- ã¯ããã«
- AWS å ¬å¼ããã°æ稿 Deployment models for AWS Network Firewall
- çããçåã¨ãã®åç
- åæ§æãã¿ã¼ã³ã®æ´çã¨æ¯è¼
- æ§ç¯æã®ãããã©ãã
- ã¾ã¨ã
ææã§ãã AWS Network Firewall ã®ç»å ´ã«ããããããã¯ã¼ã¯çµè·¯ä¸ï¼ã¤ã³ã©ã¤ã³ï¼ã§ã®ãã±ããæ¤æ»ã URL ãã£ã«ã¿ãªã³ã°ã ãã«ããã¼ã¸ããµã¼ãã¹ã®ã¿ã§è¡ããããã«ãªãã¾ããã
æ¬æ稿ã§ã¯ AWS Network Firewall 㨠AWS Transit Gateway ãæ´»ç¨ãã¦ãã«ããã¼ã¸ããµã¼ãã¹ã ãã§æ§æãããã»ãã¥ã¢ãªãã«ã VPC ç°å¢ã®ãªãã¡ã¬ã³ã¹ã¢ã¼ããã¯ãã£ããç´¹ä»ãããã¨æãã¾ãã
AWS Transit Gateway ã AWS Network Firewall ã®åºæ¬ããããããããæ¹ã¯ãç§ã®éå»ã®ããã°æ稿ããåç §ãã ããã
- Transit Gatewayã§å®ç¾ãããã«ããªã¼ã¸ã§ã³æ§æã»ãã«ãã¢ã«ã¦ã³ãæ§æ
- AWS Network Firewallãåããããã解説ãã¦ã¿ã
ã¯ããã«
以ä¸ã®å³ãã覧ã«ãªã£ããã¨ãããã§ããããã AWS å ¬å¼ã® AWS ãµã¼ãã¹å¥è³æ ã«ã¦å ¬éããã¦ããè³æ [AWS Black Belt Online Seminar] Amazon VPC ããã®æç²ã§ãã
AWS Network Firewall ã®ç»å ´ã«ãããä¸è¨ã®ãããªããï¼ã¹ãã¼ã¯åã¢ã¼ããã¯ãã£ããã«ããã¼ã¸ããµã¼ãã¹ã®ã¿ã§æ§æãããããªã£ãã¨ãããã§ãããã
é¢é£ã㦠2020 å¹´ 11 æã« AWS ãã以ä¸ã®ããã°æ稿ãå ¬éããã¾ãããåè¿°ã®ã¢ã¼ããã¯ãã£ã AWS Network Firewall ã§æ§æããéã®ã¢ãã«ãç´¹ä»ãããã®ã§ãã
2021 å¹´ 5 æç¾å¨ã¯æ¥æ¬èªè¨³ããã¦ãã¾ããããå
容ã詳細ã§åèã«ãªãã¾ãã
ä»åã®ç§ã®æ稿ã§ã¯ä¸è¨ã®ããã°æ稿ãåèã«ãã¤ã¤ã以ä¸ããã¼ãã«ãããã¨æãã¾ãã
- AWS å
¬å¼ããã°æ稿
Deployment models for AWS Network Firewall
- çããçåã¨ãã®åç
- åæ§æãã¿ã¼ã³ã®æ´çã¨æ¯è¼
- æ§ç¯æã®ãããã©ãã
AWS å
¬å¼ããã°æ稿 Deployment models for AWS Network Firewall
3 種é¡ã®ã¢ãã«ã¢ã¼ããã¯ãã£
AWS å
¬å¼ã®ããã°æ稿 Deployment models for AWS Network Firewall ãç°¡åã«è§£èª¬ãã¦ã¿ããã¨æãã¾ãã
å½è©²ããã°ã§ã¯ AWS Transit Gateway + AWS Network Firewall ãå©ç¨ããéã®ãããã¯ã¼ã¯æ§æã大ãã 3 種é¡ã«åãã¦ãã¾ãã
- Distributed AWS Network Firewall deployment model
- å訳ãããªãã°
AWS Network Firewall åæ£ãããã¤ã¢ãã«
ã§ãããããã¯ã¼ã¯ãã¼ã (EC2 ãªã©) ã®ãã VPC ãã¨ã«åå¥ã« Internet Gateway ã AWS Network Firewall ãè¨ãã¾ã
- å訳ãããªãã°
- Centralized AWS Network Firewall deployment model
AWS Network Firewall éä¸ãããã¤ã¢ãã«
ã AWS Network Firewall ãä¸ã¤ã® VPC ã«ä½æãå ¨ã¦ã®ãã±ããããããéãããã«ãã¾ãã Internet Gateway ã 1 ã¤ã® VPC ã«ä½æããå ¨ã¦ã®ã¢ã¦ããã¦ã³ã (Egress) éä¿¡ããããéãããã«ãã¾ã
- Combined AWS Network Firewall deployment model
- åè¿° 1 㨠2 ã®çµã¿åããã§ã
