Azure 檔案同步 將您的本地伺服器連接到 Azure 檔案儲存體,實現多站點同步與雲端分層功能。 因此,本地伺服器必須連接網際網路。 IT 管理員需要決定伺服器進入 Azure 雲端服務的最佳路徑。
本文將深入說明成功且安全地將您的伺服器連接到 Azure 檔案同步 的具體需求與選項。
在閱讀這份操作指南之前,先先了解 Azure 檔案同步 網路的相關事項。
Azure 檔案同步 網路概觀
Azure 檔案同步 作為 Windows Server、Azure 檔案分享以及其他幾個 Azure 服務之間的協調服務,用來同步你同步群組中描述的資料。 為了讓 Azure 檔案同步 正常運作,你需要設定你的伺服器與以下 Azure 服務進行通訊:
- Azure 儲存體
- Azure 檔案同步
- Azure Resource Manager
- 驗證服務
Note
Windows Server 上的 Azure 檔案同步 代理程式會發起所有雲端服務的請求,因此只需從防火牆角度考慮出站流量。 沒有任何 Azure 服務會主動連線到 Azure 檔案同步 agent。
Azure 檔案同步 所需端口
Azure 檔案同步 只透過 HTTPS 傳輸檔案資料和元資料,且需要 443 埠口在外站開啟。 如此一來,所有流量都會加密。
與 Azure 的網路及特殊連結
Azure 檔案同步 代理對於像 ExpressRoute 等特殊通道到 Azure 沒有要求。
Azure 檔案同步 會透過任何能讓 Azure 存取的管道運作。 它會自動適應網路特性,如頻寬與延遲,並提供管理員控制以進行微調。
Azure 檔案同步 Proxy 設定
Azure 檔案同步支援應用程式特定和整部電腦的 Proxy 設定。
特定應用程式的代理設定
應用程式專屬的代理設定允許針對 Azure 檔案同步 流量設定代理。 應用程式專屬代理設定支援於代理程式版本 4.0.1.0 或更新版本,且可在代理安裝時或使用 Set-StorageSyncProxyConfiguration PowerShell 指令程式來設定。 用 Get-StorageSyncProxyConfiguration cmdlet 回傳目前已設定的代理設定。 空白結果表示沒有設定代理設定。 要移除現有的代理設定,請使用 Remove-StorageSyncProxyConfiguration cmdlet。
以下 PowerShell 命令可用來設定應用程式特定的 Proxy 設定:
Import-Module "C:\Program Files\Azure\StorageSyncAgent\StorageSync.Management.ServerCmdlets.dll"
Set-StorageSyncProxyConfiguration -Address <url> -Port <port number> -ProxyCredential <credentials>
例如,如果您的 Proxy 伺服器需要以使用者名稱和密碼進行驗證,請執行下列 PowerShell 命令:
# IP address or name of the proxy server.
$Address="http://127.0.0.1"
# The port to use for the connection to the proxy.
$Port=8080
# The user name for a proxy.
$UserName="user_name"
# Please type or paste a string with a password for the proxy.
$SecurePassword = Read-Host -AsSecureString
$Creds = New-Object System.Management.Automation.PSCredential ($UserName, $SecurePassword)
