大éªãªãã£ã¹ã®å¯ºç°ã§ãã
ãããæ¥ã¨åãã大éªãªãã£ã¹ã«æ»å¨ä¸ã®å¯ºç°ã§ãã
æ¨æ¥ã大éªã®re:Inventã«è¡ããªãã£ãããããã¯è¡ããªãã£ãã¡ã³ãã¼ã§è¡ã£ã¦ãã re:Ikenvent ã¨ç§°ããåã¿ä¼ã«åå ããã¦ãããã¾ããã
æªããå±
é
å±ã§ããªããããå¼ãã§éè³ãå½ã¦ã人ããããã¨ãå°ãªã人æ°ãªãããã£ã¡ããªæãã§æ¥½ããã£ãã§ãã
ã§ããAWSã®æè¡çãªè©±ã¯ã»ã¨ãã©ããè¨æ¶ãããã¾ããã飲ã¿ãããããã§ã¯ãªãã¯ããªã®ã§ããã
ã¨ã¯ãããããã¯æè¡blogã
æ°ããåºããµã¼ãã¹ã§éãã§ã¿ããã¨æãã¾ãã
IPv6ãVPCã¨EC2ã«æ¥ãã®ã§è©¦ãã¦ã¿ã
IPv4ã®æ¯æ¸åé¡ããããå
¨ä¸ççã«IPv6ã®ç§»è¡ããªããã¦ããããã§ããã
AWSã§ã S3, Cloud Front WAF, Route53 ã¨å¾ã
ã«IPv6ã¸ã®å¯¾å¿ãé²ãã§ãã¾ããã
ã§ããèå¿ã®ã³ã³ãã¥ã¼ãã£ã³ã°ãªã½ã¼ã¹ãç¡ãã¨ãIPv6ã«å¯¾å¿ãããã©ã©ã使ãããã¨ããã¨ããã§ããã
ããã§ä»åã®VPCã¨EC2ã®IPv6対å¿ã§ãã
å
¬å¼blogã¸ã®ãªã³ã¯ã¯ãã¡ãã§ã
Egress-Only Internet Gateway (EGW)
IPv6ã«ãªããã¨ã§ã大éã®ã¢ãã¬ã¹ãå©ç¨å¯è½ã«ãªãã¾ãã®ã§ã
Elastic IPãGlobal IPããã¡ãã¡ã¢ã¿ããããªãã¦ããã¤ã³ã¿ã¼ãããå´ããIPv6ã®ã¢ãã¬ã¹ã§EC2ã«ç°¡åã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã¾ãã
éã«ãIPv6ã®ã¢ãã¬ã¹ãã¢ãµã¤ã³ãã¦ãã¾ãã¨ãå
¨ä¸çã«å
¬éããã¦ãã¾ãã®ã§ãå¤ããå
¥ããªãä»çµã¿ãèããå¿
è¦ãããã¾ãã
ããã§ãEGWã¨ããGWãæ°ãã«è¿½å ããã¾ããã
Inboundãç¡ãSecurity Groupã®ãVPCç(IPv6)ã®æ§ãªå®è£
ã«ãªã£ã¦ããããã§ãã
IPv4ã§å¿
è¦ã ã£ãNAT GWãè¦ããªããªããã財å¸çã«ã¯åªãããªãã¾ãã
ä½è«ã§ãããæè¡æ¤è¨¼ããã¨ãã¯ã
t2ã¤ã³ã¹ã¿ã³ã¹ããªã³ããã³ãã§ç«ã¡ä¸ãããããm3.medium ã c4.large ãã¹ãããã§èµ·åããã»ããå®ãã®ã§ããã
ç¾å¨ã®ã¨ãããã¹ãããã§ç«ã¡ä¸ããã¨IPv6ãã¤ããªããããªã®ã§ãæã§ä»ãã¦ãããå¿
è¦ãããã¾ãã
å®éã«ä½ã£ã¦ã¿ã
ä»åã®IPv6ã®å¯¾å¿ã¯ç¾å¨ã®ã¨ãããªãã¤ãªãªã¼ã¸ã§ã³ã ãã§ãã®ã§ã
ãªãã¤ãªã§ä½ã£ã¦ããã¾ãã
ä»ã®ã¨ãããä»ã¾ã§ã«ä½ã£ãVPCãIPv6ã«å¯¾å¿ããã®ã§ã¯ãªãã
æ°ããVPCãä½ããããã§IPv6ãæå¹ã«ããããé¸ã¶å¿
è¦ãããã¾ãã
æ¢åã®VPCã«IPv6ã®CIDRãã¢ãµã¤ã³ãããã¨ãå¯è½ã¨ãªã£ã¦ãã¾ãã
SubnetãåãããIPv6ã®ã¢ãã¬ã¹ãã¢ã¿ããããããé¸æããå½¢ã«ãªãã¾ãã
å¾ã¯ãä»ã¾ã§éããInternet Gateway(IGW)ãã¢ã¿ãããã¦ã
ã«ã¼ãã£ã³ã°ãã¼ãã«ãè¨å®ãã
Security Groupãä½ãå¿
è¦ãããããã§ããã
ã«ã¼ãã£ã³ã°ãã¼ãã«ã¨ãSecurity Groupã«æ¸ãã¢ãã¬ã¹ã¯ã
IPv6ã§æ¸ãå¿
è¦ãããã¾ãã
次ã«EC2ãä½æãã¦ããã¾ãã
ä»åã¯ãIPv6ã§éã³ããã®ã§ãIPv4ã®Global IPã¯è¨å®ããªãå½¢ã«ãã¾ãã
