ãããã«ã¡ã¯ä½ã æ¨ã§ãã å æ¥ãVPCã®FAQã«è¿½å ãããé ç®ã話é¡ã¨ãªã£ã¦ãã¾ããã2 ã¤ã®ã¤ã³ã¹ã¿ã³ã¹ããããªã㯠IP ã¢ãã¬ã¹ã使ç¨ãã¦éä¿¡ããå ´åããã©ãã£ãã¯ãã¤ã³ã¿ã¼ããããçµç±ãããã©ããã¨ããåãã«å¯¾ãã¦ãAWSããã¼ã¨è¨ã£ã¦ãã¾ããããã¯ãã©ããããã¨ãªã®ã§ããããï¼
ããããã©ã¤ãã¼ããããã¯ã¼ã¯ã®éä¿¡ã¨æ示ãããæå³ã¯å¤§ãã
â Takuro SASAKI (@dkfj) 2021å¹´4æ22æ¥
ãQ:2ã¤ã®ã¤ã³ã¹ã¿ã³ã¹ããããªã㯠IP ã¢ãã¬ã¹ã使ç¨ãã¦éä¿¡ããå ´åãã¾ãã¯ã¤ã³ã¹ã¿ã³ã¹ã AWS ã®ãµã¼ãã¹ã®ãããªãã¯ã¨ã³ããã¤ã³ãã¨éä¿¡ããå ´åããã©ãã£ãã¯ã¯ã¤ã³ã¿ã¼ããããçµç±ãã¾ãã?ãhttps://t.co/uy26KyCZKn
ããã®ãã¨ãèµ·ç¹ã«ãã¤ã³ã¿ã¼ãããã¨ã¯ä½ããAWSã®ãããã¯ã¼ã¯ã®ç¾ç¶ã«ã¤ãã¦èå¯ãã¦ã¿ã¾ããé£ããäºãè¨ã£ã¦ãã¾ãããã¿ããªçåã«æã£ã¦ããä¸ã®å³ã®ãï¼ãã®é¨åã®è¬è§£ãã§ãã
AWSã®VPCã®FAQ
ãã¾ãVPCã®FAQã¯ããªãã¨è¨ã£ã¦ããã®ã§ããããï¼æ¹ãã¦ç¢ºèªãã¦ã¿ã¾ãã
ãããã質å - Amazon VPC | AWS
Q: 2ã¤ã®ã¤ã³ã¹ã¿ã³ã¹ããããªã㯠IP ã¢ãã¬ã¹ã使ç¨ãã¦éä¿¡ããå ´åãã¾ãã¯ã¤ã³ã¹ã¿ã³ã¹ã AWS ã®ãµã¼ãã¹ã®ãããªãã¯ã¨ã³ããã¤ã³ãã¨éä¿¡ããå ´åããã©ãã£ãã¯ã¯ã¤ã³ã¿ã¼ããããçµç±ãã¾ãã?