# Please verify that you have entered the password correctly.
Write-Host $Creds.GetNetworkCredential().Password
Import-Module "C:\Program Files\Azure\StorageSyncAgent\StorageSync.Management.ServerCmdlets.dll"
Set-StorageSyncProxyConfiguration -Address $Address -Port $Port -ProxyCredential $Creds
整部電腦的 Proxy 設定
全機代理設定對 Azure 檔案同步 代理程式是透明的,因為整個伺服器流量都經過代理伺服器。
要設定全機代理設定,請依照以下步驟操作:
為 .NET 應用程式設定 Proxy 設定
編輯這兩個檔案:
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\machine.config
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config在 machine.config 檔案中(system.serviceModel< 區塊下方>)新增 <system.net> 區塊。 將 127.0.01:8888 變更為 Proxy 伺服器的 IP 位址和連接埠。
<system.net> <defaultProxy enabled="true" useDefaultCredentials="true"> <proxy autoDetect="false" bypassonlocal="false" proxyaddress="http://127.0.0.1:8888" usesystemdefault="false" /> </defaultProxy> </system.net>
設定 WinHTTP 代理設定
Note
要設定 Windows Server 使用代理伺服器,你可以使用多種方法,包括 WPAD、PAC 檔案、netsh 等。 本文中的步驟說明如何使用
netsh來設定 Proxy。 不過,你可以使用Windows文件中「配置代理伺服器設定」中列出的任何方法。請從提升的命令提示字元或 PowerShell 執行以下指令,以查看現有的代理設定:
netsh winhttp show proxy請從升格命令提示字元或 PowerShell 執行以下指令來設定代理設定(將 127.0.01:8888 改為代理伺服器的 IP 位址和埠口):
netsh winhttp set proxy 127.0.0.1:8888
請透過提升命令提示字元或 PowerShell 執行以下指令,重新啟動儲存同步代理服務:
net stop filesyncsvcNote
儲存同步代理程式(filesyncsvc)服務在停止後會自動啟動。
Azure 檔案同步 防火牆設定
如前一節所述,你需要開啟443號出口埠。 根據你資料中心、分支或區域的政策,你可能需要進一步限制該埠口的流量僅限特定網域。
下表描述了通訊所需的領域:
| 服務 | 公有雲端點 | Azure 政府端點 |
|---|---|---|
| Azure Resource Manager | https://management.azure.com |
https://management.usgovcloudapi.net |
| Microsoft Entra ID(驗證) | https://login.windows.nethttps://login.microsoftonline.comhttps://aadcdn.msftauth.net |
https://login.microsoftonline.us |
| Microsoft Entra ID (service principal) | https://graph.microsoft.com/ |
https://graph.microsoft.com/ |
| Microsoft Entra ID (註冊介面) | https://secure.aadcdn.microsoftonline-p.com |
https://secure.aadcdn.microsoftonline-p.com(與公共雲端點網址相同) |
| Azure 儲存體 | *.core.windows.net | *.core.usgovcloudapi.net |
| Azure 檔案同步 | *.one.microsoft.com *.afs.azure.net |
*.afs.azure.us |
| Microsoft PKI | https://www.microsoft.com/pki/mscorp/cpshttp://crl.microsoft.com/pki/mscorp/crl/http://mscrl.microsoft.com/pki/mscorp/crl/http://ocsp.msocsp.comhttp://ocsp.digicert.com/http://crl3.digicert.com/ |
https://www.microsoft.com/pki/mscorp/cpshttp://crl.microsoft.com/pki/mscorp/crl/http://mscrl.microsoft.com/pki/mscorp/crl/http://ocsp.msocsp.comhttp://ocsp.digicert.com/http://crl3.digicert.com/ |
| Microsoft 更新 | *.update.microsoft.com *.download.windowsupdate.com *.ctldl.windowsupdate.com *.dl.delivery.mp.microsoft.com *.emdl.ws.microsoft.com |
*.update.microsoft.com *.download.windowsupdate.com *.ctldl.windowsupdate.com *.dl.delivery.mp.microsoft.com *.emdl.ws.microsoft.com |
