æè¡ä¸èª²ã®ææã§ãã2019å¹´9æãAWS Transit Gatewayã§Direct Connect Gatewayãå©ç¨ã§ããæ©è½ãçºè¡¨ããã¾ããã å¾ æã®ã¢ãããã¼ãã§ãã AWS Direct Connect ã® AWS Transit Gatewayãµãã¼ããæ±äº¬ãªã¼ã¸ã§ã³ã«å¯¾å¿ãã¾ãã
ãã®ã¢ãããã¼ãã«ãããAWS Transit Gatewayãããã¨ãã¦ããªã³ãã¬ãã¹ã¨ãã«ãã¢ã«ã¦ã³ãã®AWSç°å¢ãããç°¡åã«å°ç¨ç·ã§æ¥ç¶ã§ããããã«ãªãã¾ããã æ§æã®ç¹å¾´ã注æç¹ã解説ãã¾ãã
1. æ§æã¤ã¡ã¼ã¸å³
ä¸è¨ã®ãããªæ§æå³ã®æ§æãå¯è½ã«ãªãã¾ãã
å¾æ¥ã¾ã§ï¼æ¬ã¢ãããã¼ãã®ç»å ´ã¾ã§ï¼
å¾æ¥ã¾ã§ã¯ãè¤æ°ã®AWSã¢ã«ã¦ã³ãã« Direct Connect ãå¼ããã¨èããå ´åã2ã¤ã®æ¹æ³ãããã¾ããã
- åAWSã¢ã«ã¦ã³ãã«Virtual Interfaceãä½æãã => ãªã³ãã¬å´ã«ã¼ã¿ã®è¨å®å¤æ´ãå¿ è¦
- Direct Connect Gatewayã®ãã«ãã¢ã«ã¦ã³ããµãã¼ããå©ç¨ãã => ã«ã¼ã¿è¨å®å¤æ´ã¯ä¸è¦ã ãVPCéã®éä¿¡ã¯ä¸å¯ï¼ããã«ãªããªãï¼
ãããã
ä»åã®æ§æãã¤ã¾ãTransit Gatewayã®Direct Connect Gatewayå©ç¨ã§ã¯ã以ä¸ã®ã¡ãªãããããã¾ãã
- AWSå´ã®æä½ã ãã§è¤æ°ã®AWSã¢ã«ã¦ã³ãã«Direct Connectã伸ã°ãã
- Transit Gatewayãããã«ãã¦ãVPCãããªã³ãã¬ï¼VPNï¼ãããªã³ãã¬ï¼Direct Connectï¼ãéã®éä¿¡ãã§ãã
- Transit Gatewayã®Route Tableã§åè¿°ã®éä¿¡ã®å¶å¾¡ãç´°ããè¨å®ã§ãã
ãªãTransit Gatewayã¨VPCãç´ã¥ããé㯠"Transit Gateway Attachment" ã¨ããé¢ä¿ãªã½ã¼ã¹ããVPCãåå¨ããåAWSã¢ã«ã¦ã³ãã«ä½æãããã¨ã«ãªãã¾ãã ã«ã¼ãã£ã³ã°ã®å¶å¾¡ã¯åAttachmentã«Transit Gateway Route Tableãç´ã¥ãããã¨ã«ãªãã¾ããããããã§ããã®ã¯Transit Gatewayæ¬ä½ãä½æããã¢ã«ã¦ã³ãããã®ã¿ã«ãªãã¾ãã
ã¤ã¾ããä¸å¤®AWSã¢ã«ã¦ã³ãã§ã«ã¼ãã£ã³ã°ã®å¶å¾¡ãéç´ã§ããä¸æ¹ãåAWSã¢ã«ã¦ã³ãã®ç®¡çè ã«Delegationãããããªéç¨ã¯ç¾ç¶ã§ãã¾ããã
2. åææ¡ä»¶
ãã®æ§æã«ããã«ã¯ã以ä¸ã®åææ¡ä»¶ãã¯ãªã¢ãã¦ããå¿ è¦ãããã¾ãã
- æ¥ç¶ããå ¨ã¦ã®VPCãåä¸ãªã¼ã¸ã§ã³ã«ãã
- Transit Gatewayãå©ç¨ã§ããAvailability Zoneã§ã®å©ç¨ã§ããï¼å¤ãAZã§ã¯ãªãï¼
- ï¼è£è¶³ï¼åãOrganizationsã«æå±ãã¦ããå¿ è¦ã¯ãªã
A. æ¥ç¶ããå ¨ã¦ã®VPCã¯åä¸ãªã¼ã¸ã§ã³ã«ãããã¨
Transit Gatewayã§ã¯ãªã¼ã¸ã§ã³ãã¾ããã ã¢ã¿ããã¡ã³ã(VPC, VPN, Direct Connect Gateway)ä½æã¯ã§ãã¾ããã
