Storage
|
Used Managed Disks
|
Specify whether you want Azure to automatically manage
the availability of disks to provide data redundancy and fault tolerance
without you creating and managing a storage account. Click No.
|
Storage Account
|
If you need to change the storage account for the vSRX
VM, click the right arrow to access the Choose Storage Account blade.
Select an existing storage account for the vSRX VM, or click Create new (+) to create a new one. See Create a Storage Account for details
about creating a new storage account.
|
Network
|
Virtual Network
|
If you need to change the virtual network for the vSRX
VM, click the right arrow to access the Choose Virtual Network blade.
Select an existing virtual network for the vSRX VM, or click Create new (+) to create a new one. See Create a Virtual Network for details
about creating a new virtual network.
|
Subnet
|
Enter a subnet, which is a range of IP addresses in your
virtual network to isolate VMs. Public subnets have access to the
Internet gateway, but private subnets do not.
A vSRX VM requires two public subnets and one or more private
subnets for each individual instance group. The public subnets consist
of one for the management interface (fxp0) and another for the two
revenue (data) interfaces. The private subnets, connected to other
vSRX interfaces, ensure that all traffic between applications on the
private subnets and the Internet must pass through the vSRX instance.
To modify the subset for the virtual network, click the right
arrow to access the Create Subnet blade.
Configure the following parameters:
Subnet name—A unique name for the subnet in the
Azure virtual network.
Subnet address range—The subnet’s address
range in CIDR notation. It must be contained by the address space
of the virtual network. Subnet address ranges cannot overlap one another.
By default, the address range is 10.0.0.0/24.
Note: The address range of a subnet that is already in use cannot
be edited.
|
Public IP address
|
Specify the public IP address that allows communication
to the vSRX VM from outside the Azure virtual network. To modify the
public IP address for the vSRX VM, click the right arrow to access
the Choose Public IP Address blade. Select a public IP address in
your Azure subscription and location, or click Create new (+) to create a new one.
Configure the following parameters:
Name—A unique name for the public IP address.
Assignment—There are two methods in which an IP
address is allocated to a public IP resource: dynamic or static. By
default, public IP addresses are dynamic, where an IP address is not
allocated at the time of its creation. Instead, the public IP address
is allocated when you start (or create) the resource. The IP address
associated to them may change when the vSRX VM is deleted.
To guarantee that the vSRX VM always uses the same public IP
address, we recommend you assign a static public IP address.
|
Network security group
|
Specify a network security group, which is a set of firewall
rules that control traffic to and from the vSRX VM. Each network security
group can contain multiple inbound and outbound security rules that
enable you to filter traffic by source and destination IP address,
port, and protocol. You can apply a network security group to each
NIC in the VM.
To modify the network security group for the vSRX VM to filter
traffic, click the right arrow to access the Choose Network Security
blade. Select a network security group in your Azure subscription
and location, or click Create new (+) to create a new one.
Configure the following parameters:
Name—A unique name for the network security group.
Inbound rules—You can add one or more inbound security
rules to allow or deny traffic to the vSRX VM.
Outbound rules—You can add one or more outbound
security rules to allow or deny traffic originating from the vSRX
VM.
|
Extensions
|
Extensions
|
No extensions are used for the vSRX VM.
|
High Availability
|
Availability Set
|
Confiigure two or more VMs in an availability set to
provide redundancy to an application.
Note: Availability Set should be set to None for
the vSRX VM. Availablilty Set is not used for the vSRX VM in Azure
because chassis clustering is not supported by the vSRX at this time.
|
Monitoring
|
Boot Diagnostics
|
Enables or disables the capturing of serial console output
and screenshots of the VM running on the host to help diagnose start-up
issues. The default is Enabled.
|
Guest OS Diagnostics
|
Enables or disables the ability to obtain metrics every
minute for the VM. Choices are: Disabled or Enabled. The default is Disabled.
|
Diagnostics Storage Account
|
Click the right arrow to view the details of the diagnostics
storage account. Automatically fills in with the name of the diagnostics
storage account from which you can analyze a set of metrics with your
own tools.
|