下表說明每個端點的用途:
| 服務 | Description |
|---|---|
| Azure Resource Manager | 任何使用者呼叫(例如 PowerShell)都會傳送到或經過這個 URL,包括最初的伺服器註冊呼叫。 |
| Microsoft Entra ID(驗證) | Azure Resource Manager 呼叫必須由已驗證的使用者進行。 此網址負責使用者認證。 |
| Microsoft Entra ID (service principal) | 在部署 Azure 檔案同步 時,會在訂閱的 Microsoft Entra ID 中建立服務主體。 此原則將一組最小的權利授權給 Azure 檔案同步 服務。 執行初始設定的使用者必須擁有訂閱擁有者權限。 |
| Microsoft Entra ID (註冊介面) | 會由 Azure 檔案同步伺服器註冊 UI 用來登入系統管理員的 Active Directory 驗證程式庫存取。 |
| Azure 儲存體 | 伺服器透過直接與儲存帳號中的 Azure 檔案分享者通訊,使用 SAS 金鑰,僅允許特定檔案分享存取,從而更有效率地執行資料傳輸。 |
| Azure 檔案同步 | 初始伺服器註冊後,伺服器會收到該區域 Azure 檔案同步 服務實例的區域 URL,以便直接且高效地同步通訊。 |
| Microsoft PKI | 下載與 Azure 檔案同步 服務及 Azure 檔案分享通訊所需的中間憑證。 OCSP URL 會檢查憑證狀態。 |
| Microsoft 更新 | 下載 Azure 檔案同步 代理程式更新。 |
Important
當允許流量到 *.afs.azure.net 時,流量只能傳送到同步服務。 目前沒有其他 Microsoft 服務 使用此網域。 當允許流量到 *.one.microsoft.com 時,伺服器可進行不僅限於同步服務的流量。 在子網域下還有更多 Microsoft 服務 可供選擇。
如果 *.afs.azure.net 或 *.one.microsoft.com 太廣泛,您可以僅允許對 Azure 檔案同步服務的明確區域執行個體進行通訊,藉以限制伺服器的通訊。 要選擇哪個執行個體,取決於您將伺服器部署及註冊到哪個儲存體同步服務區域。 在下表中,該區域稱為「主要端點 URL」。
為了業務持續性與災難復原(BCDR)的考量,你可以在設定為地理冗餘儲存(GRS)的儲存帳號中建立 Azure 檔案共享。 如果你選擇這個選項,Azure 檔案共享會在區域持續故障時切換到配對區域。 Azure 檔案同步會使用相同的區域配對作為儲存體。 所以如果你使用 GRS 儲存帳號,你需要啟用額外的 URL,讓伺服器能與配對區域通訊以進行 Azure 檔案同步。下表稱此為「配對區域」。 此外,您也需要啟用流量管理員的個人檔案 URL。 此 URL 確保網路流量在容錯移轉時能平順地路由至配對的區域,並在表格中稱為「發現 URL」。
公用雲端
- 如果你使用的儲存帳號設定為本地冗餘儲存(LRS)或區域冗餘儲存(ZRS),你只需要啟用「主要端點 URL」下列出的網址。
- 如果您使用設定為 GRS 的儲存體帳戶,請啟用三個 URL:您所在區域的主要端點 URL、配對區域的主要端點 URL,以及您所在區域的探索 URL。
範例: 您在 "West US" 中部署儲存同步服務,並向其註冊您的伺服器。 此情況下,允許伺服器通訊的網址如下:
- https://westus01.afs.azure.net (主要終點:美國西部)
- https://eastus01.afs.azure.net(配對的容錯移轉區域:美國東部)
- https://tm-westus01.afs.azure.net (主要區域的發現網址)
以下表格列出 Azure 公有雲區域中 Azure 檔案同步 的端點。
| 區域 | 主要端點網址 | 配對的區域 | 發現網址 |
|---|---|---|---|
| Australia East | https://australiaeast01.afs.azure.net https://kailani-aue.one.microsoft.com |
Australia Southeast | https://tm-australiaeast01.afs.azure.net https://tm-kailani-aue.one.microsoft.com |
| Australia Southeast | https://australiasoutheast01.afs.azure.net https://kailani-aus.one.microsoft.com |
Australia East | https://tm-australiasoutheast01.afs.azure.net https://tm-kailani-aus.one.microsoft.com |
| 巴西南部 | https://brazilsouth01.afs.azure.net | 美國中南部 | https://tm-brazilsouth01.afs.azure.net |
| 加拿大中部 | https://canadacentral01.afs.azure.net https://kailani-cac.one.microsoft.com |
加拿大東部 | https://tm-canadacentral01.afs.azure.net https://tm-kailani-cac.one.microsoft.com |
| 加拿大東部 | https://canadaeast01.afs.azure.net https://kailani-cae.one.microsoft.com |
加拿大中部 | https://tm-canadaeast01.afs.azure.net https://tm-kailani.cae.one.microsoft.com |
| 印度中部 | https://centralindia01.afs.azure.net https://kailani-cin.one.microsoft.com |
印度南部 | https://tm-centralindia01.afs.azure.net https://tm-kailani-cin.one.microsoft.com |
