ããã«ã¡ã¯
4æã«æ°åã§å ¥ç¤¾ãã髿©ã§ããã¯ãããã®ã§ãã10æã§ãããç§ã¨ããã°ã¹ãã¼ãã§ããããã
ãã¦ä»åã¯AWSä¸ã«Windows Server 2012ã§VPNãµã¼ããç«ã¦ã¦ã¿ããã¨æãã¾ãã
æ§æå³ã¯ä¸ã®éãã§ãã
VPCå ã®Publicãµããããã«ããVPN Serverãçµç±ããPrivateãµããããå ã®Targetã¤ã³ã¹ã¿ã³ã¹ã¨éä¿¡ãã¦ã¿ããã¨æãã¾ããéä¿¡ã¯L2TP/IPsecãæ¡ç¨ãã¾ãã
ã»ãã¥ãªãã£ã°ã«ã¼ã
Targetã¤ã³ã¹ã¿ã³ã¹ã®ã»ãã¥ãªãã£ã°ã«ã¼ãã¯ãVPN Serverã®ã»ãã¥ãªãã£ã°ã«ã¼ãããã®Inboundã¢ã¯ã»ã¹ã®ã¿ã«çµããã¨ãå¯è½ã§ãã
VPNãµã¼ãã®è¨å®
- VPN Serverã®è¨å®ãè¡ãã¾ãã
è¨å®ã®æ¹æ³ã¯ä¸è¨ã®ãªã³ã¯ãåèã«è´ãã¾ãã
WindowsServer2012ã§VPNãµã¼ãã¼ãç«ã¦ã¦ã¿ã - ã¾ã½ãã2chãPPTPãã¼ã(1723çª)ãéãã¦ããã¨å¼¾ããããã®ã§L2TPã«ç§»è¡ãã¦ã¿ã - ã¾ã½ãã ããã§ä¸ã¤æ³¨æãããå½¹å²ã¨æ©è½è¿½å ã®ã¦ã£ã¶ã¼ããã§ããªã¢ã¼ãã¢ã¯ã»ã¹ã®ãDirectAccessããã³VPNãã ãã§ãªããã«ã¼ãã£ã³ã°ããã¤ã³ã¹ãã¼ã«ãã¦ãã ããã
- 次ã«ãã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ãã¢ã¯ã»ã¹ãã®ç»é¢ã«æ»ããIPv4ã®å
¨è¬ãå³ã¯ãªãã¯ããæ°ãããã«ã¼ãã£ã³ã°ãããã³ã«ããããNATãã鏿ãã¾ãã
ããã§ã追å ã®ãããã³ã«ã¯åå¨ãã¾ãããçã®ã¨ã©ã¼ã¡ãã»ã¼ã¸ãåºãå ´åã¯ãIPv4ãå³ã¯ãªãã¯ãããææ°ã®æ å ±ã«æ´æ°ããã¯ãªãã¯ãã¦ãã ããã æ¬¡ã«ã¤ã³ã¿ãã§ã¼ã¹ã¯ã¤ã¼ãµãããã鏿ãããã¤ã³ã¿ã¼ãããã«æ¥ç¶ããããããªãã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ãã鏿ãOKãæ¼ãã¾ãã
- æ¬¡ã«æ¥ç¶ã«è¨å®ããã¦ã¼ã¶ã°ã«ã¼ãå
ã®ã¦ã¼ã¶ã®è¨å®ãè¡ãã¾ãã
ã管çãã¼ã«ã>ãã³ã³ãã¥ã¼ã¿ã¨ç®¡çã>ããã¼ã«ã«ã¦ã¼ã¶ã¨ã°ã«ã¼ãã
ããå ã»ã©è¨å®ãããæ¥ç¶ããã¦ã¼ã¶ã¼ã°ã«ã¼ããã«å«ã¾ãã¦ããããã¤æ¥ç¶ã«å©ç¨ããã¦ã¼ã¶ãå³ã¯ãªãã¯ããããããã£ã鏿ããããã¤ã¤ã«ã¤ã³ãã¿ãã®ããªã¢ã¼ãã¢ã¯ã»ã¹ã許å¯ãã«ãã§ãã¯ãå ¥ããOKãã¿ã³ãæ¼ãã¾ãã - 次ã«Windowsãã¡ã¤ã¢ã¦ã©ã¼ã«ãå ¨ã¦ç¡å¹åãã¦ãã ããã
- ããã§çµãããããã§ã¯ããã¾ããããã¨ããå°ãã§ããé å¼µãã¾ãããã
次ã«ãL2TPãããã³ã«ã§VPNæ¥ç¶ããéã®äºåå ±æãã¼ã®è¨å®ããã¾ãããã ãµã¼ãã¹ç»é¢ãå³ã¯ãªãã¯ããããããã£ãé¸ã³ã¾ãã
ã»ãã¥ãªãã£ã¿ãã鏿ãããã«ã¹ã¿ã IPsecããªã·ã¼ãL2TP/IKEv2æ¥ç¶ã§è¨±å¯ãããã«ãã§ãã¯ããäºåå ±æãã¼ãè¨å®ãã¾ããï¼å³ã§ã¯"poteto"ï¼ - ãã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ãã¢ã¯ã»ã¹ãã®ç»é¢ã®ãã¼ã«ã«ãµã¼ããå³ã¯ãªãã¯ããããããã£ãã鏿ãã¾ãããIPv4ãã¿ãã®ãIPv4 ã¢ãã¬ã¹ã®å²ãå½ã¦ããããéçã¢ãã¬ã¹ãã¼ã«ã使ããã鏿ãã¾ãã
ã追å ããã¯ãªãã¯ããã¯ã©ã¤ã¢ã³ãå´ã«ä»ä¸ããIPã¢ãã¬ã¹ã®ã¬ã³ã¸ãæå®ãã¾ãã
- ããæå¾ã«ãã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ãã¢ã¯ã»ã¹ãã®ç»é¢ã§ãµã¼ãã¹ãåèµ·åããã°ãVPNãµã¼ãå´ã®è¨å®ã¯çµããã§ãã
ã¤ã¾ã¥ããã¤ã³ã
ããã§VPNãµã¼ãã®è¨å®ãå®äºãã¾ããããããæå¾ã«ä¸ã¤ã ãAWSå´ã§è¨å®ããªãã¦ã¯ãããªããã®ãããã¾ããããã¯ãéä¿¡å /éä¿¡å ãã§ãã¯ãç¡å¹ã«ãããã§ãã
ï¼éä¿¡å /éä¿¡å ãã§ãã¯ï¼æ©è½ã¯ããã©ã«ãã§ã¯æå¹ã«ãªã£ã¦ãã¾ãããã®æ©è½ãæå¹ã«ãªã£ã¦ããã¤ã³ã¹ã¿ã³ã¹ã§ã¯ããã©ãã£ãã¯ã®å®å ãèªåèªèº«ä»¥å¤ã®å ´åãAWSå´ã§ãã®ãã©ãã£ãã¯ãå¼¾ãã¦ãã¾ãã¾ããVPNãµã¼ãã§ã¯Targetã¤ã³ã¹ã¿ã³ã¹åãã®ãã±ãããåãåãå¿ è¦ãããããããã®æ©è½ãç¡å¹å ãã¦ãããªãã¨ã«ã¼ãã£ã³ã°ãã§ããªããªãã¾ããï¼åèï¼éä¿¡å /éä¿¡å ãã§ãã¯ãç¡å¹ã«ããï¼
