You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Terraform配置Azure点到站点(Point-to-Site)VPN?

可以用Terraform配置Azure Point-to-Site VPN

完全可以通过Terraform实现Azure Point-to-Site (P2S) VPN的自动化配置,覆盖你手动完成的根证书管理、虚拟网关配置等核心步骤,以下是具体实现思路和示例:

核心配置要点

Terraform通过azurerm_virtual_network_gateway资源完成P2S VPN配置,关键是在资源块中定义point_to_site_configuration模块,结合你已生成的根证书公钥完成认证配置:

  • 根证书处理:将手动生成的根证书导出为Base64编码的CER格式(去掉证书文件中的-----BEGIN CERTIFICATE-----和-----END CERTIFICATE-----行),作为Terraform配置中根证书的公钥值。
  • 虚拟网关配置:指定VPN类型为RouteBased,配置客户端地址池(分配给P2S连接客户端的IP段),并关联根证书。

Terraform示例代码

# 配置Azure提供者
terraform {
  required_providers {
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.0"
    }
  }
}

provider "azurerm" {
  features {}
}

# 创建虚拟网络
resource "azurerm_virtual_network" "example" {
  name                = "example-vnet"
  address_space       = ["10.0.0.0/16"]
  location            = "East US"
  resource_group_name = "example-rg"
}

# 创建网关子网(必须命名为GatewaySubnet)
resource "azurerm_subnet" "gateway" {
  name                 = "GatewaySubnet"
  resource_group_name  = "example-rg"
  virtual_network_name = azurerm_virtual_network.example.name
  address_prefixes     = ["10.0.1.0/24"]
}

# 创建虚拟网络网关(包含P2S配置)
resource "azurerm_virtual_network_gateway" "example" {
  name                = "example-vpn-gateway"
  location            = "East US"
  resource_group_name = "example-rg"

  type     = "Vpn"
  vpn_type = "RouteBased"

  active_active = false
  enable_bgp    = false

  ip_configuration {
    name                          = "vnetGatewayConfig"
    public_ip_address_id          = azurerm_public_ip.example.id
    private_ip_address_allocation = "Dynamic"
    subnet_id                     = azurerm_subnet.gateway.id
  }

  # Point-to-Site配置
  point_to_site_configuration {
    address_space = ["192.168.1.0/24"] # 客户端IP分配段,不能与VNet重叠

    root_certificate {
      name         = "VPNRoot" # 根证书名称,与手动生成的CN对应
      public_key   = "MIIC5zCCAc+gAwIBAgIU..." # 根证书Base64公钥(去掉BEGIN/END行)
    }
  }
}

# 网关所需的公网IP
resource "azurerm_public_ip" "example" {
  name                = "example-gateway-pip"
  location            = "East US"
  resource_group_name = "example-rg"
  allocation_method   = "Dynamic"
}

客户端证书说明

Terraform不直接负责生成客户端证书,你仍可使用之前的PowerShell脚本生成:

$cert = New-SelfSignedCertificate -Type Custom -KeySpec Signature  -Subject "CN=VPNRoot" -KeyExportPolicy Exportable  -HashAlgorithm sha256 -KeyLength 2048  -CertStoreLocation "Cert:\CurrentUser\My" -KeyUsageProperty Sign -KeyUsage CertSign

New-SelfSignedCertificate -Type Custom -DnsName VPNCert -KeySpec Signature  -Subject "CN=VPNCert" -KeyExportPolicy Exportable  -HashAlgorithm sha256 -KeyLength 2048  -CertStoreLocation "Cert:\CurrentUser\My" -Signer $cert -TextExtension @("2.5.29.37={text}1.3.6.1.5.5.7.3.2")

生成的客户端证书需导出并安装到用户设备上,才能建立P2S连接。如果需要自动化生成,可通过Terraform的local-exec调用上述脚本,但通常建议手动生成后安全分发给用户。

注意事项

  • 网关子网必须命名为GatewaySubnet,Azure会自动识别该子网用于VPN网关部署。
  • 客户端地址池address_space不能与虚拟网络的地址段重叠,否则会导致连接失败。
  • 确保根证书公钥格式正确,否则Azure网关无法识别证书进行认证。

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 14:20:34