| Central US | https://centralus01.afs.azure.net https://kailani-cus.one.microsoft.com |
美國東部 2 | https://tm-centralus01.afs.azure.net https://tm-kailani-cus.one.microsoft.com |
| 東亞 | https://eastasia01.afs.azure.net https://kailani11.one.microsoft.com |
東南亞 | https://tm-eastasia01.afs.azure.net https://tm-kailani11.one.microsoft.com |
| 美國東部 | https://eastus01.afs.azure.net https://kailani1.one.microsoft.com |
美國西部 | https://tm-eastus01.afs.azure.net https://tm-kailani1.one.microsoft.com |
| 美國東部 2 | https://eastus201.afs.azure.net https://kailani-ess.one.microsoft.com |
Central US | https://tm-eastus201.afs.azure.net https://tm-kailani-ess.one.microsoft.com |
| 德國北部 | https://germanynorth01.afs.azure.net | 德國中西部 | https://tm-germanywestcentral01.afs.azure.net |
| 德國中西部 | https://germanywestcentral01.afs.azure.net | 德國北部 | https://tm-germanynorth01.afs.azure.net |
| 日本東部 | https://japaneast01.afs.azure.net | 日本西部 | https://tm-japaneast01.afs.azure.net |
| 日本西部 | https://japanwest01.afs.azure.net | 日本東部 | https://tm-japanwest01.afs.azure.net |
| 南韓中部 | https://koreacentral01.afs.azure.net/ | 南韓南部 | https://tm-koreacentral01.afs.azure.net/ |
| 南韓南部 | https://koreasouth01.afs.azure.net/ | 南韓中部 | https://tm-koreasouth01.afs.azure.net/ |
| 美國中北部 | https://northcentralus01.afs.azure.net | 美國中南部 | https://tm-northcentralus01.afs.azure.net |
| 北歐 | https://northeurope01.afs.azure.net https://kailani7.one.microsoft.com |
西歐 | https://tm-northeurope01.afs.azure.net https://tm-kailani7.one.microsoft.com |
| 美國中南部 | https://southcentralus01.afs.azure.net | 美國中北部 | https://tm-southcentralus01.afs.azure.net |
| 印度南部 | https://southindia01.afs.azure.net https://kailani-sin.one.microsoft.com |
印度中部 | https://tm-southindia01.afs.azure.net https://tm-kailani-sin.one.microsoft.com |
| 東南亞 | https://southeastasia01.afs.azure.net https://kailani10.one.microsoft.com |
東亞 | https://tm-southeastasia01.afs.azure.net https://tm-kailani10.one.microsoft.com |
| 瑞士北部 | https://switzerlandnorth01.afs.azure.net https://tm-switzerlandnorth01.afs.azure.net |
瑞士西部 | https://switzerlandwest01.afs.azure.net https://tm-switzerlandwest01.afs.azure.net |
| 瑞士西部 | https://switzerlandwest01.afs.azure.net https://tm-switzerlandwest01.afs.azure.net |
瑞士北部 | https://switzerlandnorth01.afs.azure.net https://tm-switzerlandnorth01.afs.azure.net |
| 阿拉伯聯合大公國中部 | https://uaecentral01.afs.azure.net | 阿拉伯聯合大公國北部 | https://tm-uaecentral01.afs.azure.net |
| 阿拉伯聯合大公國北部 | https://uaenorth01.afs.azure.net | 阿拉伯聯合大公國中部 | https://tm-uaenorth01.afs.azure.net |
| 英國南部 | https://uksouth01.afs.azure.net https://kailani-uks.one.microsoft.com |
英國西部 | https://tm-uksouth01.afs.azure.net https://tm-kailani-uks.one.microsoft.com |