EC2ã®è©³ç´°é
ç®ã«ãIPv6ã®è¨å®ã表示ãããããã«ãªã£ã¦ãã¾ãã
EGWã試ãã¦ã¿ããã®ã§ã::/0ãEGWã¸ã¨åãããã«ã¼ããã¼ãã«ã¨ããã®ã«ã¼ããã¼ãã«ãç´ä»ããSubnetãä½æãã¾ãã
æå¾ã«ä½ã£ããã©ã¤ãã¼ããµããããã¸ã¨ãIPv6ã®IPãã¢ã¿ããããã¤ã³ã¹ã¿ã³ã¹ããã¼ã³ããã¾ãã
æçµçã«è¸ã¿å°ãå¿
è¦ã ã£ãã®ã§ä¸å³ã®æ§ãªæ§æã«ãªãã¾ãã
æ¥ç¶ãã
ä»åãä¸ã®2å°ã®EC2ãä½ãã¾ãããã
ä¼ç¤¾ã®ãããã¯ã¼ã¯ããIPv6ã§åºããªããããã®ã§ã
ããä¸åãIPv6ãæã£ããVPCã¨è¸ã¿å°ã¤ã³ã¹ã¿ã³ã¹ãæ§ç¯ãã
ããã¸IPv4ã§SSHãããããã§ã
è¸ã¿å°ããIPv6ã§SSHã¨ããçµè·¯ãåãã¾ãã
è¸ã¿å°ãããä½ã£ãEC2ã¸ã¯ãIPv6ã§æ¥ç¶ãã¾ãã
[ec2-user@ip-10-1-10-6 ~]$ ssh -i dev-terada.pem 2600:1f16:6c9:5500:d981:36e:bd6e:a00f
Last login: Fri Dec 2 04:12:29 2016 from 2600:1f16:cf3:7900:20ed:737d:542b:80af
__| __|_ )
_| ( / Amazon Linux AMI
___|\___|___|
https://aws.amazon.com/amazon-linux-ami/2016.09-release-notes/
[ec2-user@ip-10-0-1-237 ~]$ ping 2001:4860:4860::8888
ping: unknown host 2001:4860:4860::8888
[ec2-user@ip-10-0-1-237 ~]$ ping6 2001:4860:4860::8888
PING 2001:4860:4860::8888(2001:4860:4860::8888) 56 data bytes
64 bytes from 2001:4860:4860::8888: icmp_seq=1 ttl=46 time=20.2 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=2 ttl=46 time=19.9 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=3 ttl=46 time=19.9 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=4 ttl=46 time=19.9 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=5 ttl=46 time=19.9 ms
^C
--- 2001:4860:4860::8888 ping statistics ---
5 packets transmitted, 5 received, 0% packet loss, time 4007ms
rtt min/avg/max/mdev = 19.903/19.984/20.201/0.210 ms
[ec2-user@ip-10-0-1-237 ~]$
IPv6ã§ã¤ã³ã¿ã¼ãããã«åºããã¨ãå¯è½ã§ãã
ãã¹ããã¼ã ã¨ãã¯IPv4ã®ã¢ãã¬ã¹ã表示ããã¦ãã¾ããã
ãã©ã¤ãã¼ããµããããã¸ä½ã£ãEC2ã¸ãåãããã«è©¦ãã¦ã¿ã¾ãã
[ec2-user@ip-10-1-10-6 ~]$ ssh -i dev-terada.pem 2600:1f16:6c9:5501:1c78:6a5d:a349:2b6f
^C
[ec2-user@ip-10-1-10-6 ~]$
ãã©ã¤ãã¼ãã§ä½ã£ãã®ã§å½ç¶ã§ãããããã§ã®ãã°ã¤ã³ã¯ã§ãã¾ããã
ä¸åº¦ãä¸ã®ãããªãã¯ã«é