ãããããããªãã¯ã¢ãã¬ã¹ã¹ãã¼ã¹ã使ç¨ããå ´åãAWS ã§ãã¹ãããã¦ããã¤ã³ã¹ã¿ã³ã¹ã¨ãµã¼ãã¹éã®ãã¹ã¦ã®é信㯠AWS ã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã使ç¨ãã¾ããAWS ãããã¯ã¼ã¯ããçºä¿¡ãããAWS ãããã¯ã¼ã¯ä¸ã®éä¿¡å ãæã¤ãã±ããã¯ãAWS ä¸å½ãªã¼ã¸ã§ã³ã¨ã®éã®ãã©ãã£ãã¯ãé¤ãã¦ãAWS ã°ãã¼ãã«ãããã¯ã¼ã¯ã«ã¨ã©ã¾ãã¾ãã
ããã«ããã¼ã¿ã»ã³ã¿ã¼ã¨ãªã¼ã¸ã§ã³ãç¸äºæ¥ç¶ãã AWS ã°ãã¼ãã«ãããã¯ã¼ã¯ãæµãããã¹ã¦ã®ãã¼ã¿ã¯ãå®å ¨æ§ãä¿è¨¼ãããæ½è¨ãé¢ããåã«ãç©çã¬ã¤ã¤ã¼ã§èªåçã«æå·åããã¾ãããã¹ã¦ã® VPC ã¯ãã¹ãªã¼ã¸ã§ã³ãã¢ãªã³ã°ãã©ãã£ãã¯ããã«ã¹ã¿ãã¼ã¾ãã¯ãµã¼ãã¹éã®ãã©ã³ã¹ãã¼ã層ã»ãã¥ãªã㣠(TLS) æ¥ç¶ãªã©ã¨ãã£ã追å ã®æå·åã¬ã¤ã¤ã¼ãããã¾ãã
ã確ãã«ããããªãã¯IPå士ã®éä¿¡ã§ãããã©ãã£ãã¯ã¯ã¤ã³ã¿ã¼ããããçµç±ããªãã§AWSã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã使ç¨ãã¦ããã¨è¨ã£ã¦ãã¾ãããã©ããããã¨ã§ãããï¼èå¯ããåã«ãããè¨ç·´ãããAWSå©ç¨è ã®åã¿ã¨ãã¦ãåæã§ããè±èªã®æ¹ã§ã確èªãã¦ã¿ã¾ãããã
- Does traffic go over the internet when two instances communicate using public IP addresses, or when instances communicate with a public AWS service endpoint?
No. When using public address space, all communication between instances and services hosted in AWS use AWS's private network. Packets that originate from the AWS network with a destination on the AWS network stay on the AWS global network, except traffic to or from AWS China Regions.
In addition, all data flowing across the AWS global network that interconnects our data centers and Regions is automatically encrypted at the physical layer before it leaves our secured facilities. Additional encryption layers exist as well; for example, all VPC cross-region peering traffic, and customer or service-to-service Transport Layer Security (TLS) connections.
