Loading...

Simplify and Centrally Manage Virtual Networks Using Azure Virtual Network Manager

Simplify and Centrally Manage Virtual Networks Using Azure Virtual Network Manager

Today, we are excited to announce the public preview of Azure Virtual Network Manager (AVNM)! AVNM is a highly scalable and available network management solution that enables customers to simplify and scale their virtual networks in Azure. Customers have sought enterprise-scale network resource configuration and management in Azure. With the ability to define and apply connectivity and security configurations to their entire network in Azure, AVNM is their one-stop shop to centralized network management across regions and subscriptions.

Screenshot 2021-11-01 165736.pngWhat Can It Do?

AVNM allows users to create logical groups of virtual networks, define and apply connectivity configurations that build their desired topology of virtual networks, define and apply security configurations to protect their network environments with admin rules that precede NSG rules, and deploy these configurations safely in desired regions.

Let’s dive into how AVNM can help customers build out entire network topologies, apply security rules consistently across their deployment, and manage network configurations at scale with confidence and simplicity.

 

Network Groups & Dynamic Membership

Network groups allow you to apply configurations at scale for your virtual networks by categorizing your virtual networks into logical groups. You can group your virtual networks by environment, department, functionality, or other business needs. Using the network group, you can apply the AVNM configurations to the virtual networks at scale. For example, you can have all your production virtual networks in a network group and test environment virtual networks in another network group. Then, you simply apply different configuration settings (e.g., the production network group to have a strict security one) to the network groups.

 

A network group can have static and dynamic membership. In static membership, you explicitly define the virtual networks to be in the network group. Using dynamic membership, you can specify the virtual networks with criteria using name, ID, resource group, tags, subscriptions, etc. For instance, you can easily select virtual network groups whose names contain “production.”

 

AVNM will automatically react to the changes in your dynamic membership, so you don’t need to configure your virtual networks manually. For instance, when there is a new virtual network that meets the criteria of the production network group appearing in your environment, AVNM will automatically apply the configuration you defined for this virtual network.

 

Connectivity Configurations

With a connectivity configuration, customers can create connections between a multitude of virtual networks at once. Connectivity configurations consist of either a mesh or hub and spoke topology.

 

In a mesh topology, a connection is established between each virtual network within the network groups that this configuration is applied to.

 

A hub and spoke topology creates peerings between a selected hub virtual network and each spoke network group’s virtual networks. Direct connectivity is also available for hub and spoke to create additional peerings between each virtual network within a spoke network group. For example, if a customer wants to connect all their production and test virtual networks to a hub virtual network, they can create a connectivity configuration with a hub and spoke topology with their production and test network groups as the spokes. Then, if the customer wants each virtual network inside their production network group to be peered, they can select direct connectivity as an option for that network group.Screenshot 2021-11-01 170809.pngCustomers can also apply combinations of connectivity configurations onto network groups to build more complex topologies as well. Instead of creating dozens or hundreds of connections between virtual networks manually, with AVNM’s connectivity configurations, connections can be created at scale in a few clicks.

 

Security Admin Configurations

Using the security admin configuration, you can create high-priority security rules (security admin rules) to protect your virtual networks. Security admin rules are evaluated prior to NSG rules, and NSG owners cannot modify, so you can make sure these rules are followed. The use cases can include enforcing organizational security policies and creating guardrail rules for your company. For example, you can allow application owners to use NSGs for their network security demands, and, as a network administrator, you use the security admin rules to enforce your company’s security policies.

 

In addition, you can ensure all of your resources are always protected by the rules. For example, you can apply the security admin configuration blocking the traffic from high-risk ports to your production network group, and all of the existing virtual machines and newly created ones will be protected.

 

The security admin configuration feature is integrated with various products. For example, you can see the effective security rules in Virtual Machine and Network Watcher. Network Watcher’s IP flow verify feature also supports security admin rules.

 

Resources to Get You Started

Published on:

Learn more
Azure Networking Blog articles
Azure Networking Blog articles

Azure Networking Blog articles

Share post:

Related posts

Routing options for VMs from Private Subnets

Virtual Machines deployed in Azure used to have Default Outbound Internet Access. Until today, this allows virtual machines to connect to...

1 year ago

Secure, High-Performance Networking for Data-Intensive Kubernetes Workloads

The intersection of Generative AI and cloud computing has been transforming how organizations build and manage their infrastructure. The deman...

1 year ago

Network Connectivity for RISE with SAP S/4HANA Cloud Private Edition on Azure

In this article, we will explore different ways to connect to RISE with SAP S/4HANA Cloud Private Edition deployment on Azure, guiding yo...

1 year ago

Optimize Azure Landing Zone with Azure Virtual Network Manager IP Address Management

Optimize Azure Landing Zone with Azure Virtual Network Manager IP Address Management What you will learn from this blog This blog explores how...

1 year ago

ExpressRoute Metro is now generally available!!

We are excited to announce general availability of ExpressRoute Metro, a new private connectivity architecture designed to enhance network res...

1 year ago

ExpressRoute guided configuration of multi-site circuits and connections is generally available

ExpressRoute guided experience for configuring multi-site resiliency circuits and connections is generally available in Azure public cloud. Th...

1 year ago

Manage NSG association on Subnets via Azure Policy

  In this blog article, we will cover how to deny the creation of a subnet in a Virtual Network if the subnet does not have a Network Sec...

1 year ago

Effortless Private Endpoint Management in Azure Landing Zones: A Streamlined and Compliant Approach

1. Challenge In Azure Landing Zones, the network infrastructure, including components like VNET Gateways and ExpressRoute circuits, is part of...

1 year ago

Unlocking Secure VM Connectivity with Azure Bastion

In today’s digital landscape, where security breaches are an unfortunate reality, safeguarding sensitive data and infrastructure has become mo...

1 year ago

Use cases of Advanced Network Observability for your Azure Kubernetes Service clusters

Introduction  Advanced Network Observability is the inaugural feature of the Advanced Container Networking Services (ACNS) suite bringing...

2 years ago
Stay up to date with latest Microsoft Dynamics 365 and Power Platform news!
* Yes, I agree to the privacy policy