Skip to main content

Connecting VMs Together in a Virtual Network (Azure)

Spinning circle, Azure VMs in a Virtual Network


Here - Don't be dismayed by the instructions.


Today's Events:

  • Configure a network security group + security rules using Powershell.
  • The application server should connect to the database server over HTTP.
  • BUT the database server shouldn't use HTTP to connect to the application server.


The first hurdle was getting the command to work.


tion>rg=Paolin
At line:1 char:39
+ az group create --name $rg --location rg=Paolin
+                                       ~
The '<' operator is reserved for future use.
+ CategoryInfo          : ParserError: (:) [], ParentContainsErrorRecordException
+ FullyQualifiedErrorId : RedirectionNotSupported
Until I tried it in bash:

rg = 32
az group create --name $rg --location eastus


Some numbers are changed below.

{
  "id": "/subscriptions/a78373f1-5023-41fe-ae36-d0742026d72f/resourceGroups/32",
  "location": "eastus",
  "managedBy": null,
  "name": "32",
  "properties": {
    "provisioningState": "Succeeded"
  },
  "tags": null,
  "type": "Microsoft.Resources/resourceGroups"
}

I made a new subnet, named it (Apps), addressed it, and tied it to a group:

m@Azure:~$ az network vnet create \
> --resource-group $rg \
> --name ERP-Servers \
> --address-prefix 10.0.0.0/16 \
> --subnet-name Apps \
> --subnet-prefix 10.0.0.0/24
There's a lot of return information:
  • DDoS protection is not enabled (This resource will have been shut off by the time this posts)
  • Provisioning state has succeeded.
  • No BGP communities
  • Private Endpoint Network Policies are Enabled

I repeat it for the Databases subnet:

az network vnet subnet create \
    --resource-group $rg \
    --vnet-name ERP-servers \
    --address-prefix 10.0.1.0/24 \
    --name Databases

The commands look similar, but they are not - one has subnet create, the other only create. They are both in Resource Group 32, but have different address prefix allotments.

Finally; The Network Security Group.

az network nsg create \
    --resource-group $rg \
    --name ERP-SERVERS-NSG

It's given a type of "Microsoft.Network/networkSecurityGroups" in Resource Group 32.


Now for the Ubuntu VMs:

wget -N https://raw.githubusercontent.com/MicrosoftDocs/mslearn-secure-and-isolate-with-nsg-and-service-endpoints/master/cloud-init.yml && \ Pulling the appropriate code from Microsoft's GitHub repository
az vm create \
    --resource-group $rg \ 32
    --name AppServer \
    --vnet-name ERP-servers \
    --subnet Applications \
    --nsg ERP-SERVERS-NSG \
    --image UbuntuLTS \
    --size Standard_B1ls \
    --admin-username azureuser \
    --custom-data cloud-init.yml \
    --no-wait \
    --admin-password
(Entered, but not shown here) this isn't the real PW!

So, I'm not a person who likes to follow the directions to the letter when learning. What do you learn if you just copy and paste commands?

Can you see the error above?

Yes, my Applications subnet is called Apps. The code spells it out Applications. So I end up deleting and remaking the resource groups while following the instructions. At least it's a learning experience!

So now we have Databases, Applications, and a Network Security Group in Resource Group 32

Let's see how our VMs are running.


Name        Provisioned    Power
----------  -------------  ----------
AppServer   Succeeded      VM running
DataServer  Succeeded      VM running

Let's check our public IP addresses so we can SSH into them.



The next command has me putting those Public IPs to variables - In a Bash Shell! Could we always do this? Technology is amazing.

The connection times out initially because of an implicit deny all to outside traffic, and I fix that with a command that:
  • Allow SSH access
  • For servers in the Group
Can we connect now?

Connection timed out during banner exchange

Hm, not quite. The instructions say you may have to wait some minutes. I check the GUI, and the new rule is in place;


Also, seeing ⚠ and 'Succeeded' doesn't make a ton of sense to me, but whatever.

The resources are still there, so I can leave this and come back later.

I had to deviate from the instructions; Return later; Go to your VM inside your resource group, and click 'Connect' at the top ribbon. Copy the 'Login using VM local account' information.


And paste it into the Bash terminal.



Run it twice; The second time should ask for the password to the VM. As stated above, Azure has been having issues all day, and they come up again here; Includes a lot of time outs and not recognizing its own commands.

At the very least, I did get two VMs into the same Virtual Network, even if the system didn't have the stamina today to go all the way.




Comments

Popular posts from this blog

What Do You Need? [AKA; List of Offered Services / My Next Role] (2020)

I am a trusted outsourced remote consultant for your company.   I enjoy having the flexibility to take on temporary projects from time to time! I start at part-time, temp work for now. If we like each other, we can renegotiate. If anything sounds weird, out there, or unusual - Feel free to e-mail me .  3 Services Offered Writing :      You want to pay me to write more of *waves hand* this blog? I am game .     I write B2C e-mails going out to over 280 people weekly. [ Example Job Description ]        Auditing :        Something doesn't work on your page or in your app. I can find it, or you can lose business. [ Here ] [ Example Job Description ]   I really enjoy testing apps and webpage concepts! I have an iPhone and Android phones ready. Technical: Still as-needed, always remote, contract, or temporary. IT Operations Tech [ Example Job Description ]     Hardware and SaaS support.     Cisco routing and switching (Networking). CCNA, A+, Sec+, Azure certified WORKING ON: Junos

Portfolio of UX/Product Feedback [Vol. 1]

I browse websites and apps, while making note of things I find frustrating for end users. You have probably been linked here from a form or my resume. If you have any questions about what I'm looking for in a role, click here .   This post is not to shame, but to point out errors and hopefully make my talent for finding and documenting such mistakes clear to someone hiring. Contents: Instances where I offer constructive feedback on someone's website, logo, or app. Actions that were taken by the developers or artists.  I'm glad you want your webpages to be the best they can be with my help; If you need your sites audited, e-mail me . Latest Update -  November 20th, 2020.   Vol. 2 is here .

Contactless Tech’s Role in the New Guest Experience ft. Intelity and The George

 Contactless hospitality technology is growing. You want to get away, and you'll be damned if a little thing like a deadly virus will stop you! But you still don't want to touch things. Ew. During the chat between INTELITY CEO Robert Stevenson and THE GEORGE Director of Operations Kerrie Hunter, you’ll learn how the historic boutique hotel has adapted a mobile-first guest experience in the wake of COVID-19—and how they see contactless technology affecting the future of hospitality. I don't remember how I found INTELITY (probably hoping to score a position with them), but I liked them enough to stay on the e-mail lists.