Create Virtual Network

This section will create the virtual network that will be used by Azure Automation, Function Apps and SQL.

Manual Steps:

Step 1: Create Virtual Network

  1. Browse and log into the Azure Portal

Use the correct URL for your environment:

Worldwide (Commercial) & GCC https://portal.azure.com
GCC-High and DoD https://portal.azure.us
  1. Type in virtual network in the top search box
  2. Select Virtual networks
View Virtual Networks

  1. Select + Create
Create Virtual Network

  1. Set the values for the virtual network
  2. Select Next
Name Value
Subscription The subscription associated with this account.
Resource Group The Resource Group created for SPARK
Virtual network name vnet-pe-spark
Region The same region as the Resource Group
Virtual Network Details

  1. Set the size of the address space to 24
  2. Select Review + Create and then Create
Virtual Network Address Space

Step 2: Configure Private DNS Zone

  1. Type in private dns in the top search box
  2. Select Private DNS Zones
View Private DNS

  1. We will create a private dns zone for each service in the table below
Service Private DNS Zone (Commercial/GCC) Private DNS Zone (GCC-H/DoD)
Azure Automation privatelink.azure-automation.net privatelink.azure-automation.us
Azure Function App privatelink.azurewebsites.net privatelink.azurewebsites.usgovcloudapi.net
Azure Storage Blob privatelink.blob.core.windows.net privatelink.blob.core.usgovcloudapi.net
Azure Storage File privatelink.file.core.windows.net privatelink.file.core.usgovcloudapi.net
Azure Storage Queue privatelink.queue.core.windows.net privatelink.queue.core.usgovcloudapi.net
Azure Storage Table privatelink.table.core.windows.net privatelink.table.core.usgovcloudapi.net

  1. Select + Create
Create Private DNS

  1. Set the values for the private dns zone
  2. Click on Next twice to get to the Virtual Network Links
Name Value
Subscription The subscription associated with this account
Resource Group The Resource Group created for SPARK
Name The value from the table in the previous step
Region The same region as the Resource Group
Create Private DNS Basic

  1. Select + Add Virtual Network Link
Create Private DNS Basic

  1. Set the values for the virtual network link
  2. Select Create
  3. Select Review + Create and then Create
Name Value
Link name [Private DNS Zone Name]-vnlink-spark
Subscription The subscription associated with this account
Virtual Network vnet-pe-spark
Create Virtual Network Link

Step 3: Configure SQL Network

  1. Type in azure sql in the top search box
  2. Select Azure SQL
View Azure SQL

  1. Select SQL logical servers
  2. Select the SPARK SQL server
Select SQL Server

  1. Select Networking under the Security navigation menu
  2. Select the option to Disable the Public Access
  3. Select Save
Remove Public Access

  1. Select Private Access
  2. Select + Create a Private Endpoint
Add Private Access

  1. Fill in the values and select Next until you get to the Virtual Network tab
Name Value
Subscription The subscription associated with this account
Resource Group The Resource Group created for SPARK
Name pe-spark-sql-svr
Create Private Endpoint SQL

  1. Fill in the values and select Next until you get to the Virtual Network tab
  2. Select Next until you get to Review + Create
  3. Select Create
Name Value
Virtual Network vnet-spark-pe
Subnet default
Private IP Configuration Statically allocate IP address
Name pipsqlServer
Private IP 10.0.0.6
Create Private Endpoint SQL