è¨å®ã®ä»æ¹ã¯ç°¡åã§ããããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§VPNãµã¼ãã鏿ãããActionsãããChange Source/Dest Checkããé¸ã³ã
[Yes,Disable]ãã¯ãªãã¯ãã¾ããããã§è¨å®ã¯å®äºã§ãã
AWSå´ã§ã®è¨å®å¤æ´ã«å°ãæéããããå ´åãããã¾ããã³ã¼ãã¼ã§ã飲ãã§è¨å®å¤æ´ãå®äºããã¾ã§å¾
ã¡ã¾ãããã
確èª
æå¾ã«æ¥ç¶ç¢ºèªããã¦ã¿ã¾ããããMacã§ã¯ãVPNæ¥ç¶è¨å®ã®ã詳細ãå ã®ããã¹ã¦ã®ãã©ãã£ãã¯ãVPNæ¥ç¶çµç±ã§éä¿¡ãã®ãã§ãã¯ãå¤ããã¨ã§ãã¤ã³ã¿ã¼ãããã¨ã®éä¿¡ã¯VPNãçµç±ããªãã§è¡ããã¨ãã§ãã¾ãã
試ãã«Targetã¤ã³ã¹ã¿ã³ã¹ã¨éä¿¡ã§ããã確èªãã¦ã¿ã¾ãã
$ traceroute 10.0.1.105 traceroute to 10.0.1.105 (10.0.1.105), 64 hops max, 52 byte packets 1 10.1.0.0 (10.1.0.0) 6.374 ms 4.841 ms 4.826 ms 2 * * * 3 10.0.1.105 (10.0.1.105) 6.615 ms 8.231 ms 8.002 ms
ãããã¡ããã¨ã§ãã¦ãã¾ããã æ¬¡ã¯ã¿ã¼ã²ããã®ã¤ã³ã¹ã¿ã³ã¹ã«ãã°ã¤ã³ããtcpdumpãå©ç¨ãã¦ã©ãããéä¿¡ãåãã¦ããã確èªãã¾ãã
[ec2-user@ip-10-0-1-105 ~]$ sudo tcpdump port 22 -c 10 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes 06:59:26.133635 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 3418137445:3418137561, ack 3260914754, win 306, options [nop,nop,TS val 765889 ecr 712173948], length 116 06:59:26.133717 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 116:232, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 116 06:59:26.134764 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 232:444, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 212 06:59:26.134808 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 444:640, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 196 06:59:26.134864 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 640:836, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 196 06:59:26.134914 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 836:1032, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 196 06:59:26.134976 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 1032:1424, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 392 06:59:26.135015 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 1424:1620, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 196 06:59:26.135053 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 1620:1816, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 196 06:59:26.135089 IP 10.0.1.105.ssh > 10.0.0.240.62576: Flags [P.], seq 1816:2012, ack 1, win 306, options [nop,nop,TS val 765890 ecr 712173948], length 196 10 packets captured 10 packets received by filter 0 packets dropped by kernel
å°ãåããã«ããã§ãããVPNãµã¼ãï¼10.0.0.240ï¼ããéä¿¡ãåãã¦ãããã¨ã確èªã§ãã¾ããã
è¨å®ããã¦ããä¸ã§ãéä¿¡å /éä¿¡å ãã§ãã¯ãç¡å¹ã«ãããã«æ°ã¥ãããæéãããªãæ¶è²»ãã¦ãã¾ãã¾ãããæ¬è¨äºã¯ããã§çµããã§ããAWSã便å©ã«ä½¿ãããªããæ¥½ãã人çã謳æãã¾ãããã