ãã ãããã®æåã®Direct Connect Gatewayã¯ãªã¼ã¸ã§ã³éã§å©ç¨ãã§ãã¾ããã¤ã¾ããªã³ãã¬ããDirect Connect Gatewayã¾ã§æ¥ã¦ãããã§åå²ãã¦åãªã¼ã¸ã§ã³ãã¨ã®Transit Gatewayã«ç¹ããããªæ§æã¯å¯è½ã§ãã
ãã ãããã®æ§æã®å ´åã¯ç°ãªããªã¼ã¸ã§ã³éã®VPCã§éä¿¡ã¯ã§ãã¾ãããããã注æãã ãããï¼ããã¾ã§ãªã³ãã¬ã¤ã¹ï½åãªã¼ã¸ã§ã³ã®VPCéã§éä¿¡ãå¯è½ã«ãªãï¼ ã¤ã¾ãã¯ç¾å¨ãTransit Gatewayã§å®ç¾ã§ããã®ã¯ãªã¼ã¸ã§ã³å
éä¿¡ã®ã¿ã§ãã
2019/12ã®ã¢ãããã¼ãã«ã¦ãå¥ãªã¼ã¸ã§ã³ã«ããTransit Gatewayå士ãæ¥ç¶ãããã¨ãã§ããããã«ãªãã¾ããã ãªã¼ã¸ã§ã³ãã¨ã«Transit Gatewayãæ§ç¯ããTransit Gatewayå士ãç¹ãããã¨ã§ããªã¼ã¸ã§ã³ééä¿¡ãå¯è½ã§ãã AWS Transit Gatewayã«ãã«ããã£ã¹ãã¨ã¤ã³ã¿ã¼ãªã¼ã¸ã§ã³ãã¢ãªã³ã°æ©è½ã追å Transit Gatewayã«ã¯åä¸ãªã¼ã¸ã§ã³ã«ããVPCã ãããæ¥ç¶ã§ããªããã¨ããç¹ã¯å¤ããã¾ããã ã¾ããé¢é£ããã°ã¸ã®ãªã³ã¯ãæ¬ãã¼ã¸ã®æ«å°¾ã«è¨è¼ãã¦ãã¾ãã
B. Transit Gatewayãå©ç¨ã§ããAvailability Zoneã§ã®å©ç¨ã§ãããã¨ï¼å¤ãAZã§ã¯ãªããã¨ï¼
Transit Gatewayã®å¶ç´ã¨ãã¦ãå¤ãAZã§ã¯Transit Gatewayãå©ç¨ã§ãã¾ããã æ±äº¬ãªã¼ã¸ã§ã³ã§ããã°å¤ãã®AWSã¢ã«ã¦ã³ãã§ãap-northeast-bãã¨ãã¦èªèãããapne1-az3ã該å½ãã¾ãã å¥ã®AZã§Transit Gatewayã®Attachmentãä½ã£ã¦ãã ãã§ãã ãªããªãTransit Gatewayãéãã¦éä¿¡ãããªã½ã¼ã¹ï¼EC2ãRDSçï¼ã®ãããã¹ã¦ã®AZã¨ãTransit Gatewayãç´ã¥ãããã¦ããå¿ è¦ãããããã§ããï¼å¾è¿°ï¼ ãã®æ±äº¬ãªã¼ã¸ã§ã³ã®æ§AZã¯ç¾å¨ã§ã¯å©ç¨ã§ããªããªã£ã¦ãã¾ãããå¤ãããAWSããå©ç¨ã®AWSã¢ã«ã¦ã³ãã§ã¯ãæ¢åãªã½ã¼ã¹ãæ®ã£ã¦ããå¯è½æ§ãããã¾ãã®ã§ã注æãã ããã æ±äº¬ãªã¼ã¸ã§ã³ã®æ§AZï¼apne1-az3)ã®å¶ç´ã«é¢ãã¦ã¯ãå¼ç¤¾ã®æ¸¡è¾ºãæ¸ããããã°ãåèã«è¼ãã¦ããã¾ãã æ§AZ(apne1-az3)ã§ã§ããªããã¨
ï¼è£è¶³ï¼åãOrganizationã«æå±ãã¦ããå¿ è¦ã¯ãªã
Transit Gatewayãè¤æ°AWSã¢ã«ã¦ã³ãã§å ±æããã«ã¯AWS Resource Access Managerï¼ä»¥ä¸ãAWS RAMï¼ãå©ç¨ãã¾ãã What Is AWS RAM? AWS RAMã¯ç°ãªãAWSã¢ã«ã¦ã³ãéã§AWSãªã½ã¼ã¹ãå ±æããAWSãµã¼ãã¹ã§ãã åä¸Organizationå ã§ãªã½ã¼ã¹å ±æãããè¨å®ãªã©ãå¯è½ã§ãããTransit Gatewayã«é¢ãã¦ã¯ãã·ã§ã¢ããAWSã¢ã«ã¦ã³ããåä¸Organiztionã«æå±ãã¦ããå¿ è¦ã¯ããã¾ããã