North-South ãã©ãã£ãã¯ã¨ East-West ãã©ãã£ãã¯ã¨ã¯
å½è©²ããã°æ稿ã§ã¯ ã VPC 㨠ã¤ã³ã¿ã¼ããã/ãªã³ãã¬ãã¹ã®éä¿¡ãã North-South ãã©ãã£ãã¯
ãã VPC ããä»ã® VPC ã¸ã®éä¿¡ãã East-West ãã©ãã£ãã¯
ã¨å¼ãã§ãã¾ããããã¯ãããã¯ã¼ã¯ã®ä¸çã§ã¯ãã°ãã°è¦ããã表ç¾ã§ãã
ãããã¯ã¼ã¯æ§æå³ã«ããã¦ãä¸å´ã«ã¤ã³ã¿ã¼ãããããä¸å´ã«ç¤¾å
ãããã¯ã¼ã¯ãããã㦠L2/L3 ã¹ã¤ããããã¼ãã«ãã¦åãã¹ããããªã¼ä¸ã«æããã¦ããçµµãã¤ã¡ã¼ã¸ãã¦ãã ããã
åä¸ãµã¤ãå
ã®ãã¹ãééä¿¡ãç·ã§æãã¨ãæ§æå³ä¸ã§ã¯æ¨ªåãã«å±±ãªãã®ç·ï¼ã¤ã¾ãå°å³ã§è¨ãã¨æ±è¥¿ï¼ã«ãªããã¤ã³ã¿ã¼ãããçã¸ã®éä¿¡ã¯ç¸¦ã®éä¿¡ï¼ååï¼ã«ãªããã¨ããããã®ãããªè¡¨ç¾ãçã¾ãããã®ã¨æããã¾ãã
Distributed AWS Network Firewall deployment model ã¨ã¯
1 ã® Distributed AWS Network Firewall deployment model
ã¯ç¹ã«é£ãããã®ã§ã¯ããã¾ããã VPC ãã¨ã«åå¥ã« Internet Gateway ã AWS Network Firewall ãä½æãã¾ãã以ä¸ã«æ§æä¾ã示ãã¾ãã
EC2 ããã¤ã³ã¿ã¼ãããã¸ã®çµè·¯ã赤ç·ã§ç¤ºãã¨ä»¥ä¸ã®ããã«ãªãã¾ããéä¸ã§ AWS Network Firewall ãéã£ã¦ãã±ãããæ¤æ»ããã¾ãã
åæ§ã«ã¤ã³ã¿ã¼ããããã ALB çµç±ã§ EC2 ã¸å°éããéä¿¡ãéä¸ã§ AWS Network Firewall ãéã£ã¦æ¤æ»ããã¾ãã
ãã®ããã« North-South ãã©ãã£ãã¯ã¯ AWS Network Firewall ã«ããæ¤æ»ããã¾ãããä¸æ¹ã§ Transit Gateway ãéã East-West ãã©ãã£ãã¯ã¯æ¤æ»ããã¾ããã
Centralized AWS Network Firewall deployment model ã¨ã¯
2 ã® Centralized AWS Network Firewall deployment model
ã§ã¯è¤æ°ã®æ§æã示ããã¦ãã¾ãã以ä¸ã«æ§æä¾ã示ãã¾ãã
ç¹å¾´çãªã®ã¯ä»¥ä¸ã®ããã« Inspection VPC (å³å·¦ä¸)ãä¸éã«è¨ãã¦ãå ¨ã¦ã®ãã±ããããããéãããã«ãã¦ãã¾ãããã® Inspection VPC ã« AWS Network Firewall ãé ç½®ããã®ã§ãã
EC2 ããã¤ã³ã¿ã¼ãããã¸ã®çµè·¯ã赤ç·ã§ç¤ºãã¨ä»¥ä¸ã®ããã«ãªãã¾ãã
ãã±ããã¯ä¸åº¦ãå³å·¦ä¸ã® Inspection VPC ãçµç±ãã¦ããå³ä¸å¤®ä¸ã® Egress VPC ã«å°éã NAT Gateway, Internet Gateway ãçµç±ãã¦ã¤ã³ã¿ã¼ãããã¸åºã¦ããã¾ããæ»ãã®ãã±ãããåæ§ã§ãã
ã¤ã³ã¿ã¼ããããã VPC ã«å ¥ã£ã¦ããéä¿¡ã«ã¤ãã¦ãå³å³ä¸ã® Ingress VPC ã® ALB ããå ¥ã Inspection VPC ãçµç±ãã¦æ¤æ»ããã¦ãã System A ã System B ã® EC2 ã«ãã©ãçãã¾ãããªã ALB ã®ã¿ã¼ã²ãã (EC2) ã ALB ã¨å¥ã® VPC ã«ãããããã¿ã¼ã²ããã°ã«ã¼ãã«ã¯ã¤ã³ã¹ã¿ã³ã¹ ID ã§ã¯ãªã IP ã¢ãã¬ã¹ã使ç¨ãã¾ãã
ã¾ã System A's VPC 㨠System B's VPC ã®éã® East-West ãã©ãã£ãã¯ãåæ§ã«ãä¸åº¦ Inspection VPC ãçµç±ãã¦éä¿¡ããã¾ãã
