You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/application-gateway/application-gateway-tls-version-retirement.md
+7-2Lines changed: 7 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ services: application gateway
5
5
author: jaesoni
6
6
ms.service: azure-application-gateway
7
7
ms.topic: concept-article
8
-
ms.date: 03/04/2025
8
+
ms.date: 04/08/2025
9
9
ms.author: greglin
10
10
---
11
11
@@ -69,7 +69,12 @@ Application Gateway V1 SKU only supports the older "Custom" policy. Beyond Augus
69
69
70
70
## Backend TLS connections
71
71
72
-
You don't need to configure anything on your Application Gateway for the backend connection's TLS version as the selection of TLS policy has no control over the backend TLS connections. After retirement, the connections to backend servers will always be with preferred TLS v1.3 and up to TLS v1.2. You must ensure that your servers in the backend pools are compatible with these updated protocol versions. This compatibility avoids any disruptions when establishing a TLS/HTTPS connection with those backend servers.
72
+
You don't need to configure anything on your Application Gateway for the backend connection's TLS version as the selection of TLS policy has no control over the backend TLS connections. After the retirement,
73
+
74
+
* For V2 SKUs: the connections to backend servers will always be with preferred TLS v1.3 and minimum up to TLS v1.2
75
+
* For V1 SKUs: the connections to backend servers will always be with TLS v1.2
76
+
77
+
You must ensure that your servers in the backend pools are compatible with these updated protocol versions. This compatibility avoids any disruptions when establishing a TLS/HTTPS connection with those backend servers.
# Azure VMware Solution private cloud and cluster concepts
11
11
12
-
Azure VMware Solution provides VMware-based private clouds in Azure. The private cloud hardware and software deployments are fully integrated and automated in Azure. Deploy and manage the private cloud through the Azure portal, CLI, or PowerShell.
12
+
Azure VMware Solution provides VMware-based private clouds in Azure. The private cloud hardware and software deployments are fully integrated and automated in Azure. Deploy and manage the private cloud through the Azure portal, the Azure CLI, or PowerShell.
13
13
14
14
A private cloud includes clusters with:
15
15
16
-
- Dedicated bare-metal server hosts provisioned with VMware ESXi hypervisor
17
-
- VMware vCenter Server for managing ESXi and vSAN
18
-
- VMware NSX software-defined networking for vSphere workload VMs
19
-
- VMware vSAN datastore for vSphere workload VMs
20
-
- VMware HCX for workload mobility
21
-
- Resources in the Azure underlay (required for connectivity and to operate the private cloud)
16
+
- Dedicated bare-metal server hosts provisioned with VMware vSphere Hypervisor (ESXi).
17
+
- VMware vCenter Server for managing ESXi and vSAN.
- Resources in the Azure underlay (required for connectivity and to operate the private cloud).
22
22
23
23
Private clouds are installed and managed within an Azure subscription. The number of private clouds within a subscription is scalable. Initially, there's a limit of one private cloud per subscription. There's a logical relationship between Azure subscriptions, Azure VMware Solution private clouds, vSAN clusters, and hosts.
24
24
25
-
The following diagram describes the architectural components of the Azure VMware Solution.
25
+
The following diagram describes the architectural components of Azure VMware Solution.
26
26
27
-
:::image type="content" source="media/concepts/hosts-clusters-private-clouds-final.png" alt-text="Diagram illustrating a single Azure subscription containing two private clouds for development and production environments." border="false" lightbox="media/concepts/hosts-clusters-private-clouds-final.png":::
27
+
:::image type="content" source="media/concepts/hosts-clusters-private-clouds-final.png" alt-text="Diagram that shows a single Azure subscription that contains two private clouds for development and production environments." border="false" lightbox="media/concepts/hosts-clusters-private-clouds-final.png":::
28
28
29
29
Each Azure VMware Solution architectural component has the following function:
30
30
31
-
- Azure Subscription: Provides controlled access, budget, and quota management for the Azure VMware Solution.
32
-
- Azure Region: Groups data centers into Availability Zones (AZs) and then groups AZs into regions.
33
-
- Azure Resource Group: Places Azure services and resources into logical groups.
34
-
- Azure VMware Solution Private Cloud: Offers compute, networking, and storage resources using VMware software, including vCenter Server, NSX software-defined networking, vSAN software-defined storage, and Azure bare-metal ESXi hosts. Azure NetApp Files, Azure Elastic SAN, and Pure Cloud Block Store are also supported.
