ããã«ã¡ã¯ãæè¡1課ã§ã®OJTä¸ã®ãæ°äººã®ä¸å±±ã§ãã
ä»åã¯ãWindows Server 2008 R2 ãã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ãã¦è¨å®ãã¦ãVPN æ¥ç¶ãè¡ãã¾ãã
VPC ãæ°ããä½æã㦠æå
ã®ãããã¯ã¼ã¯ã«åå¨ãã Windows Server ããç¹ãã¾ããæå
ã®ãããã¯ã¼ã¯ã¨ãã¦ãä»åã¯å¥ã® VPC ãç¨ãã¾ããVPC Peering ã使ãããã§ã¯ããã¾ããã
æå ã®ãããã¯ã¼ã¯ã® CIDR ã 172.31.0.0/16ãVPN æ¥ç¶ãããã VPC ã® CIDR ã 10.0.0.0/16 ã¨ãã¾ãã
ããã°ã®æµãã¯ä»¥ä¸ã®éãã§ãã
- ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ãã¦ã® Windows Server 2008 R2 (以ä¸ãWindows Server) ã®èµ·å
- Windows Server ã®è¨å®
- VPC ãCGWãVGW ã®ä½æ
- VPN æ¥ç¶ã®ä½æ
- netsh ã¹ã¯ãªãããå®è¡ã㦠VPN ãã³ãã«ãè¨å®ãã
- Windos ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®è¨å®
- åæ¢ãã¦ããã²ã¼ãã¦ã§ã¤ã®æ¤åº
- VPN æ¥ç¶ã®ãã¹ã
1. ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ãã¦ã® Windows Server ã®èµ·å
EC2ã³ã³ã½ã¼ã«ãéãã¾ãã
ã¤ã³ã¹ã¿ã³ã¹ã以ä¸ã®éãã«ä½æãã¾ãã
- AMI ã® ID 㯠[ami-58309b58] ãé¸æãã¾ãã
- èªåå²ãå½ã¦ãããªã㯠IP 㯠[ç¡å¹å] ã«ãã¾ãã
- Elastic IP ã¢ãã¬ã¹ãç´ã¥ãã¾ãã
2. Windows Server ã®è¨å®
-
Windows Server ã® [éä¿¡å
/éä¿¡å
ãã§ãã¯] ã®ç¡å¹å
EC2 ã³ã³ã½ã¼ã«ãéãã¾ãã
ããã²ã¼ã·ã§ã³ãã¤ã³ã§ã[ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹] ãé¸æãã¾ãã
ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¤ã¹ãé¸æããå³ã¯ãªãã¯ãã[éä¿¡å
/ éä¿¡å
ã®å¤æ´ãã§ãã¯] ãé¸æãã¾ãã
ãã¤ã¢ãã°ããã¯ã¹ã§ [ç¡å¹] ãé¸æãã¦ã[ä¿å] ãã¯ãªãã¯ãã¾ãã
-
Windows ã¢ããã¿è¨å®ã®æ´æ°
ã¢ããã¿è¨å®ãæ´æ°ããªãã¨ãä»ã®ã¤ã³ã¹ã¿ã³ã¹ããã®ãã©ãã£ãã¯ãã«ã¼ãã£ã³ã°ã§ããªããªããã¨ãããã¨ã®ãã¨ã§ãã
Windows Server ã«æ¥ç¶ãã¾ããæ¥ç¶æ¹æ³ã¯ãã¡ãã [ã³ã³ããã¼ã«ããã«] ãã[ããã¤ã¹ããã¼ã¸ã£ã¼]ãéãã[ãããã¯ã¼ã¯ã¢ããã¿ã¼]ã[Citrix PV Ethernet Adapter #0] ã¨é¸æãã¦ããã¾ãã Citrix PV Ethernet Adapter #0 ããããã£ã® [詳細è¨å®] ã¿ãã§ã[IPv4 Checksum Offload]ã[TCP Checksum Offload (IPv4)]ã[UDP Checksum Offload (IPv4)] ããããã£ã®å¤ã [Disabled] ã«ãã[OK] ãã¯ãªãã¯ãã¾ãã -
Windows Server ã«ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ãã¢ã¯ã»ã¹ãµã¼ãã¹ã®ã¤ã³ã¹ãã¼ã«
ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ãã¢ã¯ã»ã¹ãµã¼ãã¹ãã¤ã³ã¹ãã¼ã«ãã¦è¨å®ãããã¨ã§ããªã¢ã¼ãã¦ã¼ã¶ã¼ããããã¯ã¼ã¯ä¸ã®ãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãã¾ãã
Windows Server ã«ãã°ã¤ã³ãã¦ã [Server Manager] ãéãã¾ãã
[å½¹å²] ãé¸æãã¦ã[å½¹å²ã®è¿½å ] ãã¯ãªãã¯ãã¾ãã
[éå§ããåã«] ãã¼ã¸ã§ãè¦ä»¶ã確èªã㦠[次ã¸] ãã¯ãªãã¯ãã¾ãã [ãµã¼ãã¼ã®å½¹å²ã®é¸æ] ãã¼ã¸ã§ã[ãããã¯ã¼ã¯ããªã·ã¼ã¨ã¢ã¯ã»ã¹ãµã¼ãã¹] ããã§ãã¯ãã¦ã[次ã¸] ãã¯ãªãã¯ãã¾ãã
[ãããã¯ã¼ã¯ ããªã·ã¼ã¨ã¢ã¯ã»ã¹ ãµã¼ãã¹] ãã¼ã¸ã§ [次ã¸] ãã¯ãªãã¯ãã¾ãã [å½¹å²ãµã¼ãã¹ã®é¸æ] ãã¼ã¸ã§ [ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹ ãµã¼ãã¹] ããã§ãã¯ãã¾ãã[ã«ã¼ãã£ã³ã°] 㨠[ãªã¢ã¼ã ã¢ã¯ã»ã¹] ããã§ãã¯ããã¾ã¾ [次ã¸] ãã¯ãªãã¯ãã¾ãã
[ã¤ã³ã¹ãã¼ã«ãªãã·ã§ã³ã®ç¢ºèª] ãã¼ã¸ã§ã[ã¤ã³ã¹ãã¼ã«] ãã¯ãªãã¯ãã¾ãã
-
ã«ã¼ãã£ã³ã°ããã³ãªã¢ã¼ãã¢ã¯ã»ã¹ãµã¼ãã¼ã®è¨å®ã¨æå¹å
ãµã¼ãã¼ããã¼ã¸ã£ã¼ã§ [å½¹å²] ãå±éãã¦ã次ã«[ãããã¯ã¼ã¯ ããªã·ã¼ã¨ã¢ã¯ã»ã¹ ãµã¼ãã¹]ãå±éãã¾ãã
[ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹ ãµã¼ãã¼ ]ãå³ã¯ãªãã¯ãã¦ã[ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹ã®æ§æã¨æå¹å] ãé¸æãã¾ãã
[ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹ ãµã¼ãã¼ã®ã»ããã¢ããã¦ã£ã¶ã¼ã] ã® [ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹ ãµã¼ãã¼ã®ã»ããã¢ãã ã¦ã£ã¶ã¼ãã®éå§] ãã¼ã¸ã§ã[次ã¸] ãã¯ãªãã¯ãã¾ãã
[æ§æ] ãã¼ã¸ã§ã[ã«ã¹ã¿ã æ§æ] ããã§ãã¯ãã[次ã¸] ãã¯ãªãã¯ãã¾ãã
[LAN ã«ã¼ãã£ã³ã°] ããã§ãã¯ãã[次ã¸] ãã¯ãªãã¯ãã¾ãã
[ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹ ãµã¼ãã¼ã®ã»ããã¢ãã ã¦ã£ã¶ã¼ãã®å®äº] ãã¼ã¸ã§ã[å®äº] ãã¯ãªãã¯ãã¾ãã [ã«ã¼ãã£ã³ã°ã¨ãªã¢ã¼ã ã¢ã¯ã»ã¹] ã®ãã¤ã¢ãã°ããã¯ã¹ã表示ãããã®ã§ã[ãµã¼ãã¹ã®éå§] ãã¯ãªãã¯ãã¾ãã
3. VPC ã® VPN ã®ããã®ã³ã³ãã¼ãã³ãã®ä½æã»è¨å®
- VPC ã®ä½æ ä»åã¯ããããã¯ã¼ã¯ã® CIDR ã10.0.0.0/16 ã¨ãã¾ãã
- ãã©ã¤ãã¼ããµããããã®ä½æ ä½æãã VPC ã«ãã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤ã¸ã®ã«ã¼ãããªããã©ã¤ãã¼ããµãããããä½æãã¾ãã
-
ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã®ä½æ