ãªã AWS ããã°ã§ã¯ IP ãªã½ã¼ã¹ãç¯ç´ãããã Inspection VPC ã® IP ã¬ã³ã¸ã¨ãã¦ãã£ãªã¢ã°ã¬ã¼ã NAT ã® IP ã¬ã³ã¸ (100.64.0.0/16) ã使ããã¦ãã¾ããç¹æ®ãª IP 帯ã 㨠AWS ãµã¼ãã¹ãã¢ãã©ã¤ã¢ã³ã¹è£½åã«ãã£ã¦ã¯å®å ãæ¥ç¶å ã¨ãã¦æå®ã§ããªããã¨ãããã¾ããã Inspection VPC ã¯éä¿¡ã«å¯¾ãã¦ééçãªã®ã§å®å ãæ¥ç¶å ã¨ãã¦æå®ããããã¨ã¯ãªãã Inspection VPC ã«ä½è¨ãªãªã½ã¼ã¹ãé ç½®ããªããã°åé¡ã«ãªããã¨ã¯ããã¾ãã (å½ããã°ã§ã¯æ®éã® Private IP 帯ã使ã£ã¦ãã¾ã) ã
Combined AWS Network Firewall deployment model ã¨ã¯
3 ã® Combined AWS Network Firewall deployment model 㯠1 㨠2 ã®ããã¯ã¹ã§ãã
åå¥è¦ä»¶ã®ãã VPC ã«åå¥ã« Internet Gateway 㨠AWS Network Firewall ãé ç½®ããããå©ç¨ãã¾ãããã以å¤ã® VPC ã¯å ±éã® Inspection VPC ãå©ç¨ãã¾ãã以ä¸ã«ä¸ä¾ãå³ã§ç¤ºãã¾ãã
å³å·¦ä¸ã® System A's VPC 㯠å³å·¦ä¸ã® Inspection VPC ãéã£ã¦ Egress VPC/Ingress VPC ã§ã¤ã³ã¿ã¼ãããã¨éä¿¡ãã¾ãã
å³ä¸å¤®ä¸ã® System B's VPC 㯠èªåã® VPC ã«ãã Internet Gateway ã§ã¤ã³ã¿ã¼ãããã¨éä¿¡ãã¾ãã
çããçåã¨ãã®åç
çããçå
ããã§ã以ä¸ã®çåãåºã¦ãã¾ããã
çå1. Centralized AWS Network Firewall deployment model
ã§ã¯ Inspection å°ç¨ã® VPC ãè¨ãã¦ãã©ãã£ãã¯ãå
¨ã¦ãããéãããã«ãã¦ããããã®æ§æã 㨠AWS Transit Gateway ã®éä¿¡æéã¯å¢å¤§ãã (åããã±ããã Transit Gateway ã 2 åéããã) ã Egress VPC/Ingress VPC ã« Firewall ãç½®ãã®ã§ã¯ãããªãã®ã ããã
çå2. AWS Network Firewall ã® URL ãã£ã«ã¿ãªã³ã°æ©è½ã使ãéãéä¿¡è¦ä»¶ã®ç°ãªãæ¥ç¶å
VPC ã«å¯¾ãã¦ç°ãªã URL ãã£ã«ã¿ãªã³ã°ã«ã¼ã«ãé©ç¨ããæ¹æ³ã¯ããã ããã
çå3. å®éã«ã¢ã¼ããã¯ãã£è¨è¨ãè¡ãé㯠AWS å©ç¨æãéè¦ãªãã¡ã¯ã¿ã¼ã¨ãªããç´¹ä»ããã¦ããåã¢ãã«ã«ã¯ã©ã®ãããæéå·®ãããã ããã
çå4. å®éã«ãããã®ã¢ã¼ããã¯ãã£ãæ¡ç¨ãæ§ç¯ããéã«ããããã©ãããã¯ããã ããã
Inspection VPC ã¯ãªãå¿ è¦ãªã®ã
çå1. Centralized AWS Network Firewall deployment model
ã§ã¯ Inspection å°ç¨ã® VPC ãè¨ãã¦ãã©ãã£ãã¯ãå
¨ã¦ãããéãããã«ãã¦ããããã®æ§æã 㨠AWS Transit Gateway ã®éä¿¡æéã¯å¢å¤§ãã (åããã±ããã Transit Gateway ã 2 åéããã) ã Egress VPC/Ingress VPC ã« Firewall ãç½®ãã®ã§ã¯ãããªãã®ã ããã
ãã®çåã«å¯¾ãã¦ã¯ãããã°ãèªã¿é²ããã¨ããçããåºã¾ããã
Inspection VPC ãéä¿¡çµè·¯ã®éä¸ã«ç½®ããã¨ã®å©ç¹ã¯ã East-West ãã©ãã£ãã¯ãæ¤æ»ã§ãããã¨ã§ãã
Egress VPC ã Ingress VPC ã ãã« AWS Network Firewall ãé
ç½®ããã¨ãã¤ã³ã¿ã¼ãããã¸ã® North-South éä¿¡ã¯æ¤æ»ã§ãã¾ããã VPC éã® East-West éä¿¡ã¯æ¤æ»ã§ãã¾ããã
ãªã East-West éä¿¡ãæ¤æ»ã§ãã代åã¨ãã¦ä¸åº¦ Inspection VPC ãéã£ããã©ãã£ãã¯ãå度 Transit Gateway ã«æ»ããã Transit Gateway ã®éä¿¡æé㯠2 åçºçãã¾ãã