ãè±èªçã§ãåããã¨ãè¨ã£ã¦ãã¾ããã誤訳ã§ã¯ãªãããã§ããã§ã¯ãã©ããããã¨ãªã®ã§ããããï¼ãããèããä¸ã§ãã¾ãã¤ã³ã¿ã¼ãããã¨ã¯ä½ãã¨ããã®ãæ¹ãã¦æ´çãã¦ã¿ã¾ãããã
ã¤ã³ã¿ã¼ãããã¨èªå¾ã·ã¹ãã ï¼ãããã¯ã¼ã¯ï¼
ãã¤ã³ã¿ã¼ãããã¯ãèªæºã¨ãã¦ãå®æ ã¨ãã¦ããè¤æ°ã®ãããã¯ã¼ã¯ãç¸äºæ¥ç¶ãããããã¯ã¼ã¯ãã§ããããã¦ãããã§æããããã¯ã¼ã¯ã¨ã¯ãèªå¾ã·ã¹ãã (autonomous systemï¼AS)ã®äºã§ãããä¸ã¤ã®ãããã¯ã¼ã¯ç®¡çè ã®å ã§åä¸ã®æ確ã«å®ç¾©ãããã«ã¼ãã£ã³ã°ããªã·ã¼ã«ãã£ã¦å¶å¾¡ããã¦ãããããã¯ã¼ã¯ã®ãã¨ã§ããå³å¼åããã¨ã次ã®å³ã®ããã«ãªãã¾ãã
ã次ã«ãã¤ã³ãã«ãªãã®ãããããã¯ã¼ã¯éã®æ¥ç¶å½¢æ ã§ããæ¥ç¶ã®å¶å¾¡ã«ã¤ãã¦ã¯ãBGPã¨ãããããã³ã«ã§å¶å¾¡ãã¦ãã¾ããããã¦ãæ¥ç¶å½¢æ ã¨ãã¦ã¯ããã©ã³ã¸ããã¨ãã¢ã¨ãã2ã¤ã®å½¢æ ãããã¾ããããã¦ãã¢æ¥ç¶ã«ã¯ããã©ã¤ãã¼ãã¨ãããªãã¯ã®2種é¡ãããã¾ãããã©ã³ã¸ããã¯ä¸æµã®ASã«ä½¿ç¨æãæã£ã¦ãã©ãã£ãã¯ãæµãæ¹å¼ã§ãããã¢æ¥ç¶ã¯ã横å士ã®ASã«ç¸äºã«ãã©ãã£ãã¯ãæµãæ¹å¼ã§ããç¸äºã«æµãããã使ç¨æã¯ç¡æã§ããããã¦ãã¢æ¥ç¶ã®ãã¡ã§ãå°ç¨ç·ãå°æãã¦æ¥ç¶ãã¦ããã®ããã©ã¤ãã¼ããã¢ã§ããIXï¼Internet eXchangeï¼ã¤ã³ã¿ã¼ãããç¸äºæ¥ç¶ï¼ã®ãµã¼ãã¹ãå©ç¨ãã¦ãåç·ãå ±ç¨ãã¦æ¥ç¶ããã®ããããªãã¯ãã¢ã§ããä¸è¬çã«ãã¢ã«ããæ¥ç¶ã®æ¹ããçµè·¯ãã·ã³ãã«ã§éä¿¡å質ãé«ããªãã¾ãã
ãã¤ã³ã¿ã¼ãããã¨æ¥ç¶ã«ã¤ãã¦ã®æ¦è¦ã¯ããªãã¨ãªãç解ã§ããã§ããããï¼ãããä¸æ·ãã«ãAWSã®FAQãè¨ããã¨ãã¦ããAWS ã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã¨ã¯ä½ãããèªã¿è§£ãã¦ããã¾ãããã
AWSã®ã°ãã¼ãã«ã¤ã³ãã©ã¹ãã©ã¯ãã£
ãæ¥ç¶ã®è©±ãè¸ã¾ããä¸ã§ãAWSã®ã°ãã¼ãã«ã¤ã³ãã©ã¹ãã©ã¯ãã£ã®èª¬æãèªãã§ã¿ã¾ãããã
ãã¹ã¦ã®ãã¼ã¿ã»ã³ã¿ã¼ãAZãããã³ AWS ãªã¼ã¸ã§ã³ã¯ãå¯ç¨æ§ã®é«ãä½ã¬ã¤ãã³ã·ã¼ã®å°ç¨ãã©ã¤ãã¼ãã°ãã¼ãã«ãããã¯ã¼ã¯ã¤ã³ãã©ã¹ãã©ã¯ãã£ãä»ãã¦ç¸äºæ¥ç¶ããã¦ãã¾ãããã®ãããã¯ã¼ã¯ã¯ã大西æ´ã太平æ´ãã¤ã³ãæ´ãã¯ãããå°ä¸æµ·ãç´ æµ·ãåã·ãæµ·ã«ããã£ã¦å¤§æ´æ¨ªæã±ã¼ãã«ã§æ¥ç¶ããããå®å ¨ã«åé·æ§ãæã¤ãã©ã¬ã« 100 GbE ã¡ãããã¡ã¤ãã¼ãããã¯ã¼ã¯ä¸ã«æ§ç¯ããã¦ãã¾ãã