ä½æããã¨ããããã¯ãVPC å´ã§ã«ã¹ã¿ãã²ã¼ãã¦ã§ã¤ãæå®ããã¨ããã¤ã¡ã¼ã¸ã§ãã
ã¾ãVPC ã³ã³ã½ã¼ã«ãéãã¾ãã
ããã²ã¼ã·ã§ã³ãã¤ã³ã§ [ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤] ãé¸æãã¦ã[ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã®ä½æ] ãã¯ãªãã¯ãã¾ãã
ã«ã¼ãã£ã³ã°ã¯ [éç] ãé¸æãã¾ããIP ã¢ãã¬ã¹ã«ã¯ Windows Server ã® [Elasitc IP ã¢ãã¬ã¹]ãå
¥åãã¾ããããã¦ã[ä½æ] ãã¯ãªãã¯ãã¾ãã
-
VGW ã®ä½æãVPC ã¸ã®ã¢ã¿ãã
VPC ã³ã³ã½ã¼ã«ã®ããã²ã¼ã·ã§ã³ãã¤ã³ã§ [ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤] ãé¸æãã¦ã[ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ã®ä½æ] ãã¯ãªãã¯ãã¾ãã
ãã¤ã¢ãã°ããã¯ã¹ã表示ãããã®ã§ã[ä½æ] ãã¯ãªãã¯ãã¾ãã ä½æããä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ãé¸æãã¦ã[VPCã«ã¢ã¿ãã] ãã¯ãªãã¯ãã¾ãã
ã¢ã¿ãããã VPC ãé¸æãã¦ã[ä½æ] ãã¯ãªãã¯ãã¾ãã
-
VPN æ¥ç¶ã®ã«ã¼ãã£ã³ã°
ãã©ã¤ãã¼ããµããããã®ã«ã¼ããã¼ãã«ã«ã«ã¼ãã追å ãã¾ãã
éä¿¡å ã¯ããããã¯ã¼ã¯ã® CIDR (172.31.0.0/16)ãã¿ã¼ã²ããã«ã¯å ã»ã©ä½æããä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ãå ¥åãã¾ãã ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ã¸ã®ã«ã¼ãä¼éãæå¹ã«ãã¾ãã
ã«ã¼ããã¼ãã«ã® [ã«ã¼ãä¼é] ã¿ããéãã[ç·¨é] ãã¯ãªãã¯ãã¾ãã
[ä¼é] ããã§ãã¯ãã¦ãä¿åãã¾ãã
4. VPN æ¥ç¶ã®ä½æ
-
VPN ã®ä½æ
ã¾ãVPCã³ã³ã½ã¼ã«ãéãã¾ãã
ããã²ã¼ã·ã§ã³ãã¤ã³ã® [VPN æ¥ç¶] ãã¯ãªãã¯ãã[VPN æ¥ç¶ã®ä½æ] ãã¯ãªãã¯ãã¾ãã
[VPN æ¥ç¶] ã®ãã¤ã¢ãã°ããã¯ã¹ã§ãã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ãé¸æããã«ã¼ãã£ã³ã°ãªãã·ã§ã³ã® [éç] ããã§ãã¯ãã¾ããéç IP ãã¬ãã£ã¯ã¹ã«ã¯ããããã¯ã¼ã¯ã® CIDR ãå ¥åãã¾ããå ¥åå¾ã« [ä½æ] ãã¯ãªãã¯ãã¾ãã
-
VPN æ¥ç¶ã®è¨å®ãã¡ã¤ã«ã®ãã¦ã³ãã¼ã
VPC ã³ã³ã½ã¼ã«ã§ãä½æãã VPN ãé¸æãã¦ã[è¨å®ã®ãã¦ã³ãã¼ã] ãã¯ãªãã¯ãã¾ãã
ãã³ãã¼ã¯ [Microsoft]ããã©ãããã©ã¼ã 㯠[Windows Server]ãã½ããã¦ã§ã¢ã¯ [2008 R2] ãé¸æãã¦ã[ãã¦ã³ãã¼ã] ãã¯ãªãã¯ãã¾ãã
ããã§è¨å®ãã¡ã¤ã«ããã¦ã³ãã¼ãã§ãã¾ããã
5. netsh ã¹ã¯ãªãããå®è¡ãã¦ãVPN ãã³ãã«ãè¨å®ãã
AWSã§VPNãå¼µãå ´åã¯åé·åæ§æãããã©ã«ãã§ãããã£ã¦ããã³ãã«ã2æ¬è¨å®ãã¾ãã
è¨å®ãã¡ã¤ã«ã«ã¯æ¬¡ã®ãã㪠netsh ã¹ã¯ãªããã®ã»ã¯ã·ã§ã³ã2ã¤å«ã¾ãã¦ãã¾ãããã³ãã«ãã¨ã«1ã¤ãã¤ã§ãã