ããè¨è¨ã«ããã¦ã East-West ãã©ãã£ãã¯ã®éä¿¡ã¯æ¤æ»ããªãã¦ãã (Security Group è¨å®ãå³å¯ã«ãããã¨ã§ã«ãã¼ãã) ã North-South éä¿¡ã ããæ¤æ»ããããã«ããããã¨å²ãåããªãã°ã以ä¸ã®ãããªæ§æãå¯è½ã¨èãã¾ã (以ä¸ã®æ§æã¯æ¬æ稿ã®ãªãªã¸ãã«ã§ãã AWS ã®ããã°ã§ã¯ç´¹ä»ããã¦ãã¾ãã) ã
æ¬æ稿ã§ã¯ Centralized Inspection at Egress/Ingress VPC
ãã¿ã¼ã³ã¨å¼ç§°ãã¾ãã
ãã®æ§æã§ããã° EC2 ãã Egress VPC ã¸ãã±ãããä¸ç´ç·ã«åããããã Transit Gateway ã®éä¿¡æéãæãããã¨ãã§ãã¾ãã
VPC ééä¿¡ã®å®å
¨ã確ä¿ããããã«ã¯å VPC ã§ã¯ Security Group ãé©åã«ç®¡çããå¿
è¦ãããã¾ãã
ã¾ãå½æ§æå³ã§ã¯ Ingress VPC 㨠Egress VPC ã 1 åã® VPC ã¨ãã¦çµ±åãã¦ãã¾ããå¥ã
ã® VPC ã«åãããã¨ãå¯è½ã§ãåãããã¨ã§ Subnet Route Table ã Subnet Network ACL ãªã©ãåå¥ã«è¨å®ãããã¨ãå¯è½ã§ãã
VPC ãã¨ã«åå¥ã® URL ãã£ã«ã¿ãªã³ã°ã«ã¼ã«ãé©ç¨ããã«ã¯
çå2. AWS Network Firewall ã® URL ãã£ã«ã¿ãªã³ã°æ©è½ã使ãéãéä¿¡è¦ä»¶ã®ç°ãªãæ¥ç¶å VPC ã«å¯¾ãã¦ç°ãªã URL ãã£ã«ã¿ãªã³ã°ã«ã¼ã«ãé©ç¨ããæ¹æ³ã¯ããã ããã
AWS Network Firewall ã®ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ãã® URL ãã£ã«ã¿ãªã³ã°æ©è½ã¯ ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ã
ã¨ãã種é¡ã®ã«ã¼ã«ã°ã«ã¼ãã«ãã£ã¦å®ç¾ãã¾ãã
ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ã㯠HOME_NET
å¤æ°ã¨ãããã©ã¡ã¼ã¿ãæã£ã¦ãã¾ãã
ãã® HOME_NET å¤æ°ã¯ããã®ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ããã©ã®æ¥ç¶å
CIDR ããã®ãã±ãããæ¤æ»å¯¾è±¡ã¨ãããã示ãã¦ãããä¸ã¤ã¾ãã¯è¤æ°ã® CIDR ãè¨å®å¯è½ã§ãã
ãã® HOME_NET å¤æ°ã«ãããã¡ã¤ã³åãªã¹ã(ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ã)ãã©ã® VPC ã«é©ç¨ãããã決ãããã¨ãã§ãã¾ãã
å
ã»ã©ã® Inspection VPC ãç½®ãã¿ã¤ãã®æ§æã«ããã¦ãé©ç¨ããã VPC ã® CIDR ããã¡ã¤ã³åãªã¹ã(ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ã)ã® HOME_NET å¤æ°ã«è¨å®ããã°ãé©ç¨å¯¾è±¡ VPC ãé¸ã¶ãã¨ãã§ãã¾ãã
HOME_NET å¤æ°ã¯ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããã¯è¨å®ã§ãã AWS CLI ãªã©ãç¨ãã¦è¨å®ããå¿ è¦ãããã¾ããè¨å®æ¹æ³ã¯å ¬å¼ããã¥ã¢ã«ããåç §ãã ããã
注æç¹ã¨ãã¦ãå
ã»ã©ç´¹ä»ãã Centralized Inspection at Egress/Ingress VPC
ãã¿ã¼ã³ (Egress VPC ã« AWS Network Firewall ãç½®ãã¿ã¤ãã®æ§æ) ã§ãã¨ã AWS Network Firewall ãéããã±ããã®æ¥ç¶å
IP ã¢ãã¬ã¹ã¯ NAT Gateway ã«ãªãã¾ãã
ãã£ã¦ HOME_NET å¤æ°ãå¹ããããã¹ã¦ã®æ¥ç¶å
