注意:
请联系 feature-releases@catonetworks.com 以获取有关启用和使用此功能的更多信息。
您可以在 Azure 中部署一个应用连接器,为您的云环境提供私有应用程序的安全访问。 应用连接器在您的云环境与 Cato 之间建立连接,并连接后,您将在 CMA 中分配它并将其关联到相关的应用连接器组。
了解 Azure 工作流程中的应用连接器
以下是部署 Azure 应用连接器的高级工作流程:
在CMA中创建应用连接器对象
从 Azure Marketplace 部署 Cato 应用连接器
为连接器分配应用程序
Create an App Connector
When you create an App Connector, you can choose the behavior for connecting to a preferred PoP in the Cato Cloud:
Disabled - the App Connector automatically connects to the best available PoP (default)
Enabled - Select the PoPs to which the connector attempts to connect to
When Preferred PoP is enabled, you can restrict an App Connector to only connect to the Preferred PoP Locations that you configure. In this case, the connector doesn't connect to a non-preferred PoP location despite any connectivity or performance issues that it is experiencing. When you use this option, you must define a primary and secondary PoP location for the App Connector.
Once the App Connector is created in the CMA, copy the serial number, as you will need to provide it when deploying the App Connector in your cloud environment.

To create an App Connector in the CMA:
From the navigation menu, click Access > App Connector, and then click New.
Enter the information in the General section, such as Connector Name and Country.
Under Type, click Virtual.
In the Connector Group section, select an existing App Connector group from the list or enter a name to create a new group.
Under Preferred PoPs, select the behavior
Disabled - the App Connector tries to connect to the best available PoP
Enabled - Select the Primary and Secondary PoP locations that the connector tries to connect to
Enabled and Only connect to the preferred PoPs - Only connect to the Primary or Secondary PoP location
Click Apply.
在 Azure 中部署应用连接器
使用 Azure Marketplace 中的自动化 Cato 向导创建应用连接器的虚拟资源并将其部署到 Azure。 Azure 应用连接器镜像在 Marketplace 中公开可用。
在 Azure 中部署应用连接器
在 Azure Marketplace 中,搜索 Cato,然后选择Cato 应用连接器。
在概览屏幕中,为 Azure 资源选择计划和订阅,然后点击创建。
在基础屏幕中,为资源和成本定义以下设置:
订阅 - Azure 资源的计费账户
资源组 - 应用连接器资源关联到的 Azure 资源组
区域 - 应用连接器资源的 Azure 区域
资源前缀 - 为每个应用连接器资源添加的可选前缀
在网络屏幕中,首先确定您想要使用2或3个网卡。

2 NIC 部署使用 Standard_D2s_v5 实例类型
3 NIC 部署使用 Standard_D8ls_v5 实例类型
注意:
默认情况下,3 NIC vSockets 在启用 Azure 加速网络选项时支持高达 2Gb 的吞吐量。
这些是应用连接器子网(最小子网地址空间为/28):
MGMT 子网(仅 3 NIC 部署)– 应用连接器与 Azure API 之间的管理通信
WAN子网 - 应用连接器的外部WAN流量(互联网和Cato云)
LAN 子网 - 连接到应用连接器的内部 Azure 资源和流量
在Cato AppConnector 配置屏幕中,根据您在Cato 管理应用程序中创建的应用连接器定义以下设置。

AppConnector 序列号 (S/N) - 粘贴您在访问 > 应用连接器页面中复制的S/N。
AppConnector 名称 - 输入承载应用连接器的 VM 的名称。
AppConnector 名称不能包含空格或Azure 限制的字符。
WAN 接口 IP 分配 – 为 WAN 接口选择一个动态或静态内部 IP 地址。 对于静态IP分配,您可以分配任何IP地址.
MGMT 接口 IP 分配(仅限 3 个 NIC 部署)- 为 MGMT 接口选择一个动态或静态内部 IP 地址。 对于静态IP分配,您可以分配任何IP地址.
在可选配置屏幕中,您可以选择定义以下设置:

WAN 和/或 MGMT(仅限 3 NIC 部署)接口的公共 IP 地址
WAN、MGMT (仅限 3 NIC 部署) 和/或 LAN 接口的网络安全群组
应用连接器的可用性选项:
Azure 可用性集 - 创建新的或使用现有的
注意:可用性集必须与应用连接器位于同一资源组
Azure 可用性区域 - 在 1 到 3 的范围内选择一个可用性区域
有关这些设置的详细信息,请参见上文 ???。
在审查 + 创建屏幕中,检查应用连接器设置并点击创建。
应用连接器资源部署后,它会自动连接到 Cato 云,并检查是否需要升级到最新版本。 Cato 管理应用程序通知区域显示有关连接应用连接器状态的消息。
您可以在访问 > 应用连接器页面中查看您的应用连接器。
为连接器分配应用程序
您可以从私有应用页面或应用连接器页面为连接器分配应用程序,使用 分配应用 链接。