[英]Is there a method to allow Point-to-Site VPN connection to a Azure VNet only from specific set of public IP addresses?
I have Azure VNET and a VPN Gateway setup.我有 Azure VNET 和 VPN 网关设置。 Point-to-Site VPN connection has been setup, so users can access VMs on the VNET.
已建立点到站点 VPN 连接,因此用户可以访问 VNET 上的虚拟机。 Is there anyway I can allow VPN connection only if connection is coming from a known public facing IP address from corporate on-prem network?
无论如何,只有当连接来自公司内部网络的已知面向公众的 IP 地址时,我才能允许 VPN 连接?
Point-to-site VPN connection is between a single PC connected to your network and Azure VPN gateway over the internet.点到站点 VPN 连接是在连接到您的网络的单台 PC 和 Internet 上的 Azure VPN 网关之间。 The VPN client was assigned private IP address from the address pool.
VPN 客户端从地址池中分配了私有 IP 地址。 This on-demand connection is initiated by the user and secured by using a certificate.
这种按需连接由用户发起并使用证书进行保护。 The connection uses the SSTP protocol on port 443 to provide encrypted communication over the internet between the PC and the VNet.
该连接使用端口 443 上的 SSTP 协议在 PC 和 VNet 之间通过 Internet 提供加密通信。
If you only allow some clients to set up VPN connection, you just need to install client certificate on some specific client machine and don't install client certificate on some clients that you don't want to connect to VPN gateway.如果您只允许某些客户端建立 VPN 连接,您只需要在某些特定的客户端机器上安装客户端证书,并且不要在某些您不想连接到 VPN 网关的客户端上安装客户端证书。 If you want to restrict the access from some clients to access your VMs on the VNET.
如果您想限制某些客户端访问 VNET 上的虚拟机。 The clients should disconnect the VPN connection and restrict it's public IP address in the NSG associated with that Azure VM subnet or NIC.
客户端应断开 VPN 连接并在与该 Azure VM 子网或 NIC 关联的 NSG 中限制其公共 IP 地址。
P2S connections are useful for remote employees or those that only want to establish connectivity when they need it and can disconnect from the Azure VNet when they are finished with their tasks. P2S 连接对于远程员工或只想在需要时建立连接并在完成任务后可以从 Azure VNet 断开连接的员工非常有用。
You could get more details from this wonderful blog .您可以从这个精彩的博客中获得更多详细信息。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.