Connecting resources.
WHAT A VIRTUAL NETWORK IS
An isolated network in which your resources run.
WHAT SUBNETS DO
Divide it, allowing different rules per segment.
WHAT NETWORK SECURITY GROUPS DO
Control traffic to and from resources, by rule.
WHAT TO CONFIGURE
Deny by default, permitting only what is required.
WHAT TO NEVER EXPOSE
Management ports to the internet.
WHY
They are scanned continuously, and it is a common route to compromise.
WHAT TO USE INSTEAD
A bastion service, or a private connection.
WHAT PRIVATE ENDPOINTS PROVIDE
Reaching platform services over your private network rather than the internet.
WHY THAT MATTERS
Data does not traverse the public internet, and the service can be restricted to your network.
WHAT LOAD BALANCING PROVIDES
Distributing traffic across instances, with health checks.
WHAT CONNECTIVITY OPTIONS EXIST FOR ON-PREMISES
Encrypted connections over the internet Dedicated private circuits
WHAT TO PLAN EARLY
Address ranges that do not overlap with your existing networks.
WHY
Overlapping ranges prevent connectivity, and renumbering afterwards is painful.