çããããã«ã¡ã¯ããã¯ãã«ã«ã°ã«ã¼ãã®å±±ç°ã§ãã
ä»åã社å
ã®ç ä¿®ã§åãã¦VPCã«è§¦ããã®ã§ãããVPCãæ§ç¯ããéã«ããã£ãé¨åãä½ç®æããã£ãã®ã§ä»ã«ãããã§ããããè¿·ããåç¾ã®ããã«ãããªããããã¤ã³ããåå¿è
ã®ç®ç·ãã解説ãã¦ããã¾ãã
ãããªäºãç¥ããªãã®ãã¨æãããæ¹ãããã£ãããã¨æãã¾ãããã©ãã温ããç®ã§è¦ã¦ãã ããã°å¬ããæãã¾ãï¼
ãªããVPCã®åºæ¬çãªæ§ç¯æé ã«ã¤ãã¦ã¯ãã°ã°ãã°ããããåºã¦ããã¨æãã®ã§ãã¡ããã覧ä¸ããã
VPCã®æ§ç¯ã§æ°ã«ãªã£ãã»ããã£ããã¤ã³ã
- VPCã®ãµã¤ãºã¯å¤æ´ä¸å¯ï¼
VPCãä½æããéã«ãCIDRå½¢å¼ã§VPCã®ãµã¤ãºã決ããã¨æãã®ã§ããããã¯ä¸åº¦æ±ºãããããå¤ãããã¾ããï¼
ã¢ãã¬ã¹ç¯å²ãå¤ãããå ´åã¯ãããä¸åº¦ä½ããªããããæ¹æ³ã¯ããã¾ããã
ã©ããå¾ã§å¤ãããããã§ããï¼ã¨ããããããã£ã¦é©å½ã«æå®ããã¨å¾ã§æ³£ããè¦ããã¨ã«ãªãã®ã§ããã¯æ
éã«æ±ºãã¦ããã¾ããããã( åã¯æ³£ãã¾ãã )
- ãã©ã¤ãã¼ããµããããï¼ï¼ãããªãã¯ãµããããã£ã¦ä½ï¼ï¼
VPCã調ã¹ã¦ãã¦ãããåºã¦ããåèªã§ããã©ã¤ãã¼ããµãããããããããªãã¯ãµãããããã¨ãããã®ãããã¾ãã
å®ã¯å
ã
ããããè¨å®ãVPCã«åãã£ã¦ããã®ã§ã¯ãªãããã®ãµããããã®Route tables ã®è¨å®ã«ãã£ã¦ããã決ã¾ã£ã¦ãã¾ãã
Route tables 㧠0.0.0.0/0 (ããã©ã«ãã²ã¼ãã¦ã§ã¤ã¸ã®éä¿¡) ãã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤ã«æµãããããªè¨å®ã«ãªã£ã¦ããã®ãããããªãã¯ãµããããã ããã§ã¯ãªãã®ãããã©ã¤ãã¼ããµãããããã§ãã
åã¯ããããè¨å®ãããã®ãã¨æã£ã¦ãå°ä¸æéæ¢ãç¶ãã¦ãã¾ãã・・・
0.0.0.0/0 ã igw-xxxxxxx (ã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤) ã«æµããããã«ãªã£ã¦ããã®ã§ããã®ã«ã¼ããã¼ãã«ãè¨å®ããã¦ãããµããããã¯ãããªãã¯ãµããããã§ãã
ãã¡ãã®ã«ã¼ããã¼ãã«ã¯0.0.0.0/0 ã eni-xxxxxx/i-xxxxxxx(NATãªã©ã®ã¤ã³ã¹ã¿ã³ã¹) ã«æµããããã«ãªã£ã¦ããã®ã§ããã®ã«ã¼ããã¼ãã«ãè¨å®ããã¦ãããµããããã¯ãã©ã¤ãã¼ããµããããã«ãªãã¾ãã
ã¨ã¾ããç°¡åã«ã¾ã¨ããã¨å¤é¨ã¨éä¿¡ã§ãããµãããããããããªãã¯ãµãããããVPCå é¨ã¨ããéä¿¡ããªããµãããããããã©ã¤ãã¼ããµãããããã§ãï¼
VPCå é¨åã³ãVPNãDirectConnectãéãã¦æ¥ç¶ãããªã³ãã¬ç°å¢çã¨ãã©ã¤ãã¼ããªéä¿¡ããããµãããããããã©ã¤ãã¼ããµãããããã§ãï¼
- ãµããããã§æå®ããIPã¢ãã¬ã¹ã®ç¯å²ã®ãã¡ãæåã®4ã¤ã¨æå¾ã®1ã¤ã¯ä½¿ããªãï¼
åãµããããã®æåã®4ã¤ã¨æå¾ã®1ã¤ã®IPã¢ãã¬ã¹ã¯ Amazon ãäºç´ãã¦ãã¦ä½¿ããªãããã«ãªã£ã¦ãã¾ãï¼
ä¾ã¨ãã¦ããµããããã 10.1.0.0/24 ã®ãµãããã㧠å
