網路功能模擬Network Function Virtualization

適用於:Windows Server(以每年次管道)、Windows Server 2016Applies To: Windows Server (Semi-Annual Channel), Windows Server 2016

您可以使用本主題以深入了解網路功能模擬,可讓您部署 virtual 網路的裝置,例如 Datacenter 防火牆 multitenant RAS 閘道,以及軟體負載平衡 (SLB) 多工器 (MUX)。You can use this topic to learn about Network Function Virtualization, which allows you to deploy virtual networking appliances such as Datacenter Firewall, multitenant RAS Gateway, and Software Load Balancing (SLB) multiplexer (MUX).

注意

本主題中,除了下列網路功能模擬文件會提供。In addition to this topic, the following Network Function Virtualization documentation is available.

在今天的軟體定義資料中心硬體裝置(例如負載平衡器、防火牆、路由器、參數,等等)來執行網路功能的越來越正在擬化檔案為 virtual 裝置。In today's software defined datacenters, network functions that are being performed by hardware appliances (such as load balancers, firewalls, routers, switches, and so on) are increasingly being virtualized as virtual appliances. 這「網路功能模擬」是伺服器模擬和網路模擬自然進展。This "network function virtualization" is a natural progression of server virtualization and network virtualization. 快速新興,建立的全新市場 virtual 裝置。Virtual appliances are quickly emerging and creating a brand new market. 他們繼續產生興趣取得待發這兩個模擬平台和雲端服務。They continue to generate interest and gain momentum in both virtualization platforms and cloud services.

Microsoft 以開始使用 Windows Server 2012 R2 的 virtual 應用裝置隨附的獨立閘道。Microsoft included a standalone gateway as a virtual appliance starting with Windows Server 2012 R2 . 如需詳細資訊,請查看Windows 伺服器閘道For more information, see Windows Server Gateway. 現在與 Windows Server 2016 Microsoft 會繼續以展開及投資網路功能模擬市場。Now with Windows Server 2016 Microsoft continues to expand and invest in the network function virtualization market.

Virtual 應用裝置權益Virtual appliance benefits

Virtual 應用裝置,而且動態輕鬆變更,因為它是預先建置,自訂一樣。A virtual appliance is dynamic and easy to change because it is a pre-built, customized virtual machine. 它可以是一或多個虛擬電腦已封裝、更新,並為單位保留。It can be one or more virtual machines packaged, updated, and maintained as a unit. 一起軟體定義網路 (SDN),就會顯示靈活度和今天以雲端為基礎的基礎結構中所需的彈性。Together with software defined networking (SDN), you get the agility and flexibility needed in today's cloud-based infrastructure. 例如:For example:

  • SDN 呈現網路為集區與動態資源。SDN presents the network as a pooled and dynamic resource.

  • 幫助您承租人隔離 SDN。SDN facilitates tenant isolation.

  • SDN 發揮最大的縮放比例和效能。SDN maximizes scale and performance.

  • 可讓順暢容量擴充和工作負載行動 virtual 裝置。Virtual appliances enable seamless capacity expansion and workload mobility.

  • Virtual 設備最小化操作複雜。Virtual appliances minimize operational complexity.

  • Virtual 設備可讓您輕鬆地取得、部署及管理預先整合的方案針對。Virtual appliances let customers easily acquire, deploy, and manage pre-integrated solutions.

    • 針對可以輕鬆地移動 virtual 應用裝置任何位置點一下在雲端中。Customers can easily move the virtual appliance anywhere in the cloud.

    • 針對可縮放 virtual 設備或向下動態根據要求。Customers can scale virtual appliances up or down dynamically based on demand.

如需有關 Microsoft SDN 查看軟體定義網路For more information about Microsoft SDN see Software Defined Networking.

網路功能的問題擬化檔案?What network functions are being virtualized?

快速變大的市場模擬的網路功能。The marketplace for virtualized network functions is growing quickly. 下列網路功能的問題擬化檔案:The following network functions are being virtualized:

  • 安全性Security

    • 防火牆Firewall

    • 防毒軟體Antivirus

    • DDoS(分散式阻斷服務)DDoS (Distributed Denial of Service)

    • IPS ID(入侵防止系統日入侵偵測系統)IPS/IDS (Intrusion Prevention System/Intrusion Detection System)

  • 應用程式日 WAN 最佳化Application/WAN optimizers

  • EdgeEdge

    • 網站-閘道Site-to-site gateway

    • L3 閘道L3 gateways

    • 路由器Routers

    • 切換Switches

    • NATNAT

    • 負載平衡器(不一定是在 edge 中)Load balancers (not necessarily at the edge)

    • HTTP proxyHTTP proxy

為何 Microsoft 會 virtual 裝置變得更好的平台Why Microsoft is a great platform for virtual appliances

網路 virtual 堆疊

Microsoft 平台經過工程設計為建置及部署 virtual 裝置變得更好的平台。The Microsoft platform has been engineered to be a great platform to build and deploy virtual appliances. 原因如下:Here's why:

  • Microsoft 提供與 Windows Server 2016 金鑰模擬的網路功能。Microsoft provides key virtualized network functions with Windows Server 2016.

  • 您可以部署 virtual 應用廠商裝置的您的選擇。You can deploy a virtual appliance from the vendor of your choice.