VPC ã«åãã«ã¼ã«ãé©ç¨ãããããªããªã£ã¦ãã¾ãã¾ãã
ããã«å¯¾ããä»ã®ææ¡ã¨ãã¦ã VPC ãã¨ã«å°ç¨ã® Egress/Ingress ç¨ VPC ãæ§ç¯ãã¦å©ç¨ããã®ãä¸ã¤ã®æã§ãã
ãã®å°ç¨ Egress/Ingress VPC ã¯åãéä¿¡è¦ä»¶ãæ㤠VPC ããã¯åå©ç¨ã§ãã¾ã (以ä¸ã®æ§æã¯æ¬æ稿ã®ãªãªã¸ãã«ã§ãã AWS ã®ããã°ã§ã¯ç´¹ä»ããã¦ãã¾ãã) ã
æ¬æ稿ã§ã¯ Centralized Inspection at Multiple Egress/Ingress VPC
ãã¿ã¼ã³ã¨å¼ç§°ãã¾ãã
ãªã以ä¸ã®ããã«ãå VPC ã®æ ¹å
ã« AWS Network Firewall ãé
ç½®ããæ§æãèãã¤ãããããã¾ãããããã㯠VPC ã®ä»æ§ä¸ NG ã§ã (以ä¸ã®æ§æã¯æ¬æ稿ã®ãªãªã¸ãã«ã§ãã AWS ã®ããã°ã§ã¯ç´¹ä»ããã¦ãã¾ãã) ã
çç±ã¯ Transit Gateway ENI ã«å¯¾ã㦠Ingress Routing ãé©ç¨ã§ããªããã
ã§ãããã®æ§æã 㨠VPC ããåºã¦ãããã±ãã㯠AWS Network Firewall ã§æ¤æ»ãããã®ã§ãããæ»ãã®ãã±ããã AWS Network Firewall ãéãã¾ãããæ»ãã®ãã±ãã㯠Transit Gateway ãã VPC ã«æ»ãã¨ãã« Transit Gateway ENI ã®ãããµããããã®ã«ã¼ããã¼ãã«ã«å¾ãã¾ããããã®ã¨ã local ã®ã«ã¼ãã«å¾ã£ã¦ç´æ¥ EC2 ã«æ»ã£ã¦ãã¾ãããã§ã (AWS Network Firewall ãéããªã)ã
ãªãå®éã«æ§ç¯ãã¦è©¦ãã¦ã¿ãã¨ãããã¹ãã¼ãã¬ã¹ã«ã¼ã«ã°ã«ã¼ãã¯é©ç¨ããã¦ã«ã¼ã«ã«åè´ãããã±ããã Drop ãªã©ãã¦ããã¾ããããã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ãã¯é©ç¨ããã Deny ã«ããã¯ãã®ãã¡ã¤ã³åã¸ã® HTTP ãªã¯ã¨ã¹ããæåãã¦ãã¾ãã¾ããã
ãµãã¼ããããªãæåã§ãã®ã§ããã®æ§æãæ¡ã£ã¦ã¯ããã¾ããã
çå 3 㨠çå 4
以ä¸ã®çåã«å¯¾ããåçã¯ãå¾è¿°ãã¾ãã
çå3. å®éã«ã¢ã¼ããã¯ãã£è¨è¨ãè¡ãé㯠AWS å©ç¨æãéè¦ãªãã¡ã¯ã¿ã¼ã¨ãªããç´¹ä»ããã¦ããåã¢ãã«ã«ã¯ã©ã®ãããæéå·®ãããã ããã
çå4. å®éã«ãããã®ã¢ã¼ããã¯ãã£ãæ¡ç¨ãæ§ç¯ããéã«ããããã©ãããã¯ããã ããã
åæ§æãã¿ã¼ã³ã®æ´çã¨æ¯è¼
æ§æãã¿ã¼ã³ä¸è¦§
AWS ã®ããã°ã§ç´¹ä»ããããã¿ã¼ã³ã¨æ°ããæ¬æ稿ã§ææ¡ããæ°ãããã¿ã¼ã³ã®ä¸¡æ¹ãä¸è¦§ã«ãã¦ä¸¦ã¹ã¾ãã
ï¼å½åãåãããããããããæ¬æ稿ãªãªã¸ãã«ã®ååã«ãªã£ã¦ãã¾ãï¼
1. Distributed Inspection
2. Centralized Inspection at Inspection VPC
3. Centralized Inspection at Egress/Ingress VPC
4. Centralized Inspection at Multiple Egress/Ingress VPC
5. Combined Pattern
æ§æãã¿ã¼ã³ã®æ¯è¼
æ¯è¼è¡¨
åãã¿ã¼ã³ã®æ¯è¼è¡¨ãä½æãã¾ããã
No | ãã¿ã¼ã³å | East-West ãã©ãã£ãã¯æ¤æ» | North-Southãã©ãã£ãã¯æ¤æ» (Internet) | North-Southãã©ãã£ãã¯æ¤æ» (ãªã³ãã¬ãã¹) | ããç´°ããè¨å® | è¨å®ãã¹æã®å½±é¿ç¯å²ã®å°ãã | æé(ä¸å®æ¡ä»¶ã«ãããå¤ãå¾è¿°) |
---|---|---|---|---|---|---|---|
1 | Distributed Inspection | ä¸å¯ | å¯ | ä¸å¯ | å¯ | å°ãã | $ 14,625.8 |