â»1 â»2 â»1 Direct Connect Gatewayãã¢ã«ã¦ã³ãéå ±æããéã¯ãã¤ã¦ã¯åä¸Organizationï¼åä¸Payer IDï¼ã§ããå¿ è¦ãããã¾ãããããã®å¶éã¯ç·©åããã¾ãã(AWS Direct Connect Announces the Support for Granular Cost Allocation and Removal of Payer ID Restriction for Direct Connect Gateway Association.)ã Transit Gatewayã§ã¯ãã¨ãã¨å¿é ããå¿ è¦ã¯ããã¾ããã
â»2 AWS RAMãç¨ãã¦AWSã¢ã«ã¦ã³ãéã§ãªã½ã¼ã¹ãå ±æããå ´åãåãOrganizationã«æå±ãã¦ããå¿ è¦ããããªã½ã¼ã¹ãããã¾ããä¾ãã° Subnet ã®å ±æï¼VPC Sharing, Shared VPCï¼ãå©ç¨ããã«ã¯AWSã¢ã«ã¦ã³ããåãOrganizationã§ããå¿ è¦ãããã¾ãï¼ãã¤"å ¨ã¦ã®æ©è½ãæå¹å"ããã¦ããå¿ è¦ããï¼ãTransit Gatewayã¯ããã§ã¯ããã¾ãã
3. 注æäºé
以ä¸ã®æ³¨æäºé ã«ååã注æãã ããã
- æ¢ã«Direct Connect(ãããã¯Direct Connect Gateway)ãå©ç¨ãã¦ããå ´åã§ãTransit Virtual Interfaceã®ä½æãå¿ è¦
- æ§AZã§ã¯Transit Gatewayã使ããªããæ§AZã«ããEC2çã®ãªã½ã¼ã¹ã¨ãéä¿¡ã§ããªã
- éä¿¡å ã®VPCãªã½ã¼ã¹ãåå¨ããå ¨ã¦ã®AZã®ãµããããã¨Transit Gateway Attachmentãç´ã¥ãããã¨
A. æ¢åã®Direct Connect(ãããã¯Direct Connect Gateway)ãããå ´åã§ãTransit Virtual Interfaceã®ä½æãå¿ è¦
æ¢ã«Direct Connect Gatewayããå©ç¨é ãã¦ããå ´åã§ããæ¢åã®Private Virtual InterfaceãTransit Gatewayã«å©ç¨ãããã¨ã¯ã§ãã¾ããã Virtual Interfaceã«ã¯ "Public" "Private" "Transit" ã®3種é¡ãããããã®ãã¡Transitã¨ãã種é¡ã®Virtual Interfaceãå©ç¨ããå¿ è¦ãããã¾ãã æ¢åDirect Connectæ§æããTransit Gatewayæ§æã«åãæ¿ããéã¯ãæåã«ãã®Transit Virtual Interfaceãä½æããã¨ããä½æ¥ãå¿ è¦ã§ãã ãã®ã¨ãã«ãªã³ãã¬å´ã«ã¼ã¿ã®è¨å®è¿½å ãããã³ãã¡ãã¸ã®çµè·¯åæ¿ãå¿ è¦ã§ãã®ã§ã注æãã¾ãããã
B. æ§AZã§ã¯Transit Gatewayã使ããªããæ§AZã«ããEC2çã®ãªã½ã¼ã¹ã¨ãéä¿¡ã§ããªã
åè¿°ã®éãã§ãã ç¾å¨ã§ã¯ãã®æ§AZã¯å©ç¨ã§ããªããããæè¿AWSã¢ã«ã¦ã³ããéè¨ãããæ¹ã¯åé¡ããã¾ããããå¤ãããAWSããå©ç¨ã®AWSã¢ã«ã¦ã³ãã§ã¯ãæ¢åã®ãªã½ã¼ã¹ãæ®ã£ã¦ããå¯è½æ§ãããã¾ãã®ã§ã注æãã ããã æ§AZã®ãªã½ã¼ã¹ã¨éä¿¡ããããå ´åã¯ãå¾æ¥éãã«VPC PeeringãVirtual Private Gateway(VGW)ãæ®ãã¦ããå¿ è¦ããããããæ··å¨ã®æ§æã¨ãªãå ´åã¯æ³¨ææ·±ãè¨è¨ããå¿ è¦ãããã¾ãã
