPrivate
    區域Region 選取 (美國) 美國東部Select (US) East US
    可用性選項Availability Options 選取 [不需要基礎結構備援]Select No infrastructure redundancy required
    映像Image 選取 [Windows Server 2019 Datacenter]Select Windows Server 2019 Datacenter
    Azure Spot 執行個體Azure Spot instance 選取 [否]Select No
    大小Size 選擇 VM 大小或接受預設設定Choose VM size or take default setting
    系統管理員帳戶Administrator account
    使用者名稱Username 輸入使用者名稱Enter a username
    密碼Password 輸入密碼Enter a password
    確認密碼Confirm password 再次輸入密碼Reenter password
    輸入連接埠規則Inbound port rules
    公用輸入連接埠Public inbound ports 選取 [無]。Select None.
  3. 選取 [網路] 索引標籤,或選取 [下一步:磁碟] ,然後選取 [下一步:網路]Select the Networking tab, or select Next: Disks, then Next: Networking.

  4. 在 [網路功能] 索引標籤中,選取或輸入:In the Networking tab, select or enter:

    設定Setting Value
    網路介面Network interface
    虛擬網路Virtual network 選取 [ myVirtualNetwork]。Select myVirtualNetwork.
    子網路Subnet 選取 Select Private
    公用 IPPublic IP 選取 [無]Select None
    NIC 網路安全性群組NIC network security group 選取 [基本]Select Basic
    公用輸入埠網路Public inbound ports network 選取 [無]。Select None.
  5. 選取 [ 審核 + 建立 ] 索引標籤,或選取頁面底部的 [藍色 審核] + [建立 ] 按鈕。Select the Review + create tab, or select the blue Review + create button at the bottom of the page.

  6. 檢閱設定,然後選取 [建立]。Review the settings, and then select Create.

透過 NVA 路由傳送流量Route traffic through an NVA

登入私用 vmSign in to private vm

  1. 移至 Azure 入口網站,以管理您的私人 VM。Go to the Azure portal to manage your private VM. 搜尋並選取 [虛擬機器]。Search for and select Virtual machines.

  2. 挑選私用虛擬機器 myVmPrivate 的名稱。Pick the name of your private virtual machine myVmPrivate.

  3. 在 VM 功能表列中,選取 [連線], 然後選取 [防禦]。In the VM menu bar, select Connect, then select Bastion.

  4. 在 [連線] 頁面中,選取藍色的 [使用 防禦 ] 按鈕。In the Connect page, select the blue Use Bastion button.

  5. 在 [防禦] 頁面中,輸入您先前為虛擬機器建立的使用者名稱和密碼。In the Bastion page, enter the username and password you created for the virtual machine previously.

  6. 選取 [連線]。Select Connect.

設定防火牆Configure firewall

在後續步驟中,您將使用追蹤路由工具來測試路由。In a later step, you'll use the trace route tool to test routing. 追蹤路由會使用網際網路控制訊息通訊協定 (ICMP),但 Windows 防火牆依預設會加以拒絕。Trace route uses the Internet Control Message Protocol (ICMP), which the Windows Firewall denies by default.

讓 ICMP 可通過 Windows 防火牆。Enable ICMP through the Windows firewall.

  1. myVMPrivate 的防禦連接中,以系統管理許可權開啟 PowerShell。In the bastion connection of myVMPrivate, open PowerShell with administrative privileges.

  2. 輸入此命令:Enter this command:

    New-NetFirewallRule –DisplayName "Allow ICMPv4-In" –Protocol ICMPv4
    

    在本教學課程中,您將使用追蹤路由來測試路由。You'll be using trace route to test routing in this tutorial. 在生產環境中,我們不建議允許 ICMP 通過 Windows 防火牆。For production environments, we don't recommend allowing ICMP through the Windows Firewall.

開啟 myVMNVA 內的 IP 轉送Turn on IP forwarding within myVMNVA

您已使用 Azure 為 VM 的網路介面開啟 IP 轉送You turned on IP forwarding for the VM's network interface using Azure. 虛擬機器的作業系統也必須轉送網路流量。The virtual machine's operating system also has to forward network traffic.

使用這些命令開啟 IP 轉送以進行 myVMNVATurn on IP forwarding for myVMNVA with these commands.

  1. myVMPrivate vm 上的 PowerShell,開啟 myVMNVA vm 的遠端桌面:From PowerShell on the myVMPrivate VM, open a remote desktop to the myVMNVA VM:

    mstsc /v:myvmnva
    
  2. myVMNVA VM 上的 PowerShell,輸入下列命令以開啟 IP 轉送:From PowerShell on the myVMNVA VM, enter this command to turn on IP forwarding:

    Set-ItemProperty -Path HKLM:\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters -Name IpEnableRouter -Value 1
    
  3. 重新開機 myVMNVARestart myVMNVA.