2 | Centralized Inspection at Inspection VPC | å¯ | å¯ | å¯ | å¯ | 大ãã | $ 8,186.976 |
3 | Centralized Inspection at Egress/Ingress VPC | ä¸å¯ | å¯ | ä¸å¯ | ä¸å¯ | 大ãã | $ 3,882.44 |
4 | Centralized Inspection at Multiple Egress/Ingress VPC | ä¸å¯ | å¯ | ä¸å¯ | å¯ | ä¸ç¨åº¦ | $ 5,801.96 |
5 | Combined Pattern | å¯ | å¯ | å¯ | å¯ | ä¸ç¨åº¦ | $ 10,158.576 |
AWS å©ç¨æéã®è©³ç´°
åè¿°ã®è¡¨ã§ã¯å©ç¨æéãä¸å®æ¡ä»¶ä¸ã«ãããå¤ã§è¨ç®ãã¾ããã
å®éã«ã¯æ§æã«åããã¦å¤ãå¤åããã試ç®ãã¦ãã ããã
以ä¸ã«ãå³å¯ãªè¨ç®çµæãè¨è¼ãã¾ãã
ã¾ããè¨ç®ã®åææ¡ä»¶ã¯ä»¥ä¸ã®éãã§ãã
- VPC æ°ã¯ 20 å
- 使ã AZ 㯠2 ã¤ã¨ã㦠NAT Gateway ã AWS Network Firewall Endpoint ã¯å AZ ã«ãããã¤ãã
- North-South ãã©ãã£ãã¯é㯠VPC ããã 30 GB/æ¥
- è¨ç®ã®åç´åã®ãã ALB ã®è¨ç®ã¯ããå ¨ã¦ NAT Gateway ã®éä¿¡ã¨ãã¦è¨ç®
- East-West ãã©ãã£ãã¯é㯠VPC ããã 50 GB/æ¥
3. Centralized Inspection at Egress/Ingress VPC
ã¨4. Centralized Inspection at Multiple Egress/Ingress VPC
ã«ããã¦ã¯ Ingress VPC 㨠Egress VPC ã¯åä¸ VPC ã«åå±4. Centralized Inspection at Multiple Egress/Ingress VPC
ãã¿ã¼ã³ã«ãã㦠Egress/Ingress VPC ã®æ°ã¯ 4 å5. Combined Pattern
ã«ããã¦åå¥ã® Internet Gateway/AWS Network Firewall ãæ㤠VPC ã®æ°ã¯ 4 å- 1ã«æ㯠31 æ¥ (744h) ã§è¨ç®
- 2021/5/24 ç¾å¨ã®æ±äº¬ãªã¼ã¸ã§ã³ã®æéã§è¨ç®
ãã®æ¡ä»¶ã§ãã¨ã課éè¦ç´ ã® Quantity ã®æ°ã¯ä»¥ä¸ã®éãã§ãã
No | ãã¿ã¼ã³å称 | NAT Gatewayæé | NAT Gatewayãã¼ã¿ | Firewall Endpointæé | Firewall Endpointãã¼ã¿ | TGW Attachmentæé | TGW Traffic |
---|---|---|---|---|---|---|---|
1 | Distributed Inspection | 0 | 0 | 40å * 744h | 18,600 GB | 20 å * 744h | 31,000 GB |
2 | Centralized Inspection at Inspection VPC | 2 å * 744h | 18,600 GB | 2 å * 744h | 49,600 GB | 22 å * 744h | 99,200 GB |
3 | Centralized Inspection at Egress/Ingress VPC | 0 | 0 | 2 å * 744h | 18,600 GB | 21 å * 744h | 49,600 GB |
4 | Centralized Inspection at Multiple Egress/Ingress VPC | 0 | 0 | 8 å * 744h | 18,600 GB | 24 å * 744h | 49,600 GB |
5 | Combined Pattern | 2 å * 744h | 14,880 GB | 10 å * 744h | 49,600 GB | 22 å * 744h | 91,760 GB |
AWS Network Firewall Endpoint 1 ã¤ã«ã¤ã NAT Gateway 1 ã¤ã®æéæéã»ãã¼ã¿å¦çæéãç¡æã«ãªããã¨ã«æ³¨æãã¾ãã
