Home

Question about Infrastructure

%3CLINGO-SUB%20id%3D%22lingo-sub-138850%22%20slang%3D%22en-US%22%3EQuestion%20about%20Infrastructure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-138850%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20!%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20have%20a%20project%20that%20has%203%20remote%20site%2C%20with%20the%20requirement%20of%20a%20file%20server%2C%3CBR%20%2F%3Eprinter%20management%2C%20ERP%20integration%2C%20cross-site%20networking%20and%20a%20mail%20solution.%3C%2FP%3E%0A%3CP%3ETo%20answer%20it%2C%20I%20would%20like%20to%20propose%20a%20100%25%20cloud%20solution%2C%20via%20Azure.%3C%2FP%3E%0A%3CP%3EBy%20cons%2C%20I%20can%20not%20find%20information%20on%20different%20points%3A%3C%2FP%3E%0A%3CP%3EFor%20the%20file%20server%3A%3CBR%20%2F%3E-Create%20a%20virtual%20network%3CBR%20%2F%3E-%20Create%20a%20VPN%20gateway%3CBR%20%2F%3E-%20Parameterize%20a%20VM%20with%20the%20role%20ADFS%20%2F%20DNS%20%2F%20Server%20files%3C%2FP%3E%0A%3CP%3EMy%20question%20%3A%3C%2FP%3E%0A%3CP%3Eif%20i%20implement%20this%20solution%2C%20can%20i%20be%20satisfied%20with%20the%20onmicrosoft.com%20domain%3F%3CBR%20%2F%3Eor%20should%20I%20have%20a%20domain%3F%3CBR%20%2F%3EWith%20the%20VPN%20gateway%20service%20there%20is%20a%20limit%20of%20128%20users%3F%3CBR%20%2F%3EThe%20company%20in%20question%20has%20about%20200%20users%2C%20do%20I%20have%20to%20subscribe%20to%20the%20express%20route%3F%3CBR%20%2F%3EIs%20the%20point-to-site%20VPN%20type%20possible%20with%20a%20full%20cloud%20infrastrutuce%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%20for%20your%20help%20!%26nbsp%3B%3C%2FP%3E%0A%3CP%3EJonh.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-138850%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Active%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20Essentials%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-140588%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20about%20Infrastructure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-140588%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3Eif%20i%20implement%20this%20solution%2C%20can%20i%20be%20satisfied%20with%20the%20onmicrosoft.com%20domain%3F%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3Eor%20should%20I%20have%20a%20domain%3F%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20prefer%20to%20use%20a%20domain%2C%20one%20of%20the%20core%20problems%20with%20solely%20using%20AAD%20is%20that%20it%20isn't%20multi-region%20capable%20(well%20at%20least%20it%20wasn't%20for%20some%20time%2C%20i%20haven't%20checked%20recently%20to%20see%20if%20that%20is%20now%20resolved)%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CSPAN%3EWith%20the%20VPN%20gateway%20service%20there%20is%20a%20limit%20of%20128%20users%3F%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EThe%20point%20to%20site%20solution%20is%20ok%20on%20a%20small%20site%2C%20most%20of%20the%20documentation%20states%20to%20use%20self%20signed%20certs%2C%20you%20can%20also%20use%20your%20on%20prem%20pki%20if%20you%20want.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CSPAN%3EThe%20company%20in%20question%20has%20about%20200%20users%2C%20do%20I%20have%20to%20subscribe%20to%20the%20express%20route%3F.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20do%20not%20need%20express%20route%20it%20is%20simply%20the%20high%20performance%20tier%20of%20the%20site%20to%20site%20gateway.%20For%20a%20site%20that%20small%20you%20may%20get%20away%20with%20a%20standard%20site%20to%20site%20link.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CSPAN%3EIs%20the%20point-to-site%20VPN%20type%20possible%20with%20a%20full%20cloud%20infrastrutuce%3F%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Eyes%20you%20can%20use%20a%20point%20to%20site%20solution.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EYou%20mentioned%20building%20AD%20%2F%20ADFS%20in%20the%20cloud.%20If%20you%20are%20going%20down%20this%20route%20i%20would%20recommend%20a%20hub%20n%20spoke%20topology.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EYou%20essentially%20put%20all%20your%20AD%20%2F%20ADFS%20content%20into%20the%20hub%20network.%20the%20you%20use%20vnet%20peering%20to%20link%20your%20resource%20systems.%20The%20benefits%20you%20get%20out%20of%20this%20implementation%20is%20that%20it%20is%20highly%20scalable.%20As%20you%20organisation%20grows%20you%20can%20grow%20the%20solution%20exponentially%20as%20well%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Ethe%20other%20benefit%20here%20is%20that%20your%20spoke%20networks%20will%20inherit%20the%20security%20of%20the%20hub%20network.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Etypically%20you%20would%20lock%20down%20your%20hub%20network%20so%20people%20cannot%20deploy%20content%20into%20it%20to%20ensure%20it%20stays%20secure.%20The%20spokes%20are%20less%20restrictive%20although%20you%20would%20want%20to%20prevent%20public%20ip's%20etc%20in%20the%20spokes%20and%20force%20them%20to%20route%20through%20the%20hub%20network.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Eit%20is%20quite%20a%20complex%20setup%20but%20highly%20secure%20and%20highly%20scalable.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-139887%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20about%20Infrastructure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-139887%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAs%20per%20your%20queries%2C%20i%20suggest%20you%20can%20go%20ahead%20with%20Azure%20File%20Sync%20service%20in%20Azure...%26nbsp%3BIf%20users%20want%20to%20access%20the%20files%20from%20organization%20network%20then%20create%20the%20VPN%20based%20on%20the%20users...%26nbsp%3BIf%20users%20are%20very%20less%20then%20go%20for%20P2S%20or%20if%20users%20are%20good%20in%20number%20then%20opt%20for%20S2S%20connection...%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20email%2C%20the%20solution%20goes%20for%20O365%20and%20do%20the%20ERP%20integration.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-introduction-%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fstorage%2Ffiles%2Fstorage-files-introduction-%3C%2FA%3E%20Azure%20file%20Sync%20Brief%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fgallery.technet.microsoft.com%2Foffice%2Fmigrate-office-365-to-sap-aad0636f%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgallery.technet.microsoft.com%2Foffice%2Fmigrate-office-365-to-sap-aad0636f%3C%2FA%3E%20-%20O365%20email%20and%20ERP%20integration%20like%20SAP.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-139182%22%20slang%3D%22en-US%22%3ERe%3A%20Question%20about%20Infrastructure%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-139182%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20would%20suggest%20to%20go%20for%20Office%20365%20for%20mail%2C%20file%20sharing%20and%20productivity%20solution.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EERP%20you%20can%20host%20on%20Azure.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EGo%20for%20your%20own%20domain.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ecreate%20site%20to%20site%20VPN%20from%203%20sites%20to%20Azure.%20Use%20Point%20to%20site%20for%20mobile%20workers.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAny%20further%20questions%2C%20please%20do%20post.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Jonathan BARTHELEMY
Occasional Visitor