! Script for Tunnel 1:
netsh advfirewall consec add rule Name="vgw-b0ee58b1 Tunnel 1" ^
Enable=Yes Profile=any Type=Static Mode=Tunnel ^
LocalTunnelEndpoint=[Windows_Server_Private_IP_address] ^
RemoteTunnelEndpoint=103.246.152.29 Endpoint1=[Your_Static_Route_IP_Prefix] ^
Endpoint2=[Your_VPC_CIDR_Block] Protocol=Any Action=RequireInClearOut ^
Auth1=ComputerPSK Auth1PSK=xxxxxxxx ^
QMSecMethods=ESP:SHA1-AES128+60min+100000kb ^
ExemptIPsecProtectedConnections=No ApplyAuthz=No QMPFS=dhgroup2 ! Script for Tunnel 2:
netsh advfirewall consec add rule Name="vgw-b0ee58b1 Tunnel 2" ^
Enable=Yes Profile=any Type=Static Mode=Tunnel ^
LocalTunnelEndpoint=[Windows_Server_Private_IP_address] ^
RemoteTunnelEndpoint=103.246.152.39 Endpoint1=[Your_Static_Route_IP_Prefix] ^
Endpoint2=[Your_VPC_CIDR_Block] Protocol=Any Action=RequireInClearOut ^
Auth1=ComputerPSK Auth1PSK=xxxxxxxx ^
QMSecMethods=ESP:SHA1-AES128+60min+100000kb ^
ExemptIPsecProtectedConnections=No ApplyAuthz=No QMPFS=dhgroup2
[]ã§å²ã¾ãã¦ããé¨åã®ãã©ã¡ã¼ã¿ãç½®ãæãã¾ãã
[Windows_Server_Private_IP_address] ã¯ãããã¯ã¼ã¯ã® Windows Server ã®ãã©ã¤ãã¼ã IP ã¢ãã¬ã¹ã§ç½®ãæãã¾ãã
[Your_Static_Route_IP_Prefix] 㯠Windows Server ãåå¨ãããããã¯ã¼ã¯ã® CIDR ã§ç½®ãæãã¾ãã
[Your_VPC_CIDR_Block] 㯠VPC ã® CIDR ã§ç½®ãæãã¾ãã
Windows Server ã®ã³ãã³ãããã³ããã§ããã©ã¡ã¼ã¿ãç½®ãæããã¹ã¯ãªãããå®è¡ãã¾ãã
6.Windows ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®è¨å®
[ãµã¼ãã¼ããã¼ã¸ã£ã¼] ãéãã[æ§æ]ã[ã»ãã¥ãªãã£ãå¼·åããã Windows ãã¡ã¤ã¢ã¦ã©ã¼ã«]ã[ããããã£] ã¨é²ãã¦ããã¾ãã
[IP sec ã®è¨å®] ã¿ã㧠[IP sec æ¢å®] ã®é
ç®ã® [ã«ã¹ã¿ãã¤ãº] ãã¯ãªãã¯ãã¾ãã
[ãã¼äº¤æ (ã¡ã¤ã³ ã¢ã¼ã)] ã®é
ç®ã® [詳細è¨å®] ã«ãã§ãã¯ãå
¥ã㦠[ã«ã¹ã¿ãã¤ãº] ãã¯ãªãã¯ãã¾ãã
[ãã¼äº¤æãªãã·ã§ã³] ã® [Diffie-Hellman ã使ç¨ãã¦ã»ãã¥ãªãã£ãå¼·åãã] ããã§ãã¯ãã¦ã[OK] ãã¯ãªãã¯ãã¾ãã
[ãã¼ã¿ä¿è· ã¯ã¤ãã¯ã¢ã¼ã)] ã®é
ç®ã® [詳細è¨å®] ã«ãã§ãã¯ãå
¥ãã¦ã[ã«ã¹ã¿ãã¤ãº] ãã¯ãªãã¯ãã¾ãã
[ãã®è¨å®ã使ç¨ãããã¹ã¦ã®æ¥ç¶ã»ãã¥ãªãã£è¦åã«æå·åãè¦æ±ãã] ã«ãã§ãã¯ãå