ç½®ããã¤ã³ã¹ã¿ã³ã¹ã«ãã°ã¤ã³ããããã§ã
ã¢ã¯ã»ã¹ãã¾ãã
[ec2-user@ip-10-1-10-6 ~]$ ssh -i dev-terada.pem 2600:1f16:6c9:5500:d981:36e:bd6e:a00f
Last login: Fri Dec 2 06:18:11 2016 from 2600:1f16:6c9:5500:d981:36e:bd6e:a00f
__| __|_ )
_| ( / Amazon Linux AMI
___|\___|___|
https://aws.amazon.com/amazon-linux-ami/2016.09-release-notes/
[ec2-user@ip-10-0-1-237 ~]$ ssh -i dev-terada.pem 2600:1f16:6c9:5501:1c78:6a5d:a349:2b6f
The authenticity of host '2600:1f16:6c9:5501:1c78:6a5d:a349:2b6f (2600:1f16:6c9:5501:1c78:6a5d:a349:2b6f)' can't be established.
ECDSA key fingerprint is 13:b5:ec:89:c4:d9:32:52:cf:fc:0e:71:c0:7b:f2:cc.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '2600:1f16:6c9:5501:1c78:6a5d:a349:2b6f' (ECDSA) to the list of known hosts.
__| __|_ )
_| ( / Amazon Linux AMI
___|\___|___|
https://aws.amazon.com/amazon-linux-ami/2016.09-release-notes/
[ec2-user@ip-10-0-2-84 ~]$ ping6 2001:4860:4860::8888
PING 2001:4860:4860::8888(2001:4860:4860::8888) 56 data bytes
64 bytes from 2001:4860:4860::8888: icmp_seq=1 ttl=46 time=19.7 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=2 ttl=46 time=20.0 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=3 ttl=46 time=19.7 ms
64 bytes from 2001:4860:4860::8888: icmp_seq=4 ttl=46 time=19.7 ms
^C
--- 2001:4860:4860::8888 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 19.748/19.836/20.067/0.193 ms
[ec2-user@ip-10-0-2-84 ~]$
EGWãéããã¤ã³ã¿ã¼ãããã¸ã®æ¥ç¶ãåé¡ãªãã§ãã¾ãã
ã¾ã¨ã
ç°¡åã«IPv6ã®ãã¹ããè¡ãã¾ããã
ç¾å¨ã®ã¨ãããVPCã¨ãã¦ã¯IPv4ã«IPv6ãä»ã足ããå½¢ã®å®è£
ã¨ãªã£ã¦ãã¾ãã
ã¾ããIPv6ã使ããããã«ãªã£ãããã¨è¨ã£ã¦ãIPv6ãããã«å¿
é ã«ãªããã¨ã¯ãªãã¨èãããã¾ãã
ããããã¢ããã«ãiOSã®ã¢ããªã±ã¼ã·ã§ã³ã§ãIPv6対å¿ãå¿
è¦ã¨ãããã
確å®ã«æµãã¯IPv6ã«åãã¦ãã¾ãã
ã¾ããNATããããªããªã£ãããªã©ã§ããããã¯ã¼ã¯ã»ãããã¸ã¼ããä½æ³ãå¤ãããããè¨è¨ãã¬ã©ãã¨å¤ãããã¨ã«ãªãã¾ãã
(ãã®è¨äºã®ããã«çµæ§èª¿ã¹ã¾ããã)
æ±äº¬ãªã¼ã¸ã§ã³ã«æ¥ãã¾ã§ã¯ããå°ãæéããããããã§ããã
æ©ãã«æ
£ãã¦ããããã¨ããã§ãã