Hi ! 

I have a project that has 3 remote site, with the requirement of a file server,
printer management, ERP integration, cross-site networking and a mail solution.

To answer it, I would like to propose a 100% cloud solution, via Azure.

By cons, I can not find information on different points:

For the file server:
-Create a virtual network
- Create a VPN gateway
- Parameterize a VM with the role ADFS / DNS / Server files

My question :

if i implement this solution, can i be satisfied with the onmicrosoft.com domain?
or should I have a domain?
With the VPN gateway service there is a limit of 128 users?
The company in question has about 200 users, do I have to subscribe to the express route?
Is the point-to-site VPN type possible with a full cloud infrastrutuce?

 

Thanks for your help ! 

Jonh.

 

3 Replies

Hi,

 

I would suggest to go for Office 365 for mail, file sharing and productivity solution.

 

ERP you can host on Azure.

 

Go for your own domain.

 

create site to site VPN from 3 sites to Azure. Use Point to site for mobile workers.

 

Any further questions, please do post.

Hi, 

 

As per your queries, i suggest you can go ahead with Azure File Sync service in Azure... If users want to access the files from organization network then create the VPN based on the users... If users are very less then go for P2S or if users are good in number then opt for S2S connection... 

 

For email, the solution goes for O365 and do the ERP integration. 

 

 https://docs.microsoft.com/en-us/azure/storage/files/storage-files-introduction- Azure file Sync Brief

https://gallery.technet.microsoft.com/office/migrate-office-365-to-sap-aad0636f - O365 email and ERP integration like SAP.

 

 

 

 

if i implement this solution, can i be satisfied with the onmicrosoft.com domain?
or should I have a domain?

 

If prefer to use a domain, one of the core problems with solely using AAD is that it isn't multi-region capable (well at least it wasn't for some time, i haven't checked recently to see if that is now resolved) 


With the VPN gateway service there is a limit of 128 users?

The point to site solution is ok on a small site, most of the documentation states to use self signed certs, you can also use your on prem pki if you want. 


The company in question has about 200 users, do I have to subscribe to the express route?.

 

You do not need express route it is simply the high performance tier of the site to site gateway. For a site that small you may get away with a standard site to site link. 


Is the point-to-site VPN type possible with a full cloud infrastrutuce?

 

yes you can use a point to site solution. 

 

You mentioned building AD / ADFS in the cloud. If you are going down this route i would recommend a hub n spoke topology. 

 

You essentially put all your AD / ADFS content into the hub network. the you use vnet peering to link your resource systems. The benefits you get out of this implementation is that it is highly scalable. As you organisation grows you can grow the solution exponentially as well 

 

the other benefit here is that your spoke networks will inherit the security of the hub network. 

 

typically you would lock down your hub network so people cannot deploy content into it to ensure it stays secure. The spokes are less restrictive although you would want to prevent public ip's etc in the spokes and force them to route through the hub network. 

 

it is quite a complex setup but highly secure and highly scalable.