{"id":19202,"date":"2020-03-20T16:46:08","date_gmt":"2020-03-20T23:46:08","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=19202"},"modified":"2020-03-20T16:46:08","modified_gmt":"2020-03-20T23:46:08","slug":"new-networking-services-in-azure-government","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/new-networking-services-in-azure-government\/","title":{"rendered":"New networking services in Azure Government"},"content":{"rendered":"<p>Improve connectivity and security with networking services that help you accelerate service delivery, optimize traffic and privacy, and shield VMs from common threats. New networking services in Azure Government include Azure Bastion, Azure Private Link, Azure Front Door, Azure Content Delivery Network, Azure Virtual WAN, and Azure DNS private zones.<\/p>\n<p>Learn more about these services below, and reach out to us with any questions at <a href=\"mailto:azgovfeedback@microsoft.com\">azgovfeedback@microsoft.com<\/a>. For a complete list of services, view Azure <a href=\"https:\/\/azure.microsoft.com\/en-us\/global-infrastructure\/services\/\">services by region<\/a>.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>Azure Bastion<\/strong><\/span><\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/bastion\/\">Azure Bastion<\/a> is a fully managed PaaS service that provides secure and seamless RDP and SSH access to your virtual machines directly through the Azure Portal. Azure Bastion is provisioned directly in your Virtual Network (VNet) and supports all VMs in your Virtual Network (VNet) using SSL without any exposure through public IP addresses.<\/p>\n<p>Using a bastion host can help limit threats such as port scanning and other types of malware targeting your VMs. Azure Bastion provides an integrated platform alternative to manually deploying and managing jump servers to shield your virtual machines.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-19205\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-image1-AzureBastion.png\" alt=\"Image Networking blog image1 AzureBastion\" width=\"607\" height=\"410\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-image1-AzureBastion.png 711w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-image1-AzureBastion-300x203.png 300w\" sizes=\"(max-width: 607px) 100vw, 607px\" \/><\/p>\n<p><em><span style=\"font-size: 10pt;\">Azure Bastion deployment architecture: (1) The Bastion host is deployed in the virtual network. (2) The user connects to the Azure portal using any HTML5 browser. (3) The user selects the virtual machine to connect to. (4) With a single click, the RDP\/SSH session opens in the browser. (5) No public IP is required on the Azure VM.<\/span><\/em><\/p>\n<p><strong>Azure Bastion resources<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/bastion\/\">Azure Bastion documentation<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/bastion\/bastion-create-host-portal\">Create an Azure Bastion host using the portal<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/videoplayer\/embed\/RE39WT5\">Working with Azure Bastion (video)<\/a><\/li>\n<\/ul>\n<p><strong><span style=\"font-size: 14pt;\">Azure Private Link<\/span><\/strong><\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/private-link\/\">Azure Private Link<\/a> provides private connectivity from a virtual network to Azure platform as a service (PaaS), customer-owned, or Microsoft partner services. It simplifies the network architecture and secures the connection between endpoints in Azure by eliminating data exposure to the public internet.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-19206\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image2-AzurePrivateLink.png\" alt=\"Image Networking blog Image2 AzurePrivateLink\" width=\"658\" height=\"308\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image2-AzurePrivateLink.png 868w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image2-AzurePrivateLink-300x140.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image2-AzurePrivateLink-768x359.png 768w\" sizes=\"(max-width: 658px) 100vw, 658px\" \/><\/p>\n<p><em><span style=\"font-size: 10pt;\">Access private endpoints over private peering or VPN tunnels from on-premises or peered virtual networks. Microsoft hosts the traffic, so you don\u2019t need to set up public peering or use the internet to migrate your workloads to the cloud.<\/span><\/em><\/p>\n<p><strong>Azure Private Link resources<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/private-link\/\">Azure Private Link documentation<\/a><\/li>\n<li><a href=\"https:\/\/www.youtube.com\/watch?v=aVFV1_ZwAEY\">Private connectivity to Azure PaaS services using Private Link (video)<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/private-link\/create-private-endpoint-portal\">Create a private endpoint using Azure Portal<\/a><\/li>\n<\/ul>\n<p><strong>Azure Front Door<\/strong><\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/\">Azure Front Door<\/a> provides a scalable and secure entry point for fast delivery of your global applications Flexibly route your users to the closest available backend, with instant failover for changes in availability or on-the-path performance. Front Door supports different load balancing algorithms including round-robin, weighted round-robin, active\/standby configurations, and cookie-based session affinity.<\/p>\n<p><strong>Azure Front Door resources<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/\">Azure Front Door documentation<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/front-door-routing-architecture\">Azure Front Door routing architecture<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/frontdoor\/front-door-tutorial-geo-filtering\">Set up a geo-filtering WAF policy<\/a><\/li>\n<\/ul>\n<p><strong><span style=\"font-size: 14pt;\">Azure Content Delivery Network<\/span><\/strong><\/p>\n<p>In online content delivery, user experience is everything. <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/cdn\/\">Azure Content Delivery Network (CDN)<\/a> lets you reduce load times, save bandwidth, and speed responsiveness\u2014whether you\u2019re developing or managing websites or mobile apps, or encoding and distributing streaming media, gaming software, firmware updates, or IoT endpoints.