ä»åã®æ¤è¨¼å 容
AWSã®VGW(ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤)ã¨Cradlepoint社ã®ã«ã¼ã¿IBR900ãVPNæ¥ç¶ãã¾ãã
NetCloudã使ãå ´åãåºæ¬çã«ã¯172.86.160.0/20ã®ãªã¼ãã¬ã¤ãããã¯ã¼ã¯ã§éä¿¡ããã®ã§VPNã¯ä¸è¦ã¨èãã¦ãã¾ãã
ãã ãããNetCloudã使ãããç°å¢ãã¨ãNetCloudã使ããããªãç°å¢ããæ··å¨ããæã¯ãAWSã¨VPNããããªãããããã¾ããã
ä»åã¯ä¸è¨ã®æ§æã§æ¤è¨¼ãã¾ããã
çµæãå ã«æ¸ãã¨ãã¯ã©ã¤ã¢ã³ã端æ«(Macbook pro)ã¨EC2ã¯ãä¸è¨ãä½µç¨ã§ããããã«ãªãã¾ãã
- NetCloud(172.86.160.0/20)ã使ã£ãéä¿¡
- VPN(ãã©ã¤ãã¼ãã¢ãã¬ã¹)ã使ã£ãéä¿¡
æ§ç¯æé
ä¸è¨ã«æ§ç¯æé ãè¨è¼ãã¾ãã
åææ¡ä»¶
- AWSã§åºæ¬çãªæ§æ(VPC,Subnet,ec2ç)ã¯ä½ææ¸ã¿
- IBR900ã®NetCloud OSã®ãã¼ã¸ã§ã³ã¯ã6.4.0(2017-08-03)
AWSå´ã®è¨å®
ã¾ããAWSå´ã§VPNè¨å®ããã¾ãã
ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã®ä½æ
[AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«] VPC > ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ > ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã®ä½æ
ä¸è¨ç»åã®ãããªè¨å®ãå
¥ãã¦ãã ããã
ä»åã¯Staticã«ã¼ãã£ã³ã°ã§æ¤è¨¼ãã¾ããã
BGPã使ã£ãåçã«ã¼ãã£ã³ã°ã«é¢ãã¦ã¯å¥ã®è¨äºã§ç´¹ä»ããäºå®ã§ãã
ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ã®ä½æ
[AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«] VPC > ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ > ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ã®ä½æ
ä¸è¨ç»åã®ããã«é©å½ãªååãå ¥ããã ãã§ããã
ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ãVPCã«ã¢ã¿ãã
ä¸è¨ã§ä½æããVGWãVPCã«ã¢ã¿ãããã¾ãã
[AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«] VPC > ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ > ä»®æ³ãã©ã¤ãã¼ãã²ã¼ãã¦ã§ã¤ã®ã¢ã¿ãã
VPNæ¥ç¶ã®ä½æ
[AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«] VPC > VPNæ¥ç¶ > VPNæ¥ç¶ã®ä½æ
ä¸è¨ç»åã®ãããªè¨å®ãå ¥ãã¦ãã ããã
ã«ã¼ãä¼æ
EC2ãã·ã³ããããµããããã§ä½¿ç¨ãã¦ããã«ã¼ããã¼ãã«ãç·¨éãã¦ãVGWããã«ã¼ãä¼æãããããã«ãã¦ãã ããã
ããã«ãã£ã¦VGWã§è¨å®ããStaticã«ã¼ãæ
å ±ããã®ãµããããã«ãä¼æããä»åã®ä¾ã§ããã¨ã192.168.0.0/24å®ã®éä¿¡ãVGWã«åãã¾ãã
[AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«] > VPC > ã«ã¼ããã¼ãã«
VPNæ¥ç¶ã®è¨å®ããã¦ã³ãã¼ã
ä½æããVPNæ¥ç¶ãé¸æããè¨å®ã®ãã¦ã³ãã¼ããã¯ãªãã¯ãã¦ãã ããã
ãã³ãã¼ã®é
ç®ã«Checkpointã¨ãCiscoã¨ãåºã¦ãã¾ãããCradlepointã¯ç¡ãã®ã§ãGenericãé¸ã³ã¾ãã
ããã¹ãå½¢å¼ã®è¨å®ãã¡ã¤ã«ããã¦ã³ãã¼ãã§ãã¾ãã
