Skip to content

Commit bfa7538

Browse files
authored
Merge pull request #232495 from asudbring/vnet-old-review-1
Review of Azure Virtual Network TAP overview. Updated image link and acrolinx.
2 parents 41893a5 + c314214 commit bfa7538

File tree

1 file changed

+25
-12
lines changed

1 file changed

+25
-12
lines changed

articles/virtual-network/virtual-network-tap-overview.md

Lines changed: 25 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,28 +1,29 @@
11
---
22
title: Azure virtual network TAP overview
3-
description: Learn about virtual network TAP. Virtual network TAP provides you a deep copy of virtual machine network traffic that can be streamed to a packet collector.
4-
services: virtual-network
3+
description: Learn about virtual network TAP. Virtual network TAP provides you with a copy of virtual machine network traffic that can be streamed to a packet collector.
54
author: asudbring
6-
manager: ganesr
7-
tags: azure-resource-manager
85
ms.service: virtual-network
96
ms.topic: conceptual
10-
ms.workload: infrastructure-services
11-
ms.date: 04/14/2019
7+
ms.date: 03/28/2023
128
ms.author: allensu
139
---
1410

1511
# Virtual network TAP
12+
1613
> [!IMPORTANT]
1714
> Virtual network TAP Preview is currently on hold in all Azure regions. You can email us at <[email protected]> with your subscription ID and we will notify you with future updates about the preview. In the interim, you can use agent based or NVA solutions that provide TAP/Network Visibility functionality through our [Packet Broker partner solutions](#virtual-network-tap-partner-solutions) available in [Azure Marketplace Offerings](https://azuremarketplace.microsoft.com/marketplace/apps/category/networking?page=1&subcategories=appliances%3Ball&search=Network%20Traffic&filters=partners).
1815
1916
Azure virtual network TAP (Terminal Access Point) allows you to continuously stream your virtual machine network traffic to a network packet collector or analytics tool. The collector or analytics tool is provided by a [network virtual appliance](https://azure.microsoft.com/solutions/network-appliances/) partner. For a list of partner solutions that are validated to work with virtual network TAP, see [partner solutions](#virtual-network-tap-partner-solutions).
20-
The following picture shows how virtual network TAP works. You can add a TAP configuration on a [network interface](virtual-network-network-interface.md) that is attached to a virtual machine deployed in your virtual network. The destination is a virtual network IP address in the same virtual network as the monitored network interface or a [peered virtual](virtual-network-peering-overview.md) network. The collector solution for virtual network TAP can be deployed behind an Azure Internal Load balancer for high availability.
21-
![How virtual network TAP works](./media/virtual-network-tap/architecture.png)
17+
18+
The following diagram shows how virtual network TAP works. You can add a TAP configuration on a [network interface](virtual-network-network-interface.md) that is attached to a virtual machine deployed in your virtual network. The destination is a virtual network IP address in the same virtual network as the monitored network interface or a [peered virtual](virtual-network-peering-overview.md) network. The collector solution for virtual network TAP can be deployed behind an Azure Internal Load balancer for high availability.
19+
20+
:::image type="content" source="./media/virtual-network-tap/architecture.png" alt-text="Diagram of how virtual network TAP works.":::
2221

