ã¯ããã«
ãVPC Ingress Routingããªããã®ããªãªã¼ã¹ããã¾ããã®ã§ã試ãã¦ã¿ã¾ããã
New â VPC Ingress Routing â Simplifying Integration of Third-Party Appliances
å¾æ¥åºæ¥ãªãã£ããã¨
å¾æ¥ãã¤ã³ã¿ã¼ããããVPNçµç±ã§ãEC2ä¸ã«æ§ç¯ãããã¡ã¤ã¢ã¦ã©ã¼ã«(FW)çãæãã§VPCå ã®ä»ã®ãµã¼ãã«ã¢ã¯ã»ã¹ããããå ´åã
- FWã§å®å IPãNATãã
- ã¯ã©ã¤ã¢ã³ãã¨FWã§ãã³ãã«ãè²¼ã
ã®ãããªæ§æããåããªãã£ãã¨æãã¾ãã ãããã£ã¦ãä¾ãã°ãå®å ã®ãµã¼ãã®IPã¢ãã¬ã¹ãæå®ãã¦éä¿¡ããè¦ä»¶ãå®ç¾ããã«ã¯ä¸å³ã®å³å´ã®ãã³ãã«ãè²¼ãæ§æãåãããç¡ããè¤éãªè¨è¨ã¨æ§ç¯ãããå¿ è¦ãããã¾ããã
ããã¯VPCã«å¿ ãåå¨ãæåªå ã§å¦çãããããã¼ã«ã«ã«ã¼ãããVPCã®CIDRå®ã®ãã±ãããå¦çãã¦ãã¾ããããVPCã®CIDRå®ã®ãã±ããã¯å¿ ãå®å ã®ã¤ã³ã¹ã¿ã³ã¹ã«ç´æ¥å±ãã¦ãã¾ããã¨ã«ãããã®ã§ããï¼VPCã®CIDRããçãCIDRã®ã«ã¼ãã¯ç¡å¹ã¨ãªãããã³ã²ã¹ããããã®ããã«åªå ãã¦å¦çã§ããªãã£ãï¼ã
ã«ã¼ããã¼ãã« - Amazon Virtual Private Cloud
VPC Ingress Routingã§åºæ¥ãããã«ãªããã¨
ä»åã®ãªãªã¼ã¹ã«ãããããã©ã«ãã®ãã¼ã«ã«ã«ã¼ãããåªå ããçµè·¯ãè¨å®ã§ãããã²ã¼ãã¦ã§ã¤ã«ã¼ããã¼ãã«ãã¨ãããã®ãè¨å®ã§ããããã«ãªãã¾ãã(â»1)ã ããããããã¼ã«ã«ã«ã¼ãããï¼ãã³ã²ã¹ããããçã«ï¼åªå ãããã«ã¼ããã¼ãã«ãä½æãã¦ããï¼â»2ï¼ãIGWãVGWã«ç´ä»ãã¾ããããã«ãããIGWãVGWçµç±ã§VPCã«å ¥ã£ã¦ãããã±ãããå®å IPã®ãµã¼ãã«å°éããåã«EC2ä¸ã«æ§ç¯ããFWçãçµç±ããããã¨ãåºæ¥ã¾ãã
ããã¥ã¡ã³ãçã«ã¯ä»¥ä¸ã®ãã®ãåãããããã¨æãã¾ãã Route Tables - Gateway Route Tables
â»1 ããã¥ã¡ã³ããæ¬è¨äºå·çæç¹ã§è±èªã®ãã®ããç¡ããããæ£å¼ãªæ¥æ¬èªåã¯ç°ãªãå¯è½æ§ãããã¾ã â»2 ãã¼ã«ã«ã«ã¼ãã¨å ¨ãåãCIDRã®ã«ã¼ãã¯è¨å®ã§ãã¾ãã
試ãã¦ã¿ã
AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§å®éã«è©¦ãã¦ã¿ã¾ããã
ä»åã®æ§æ
å°ãç°¡æã§ããã以ä¸ã®ããã«VPCã¨EC2ã¤ã³ã¹ã¿ã³ã¹ãæ§ç¯ãã¦ããã¾ããIGWçµç±ã®ãã©ãã£ãã¯ãç¹å®ã®ã¤ã³ã¹ã¿ã³ã¹ï¼å³ä¸ã®ãã¢ãã©ã¤ã¢ã³ã¹ãï¼ãçµç±ããããã«ãã¾ããã¾ããã¢ãã©ã¤ã¢ã³ã¹ãã¤ã³ã¹ã¿ã³ã¹ã®ENIã®ãéä¿¡å å ãã§ãã¯ãã¯ç¡å¹åãã¦ããã¾ãã両ã¤ã³ã¹ã¿ã³ã¹ã«Public IPãä»ä¸ãã¦ããã¾ãã ãã¤ã³ãã¯ä¸é¨ã®ã«ã¼ããã¼ãã«ããããããä½æãã¦ãããã¨ã§ããé信対象ã®ãµããããã®CIDRã¨éä¿¡ãçµç±ãããããµã¼ãã®ENIãæå®ããç¹å®ã®ãµããããã«ã¯ç´ä»ããªãããã«ãã¦ããã¾ãã
è¨å®
ä¸è¨ã®ãã²ã¼ãã¦ã§ã¤ã«ã¼ããã¼ãã«ããIGWã«ç´ä»ãã¾ãã
ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã®ã«ã¼ããã¼ãã«ã®ãã¼ã¸ãéããä½æãã¦ããããã²ã¼ãã¦ã§ã¤ã«ã¼ããã¼ãã«ããé¸æï¼ç»åã§ã¯ Ingress
ï¼ããä¸é¨ã¿ãã®ãEdge Associationsããé¸æãããEdit Edge Associationsããé¸æãã¾ãã
次ã«ãããããä½æãã¦ãããIGWãé¸æãããSaveããé¸æãã¾ãã 以ä¸ã§ããç°¡åã§ããã
åä½ç¢ºèª
ããã§ã¯å®éã«åä½ç¢ºèªãã¦ã¿ã¾ãããã ã¯ã©ã¤ã¢ã³ã端æ«ããå³ä¸ã®ããµã¼ããã®Public IPã«pingãã¤ã¤ããã¢ãã©ã¤ã¢ã³ã¹ãã¤ã³ã¹ã¿ã³ã¹ã§tcpdumpãå®è¡ãã¦ããã¾ãã
以ä¸ã¯ãã¢ãã©ã¤ã¢ã³ã¹ãã¤ã³ã¹ã¿ã³ã¹ã§ãã£ããã£ããæ§åã§ãããããèªåï¼.212ï¼å®ã¦ã§ã¯ç¡ãå®å ã®ãã±ããï¼.210ï¼ããã£ããåä¿¡ãã¦ãã¾ããï¼ãã¨ã¯ç ®ããªãç¼ããªããã¾ãããã
ãããã«
ä»åããªãªã¼ã¹ã»ãã»ãã®VPC Ingress Routingã試ãã¦ã¿ã¾ããã è¨äºä¸ã§ã¯IGWãåæã«è©¦ãã¦ã¿ã¾ããããVGWã使ãã±ã¼ã¹ã§ãããããå ´é¢ãå¤ãããªæ°ããã¾ãã ä»ã«ãé¢ç½ãããªãªãªã¼ã¹æ å ±ãé£ã³äº¤ã£ã¦ããã®ã§ã楽ããã¦ä»äºãæã«ä»ããªãã§ãããð