35
-
- Azure VMware Solution Resource Cluster: Provides compute, networking, and storage resources for customer workloads by scaling out the Azure VMware Solution private cloud using VMware software, including vSAN software-defined storage and Azure bare-metal ESXi hosts. Azure NetApp Files, Azure Elastic SAN, and Pure Cloud Block Store are also supported.
36
-
- VMware HCX: Delivers mobility, migration, and network extension services.
37
-
- VMware Site Recovery: Automates disaster recovery and storage replication services with VMware vSphere Replication. Third-party disaster recovery solutions Zerto Disaster Recovery and JetStream Software Disaster Recovery are also supported.
38
-
- Dedicated Microsoft Enterprise Edge (D-MSEE): Router that connects Azure cloud and the Azure VMware Solution private cloud instance.
- Azure Route Server: Exchanges dynamic route information with Azure networks.
41
-
- Azure Virtual Network Gateway: Connects Azure services and resources to other private networks using IPSec VPN, ExpressRoute, and VNet to VNet.
42
-
- Azure ExpressRoute: Provides high-speed private connections between Azure data centers and on-premises or colocation infrastructure.
43
-
- Azure Virtual WAN (vWAN): Combines networking, security, and routing functions into a single unified Wide Area Network (WAN).
31
+
-**Azure subscription**: Provides controlled access, budget, and quota management for Azure VMware Solution.
32
+
-**Azure region**: Groups datacenters into availability zones and then groups availability zones into regions.
33
+
-**Azure resource group**: Places Azure services and resources into logical groups.
34
+
-**Azure VMware Solution private cloud**: Offers compute, networking, and storage resources by using VMware software, including vCenter Server, NSX software-defined networking, vSAN software-defined storage, and Azure bare-metal ESXi hosts. Azure NetApp Files, Azure Elastic SAN, and Pure Cloud Block Store are also supported.
35
+
-**Azure VMware Solution resource cluster**: Provides compute, networking, and storage resources for customer workloads by scaling out the Azure VMware Solution private cloud by using VMware software, including vSAN software-defined storage and Azure bare-metal ESXi hosts. Azure NetApp Files, Elastic SAN, and Pure Cloud Block Store are also supported.
36
+
-**VMware HCX**: Delivers mobility, migration, and network extension services.
37
+
-**VMware Site Recovery**: Automates disaster recovery and storage replication services with VMware vSphere Replication. Non-Microsoft disaster recovery solutions Zerto disaster recovery and JetStream Software disaster recovery are also supported.
38
+
-**Dedicated Microsoft Enterprise Edge**: Router that connects Azure Cloud Services and the Azure VMware Solution private cloud instance.
39
+
-**Azure Virtual Network**: Connects Azure services and resources together.
40
+
-**Azure Route Server**: Exchanges dynamic route information with Azure networks.
41
+
-**Azure Virtual Network gateway**: Connects Azure services and resources to other private networks by using IPSec virtual private network, Azure ExpressRoute, and virtual network to virtual network.
42
+
-**Azure ExpressRoute**: Provides high-speed private connections between Azure datacenters and on-premises or colocation infrastructure.
43
+
-**Azure Virtual WAN**: Combines networking, security, and routing functions into a single unified wide area network (WAN).
## Azure Region Availability Zone (AZ) to SKU mapping table
49
+
## Azure region availability zone to host type mapping table
50
50
51
-
When planning your Azure VMware Solution design, use the following table to understand what SKUs are available in each physical Availability Zone of an [Azure region](https://azure.microsoft.com/explore/global-infrastructure/geographies/#geographies).
51
+
When you plan your Azure VMware Solution design, use the following table to understand what host types are available in each physical availability zone of an [Azure region](https://azure.microsoft.com/explore/global-infrastructure/geographies/#geographies).
52
52
53
53
>[!IMPORTANT]
54
-
> This mapping is important for placing your private clouds in close proximity to your Azure native workloads, including integrated services such as Azure NetApp Files and Pure Cloud Block Store (CBS).
54
+
> This mapping is important for placing your private clouds in close proximity to your Azure native workloads, including integrated services such as Azure NetApp Files and Pure Cloud Block Store.
55
55
56
-
The Multi-AZ capability for Azure VMware Solution Stretched Clusters is also tagged in the following table. Customer quota for Azure VMware Solution is assigned by Azure region, and you aren't able to specify the Availability Zone during private cloud provisioning. An auto selection algorithm is used to balance deployments across the Azure region. If you have a particular Availability Zone you want to deploy to, open a [Service Request](https://rc.portal.azure.com/#create/Microsoft.Support) with Microsoft requesting a "special placement policy" for your subscription, Azure region, Availability Zone, and SKU type. This policy remains in place until you request it be removed or changed.
