In this article, I will writing about creating and configuration Azure Bastion and what it is purpose of using. It allows us to make RDP/SSH connections to our virtual machines via TLS using port 433 safely and smoothly. While connecting with Azure Bastion, your machines don’t need a Public IP address. Therefore, it protects against threats and attacks from outside.
You don’t need an RDP or SSH client to access RDP / SSH to your Azure virtual machine in your Azure portal. You can use the Azure portal to enable us to get RDP / SSH access directly from the browser.
Create and Configuration
Firstly, we are going to Subnet section from the Virtual Network menu where the virtual machine is located. We are adding a subnet named AzureBastionSubnet, provided we use a / 27 or larger subnet. Important point subnet name must be Azure Bastion Subnet.
data:image/s3,"s3://crabby-images/53848/53848f4836c6b8a89f271553058fddb80ed731c9" alt=""
We are coming to the Bastion Screen via Azure Portal page and clicking on Add.
data:image/s3,"s3://crabby-images/d6d7c/d6d7cbabe311d37d4a65bf8aa3c911721f0a1988" alt=""
- Name : We are giving a name to the Bastion.
- Subnet : We are choosing the subnet where Bastion will be deployed so we are choosing AzureBastionSubnet.
- Public IP address : This is the public IP of the Bastion resource on which RDP/SSH will be accessed (over port 443).
After doing all the operations, we continue with Review + Create and on the validation screen, we’re clicking on Create.
data:image/s3,"s3://crabby-images/45227/452270f1b519c4f525f4bf7c7151a363496b793d" alt=""
We can see that your Azure Bastion create has been successfully completed.
data:image/s3,"s3://crabby-images/0b1f4/0b1f4afa1a6d8ff5ad9d8bd0bf56acc3c28b6151" alt=""
We are going to the Networking> NIC Public IP section of virtual machine and we’re moving public IP.
data:image/s3,"s3://crabby-images/97433/974332f01d96449c4c0a759a144632f63cc089ad" alt=""
We can see that the public IP address has been removed.
data:image/s3,"s3://crabby-images/c20c7/c20c74676ae5ef0237ca770d50f597c7171d6b2f" alt=""
We are selecting Bastion from the Connection section and typing the username and password for your virtual machine.
data:image/s3,"s3://crabby-images/b956b/b956bcd5e1978f775c643c0860bdd1de936d25cd" alt=""
After we’re clicking Connect and our virtual machine is opening in a new tab.
data:image/s3,"s3://crabby-images/72885/72885615237f02aec924c4f824ceec6465243a7a" alt=""
At the same time, you can see the sessions opened with Bastion in the Session section under the Azure Bastion page.
data:image/s3,"s3://crabby-images/627ca/627ca941845b12887ba8340d8f3ec911f4a4dd25" alt=""
Referanslar: https://docs.microsoft.com/en-us/azure/bastion/bastion-overview
https://docs.microsoft.com/en-us/azure/bastion/quickstart-host-portal