ãAWSã®ãããã¯ã¼ã¯å ¨ä½ãã©ã®ãããªæ§æã«ãªã£ã¦ããã®ããç§ã¯ææ¡ã¯ãã¦ããã¾ããããã ãåã ã®AWSã®ãã¼ã¿ã»ã³ã¿ã¼ã¯ãTier III+ ã¬ã¤ãã©ã¤ã³ã«åã£ã¦éç¨ããã¦ããã¨æè¨ããã¦ãã¾ããã¾ããä¸è¨ã®æç« ã§ãAZåã³AWSãªã¼ã¸ã§ã³ã¯ãï¼ä¸å½ãé¤ãï¼AWSãä¿æããå°ç¨ç·ã§ãã©ã¤ãã¼ãæ¥ç¶ããã¦ããã¨æ¸ãã¦ãã¾ããã¤ã¾ããAZï¼ããã³å é¨ã®ãã¼ã¿ã»ã³ã¿ã¼ï¼ã¯ãç¸äºã«ãã©ã¤ãã¼ããã¢æ¥ç¶ããã¦ããã¨ãããã¨ã§ãããã
AWSã®ãããªãã¯IPéã®éä¿¡ããã©ã¤ãã¼ãæ¥ç¶ã¨ãããã¨ã¯ï¼
ãããã¾ã§è¾æ±å¼·ãèªãã§ããã ããæ¹ã¯ãAWSã®ãããªãã¯IPéã®éä¿¡ããã©ã¤ãã¼ãæ¥ç¶ã¨ãããã¨ã®æå³ãç解ã§ããããã«ãªã£ãã§ããããã¤ã¾ããï¼ä¸å½ãé¤ãï¼ãã¹ã¦ã®ãªã¼ã¸ã§ã³ãä»ç¤¾ã管çãããããã¯ã¼ã¯ï¼ASï¼ãå°ç¨ç·ãçµç±ãããã¨ãªããå ¨ã¦AWS管çä¸ã®ãããã¯ã¼ã¯å ã§éä¿¡ãå®çµããã¨ãããã¨ã§ããæåã®å³ããã®ãããªæãã«ãªãã¾ã
PrivateLinkãVPC Endpointã®æå³ã¯ï¼
ãAWSå
ã§ã¯ããã¨ãã°ãã¼ãã«IPã使ã£ãéä¿¡ã§ããã¤ã³ã¿ã¼ãããï¼ä»ç¤¾ç®¡çã®ãããã¯ã¼ã¯ï¼ãçµç±ããªãã¨ãããã¨ã解ãã¾ãããããã§ãä¸ã¤ã®çåãåºã¦ããã¨æãã¾ããPrivateLinkãVPC Endpointã使ãæå³ã¯ããã®ãã¨ãããã¯é常ã«éè¦ãªè«ç¹ã ã¨æãã¾ããéä¿¡æã®è¦³ç¹ã§ããã¨ãåä¸ãªã¼ã¸ã§ã³ã®EC2ã¨S3ã®éä¿¡æã¯ã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤ãä»ããå ´åã¯ç¡æã¨ãªãã¾ããä¸æ¹ã§ãPrivateLinkãVPC Endpointãä»ããå ´åããã¼ã¿éã«å¿ããéä¿¡æãçºçãã¾ãã大éã®ãã¼ã¿ãæ±ãå ´åãPrivateLinkã®éä¿¡æãç¡è¦ã§ããªãã±ã¼ã¹ã¯å¤ã
ããã¾ãã
ãAWSå
ã§å®çµããå¦çã§ããã°ãã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤ãä»ãã¦ãã¤ã³ã¿ã¼ãããã«åºãªããã¨ã確ç´ããã¦ããã®ã§ããã°ãæ¢ãã¦PrivateLinkã使ããªãã¨ããé¸æè¢ãå
åããããã¨æãã¾ãã
ããã ããã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤ãä½ã£ãå ´åãAWSå¤ã®éä¿¡ãå½ç¶ã§ãã¦ãã¾ãã¾ããããã®å¶å¾¡ã¯ã©ããããã¯ãåã
ã®å¤æã§èããå¿