<\/p>\n<p>Azure CDN offers developers a global solution for rapidly delivering high-bandwidth content to users by caching their content at strategically placed physical nodes across the world. Azure CDN can also accelerate dynamic content, which cannot be cached, by leveraging various network optimizations using CDN point of presence (POP) locations.<\/p>\n<p><strong>Azure CDN resources<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/cdn\/cdn-pop-locations\">Azure CDN documentation<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/cdn\/cdn-features\">Compare Azure CDN features<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/cdn\/cdn-pop-locations\">Azure CDN coverage by metro<\/a><\/li>\n<\/ul>\n<p><span style=\"font-size: 14pt;\"><strong>Azure Virtual WAN<\/strong><\/span><\/p>\n<p>Gain simple, unified, global connectivity and security with <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-wan\/\">Azure Virtual WAN<\/a>.<\/p>\n<p>Azure Virtual WAN is a networking service that provides optimized and automated branch connectivity to, and through, Azure. Azure regions serve as hubs that you can choose to connect your branches to. You can leverage the Azure backbone to also connect branches and enjoy branch-to-VNet connectivity. We have a list of partners that support connectivity automation with Azure Virtual WAN VPN. For more information, see the <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-wan\/virtual-wan-locations-partners\">Virtual WAN partners and locations<\/a> article.<\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-19207\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image3-AzureVirtualWan.png\" alt=\"Image Networking blog Image3 AzureVirtualWan\" width=\"655\" height=\"406\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image3-AzureVirtualWan.png 850w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image3-AzureVirtualWan-300x186.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2020\/03\/Networking-blog-Image3-AzureVirtualWan-768x476.png 768w\" sizes=\"(max-width: 655px) 100vw, 655px\" \/><\/p>\n<p><em><span style=\"font-size: 10pt;\">Azure Virtual WAN brings together many Azure cloud connectivity services such as site-to-site VPN, User VPN (point-to-site), and ExpressRoute into a single operational interface.<\/span><\/em><\/p>\n<p><strong>Azure Virtual WAN resources<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-wan\/\">Azure Virtual WAN documentation<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-wan\/migrate-from-hub-spoke-topology\">Migrate to Azure Virtual WAN<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/virtual-wan\/virtual-wan-locations-partners\">Working with location and partners<\/a><\/li>\n<\/ul>\n<p><span style=\"font-size: 14pt;\"><strong>Azure Private DNS <\/strong><\/span><\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/dns\/private-dns-privatednszone\">Azure Private DNS<\/a> provides a reliable, secure DNS service to manage and resolve domain names in a virtual network without the need to add a custom DNS solution. By using private DNS zones, you can use your own custom domain names rather than Azure-provided names. The records contained in a private DNS zone are not resolvable from the Internet. DNS resolution against a private DNS zone works only from virtual networks that are linked to it.<\/p>\n<p><strong>Azure Private DNS resources<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/dns\/private-dns-privatednszone\">Azure Private DNS documentation<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/dns\/private-dns-scenarios\">Azure Private DNS zones scenarios<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/dns\/private-dns-getstarted-portal\">Create an Azure private DNS zone using the Azure portal<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Improve connectivity and security with networking services that help you accelerate service delivery, optimize traffic and privacy, and shield VMs from common threats. New networking services in Azure Government include Azure Bastion, Azure Private Link, Azure Front Door, Azure Content Delivery Network, Azure Virtual WAN, and Azure DNS private zones. Learn more about these services [&hellip;]<\/p>\n","protected":false},"author":1804,"featured_media":19209,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[95,184,426],"class_list":["post-19202","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azuregov","tag-azure-government","tag-cloud-strategy","tag-networking"],"acf":[],"blog_post_summary":"<p>Improve connectivity and security with networking services that help you accelerate service delivery, optimize traffic and privacy, and shield VMs from common threats. New networking services in Azure Government include Azure Bastion, Azure Private Link, Azure Front Door, Azure Content Delivery Network, Azure Virtual WAN, and Azure DNS private zones. Learn more about these services [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/19202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/1804"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=19202"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/19202\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/19209"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=19202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=19202"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=19202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}