| 英國西部 | https://ukwest01.afs.azure.net https://kailani-ukw.one.microsoft.com |
英國南部 | https://tm-ukwest01.afs.azure.net https://tm-kailani-ukw.one.microsoft.com |
| 美國中西部 | https://westcentralus01.afs.azure.net | 美國西部 2 | https://tm-westcentralus01.afs.azure.net |
| 西歐 | https://westeurope01.afs.azure.net https://kailani6.one.microsoft.com |
北歐 | https://tm-westeurope01.afs.azure.net https://tm-kailani6.one.microsoft.com |
| 美國西部 | https://westus01.afs.azure.net https://kailani.one.microsoft.com |
美國東部 | https://tm-westus01.afs.azure.net https://tm-kailani1.one.microsoft.com |
| 美國西部 2 | https://westus201.afs.azure.net | 美國中西部 | https://tm-westus201.afs.azure.net |
Azure Government
以下表格列出 Azure Government 區域中 Azure 檔案同步 的端點。
| 區域 | 主要端點網址 | 配對的區域 | 發現網址 |
|---|---|---|---|
| 美國亞利桑那州政府 | https://usgovarizona01.afs.azure.us | US Gov 德克薩斯州 | https://tm-usgovarizona01.afs.azure.us |
| US Gov 德克薩斯州 | https://usgovtexas01.afs.azure.us | 美國亞利桑那州政府 | https://tm-usgovtexas01.afs.azure.us |
Microsoft Azure 由 21Vianet 運營
下表列出由21Vianet區域在Microsoft Azure中運作的Azure 檔案同步端點。
| 區域 | 主要端點網址 | 配對的區域 | 發現網址 |
|---|---|---|---|
| 中國東部 2 | https://chinaeast201.afs.azure.cn | 中國北部 2 | https://tm-chinaeast201.afs.azure.cn |
| 中國北部 2 | https://chinanorth201.afs.azure.cn | 中國東部 2 | https://tm-chinanorth201.afs.azure.cn |
Azure 檔案同步 IP 位址的允許清單
Azure 檔案同步支援使用服務標籤,這些標籤代表給定 Azure 服務的一組 IP 位址前置詞。 您可以使用服務標籤來建立防火牆規則,以啟用與 Azure 檔案同步服務間的通訊。 Azure 檔案同步 的服務標籤為 StorageSyncService.
如果你在 Azure 內使用 Azure 檔案同步,可以在網路安全群組直接使用服務名稱標籤來允許流量。 想了解更多相關資訊,請參閱 網路安全群組。
如果你在本地使用 Azure 檔案同步,可以使用服務標籤 API,取得防火牆允許清單中特定的 IP 位址範圍。 有兩種方法可以取得此資訊:
- 所有支援服務標籤之 Azure 服務的目前 IP 位址範圍清單,都會以 JSON 文件的形式,每週在 Microsoft 下載中心發佈。 每個 Azure 雲端都有自己的 JSON 文件,其中包含與該雲端相關的 IP 位址範圍:
- 服務標籤發現 API 允許程式化檢索目前的服務標籤清單。 您可以根據您的自動化喜好設定來使用 API 介面:
由於服務標籤發現 API 更新頻率可能不如發佈到 Microsoft 下載中心 的 JSON 文件,我們建議使用 JSON 文件來更新本地防火牆的允許清單。 以下步驟可以達到此目的:
# The specific region to get the IP address ranges for. Replace westus2 with the desired region code
# from Get-AzLocation.
$region = "westus2"
# The service tag for Azure File Sync. Don't change unless you're adapting this
# script for another service.
$serviceTag = "StorageSyncService"
# Download date is the string matching the JSON document on the Download Center.
$possibleDownloadDates = 0..7 | `
ForEach-Object { [System.DateTime]::Now.AddDays($_ * -1).ToString("yyyyMMdd") }
# Verify the provided region
$validRegions = Get-AzLocation | `
Where-Object { $_.Providers -contains "Microsoft.StorageSync" } | `
Select-Object -ExpandProperty Location
if ($validRegions -notcontains $region) {
Write-Error `
-Message "The specified region $region isn't available. Either Azure File Sync isn't deployed there or the region doesn't exist." `