è¦ãããã¾ããAWSã®IPã¢ãã¬ã¹ãããã¯ãã¨ã³ããã¤ã³ãã®ãã¡ã¤ã³ãããã¯FQDNã§çµãã¨ããæ¹æ³ãããã¾ããããããä¸ã
é£ããã®ã§ããIPã¢ãã¬ã¹ã§ã®å¶éã¯ãè¨å¤§éãã¦ã»ã¼ç®¡çä¸è½ã§ããã¾ããã¡ã¤ã³ããµã¼ãã¹ãã¨ã«å¹¾ã¤ããã¿ã¼ã³ãããããµã¼ãã¹å¢å ã¨ã¨ãã«å¢ãã¦ãã¾ãã管çã«ã¯å¾®å¦ã«æéããããã¾ãã
ä»ã¾ã§ããªãæè¨ããã¦ããªãã£ãã®ãï¼
ãæåã®ã¤ã¶ããã§ããæ示ãããæå³ã¯å¤§ãããã¨æ¸ãã¾ãããä»ã¾ã§ããªããã©ã¤ãã¼ããããã¯ã¼ã¯ã¨æ示ããªãã£ãã®ã§ãããï¼ããã¯ããã©ã¤ãã¼ããããã¯ã¼ã¯ã§ã¯ãªããã¤ã³ã¿ã¼ããããä»ãéä¿¡ããã£ãããã§ããä¾ãã°ããªã¼ã¸ã§ã³éã®æ¥ç¶ãAWSã®å°ç¨ç·ã«ãªã£ãã®ã¯ããæè¿ã§ããå米大é¸ã¯ãããã¨æ©ã段éã§ãªã¼ã¸ã§ã³éãå°ç¨ç·ã§ã¤ãªãã ã¨ã¢ãã¦ã³ã¹ããã¾ãããããã®ä»ã«ã¤ãã¦ã¯å°æ¥çãªå¯¾å¿ã¨ãããã¨ã§ãããä»åã®ããã®ã¤ã¶ããããã£ããã«èª¿ã¹ç´ãã¦ãå
¨ã¦å¯¾å¿ããã¨ãããã¨ãç§ãç¥ãã¾ããã
ãã¾ãããã以åã«ãªã¼ã¸ã§ã³å
ã®éä¿¡ããåæã¯IXããã©ã³ã¸ãããçµç±ããã¤ã³ã¿ã¼ããããçµç±ããéä¿¡ã ã£ãããã§ããããã段éçã«æ´çããã¦ãã£ãã¨ãããã¨ãªã®ã§ããããã¤ã¾ããä»åVPCã®FAQã§æ示ãããã¨ã§ããªã¼ã¸ã§ã³å
ããªã¼ã¸ã§ã³éããã¹ã¦AWSã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã§å®çµãããããªå¯¾å¿ãå®äºãããã¨ãã宣è¨ã§ãããããã§ãããããæå³ãããã¨ã¯å¤§ããã§ãã
AWSã®Edgeãµã¼ãã¹ã¨AWSã®ã°ãã¼ãã«ãããã¯ã¼ã¯
ãã¡ãªã¿ã«ãAmazon CloudFrontã®ãããªAWSã®Edgeãµã¼ãã¹ä¸ã§å±éããããµã¼ãã¹ã«ã¤ãã¦ã¯ãä¸è¨ã®ãããªAWSã®ã°ãã¼ãã«ãããã¯ã¼ã¯å ã«éããéä¿¡ã§ã¯ãªãããã§ãããã®ç¹ã¯ãã注æãã ãããEdgeãããã¯ã¼ã¯ã¨ããç¹æ§ãèããã¨å½ç¶ã¨ããã°å½ç¶ã§ããããã®ãã¡ãå ¨é¨ç¶²ç¾ ããã¨ããéæãæã£ã¦ãããã§æãã§ãã
ã¾ã¨ã
ãã¤ã³ã¿ã¼ãããã®æ§é ã¨ãããããã®ãããã¯ã¼ã¯ã®æ¥ç¶å½¢æ ï¼ãã©ã³ã¸ããã¨ãã¢æ¥ç¶ï¼ãè¸ã¾ãã¦ãä»åã®AWSã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã®æå³ãèªã¿è§£ãã¦ã¿ã¾ããããã ãFAQã®å¾åã®æ¹ã«ã¯ãAWS ã°ãã¼ãã«ãããã¯ã¼ã¯ãæµãããã¹ã¦ã®ãã¼ã¿ã®æå·åã®è©±ãæ¸ãã¦ããã¾ããããã¯å ·ä½çã«ä½ããã£ã¦ããã®ãå ¨ç¶ç¥ãã¾ãããã¾ãæ©ä¼ãè¦ã¤ãã¦ã調ã¹ã¦ãããã¨æãã¾ãã