é ãã2çªç®ã®ã¢ãã¬ã¹ 10.1.0.1ãæå®ããã¨ä»¥ä¸ã®æ§ãªã¨ã©ã¼ãåºã¦ãã¾ãã¾ãã
10.1.0.0/24 ã®ãµãããããä¾ã«ãã¦è¨ãã¨ãäºç´ããã¦ããã¢ãã¬ã¹ã¯10.1.0.0ã10.1.0.1ã10.1.0.2ã10.1.0.3ã10.1.0.255 ã®5ã¤ã§ãèªç±ã«ä½¿ããã®ã¯ãã以å¤ã® 251å ã®ã¢ãã¬ã¹ã«ãªãã¾ãã
â»åèãAmazon Virtual Private Cloud FAQ ( http://aws.amazon.com/jp/vpc/faqs/#I8 )
- EC2ã§ä½¿ã£ã¦ããSecurityGroupã¯ä½¿ããªãï¼
EC2ã®SecurityGroupã¨VPCå
ã§ä½¿ãSecurityGroupã¯å¥ç©ã§ãã
EC2ã®SecurityGroupã¯Inboundã ãè¨å®åºæ¥ãã®ã§ãããVPCã®SecurityGroupã¯
Outboundã¾ã§å¶å¾¡ãããã¨ãã§ãã¾ãã
- SecurityGroupã¯ç¥ã£ã¦ããã©ãNetworkACL (以ä¸ãNACL)ã£ã¦ä½ï¼
EC2ã§ã¯ã»ãã¥ãªãã£ã°ã«ã¼ãã ããè¨å®ããã°è¯ãã£ãã®ã§ãããVPCã«ã¯ãããã¯ã¼ã¯ã®I/Oãå¶å¾¡ããããã®è¨å®ãããä¸ã¤NACLã¨ãããã®ãããã¾ãã
ã©ã¡ããä»®æ³ã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®ãããªãã®ã¨ãã¦æ©è½ããã®ã§ãããSecurityGroupã¯ã¤ã³ã¹ã¿ã³ã¹åä½ãNACLã¯ãµããããåä½ã«è¨å®ãã¾ãã
- SecurityGroupãä»ãããå¤ããããèªç±ï¼
EC2ã®ã¤ã³ã¹ã¿ã³ã¹ãç«ã¡ä¸ããéã«SecurityGroupãæå®ããã¨æãã®ã§ãããã¿ãªãããåç¥ã®éãEC2ã®å ´åã¯ä¸åº¦ç´ä»ããSecurityGroupã¯å¤æ´ããäºãã§ãã¾ããã
ã§ãããVPCå
ã®EC2ã¤ã³ã¹ã¿ã³ã¹ã¯èªç±ã«SecurityGroupãä»ãæ¿ãããããã§ãï¼
ãããããããããâ
ãã®ããã«ãAWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããã§ãæ軽ã«å¤æ´ããäºãã§ãã¾ãã
ã¾ã¨ã
ä»åãåå¿è
ãæ°ã«ãªã£ãã»ãããããããã¤ã³ããã¾ã¨ããã¨ããå½¢ã§ããã°ãæ¸ããã¦ããã ãã¾ããã
VPCã¨ããæ¦å¿µãç解ããã¾ã§ã¯æéããããã¾ããããæ
£ãã¦ãã¾ãã°ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§ç°¡åã«ä½ãã¦ãã¾ãã¾ãã次ã¯ã³ãã³ãã©ã¤ã³ãã¼ã«ã§ææ¦ãã¦ã¿ããã§ãã
ã¾ããããããç ä¿®ãé²ãã¦ããä¸ã§ä»åã®ãããªããã£ã¦ãã¾ãå ´é¢ã¯ããããåºã¦ããã¨æãã®ã§ããã§æç« åãã¦å ±æãã¦çããã¨ä¸ç·ã«æé·ãã¦ãããã°ãªã¨æãã¾ãã
è¿½è¨ : AWS ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ãã®èæ¨æ§ãããææãããã ããã®ã§è¿½è¨ãã¾ãã
誤ï¼VPCå
é¨ã¨ããéä¿¡ããªããµãããã
â
æ£ï¼VPCå
é¨åã³ãVPNãDirectConnectãéãã¦æ¥ç¶ãã
ãããªã³ãã¬ç°å¢çã¨ãã©ã¤ãã¼ããªéä¿¡ããããµãããã
èæ¨æ§ãææãããã¨ããããã¾ãããåå¼·ã«ãªãã¾ããã