ä¸è¨ã® Quantity ã§æéãè¨ç®ããã¨ã以ä¸ã®éãã§ãã
No | ãã¿ã¼ã³å称 | NAT Gatewayæéæé | NAT Gatewayãã¼ã¿æé | Firewall Endpointæéæé | Firewall Endpointãã¼ã¿æé | TGW Attachmentæéæé | TGW Trafficæé | è¨ |
---|---|---|---|---|---|---|---|---|
1 | Distributed Inspection | 0 | 0 | $ 11,755.2 | $ 1,209 | $ 1,041.6 | $ 620 | $ 14,625.8 |
2 | Centralized Inspection at Inspection VPC | $ 92.256 | $ 1,153.2 | $ 587.76 | $ 3,224 | $ 1,145.76 | $ 1,984 | $ 8,186.976 |
3 | Centralized Inspection at Egress/Ingress VPC | 0 | 0 | $ 587.76 | $ 1,209 | $ 1,093.68 | $ 992 | $ 3,882.44 |
4 | Centralized Inspection at Multiple Egress/Ingress VPC | 0 | 0 | $ 2,351.04 | $ 1,209 | $ 1,249.92 | $ 992 | $ 5,801.96 |
5 | Combined Pattern | $ 92.256 | $ 922.56 | $ 2,938.8 | $ 3,224 | $ 1,145.76 | $ 1,835.2 | $ 10,158.576 |
æ§ç¯æã®ãããã©ãã
ããããã¯å®éã«æ§ç¯ããéãç¹ã«æ°ãä»ããã¹ããã¤ã³ããè¨è¼ãã¾ãã
ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ãã® HOME_NET å¤æ°
ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ã(URL ãã£ã«ã¿ãªã³ã°ãªã©)㯠HOME_NET
å¤æ°ã¨ãããã©ã¡ã¼ã¿ãæã£ã¦ãã¾ãã
ãã®å¤æ°ã¯åè¿°ã®éãããã®ã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ããã©ã®æ¥ç¶å CIDR ããã®ãã±ãããæ¤æ»å¯¾è±¡ã¨ãããã示ãã¦ãããè¤æ°ã® CIDR ãè¨å®å¯è½ã§ããHOME_NET å¤æ°ã«ç¡ã CIDR ããæ¥ããã±ããã«ã¯ã«ã¼ã«ã°ã«ã¼ããé©ç¨ãããããã¹ã¹ã«ã¼ (Allow) ããã¦ãã¾ãã¾ããæ示çã«è¨å®ããã¦ããªãå ´å㯠AWS Network Firewall ããããã¤ããã VPC ã® CIDR ãé©ç¨ããã¾ããã¤ã¾ã AWS Network Firewall ã¨åã VPC å ã® EC2 çããåºããã±ããããæ¤æ»å¯¾è±¡ã«ãªãã¾ããã
ã¤ã¾ã HOME_NET å¤æ°ã®åå¨ãç¥ããã«æªè¨å®ã¨ãã¦ãã¾ãã¨ããã£ãã Inspection VPC ãä½ã£ã¦ãã¹ãã¼ããã«ã«ã¼ã«ã°ã«ã¼ããé©ç¨ãããã«ãã±ãããéã£ã¦ãã¾ãã¾ãã Inspection VPC ã« AWS Network Firewall ãç½®ãã¨ãå
¨ã¦ã®æ¤æ»å¯¾è±¡ãã±ãã㯠VPC å¤ããæ¥ããã¨ã«ãªãããã§ãã
2. Centralized Egress & Centralized Inspection at Inspection VPC
ã 5. Combined pattern
ãæ¡ç¨ããå ´åã¯ååã注æãã ããã
éã«ããã¨ã使ãããªãã°æ¥ç¶å
VPC ãã¨ã«é©ç¨ããã«ã¼ã«ãå¤ãããã¨ãã§ãã¾ãããªã 3. Centralized Inspection at Egress/Ingress VPC
ã 4. Centralized Inspection at Multiple Egress/Ingress VPC
ã¯ã¤ã³ã¿ã¼ãããã¸åºã¦ãããã±ããã®æ¥ç¶å
IP ã¢ãã¬ã¹ã NAT Gateway ã®ãã®ã¨ãªãã®ã§ãæ¥ç¶å
VPC ãã¨åå¥ã«ã«ã¼ã«ãé©ç¨ãããã¨ã¯ã§ãã¾ããã