56
+
The capability for Azure VMware Solution stretched clusters to deploy resources in multiple availability zones (Multi-AZ) is also tagged in the following table. The customer quota for Azure VMware Solution is assigned by Azure region. You can't specify the availability zone during private cloud provisioning. An autoselection algorithm is used to balance deployments across the Azure region.
57
57
58
-
**SKUs** marked in **bold** are of limited availability due to customer consumption and quota may not be available upon request. The AV64 SKU should be used instead when AV36, AV36P, or AV52 SKUs are limited.
58
+
If you have a particular availability zone to which you want to deploy, open a [Service Request](https://rc.portal.azure.com/#create/Microsoft.Support) with Microsoft. Request a "special placement policy" for your subscription, Azure region, availability zone, and host type. This policy remains in place until you request it to be removed or changed.
59
59
60
-
AV64 SKUs are available per Availability Zone, the table below lists the Azure regions that support this SKU. For RAID-6 FTT2 and RAID-1 FTT3 storage policies, six and seven Fault Domains (FDs) are needed respectively, the FD count for each Azure region is listed in the "AV64 FDs Supported" column.
60
+
Host types marked in bold type are of limited availability because of customer consumption and might not be available upon request. Use the AV64 host type when AV36, AV36P, or AV52 host types are limited.
61
61
62
-
| Azure region | Availability Zone | SKU | Multi-AZ SDDC | AV64 FDs Supported |
62
+
AV64 host types are available per availability zone. The following table lists the Azure regions that support this host type. For RAID-6 FTT2 and RAID-1 FTT3 storage policies, six and seven fault domains are needed, respectively. The fault domain count for each Azure region is listed in the column labeled **AV64 fault domains supported**.
63
+
64
+
| Azure region | Availability zone | Host type | Multi-AZ SDDC | AV64 fault domains supported |
63
65
| :--- | :---: | :---: | :---: | :---: |
64
66
| Australia East | AZ01 | AV36P, AV64 | Yes | 7 |
65
67
| Australia East | AZ02 | AV36, AV64| Yes | 7 |
@@ -122,27 +124,27 @@ AV64 SKUs are available per Availability Zone, the table below lists the Azure r
122
124
123
125
## VMware software versions
124
126
125
-
Microsoft is a member of the VMware Metal-as-a-Service (MaaS) program and uses the [VMware Cloud Provider Stack (VCPS)](https://docs.vmware.com/en/VMware-Cloud-Provider-Stack/1.1/com.vmware.vcps.gsg.doc/GUID-5D686FB2-9886-44D3-845B-FDEF650C7575.html) for Azure VMware Solution upgrade planning.
127
+
Microsoft is a member of the VMware metal as a service (MaaS) program and uses the [VMware Cloud Provider Stack](https://docs.vmware.com/en/VMware-Cloud-Provider-Stack/1.1/com.vmware.vcps.gsg.doc/GUID-5D686FB2-9886-44D3-845B-FDEF650C7575.html) for Azure VMware Solution upgrade planning.
Azure VMware Solution private cloud vCenter Server and HCX Manager (if enabled) configurations are on a daily backup schedule and NSX configuration has an hourly backup schedule. The backups are retained for a minimum of three days. Open a [support request](https://rc.portal.azure.com/#create/Microsoft.Support) in the Azure portal to request restoration.
133
+
Azure VMware Solution private cloud vCenter Server and HCX Manager (if enabled) configurations are on a daily backup schedule. The NSX configuration has an hourly backup schedule. The backups are retained for a minimum of three days. Open a [support request](https://rc.portal.azure.com/#create/Microsoft.Support) in the Azure portal to request restoration.
132
134
133
135
> [!NOTE]
134
136
> Restorations are intended for catastrophic situations only.
135
137
136
-
Azure VMware Solution continuously monitors the health of both the physical underlay and the VMware Solution components. When Azure VMware Solution detects a failure, it takes action to repair the failed components.
138
+
Azure VMware Solution continuously monitors the health of both the physical underlay and the Azure VMware Solution components. When Azure VMware Solution detects a failure, it takes action to repair the failed components.
137
139
138
-
## Next steps
140
+
## Related content
139
141
140
-
Now that you've covered Azure VMware Solution private cloud concepts, you might want to learn about:
142
+
Now that you learned about Azure VMware Solution private cloud concepts, you might want to read:
141
143
142
144
-[Azure VMware Solution networking and interconnectivity concepts](architecture-networking.md)
143
145
-[Azure VMware Solution private cloud maintenance best practices](azure-vmware-solution-host-remediation.md)
0 commit comments