¥ãã¦ã[OK] ãã¯ãªãã¯ãã¾ãã
7. åæ¢ãã¦ããã²ã¼ãã¦ã§ã¤ã®æ¤åº
Windows Server ã§ã¬ã¸ã¹ã㪠ã¨ãã£ã¿ãèµ·åãã¾ãã
[HKEY_LOCAL_MACHINE]ã[SYSTEM]ã[CurrentControlSet]ã[Service]ã[Tcpip]ã[Paremeters] ã¨å±éãã¾ãã
å³å´ã®ãã¤ã³ã§å³ã¯ãªãã¯ãã[æ°è¦]ã[DWORD (32-bit) Value] ã¨é²ãã¾ãã
åå㯠[EnableDeadWDetect] ãå ¥åãã¾ãã
[EnableDeadWDetect] ãå³ã¯ãªãã¯ãã[ä¿®æ£] ãéãã¾ãã
[å¤ã®ãã¼ã¿] ã« [1] ãå
¥åãã[OK] ãã¯ãªãã¯ãã¾ãã
ã¬ã¸ã¹ããªã¨ãã£ã¿ãçµäºããWindows Server ãåèµ·åãã¾ãã
8. VPN ã®æ¥ç¶ãã¹ã
-
ãããã¯ã¼ã¯ã¨ VPC ã®éã®éä¿¡ã®è¨±å¯ãã»ãã¥ãªãã£ã°ã«ã¼ãã®ä½æ
ãããã¯ã¼ã¯ããã®ãã©ãã£ãã¯ã許å¯ããã«ã¼ã«ãä½æãã¾ãã - VPC ã®ãã©ã¤ãã¼ããµããããã«ã¤ã³ã¹ã¿ã³ã¹ãèµ·åãã
-
ping ã®éä¿¡
Windows Server ãããå ç¨ä½æããã¤ã³ã¹ã¿ã³ã¹ã®ãã©ã¤ãã¼ã IP ã¢ãã¬ã¹ã対象ã«ãã¦ãping ãå®è¡ãã¾ãã
æ¥ç¶ã§ãã¾ããã VPC ã³ã³ã½ã¼ã«ãããããã³ãã«ã®ã¹ãã¼ã¿ã¹ã [Up] ã«ãªã£ã¦ãããã¨ã確èªã§ãã¾ãã
ã¡ãªã¿ã«ãWindows Server ã® Windows ãã¡ã¤ã¢ã¦ã©ã¼ã«ãç¡å¹ã«ããã¨ãããIPsec ã®ãã©ãã£ãã¯ãæµããªããªãã¾ããã
AWS ãµãã¼ãã«åãåããã¦ã¿ãã¨ããã
Windowsã®æ©è½ã®ä¸é¨ã§ãããWindows Firewall with Advanced Securityãã«ãã£ã¦VPNãã³ãã«ãå©ç¨ãã¦ãã¾ãã VPNãIPSecãç¨ããã»ãã¥ãªãã£æ©è½ã®ä¸ã¤ã§ãããåããã»ãã¥ãªãã£ç¢ºä¿ã®ããã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®ä¸é¨ã®æ©è½ã¨ãªã£ã¦ãã¾ãã ãã£ã¦Windowsã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ãç¡å¹åããå ´åã«ã¯æ¬æ©è½ãå©ç¨ã§ããªããªã£ã¦ããå¯è½æ§ããããã¾ãã
ã¨ãããã¨ãããã§ãã
ã¾ã¨ã
ä»å㯠Windows Server 2008 R2 ãã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ãã¦è¨å®ãã¦ãVPN æ¥ç¶ãè¡ãæ¹æ³ããç´¹ä»ãã¾ããã
ç§èªèº« VPN ã«è§¦ããã®ã¯åãã¦ã§ããããAWS ã®ããã¥ã¡ã³ããåãããããã£ãã®ã§ç¡äºã«æ¥ç¶ããããã¨ãã§ãã¾ãããåèãã¼ã¸ã¯ãã¡ãã
ç´°ããè¨å®ãå¹¾ã¤ããã£ã¦ãããããã§ãããã¡ã¤ã³ã®ãã³ãã«ã®è¨å®ã¯ãããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãããã¦ã³ãã¼ãããè¨å®ãã¡ã¤ã«ã«è¨è¼ããã¦ããã¹ã¯ãªããã§æ¸ãã§ãã¾ãã¾ããã
Windows server 以å¤ã«ãVPC ã§ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ãã¦æ©è½ããããã¤ã¹ã¯å¤ãããã®ã§ãè²ã
ã¨è©¦ãã¦ã¿ããã§ãã
以ä¸ã§ããæå¾ã¾ã§èªãã§ãã ãã£ã¦ãããã¨ããããã¾ããã