  • 您可以部署、設定及管理您使用的是 Windows Server 2016 的 Microsoft Network Controller 的 virtual 裝置。You can deploy, configure, and manage your virtual appliances with the Microsoft Network Controller which comes with Windows Server 2016. 如需 Network Controller 的詳細資訊,請查看Network ControllerFor more information about the Network Controller, see Network Controller.

  • HYPER-V 可以主機頂端來賓作業系統,您需要。Hyper-V can host the top guest operating systems that you need.

Windows Server 2016 中的網路功能模擬Network function virtualization in Windows Server 2016

Microsoft 所提供的 virtual 設備函式Virtual appliances functions provided by Microsoft

提供下列 virtual 裝置與 Windows Server 2016:The following virtual appliances are provided with Windows Server 2016:

軟體負載平衡器Software load balancer

層級 4 負載平衡器在 datacenter 縮放作業。A layer-4 load balancer operating at datacenter scale. 這是在縮放 Azure 環境中部署的 Azure 負載平衡器版本類似。This is a similar version of Azure's load balancer that has been deployed at scale in the Azure environment. 如需 Microsoft 軟體負載平衡器,請查看軟體負載平衡 (SLB) SDN 的For more information about the Microsoft Software Load Balancer, see Software Load Balancing (SLB) for SDN. 如需 Microsoft Azure 負載平衡服務的詳細資訊,請查看Microsoft Azure 負載平衡服務For more information about Microsoft Azure Load Balancing Services, see Microsoft Azure Load Balancing Services.

閘道Gateway. RAS 閘道提供所有下列閘道功能的組合。RAS Gateway provides all combinations of the following gateway functions.

  • 網站-閘道Site-to-Site gateway

    RAS 閘道提供邊境閘道通訊協定 (BGP)-可讓您存取及管理他們的資源從遠端網站,以網站 VPN 連接到 tenants 並允許 virtual 資源中的雲端和承租人實體網路間網路流量的功能、multitenant 閘道。RAS Gateway provides a Border Gateway Protocol (BGP)-capable, multitenant gateway that allows your tenants to access and manage their resources over site-to-site VPN connections from remote sites, and that allows network traffic flow between virtual resources in the cloud and tenant physical networks. 如需 RAS 閘道的詳細資訊,請查看RAS 閘道可用性RAS 閘道For more information about the RAS Gateway, see RAS Gateway High Availability and RAS Gateway.

  • 轉送閘道Forwarding gateway

    RAS 閘道傳送 virtual 網路與控管提供者實體網路間流量。RAS Gateway routes traffic between virtual networks and the hosting provider physical network. 例如,如果 tenants 建立一或多個 virtual 網路,必須存取實體網路裝載的提供者共用資源轉接閘道可以傳送 virtual 網路與提供使用者使用 virtual 服務所需的網路上的實體網路間流量。For example, if tenants create one or more virtual networks, and need access to shared resources on the physical network at the hosting provider, the forwarding gateway can route traffic between the virtual network and the physical network to provide users working on the virtual network with the services that they need. 如需詳細資訊,請查看RAS 閘道可用性RAS 閘道For more information, see RAS Gateway High Availability and RAS Gateway.

  • GRE 通道閘道GRE tunnel gateways

    GRE 根據承租人 virtual 網路之間外部網路的通道讓連接。GRE based tunnels enable connectivity between tenant virtual networks and external networks. 因為 GRE 通訊協定輕量型與支援 GRE 是網路的大部分裝置上,它會變成的資料加密不需要理想選擇的通道。Since the GRE protocol is lightweight and support for GRE is available on most network devices, it becomes an ideal choice for tunneling where data encryption is not required. 支援網站 (S2S) 通道 GRE 下轉接承租人 virtual 網路與承租人外部網路使用多承租人閘道之間的GRE support in Site to Site (S2S) tunnels solves the problem of forwarding between tenant virtual networks and tenant external networks using a multi-tenant gateway. 如需 GRE 可愛的詳細資訊,請查看在 Windows Server 2016 的 GRE 通道For more information about GRE tunnels, see GRE Tunneling in Windows Server 2016.

使用 BGP 路由控制平面Routing control plane with BGP

HYPER-V 網路模擬 (HNV) 路由控制項是控制平面,帶來客戶地址平面路徑和動態學習,然後更新分散式的 RAS 閘道路由器 virtual 網路中的邏輯,打造實體。Hyper-V Network Virtualization (HNV) Routing Control is the logical, centralized entity in the control plane, which carries all the Customer Address plane routes and dynamically learns and then updates the distributed RAS Gateway routers in the virtual network. 如需詳細資訊,請查看RAS 閘道可用性RAS 閘道For more information, see RAS Gateway High Availability and RAS Gateway.

散發多承租人防火牆Distributed multi-tenant firewall

防火牆保護網路 virtual 網路層的級。The firewall protects the network layer of virtual networks. 原則會執行的每個承租人 VM SDN-vSwitch 連接埠。The policies are enforced at the SDN-vSwitch port of each tenant VM. 保護所有流量:東西和北南。It protects all traffic flows: east-west and north-south. 原則會透過承租人入口網站推入和 Network Controller 它們分散至所有適用的主機。The policies are pushed through the tenant portal and the Network Controller distributes them to all applicable hosts. 如需分散式多承租人防火牆的詳細資訊,請查看Datacenter 防火牆概觀For more information about the distributed multi-tenant firewall, see Datacenter Firewall Overview.