-ErrorAction Stop
}
# Get the Azure cloud. This should automatically based on the context of
# your Az PowerShell login, however if you manually need to populate, you can find
# the correct values using Get-AzEnvironment.
$azureCloud = Get-AzContext | `
Select-Object -ExpandProperty Environment | `
Select-Object -ExpandProperty Name
# Build the download URI
$downloadUris = @()
switch($azureCloud) {
"AzureCloud" {
$downloadUris = $possibleDownloadDates | ForEach-Object {
"https://download.microsoft.com/download/7/1/D/71D86715-5596-4529-9B13-DA13A5DE5B63/ServiceTags_Public_$_.json"
}
}
"AzureUSGovernment" {
$downloadUris = $possibleDownloadDates | ForEach-Object {
"https://download.microsoft.com/download/6/4/D/64DB03BF-895B-4173-A8B1-BA4AD5D4DF22/ServiceTags_AzureGovernment_$_.json"
}
}
"AzureChinaCloud" {
$downloadUris = $possibleDownloadDates | ForEach-Object {
"https://download.microsoft.com/download/9/D/0/9D03B7E2-4B80-4BF3-9B91-DA8C7D3EE9F9/ServiceTags_China_$_.json"
}
}
"AzureGermanCloud" {
$downloadUris = $possibleDownloadDates | ForEach-Object {
"https://download.microsoft.com/download/0/7/6/076274AB-4B0B-4246-A422-4BAF1E03F974/ServiceTags_AzureGermany_$_.json"
}
}
default {
Write-Error -Message "Unrecognized Azure Cloud: $_" -ErrorAction Stop
}
}
# Find most recent file
$found = $false
foreach($downloadUri in $downloadUris) {
try { $response = Invoke-WebRequest -Uri $downloadUri -UseBasicParsing } catch { }
if ($response.StatusCode -eq 200) {
$found = $true
break
}
}
if ($found) {
# Get the raw JSON
$content = [System.Text.Encoding]::UTF8.GetString($response.Content)
# Parse the JSON
$serviceTags = ConvertFrom-Json -InputObject $content -Depth 100
# Get the specific $ipAddressRanges
$ipAddressRanges = $serviceTags | `
Select-Object -ExpandProperty values | `
Where-Object { $_.id -eq "$serviceTag.$region" } | `
Select-Object -ExpandProperty properties | `
Select-Object -ExpandProperty addressPrefixes
} else {
# If the file cannot be found, that means there hasn't been an update in
# more than a week. Please verify the download URIs are still accurate
# by checking https://learn.microsoft.com/azure/virtual-network/service-tags-overview
Write-Verbose -Message "JSON service tag file not found."
return
}
接著你可以利用 IP $ipAddressRanges 位址範圍來更新防火牆。 請查看防火牆/網路設備的網站,以取得如何更新防火牆的相關資訊。
測試服務端點的網路連線
一旦伺服器註冊於 Azure 檔案同步 服務,Test-StorageSyncNetworkConnectivity指令長檔與 ServerRegistration.exe 即可測試與該伺服器所有特定端點(URL)的通訊。 當通訊不完整導致伺服器無法完全支援 Azure 檔案同步 時,這個 cmdlet 可以幫助排除故障,並可用來微調代理與防火牆設定。
要執行網路連線測試,請執行以下 PowerShell 指令:
Import-Module "C:\Program Files\Azure\StorageSyncAgent\StorageSync.Management.ServerCmdlets.dll"
Test-StorageSyncNetworkConnectivity
若測試失敗,請收集 WinHTTP 除錯追蹤以排除故障: netsh trace start scenario=InternetClient_dbg capture=yes overwrite=yes maxsize=1024
再跑一次網路連線測試,然後停止收集追蹤: netsh trace stop
把產生 NetTrace.etl 的檔案放進 ZIP 壓縮檔,開啟支援案件,然後把檔案分享給客服。
防火牆與代理需求摘要
本文件前述的清單包含 Azure 檔案同步 所通訊的網址。 防火牆必須允許這些網域的外發流量。 Microsoft 致力於保持這份名單的更新。
設定限制網域的防火牆規則可以作為提升安全性的措施。 如果使用這些防火牆設定,請記得網址會被新增,甚至可能隨時間改變。 定期查看這篇文章。