2322
## Prerequisites
2423

25-
Before you create a virtual network TAP, you must have received a confirmation mail that you're enrolled in the preview, and have one or more virtual machines created using [Azure Resource Manager](../azure-resource-manager/management/overview.md?toc=%2fazure%2fvirtual-network%2ftoc.json) deployment model and a partner solution for aggregating the TAP traffic in the same Azure region. If you don't have a partner solution in your virtual network, see [partner solutions](#virtual-network-tap-partner-solutions) to deploy one. You can use the same virtual network TAP resource to aggregate traffic from multiple network interfaces in the same or different subscriptions. If the monitored network interfaces are in different subscriptions, the subscriptions must be associated to the same Azure Active Directory tenant. Additionally, the monitored network interfaces and the destination endpoint for aggregating the TAP traffic can be in peered virtual networks in the same region. If you're using this deployment model ensure that the [virtual network peering](virtual-network-peering-overview.md) is enabled before you configure virtual network TAP.
24+
Before you can create a virtual network TAP, ensure you've received the confirmation email that you're enrolled in the preview. You must have one or more virtual machines created with [Azure Resource Manager](../azure-resource-manager/management/overview.md?toc=%2fazure%2fvirtual-network%2ftoc.json) and a partner solution for aggregating the TAP traffic in the same Azure region. If you don't have a partner solution in your virtual network, see [partner solutions](#virtual-network-tap-partner-solutions) to deploy one.
25+
26+
You can use the same virtual network TAP resource to aggregate traffic from multiple network interfaces in the same or different subscriptions. If the monitored network interfaces are in different subscriptions, the subscriptions must be associated to the same Azure Active Directory tenant. Additionally, the monitored network interfaces and the destination endpoint for aggregating the TAP traffic can be in peered virtual networks in the same region. If you're using this deployment model, ensure that the [virtual network peering](virtual-network-peering-overview.md) is enabled before you configure virtual network TAP.
2627

2728
## Permissions
2829

@@ -31,34 +32,46 @@ The accounts you use to apply TAP configuration on network interfaces must be as
3132
| Action | Name |
3233
|---|---|
3334
| Microsoft.Network/virtualNetworkTaps/* | Required to create, update, read and delete a virtual network TAP resource |
34-
| Microsoft.Network/networkInterfaces/read | Required to read the network interface resource on which the TAP will be configured |
35+
| Microsoft.Network/networkInterfaces/read | Required to read the network interface resource on which the TAP is configured |
3536
| Microsoft.Network/tapConfigurations/* | Required to create, update, read and delete the TAP configuration on a network interface |
3637

37-
3838
## Virtual network TAP partner solutions
3939

4040
### Network packet brokers
4141

4242
- [GigaVUE Cloud Suite for Azure](https://www.gigamon.com/solutions/cloud/public-cloud/gigavue-cloud-suite-azure.html)
43+
4344
- [Ixia CloudLens](https://www.ixiacom.com/cloudlens/cloudlens-azure)
45+
4446
- [Nubeva Prisms](https://www.nubeva.com/azurevtap)
47+
4548
- [Big Switch Big Monitoring Fabric](https://www.arista.com/en/bigswitch)
4649

4750
### Security analytics, network/application performance management
4851

4952
- [Awake Security](https://www.arista.com/partner/technology-partners)
53+
5054
- [Cisco Stealthwatch Cloud](https://blogs.cisco.com/security/cisco-stealthwatch-cloud-and-microsoft-azure-reliable-cloud-infrastructure-meets-comprehensive-cloud-security)
55+
5156
- [Darktrace](https://www.darktrace.com)
57+
5258
- [ExtraHop Reveal(x)](https://www.extrahop.com/partners/tech-partners/microsoft/)
59+
5360
- [Fidelis Cybersecurity](https://www.fidelissecurity.com/technology-partners/microsoft-azure )
61+
5462
- [Flowmon](https://www.flowmon.com/en/blog/azure-vtap)
63+
5564
- [NetFort LANGuardian](https://www.netfort.com/languardian/solutions/visibility-in-azure-network-tap/)
65+
5666
- [Netscout vSTREAM]( https://www.netscout.com/marketplace-azure)
67+
5768
- [Noname Security](https://nonamesecurity.com/)
69+
5870
- [Riverbed SteelCentral AppResponse]( https://www.riverbed.com/products/steelcentral/steelcentral-appresponse-11.html)
71+
5972
- [RSA NetWitness® Platform](https://community.netwitness.com/t5/netwitness-platform-integrations/ixia-cloudlens-rsa-netwitness-packets-implementation-guide/ta-p/564238)
60-
- [Vectra Cognito](https://www.vectra.ai/products/cognito-platform)
6173

74+
- [Vectra Cognito](https://www.vectra.ai/products/cognito-platform)
6275

6376
## Next steps
6477

0 commit comments

Comments
 (0)