HOME_NET å¤æ°ã¯ "10.100.50.0/24", "10.100.60.0/24".... ã®ããã«è¤æ°è¨å®ãã¦ãããã§ããã "10.100.0.0/16" ã®ããã«ç¯å²è¨å®ãããã¨ãã§ãã¾ãã
è¤æ°ã«ã¼ã«ã§ HOME_NET å¤æ°ã«è¨å®ãã CIDR ãéè¤ãã¦ããå ´åãªã©ãæåã«ã¯ã»ããããããããã¯ã¾ãå¥éããã°æ稿ã§ã¾ã¨ãããã¨æãã¾ãã
ãªãHOME_NET å¤æ°ã¯ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããã¯è¨å®ã§ãã AWS CLI ãªã©ãç¨ãã¦è¨å®ããå¿ è¦ãããã¾ãã è¨å®æ¹æ³ã¯å ¬å¼ããã¥ã¢ã«ããåç §ãã ããã
AWS ããã¼ã¸ãã«ã¼ã«ã°ã«ã¼ãã使ç¨ããå ´å㯠HOME_NET å¤æ° ã®å¤æ´ãã§ãã¾ãã (2022/3/16 å±±æ¬è¿½è¨)
AWS ããã¼ã¸ãã«ã¼ã«ã°ã«ã¼ãã使ç¨ããå ´å㯠HOME_NET å¤æ° ã«ã¯ AWS Network Firewall ãé
ç½®ãã VPC ã® CIDR ãå
¥ãã¾ã
å¤æ´ä¸å¯ã¨ãªãã¾ã
Inspection VPC ã®æ§æãåãå ´åã«ã¯äºåã«ãã®ãã¨ãèæ
®ãã¦ããã¾ããã
以ä¸ã®è¨äºã«è©³ç´°ãè¨è¼ãã¦ãã¾ã
You can't override the Suricata HOME_NET variable in AWS Managed Rules.
å訳ï¼AWSããã¼ã¸ãã«ã¼ã«ã§Suricata ã®HOME_NETå¤æ°ãå¤æ´ãããã¨ã¯ã§ãã¾ããã
Limitations for AWS Managed Rules in AWS Network Firewall - AWS Network Firewall
Transit Gateway ã®ã¢ãã©ã¤ã¢ã³ã¹ã¢ã¼ãã®æå¹å
ãã¡ãã 2. Centralized Egress & Centralized Inspection at Inspection VPC
ã 5. Combined pattern
ã® 2 ã¤ãããªãã¡ Inspection VPC ã使ã£ã¦ East-West ãã©ãã£ãã¯ãæ¤æ»ããæ§æã®ã¨ãã«æ³¨æãå¿
è¦ã§ãã
ãã VPC ã® AZ-1a ã«ãã EC2 ã¤ã³ã¹ã¿ã³ã¹ããå¥ã® VPC ã® AZ-1c ãªã©å¥ã® AZ ã®ã¤ã³ã¹ã¿ã³ã¹çã«æ¥ç¶ããå ´åã Transit Gateway ã® ã¢ãã©ã¤ã¢ã³ã¹ã¢ã¼ã
ãæå¹åããå¿
è¦ãããã¾ããæå¹åããªãã¨è¡ãã®ãã±ããã¨è¿ãã®ãã±ããã§éä¿¡çµè·¯ãå¤ãã£ã¦ãã¾ãééãã AWS Network Firewall ãå¤ãã£ã¦ãã¾ããã¨ããããã±ãããç ´æ£ããã¦ãã¾ãã¾ãã
ã¢ãã©ã¤ã¢ã³ã¹ã¢ã¼ãã«ã¤ãã¦è©³ããã¯å½ç¤¾ã®ããã°ããåç §ãã ããã
ã¾ã¨ã
AWS Transit Gateway + AWS Network Firewall ãå©ç¨ããè¤æ°ã®æ§æãã¿ã¼ã³ã¨ãã®æ³¨æç¹ããç´¹ä»ãã¾ããã
ãããã®ãã¿ã¼ã³ãæ¡ããã以ä¸ã«çç®ãã¦ååæ¤è¨ããã»ãã¥ã¢ã§ä½éç¨ã³ã¹ããªç°å¢ãæ§ç¯ãã¦ãã ããã
- VPC æ°ã®ä»å¾ã®å¢å è¦è¾¼ã¿
- ã»ãã¥ãªãã£è¦ä»¶
- AWSå©ç¨æéæ¯è¼
- AWS Network Firewall ã§åºæ¥ããã¨
ææ å馬 (è¨äºä¸è¦§)
ãµã¼ãã¼ã¯ã¼ã¯ã¹ â æ ªå¼ä¼ç¤¾G-gen å·è¡å½¹å¡CTO
2021 Japan APN Ambassadors / 2021 APN All AWS Certifications Engineers
ãã«ãAWSã¢ã«ã¦ã³ã管çéç¨ããããã¯ã¼ã¯é¢ä¿ã®AWSãµã¼ãã¹ã«é¢ããããã°è¨äºãéå»ã«å·çã
2021å¹´09æããæ ªå¼ä¼ç¤¾G-genã«åºåãGoogle Cloud(GCP)ãå°éã«ãG-genã§ãGoogle Cloud (GCP) ã®æè¡ããã°ãå·çä¸ã