    Restart-Computer
    
  4. MyVMNVA 重新開機之後,請建立 myVMPublic 的遠端桌面會話。After myVMNVA restarts, create a remote desktop session to myVMPublic.

    在仍連接至 myVMPrivate 的情況下,開啟 PowerShell 並執行此命令:While still connected to myVMPrivate, open PowerShell and run this command:

    mstsc /v:myvmpublic
    
  5. myVMPublic 的遠端桌面中,開啟 PowerShell。In the remote desktop of myVMPublic, open PowerShell.

  6. 輸入下列命令,讓 ICMP 可通過 Windows 防火牆:Enable ICMP through the Windows firewall by entering this command:

    New-NetFirewallRule –DisplayName "Allow ICMPv4-In" –Protocol ICMPv4
    

測試網路流量的路由Test the routing of network traffic

首先,讓我們測試從 myVMPublicmyVMPrivate 的網路流量路由。First, let's test routing of network traffic from myVMPublic to myVMPrivate.

  1. myVMPublic 上的 PowerShell,輸入此命令:From PowerShell on myVMPublic, enter this command:

    tracert myvmprivate
    

    回應如下列範例所示:The response is similar to this example:

    Tracing route to myvmprivate.q04q2hv50taerlrtdyjz5nza1f.bx.internal.cloudapp.net [10.0.1.4]
    over a maximum of 30 hops:
    
      1     1 ms     *        2 ms  myvmnva.internal.cloudapp.net [10.0.2.4]
      2     2 ms     1 ms     1 ms  myvmprivate.internal.cloudapp.net [10.0.1.4]
    
    Trace complete.
    
    • 您可以看到第一個躍點是10.0.2.4,也就是 myVMNVA 的 私人 IP 位址。You can see the first hop is to 10.0.2.4, which is myVMNVA's private IP address.

    • 第二個躍點是 myVMPrivate:10.0.1.4 的私人 IP 位址。The second hop is to the private IP address of myVMPrivate: 10.0.1.4.

    您先前已將路由新增至 myRouteTablePublic 路由表,並建立該路由表與公用子網路的關聯。Earlier, you added the route to the myRouteTablePublic route table and associated it to the Public subnet. Azure 會透過 NVA 傳送流量,而不是直接傳送至 私人 子網。Azure sent the traffic through the NVA and not directly to the Private subnet.

  2. 關閉要 myVMPublic 的遠端桌面會話,這會讓您仍然連線到 myVMPrivateClose the remote desktop session to myVMPublic, which leaves you still connected to myVMPrivate.

  3. myVMPrivate 上開啟 PowerShell,輸入此命令:Open PowerShell on myVMPrivate, enter this command:

    tracert myvmpublic
    

    此命令會測試從 myVmPrivate VM 到 myVmPublic VM 的網路流量路由。This command tests the routing of network traffic from the myVmPrivate VM to the myVmPublic VM. 回應如下列範例所示:The response is similar to this example:

    Tracing route to myvmpublic.q04q2hv50taerlrtdyjz5nza1f.bx.internal.cloudapp.net [10.0.0.4]
    over a maximum of 30 hops:
    
      1     1 ms     1 ms     1 ms  myvmpublic.internal.cloudapp.net [10.0.0.4]
    
    Trace complete.
    

    您可以看到 Azure 會將流量直接從 myVMPrivate 路由傳送至 myVMPublicYou can see that Azure routes traffic directly from myVMPrivate to myVMPublic. 根據預設,Azure 會直接路由傳送子網路之間的流量。By default, Azure routes traffic directly between subnets.

  4. 關閉要 myVMPrivate 的防禦會話。Close the bastion session to myVMPrivate.

清除資源Clean up resources

當不再需要資源群組時,請刪除 myResourceGroup 及其包含的所有資源:When the resource group is no longer needed, delete myResourceGroup and all the resources it contains:

  1. 移至 Azure 入口網站,以管理您的資源群組。Go to the Azure portal to manage your resource group. 搜尋並選取 [資源群組]。Search for and select Resource groups.

  2. 選取資源群組 myResourceGroup 的名稱。Select the name of your resource group myResourceGroup.

  3. 選取 [刪除資源群組]。Select Delete resource group.

  4. 在 [確認] 對話方塊的 [輸入資源群組名稱] 中,輸入「myResourceGroup」,然後選取 [刪除]。In the confirmation dialog box, enter myResourceGroup for TYPE THE RESOURCE GROUP NAME, and then select Delete.

後續步驟Next steps

在本教學課程中,您:In this tutorial, you:

  • 建立路由表,並將其關聯至子網。Created a route table and associated it to a subnet.
  • 建立簡單的 NVA,將來自公用子網的流量路由傳送至私人子網。Created a simple NVA that routed traffic from a public subnet to a private subnet.

您可以從 Azure Marketplace部署不同的預先設定 nva,以提供許多有用的網路功能。You can deploy different pre-configured NVAs from the Azure Marketplace, which provide many useful network functions.

若要深入了解路由,請參閱路由概觀管理路由表To learn more about routing, see Routing overview and Manage a route table.

若要篩選虛擬網路中的網路流量,請參閱:To filter network traffic in a virtual network, see: