å æ¥ãGCPã§NATã¤ã³ã¹ã¿ã³ã¹ãæ§ç¯ããè¨äº ãæ¸ããã°ããã§ããããªãã¨ããã¼ã¸ãNATãµã¼ãã¹ Cloud NATããã¼ã¿çã§ãªãªã¼ã¹ããã¾ããã
ãªãªã¼ã¹ãããã®ã§ããã¥ã¡ã³ããèªãã§æ°ã«ãããã¤ã³ããæ´ç & å®éã«è©¦ãã¦ã¿ã¾ããã
- GCP Cloud NATãã¢ããçç±
- NATã«è¨å®ããIPã¢ãã¬ã¹ã«ã¤ãã¦
- ãã¼ãæ°ã¨æ¥ç¶æ°ã®å¶é
- ã¿ã¤ã ã¢ã¦ã
- 帯åå¹
- Googleãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ã«ã¤ãã¦
- ä¾¡æ ¼
- Cloud NATã使ã£ã¦ã¿ã
- Cloud NATçµç±ã§GCEã¤ã³ã¹ã¿ã³ã¹ãå©ç¨ããã
- åèURL
GCP Cloud NATãã¢ããçç±
ããã¼ã¸ãNATãµã¼ãã¹ã¯ä»ã®ã¯ã©ã¦ããµã¼ãã¹ã§ããªãªã¼ã¹ããã¦ãããã¨æãã¾ãããGCP Cloud NATã®ç¹å¾´ã¨ãã¦ãAndromeda ã¨ããSDNãNATãæ
ãç¹ã§ãã
å¾æ¥ã ã¨NATãããã·ã¤ã³ã¹ã¿ã³ã¹ãéã«å
¥ãããããã®ã¤ã³ã¹ã¿ã³ã¹ã帯åã«ããã«ããã¯ã«ãªã£ããã¨ã¹ã«ã¼ãããã«æ§è½å·®ãã§ã¦ãã¾ã£ã¦ãã¾ããããCloud NATã¯NATãããã·ã¤ã³ã¹ã¿ã³ã¹(ãã§ã¼ã¯ãã¤ã³ã)ããªããããã¬ã¤ãã³ã·ãã¹ã«ã¼ããããå®å®ãã¦ããã¨ã®ãã¨ã§ãã
https://cloud.google.com/nat/docs/overview#under_the_hood
NATã«è¨å®ããIPã¢ãã¬ã¹ã«ã¤ãã¦
Cloud NATã«å²ãå½ã¦ãã°ãã¼ãã«IPã¢ãã¬ã¹ãèªåãæåã§è¨å®ãã§ãã¾ãããã®ã°ãã¼ãã«IPã¢ãã¬ã¹ã¯VPCå é¨ããWANã«åºãéã®ã¢ã¯ã»ã¹å IPã¢ãã¬ã¹ã¨ãªãã¾ãã
èªåå²ãå½ã¦
èªåçã«ã°ãã¼ãã«IPã¢ãã¬ã¹ãåå¾ãCloud NATã«å²ãå½ã¦ã¦ããã¾ãã使ç¨VMæ°ããã¼ãæ°ã«å¿ãã¦èªåçã«ã¹ã±ã¼ã«ãã¦ããã(=ã°ãã¼ãã«IPã¢ãã¬ã¹æ°ãå¢æ¸ãã)ã®ã§ç®¡çã³ã¹ããä¸ãããããããã¥ã¡ã³ãã§ã¯ãã¡ãã®æ¹æ³ãæ¨å¥¨ããã¦ãã¾ãã
ããããå²ãå½ã¦ãããã°ãã¼ãã«IPã¢ãã¬ã¹ããã©ã¦ã¶ã³ã³ã½ã¼ã«ä¸ãã確èªã§ãããã©ã®ã°ãã¼ãã«IPã¢ãã¬ã¹ãéãããããããã¾ãããã¾ããå²ãå½ã¦ & éæ¾ã®åº¦ã«IPã¢ãã¬ã¹ãã³ãã³ãå¤ãããããã¢ã¯ã»ã¹å
ãå¶éãããã¯ã¤ããªã¹ãæ¹å¼ã§ã¯ä¸åãã§ãã
æåå²ãå½ã¦
éçIPã¢ãã¬ã¹ãåå¾ããCloud NATã«å²ãå½ã¦ãæ¹æ³ã§ããèªåå²ãå½ã¦ã¨ç°ãªããIPã¢ãã¬ã¹ãåæã«å²ãå½ã¦ãéæ¾ãããªããããã¯ã¤ããªã¹ãæ¹å¼ã«åãã¦ãã¾ãã
ããããã°ãã¼ãã«IPã¢ãã¬ã¹ä¸ã¤ãããã«ä½¿ç¨ã§ããVMæ°ã¨ãã¼ãæ°ã«å¶éããã(å¾è¿°)ããã使ç¨ç¶æ³ãã¿ã¦ä½è£ããã£ã¦IPã¢ãã¬ã¹ãå²ãå½ã¦ã¦å¿
è¦ãããã¾ãã
ããã¥ã¡ã³ãã«ããã¨ãIPã¢ãã¬ã¹æ°ãå¶æ°åã§ãããã¨ãæ¨å¥¨ããã¦ãã¾ãã
ãã¼ãæ°ã¨æ¥ç¶æ°ã®å¶é
Cloud NATã«å²ãå½ã¦ãIPã¢ãã¬ã¹ä¸ã¤ã«ã¤ããTCPãUDPã¨ãã« 65,536 åã®ãã¼ããããã¾ãããã®ãã¡ã1024 ã¾ã§ã®ã¦ã§ã«ãã¦ã³ãã¼ãã¯ä½¿ç¨ã§ããªãããã64,512 åã®ãã¼ãã使ãããã¨ã«ãªãã¾ãã
ããã©ã«ãã§ã¯ãä¸ã¤ã®VMã«ã¤ã64ãã¼ã(TCP 64åãUDP 64å)ãåå¾ãã¾ãããããã£ã¦ãä¸ã¤ã®NAT IPã¢ãã¬ã¹ã«ã¤ããæ大ã§1,008åã®VMã¤ã³ã¹ã¿ã³ã¹ã¾ã§NATçµç±ã§ä½¿ç¨å¯è½ã«ãªãã¾ãã
ä¸ã¤ã®VMããããåå¾ãããã¼ãæ°ã¯å¤æ´å¯è½ã§ãããå¤ãããã°ããã ãä¸ã¤ã®NAT IPã¢ãã¬ã¹ã§ã¾ããªããVMã¤ã³ã¹ã¿ã³ã¹æ°ã¯æ¸ãã¾ããã¾ããä¸åº¦å¢ããããæ¸ãããã¨ãã§ããããã®å ´åã¯Cloud NATãåä½æããå¿ è¦ãããã¾ãã *1
ã¿ã¤ã ã¢ã¦ã
ããã©ã«ãå¤ã¯ä»¥ä¸ã®éãã§ããè¨å®ã§å¤æ´å¯è½ã§ãã
- UDPãããã³ã°ã¢ã¤ãã«ã¿ã¤ã ã¢ã¦ãï¼30ç§
- ICMPãããã³ã°ã¢ã¤ãã«ã¿ã¤ã ã¢ã¦ãï¼30ç§
- TCP確ç«æ¥ç¶ã¢ã¤ãã«ã¿ã¤ã ã¢ã¦ãï¼1200 ç§
- TCPä¸ææ¥ç¶ã¢ã¤ãã«ã¿ã¤ã ã¢ã¦ãï¼30ç§
帯åå¹
Cloud NATçµç±ã«ãªãã¨ãã°ãã¼ãã«IPã¢ãã¬ã¹ãä»ä¸ããVMã¨åãç¨åº¦ã®å¸¯åå¹ ã«ãªãã¨ã®ãã¨ã§ãã
Googleãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ã«ã¤ãã¦
Cloud NATã§ã¯ãµãã¼ããã¦ãã¾ããããCloud NATãæå¹ã«ãªã£ã¦ãããµããããã¯èªåçã«Googleãã©ã¤ãã¼ãã¢ã¯ã»ã¹ãæå¹åããã¾ãã
ä¾¡æ ¼
ãã¼ã¿ãªãªã¼ã¹ä¸ã¯ç¡æã§ããGAã«ãªã£ãå ´åã¯ä»¥ä¸ã®ä¾¡æ ¼ãåºæºã«ãªãã¨ã®ãã¨ã§ãã
æ±äº¬ãªã¼ã¸ã§ã³ã ã¨ãããã«ãªããã¯ç¾æç¹ã§åããã¾ããã
- an hourly price for the NAT gateway, starting at $0.045 per NAT gateway hour
- a per/GB cost for ingress and egress traffic processed by the gateway
- egress pricing to send traffic from the VM out of the network remains unchanged
ãã ããä½æããéçIPã¢ãã¬ã¹ã«å¯¾ããæéã¯çºçããã®ã§æ³¨æãã¦ãã ããã
Cloud NATã使ã£ã¦ã¿ã
ããããä»æ§ã確èªããã¨ããã§ãå®éã«Cloud NATãä½æãã¦ã¿ã¾ããã
ãã§ã«VPCãããã¯ã¼ã¯ããµãããããä½ææ¸ã¿ã§ãããã¨ãåæã§ãã
ããä½ãä½æãã¦ããªãå ´å㯠ããã¥ã¡ã³ã ãåèã«ãµã³ãã«ç¨ã®VPCãããã¯ã¼ã¯ã¨ãµãããããä½æãã¾ãã
ä»åã¯æ±äº¬ãªã¼ã¸ã§ã³ã§ä½æãã¾ããã
Cloud Routerã®ä½æ
$ gcloud beta compute routers create nat-router-tokyo \ --network sample-network \ --region asia-northeast1
Cloud NATã®ä½æ
æãåºæ¬çãªä½æã³ãã³ãã¯ãã¡ãã§ãã
$ gcloud beta compute routers nats create nat-tokyo \ --router-region asia-northeast1 \ --router nat-router-tokyo \ --auto-allocate-nat-external-ips \ --nat-all-subnet-ip-ranges
--auto-allocate-nat-external-ips
ã¯IPã¢ãã¬ã¹ãèªåçã«å²ãå½ã¦ã¾ã--nat-all-subnet-ip-ranges
ã¯VPCãããã¯ã¼ã¯å ã®ãã¹ã¦ã®ãµããããã«å¯¾ãã¦Cloud NATãæå¹åãã¾ã
ç¹å®ã®ãµããããã ãã«éå®ãããå ´å
--nat-custom-subnet-ip-ranges
ãªãã·ã§ã³ã§æå®ãã¾ãã
$ gcloud beta compute routers nats create nat-tokyo \ --router-region asia-northeast1 \ --router nat-router-tokyo \ --auto-allocate-nat-external-ips \ --nat-custom-subnet-ip-ranges=subnet-1,subnet-2
éçIPã¢ãã¬ã¹ã«ããæåå²ãå½ã¦ããå ´å
éçIPã¢ãã¬ã¹ãåå¾ãã¾ããããã¥ã¡ã³ãã«ããã¨ãããä»åã¯2ååå¾ãã¾ãã
$ gcloud compute addresses create managed-nat-tokyo-1 --region asia-northeast1 $ gcloud compute addresses create managed-nat-tokyo-2 --region asia-northeast1
--nat-external-ip-pool
ãªãã·ã§ã³ã§éçIPã¢ãã¬ã¹ãæå®ãã¾ãã
$ gcloud beta compute routers nats create nat-tokyo \ --router-region asia-northeast1 \ --router nat-router-tokyo \ --nat-external-ip-pool=managed-nat-tokyo-1,managed-nat-tokyo-2 \ --nat-all-subnet-ip-ranges
ä½æå¾ããã©ã¦ã¶ã³ã³ã½ã¼ã«ä¸ã¯ãã®ããã«ãªãã¾ãã
éçIPã¢ãã¬ã¹ã®ç»é¢ã§ãããªãã使ç¨ãªã½ã¼ã¹ã空ã«ãªã£ã¦ã¾ãã・・・ã
ãã以å¤ã®ãªãã·ã§ã³ã¯ããã¥ã¡ã³ãããåç
§ãã ããã
gcloud beta compute routers nats create  | Cloud SDK  | Google Cloud
Cloud NATçµç±ã§GCEã¤ã³ã¹ã¿ã³ã¹ãå©ç¨ããã
Cloud NATãæå¹ã«ãªã£ã¦ãããµãããããæå®ããå¤é¨IPããªãã«ãã¦èµ·åããã ãã§ãã
åèURL
*1:ãã¼ã¿çã§ã®åä½ãªã®ã§ä»å¾æ¸ãããã¨ã¯å¯è½ã«ãªãããããã¾ãã