C. éä¿¡å ã®VPCãªã½ã¼ã¹ãåå¨ããå ¨ã¦ã®AZã®ãµããããã¨Transit Gateway Attachmentãç´ã¥ãããã¨
Transit Gatewayã¨VPCãç´ã¥ããé㯠"Transit Gateway Attachment" ã¨ããé¢ä¿ãªã½ã¼ã¹ãä½æãã¾ãã Transit Gateway Attachmentä½æã®éã«ã¯ãã©ã®ãµããããã¨ç´ã¥ããããé¸æãã¾ããåAZã§1ã¤ã®ãµãããããé¸æã§ãã¾ãã ãã®ã¨ããVPCã®ä¸ã®ã©ããä¸ã¤ã®AZã®ãµããããã¨Transit Gateway Attachmentãç´ã¥ãã¦ããã°ãããã®ã§ã¯ãªããéä¿¡ããããªã½ã¼ã¹ãåå¨ããå ¨ã¦ã®AZã®ãµããããã¨Transit Gateway Attachmentãç´ã¥ãããå¿ è¦ãããã¾ãã
ä¾ãã°Transit Gateway AttachmentãAZ-1aã®ãµããããã¨ã ãç´ã¥ãã¦ããã¨ãã¾ãã ãã®ç¶æ ã§AZ-1cã«ããEC2ã«ã¯ãTransit Gatewayçµç±ã§ã¯éä¿¡ã§ãã¾ããã ãã®ç¶æ ã§AZ-1cã®ãµããããã®ã«ã¼ããã¼ãã«ããTransit Gatewayã«å¯¾ãã¦ã«ã¼ããåãã¦ããéä¿¡ãããã¨ãã§ããªãã®ã§ãã AZ-1cã®ãµããããã«ããç´ã¥ããå¿ è¦ãããã¾ãã ãªãTransit Gateway Attachmentãç´ã¥ãããµããããã«ã¯Transit Gatewayã®ENIãè¤æ°ä½æããPrivate IPã¢ãã¬ã¹ãæ¶è²»ãããã®ã§æ³¨æãå¿ è¦ã§ãã
4. ãããã«
Transit Gatewayãå©ç¨ãããã¨ã§ãVPC-ãªã³ãã¬éã®è©³ç´°ãªçµè·¯å¶å¾¡ãTransit Gatewayã«éç´ãããã¨ãã§ãã¾ãã ã¾ãããã¤ã¦ã¯Direct Connectãè¤æ°AWSã¢ã«ã¦ã³ãã«å¼ããã¨ããã¨ãªã³ãã¬ã«ã¼ã¿ã®è¨å®å¤æ´ãªã©æéãçãã¦ãã¾ããããTransit Gatewayãå©ç¨ãããã¨ã§AWSä¸ã®æä½ã§å®ç¾ãããã¨ãã§ãã¾ãã ï¼Direct Connect Gatewayã§ãå®ç¾ã§ãã¾ããããTransit Gatewayã«ãããã¨ã§ãã詳細ã«çµè·¯ãå¶å¾¡ããããVPCééä¿¡ãå®ç¾ã§ãããããï¼ ãåèã«ãé¡ããããã¾ãã
ï¼è¿½è¨ï¼2019å¹´12æã«ãTransit Gatewayããã«ããªã¼ã¸ã§ã³ãã¢ãªã³ã°ã«å¯¾å¿ãã¾ãããä¸è¨ã®ããã°ããåç §ãã ããã Transit Gatewayã§å®ç¾ãããã«ããªã¼ã¸ã§ã³æ§æã»ãã«ãã¢ã«ã¦ã³ãæ§æ
ææ å馬 (è¨äºä¸è¦§)
ãµã¼ãã¼ã¯ã¼ã¯ã¹ â æ ªå¼ä¼ç¤¾G-gen å·è¡å½¹å¡CTO
2021 Japan APN Ambassadors / 2021 APN All AWS Certifications Engineers
ãã«ãAWSã¢ã«ã¦ã³ã管çéç¨ããããã¯ã¼ã¯é¢ä¿ã®AWSãµã¼ãã¹ã«é¢ããããã°è¨äºãéå»ã«å·çã
2021å¹´09æããæ ªå¼ä¼ç¤¾G-genã«åºåãGoogle Cloud(GCP)ãå°éã«ãG-genã§ãGoogle Cloud (GCP) ã®æè¡ããã°ãå·çä¸ã