[AWSããã¼ã¸ã¡ã³ãã³ã³ã½ã¼ã«] VPC > VPNæ¥ç¶
ãã®ãã¡ã¤ã«ãåç
§ãã¤ã¤ãCradlepointã«ã¼ã¿ãè¨å®ãã¾ãã
é·ã
ã¨è±èªã§æ¸ãã¦ããã®ã§ãããå¿
è¦ãªãã©ã¡ã¼ã¿ãæç²ãã¾ãã
IPSec Tunnel #1 ================================================================================ #1: Internet Key Exchange Configuration â IKE version : IKEv1 â Authentication Method : Pre-Shared Key â Pre-Shared Key : xxxxxxxxxxxxxxxxxxxxxxxxxx â Authentication Algorithm : sha1 â Encryption Algorithm : aes-128-cbc â Lifetime : 28800 seconds â Phase 1 Negotiation Mode : main â Diffie-Hellman : Group 2 #2: IPSec Configuration â Protocol : esp â Authentication Algorithm : hmac-sha1-96 â Encryption Algorithm : aes-128-cbc â Lifetime : 3600 seconds â Mode : tunnel â Perfect Forward Secrecy : Diffie-Hellman Group 2 #3: Tunnel Interface Configuration Outside IP Addresses: â Customer Gateway : xx.xx.xx.xx â Virtual Private Gateway : yy.yy.yy.yy
ãªãããIPSec Tunnel #2ãããããåé·åã®ããã«ï¼æ¬ç®ã®VPNãå¼µããã¨ãã§ãããã§ãããä»åã¯è©¦ãã¦ãã¾ããã
IBR900å´ã®è¨å®
ã«ã¼ã¿ã«GUIãã°ã¤ã³ããè¨å®ãã¾ãã
VPNè¨å®
IPã¢ãã¬ã¹ãæå·è¨å®ãªã©ã¯ãä¸è¨ã§ãã¦ã³ãã¼ãããè¨å®ãã¡ã¤ã«ã«å¾ããè¨å®ãã¾ãã
[IBR900 GUI] NETWORKING -> Tunnels -> IPsec VPN
ä¸è¨ã¾ã§è¨å®ã§ããã¨æ¬¡ã®ãããªç»é¢ã«ãªãã¾ãã
Firewall Zoneã®è¿½å
Firewall Zoneã追å ãã¾ãã
[IBR900 GUI] SECURITY > Zone Firewall > Zone Definition
Firewall
ä¸è¨ã®ããã«è¨å®ãã¾ãã
ããã§VPNçµç±ã®åæ¹åéä¿¡ãå
¨ã¦è¨±å¯ãããã¨ã«ãªãã¾ãã
[IBR900 GUI] SECURITY > Zone Firewall > Zone Forwarding
ãªããNCMçµç±ã§ã«ã¼ã¿ã¼ã«ãã°ã¤ã³ãã¦ããå ´åãè¨å®å¤æ´ãåæ ãããããã«ã¯ãCommit Changesããå¿ è¦ã§ãã
åèãã¼ã¸
NCOS: Virtual Tunnel Interface (VTI) IPSec VPN
ã¾ã¨ã
æåã«ãæ¸ãã¾ããããä¸è¨ã®ããã«æå¾ éãã®åãããã¦ããã¾ããã
çµæãå ã«æ¸ãã¨ãã¯ã©ã¤ã¢ã³ã端æ«(Macbook pro)ã¨EC2ã¯ãä¸è¨ãä½µç¨ã§ããããã«ãªãã¾ãã
- NetCloud(172.86.160.0/20)ã使ã£ãéä¿¡
- VPN(ãã©ã¤ãã¼ãã¢ãã¬ã¹)ã使ã£ãéä¿¡
ããä½è«ã§ãããä»åã«ã¼ã¿ãè¨å®ããã®ã«ã«ã¼ã¿ã®IPã¢ãã¬ã¹ã«ç´æ¥ãã°ã¤ã³ãããNCM(NetCloudManager)çµç±ã§è¨å®ãã¾ããã
NCMã«ãããã°ã¤ã³ã§ããã°ã管çä¸ã®æ©å¨ã«ãã°ã¤ã³ã§ããã®ã§æ¥½ã§ããã
顧客ç°å¢ã¸ã®å°å
¥ä½æ¥ãèããã¨ãã«ã¼ã¿ãNCMã¸ç»é²ããããã°ãVPNè¨å®ãªã©ã¯ãªã¢ã¼ãã§ã§ããã®ã§å¼ç¤¾ã®ãããªæ§ç¯ã»éç¨ãããä¼ç¤¾ã¨ãã¦ãããæ©è½ã ã¨æãã¾ããã
渡辺 ä¿¡ç§(è¨äºä¸è¦§)
2017å¹´å
¥ç¤¾ / å°å³ãªå
容ãä¸å¯§ã«æ¸ããã