You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure跨不同虚拟网络VM的非VPN/ExpressRoute连通方法咨询

How to Connect Your Two Azure VMs Without VPN/ExpressRoute

Hey there! Since you don’t want to use VPN or ExpressRoute, Virtual Network Peering is exactly the native Azure solution you need here—it’s the closest equivalent to the OpenStack approach you’re familiar with, and it fits your scenario perfectly (your VNets have non-overlapping private IP spaces, which is a key requirement).

Let’s break down the setup step by step, plus how to verify connectivity:

Prerequisites You Already Meet

First, let’s confirm you’ve checked all the boxes for peering to work:

  • Your VNets have distinct, non-overlapping address spaces (172.16.10.0/24 and 172.16.20.0/24—perfect)
  • NSGs are configured to allow all traffic between subnets
  • VMs are attached to their respective subnets via NICs

Step 1: Set Up Bidirectional VNet Peering

Peering is bidirectional, so you need to create connections in both directions (one from vnet1 to vnet2, and another from vnet2 to vnet1). You can do this via the Azure Portal or CLI—here’s both options:

Portal Walkthrough

  1. Navigate to vnet1 in the Azure Portal
  2. Under the Settings menu, select Peerings
  3. Click + Add to create a new peering:
    • Name it something like vnet1-to-vnet2
    • For Virtual network, select vnet2 from the dropdown (or enter its resource ID if it’s in a different subscription/resource group)
    • Ensure Allow virtual network access from vnet1 to vnet2 is checked
    • Leave other settings (forwarded traffic, gateway transit) as default unless you need them (you don’t for basic VM connectivity)
    • Click OK
  4. Repeat the process for vnet2:
    • Go to vnet2’s Peerings page, click + Add
    • Name it vnet2-to-vnet1
    • Select vnet1 as the remote virtual network
    • Check Allow virtual network access from vnet2 to vnet1
    • Click OK

Azure CLI Commands

Run these in Azure Cloud Shell or your local CLI (make sure you’re logged into the correct subscription):

# Create peering from vnet1 to vnet2
az network vnet peering create \
  --name vnet1-to-vnet2 \
  --resource-group your-resource-group-name \
  --vnet-name vnet1 \
  --remote-vnet vnet2 \
  --allow-vnet-access

# Create reverse peering from vnet2 to vnet1
az network vnet peering create \
  --name vnet2-to-vnet1 \
  --resource-group your-resource-group-name \
  --vnet-name vnet2 \
  --remote-vnet vnet1 \
  --allow-vnet-access

Step 2: Verify Connectivity

Once both peerings show a Connected status in the portal:

  1. RDP/SSH into one of your VMs
  2. Ping or traceroute the private IP of the other VM—since your NSGs allow all traffic, this should work immediately
  3. You can also check the effective route table for each VM’s NIC: Azure automatically adds routes to the peered VNet’s address space, so no manual route creation is needed.

Quick Notes to Keep in Mind

  • Peering works for VNets in the same region or cross-region (called Global VNet Peering)
  • Your VNets’ address spaces must never overlap—if they did, peering would fail (you’re good here)
  • Peering is low-latency and cost-effective, since it doesn’t require any gateways

内容的提问来源于stack exchange,提问作者Sudhakar Reddy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:45:55