ã¼ã¡ã¼ã¡Amazon VPCã触ãå§ãã¦ã¿ã¾ããã
ä»æ´ãªæãããã¾ãããAmazon VPCã®Private Subnetã«Hardware VPN(IPsec VPN)ã使ã£ã¦æ¥ç¶ã§ããä»æç¹ã§ã®è©³ããæé ãæ®ãã¦ãããã¨æãã¾ãã(ã·ãªã¼ãºåãã¾ããå¤åã)
Amazon VPCã®æ¦è¦ã¯ãä¸è¨å
¬å¼ãµã¤ãã®èª¬æã«ä»»ãã¾ãããç°¡åã«èª¬æããã¨ãAmazon VPCã使ããã¨ã§ãAWSã¯ã©ã¦ãå
ã«ãã©ã¤ãã¼ããããã¯ã¼ã¯ãä½æãããã¨ãã§ããã®ã§ãå¾æ¥ãããããã¯ã¼ã¯ã¬ãã«ã§ã®ç´°ãããªã¢ã¯ã»ã¹ã³ã³ããã¼ã«ãå®ç¾ã§ãã¾ãã
ã¾ããVPNæ¥ç¶ããµãã¼ããã¦ããã®ã§ãä¼ç¤¾ããã¼ã¿ã»ã³ã¿ã¼ã¨æ¥ç¶ãããã¨ã§ããã©ã¤ãã¼ããããã¯ã¼ã¯å
ã§AWSã®ãªã½ã¼ã¹ãã·ã¼ã ã¬ã¹ã«æ±ããã¨ãã§ããããã«ãªãã¾ããã¤ã¾ããèªç¤¾ãããã¯ã¼ã¯ã®ã¢ãã¬ã¹ãAmazon EC2ã®ã¤ã³ã¹ã¿ã³ã¹ã«æ¯ããã¨ãã§ãããã¿ãããªã¤ã¡ã¼ã¸ã§ãã
åæã¨ãªãæ§æ
VPCã®åæã¦ã£ã¶ã¼ãã§ãä¸çªçãè¾¼ãã ãPublic/Private Subnetãç¨æããPrivate Subnetã«ã¯VPNã§ã¤ãªããã¿ã¼ã³ãé¸æãã¦ã¿ã¾ããã
ãã¿ã¼ã³ã¯ä»ãå«ããã¨ä»¥ä¸ã®éãã§ãã
http://aws.amazon.com/jp/vpc/faqs/#G4
- 1ã¤ã®ãããªã㯠ãµããããã®ã¿ãæ㤠VPC
- ãããªãã¯ã¨ãã©ã¤ãã¼ã ãµãããããæ㤠VPC
- ãããªãã¯ã¨ãã©ã¤ãã¼ã ãµããããããã³ãã¼ãã¦ã§ã¢ VPN ã¢ã¯ã»ã¹ãæ㤠VPC
- 1ã¤ã®ãã©ã¤ãã¼ã ãµããããã®ã¿ãããã³ãã¼ãã¦ã§ã¢ VPN ã¢ã¯ã»ã¹ãæ㤠VPC
ã¡ãªã¿ã«ãVPNãã¯ãããã«å©ç¨ããã«ã¼ã¿ã¼ã¯ãCisco社ã®1921ã·ãªã¼ãºã§ãã
使ããã«ã¼ã¿ã¼(VPN)ã®è¦ä»¶
Amazon VPCã«æ¥ç¶ãããã¿ã¼ã³ã¨ãã¦ãéçã«ã¼ãã£ã³ã°ã使ã£ãVPNæ¥ç¶ã¨ãåçã«ã¼ãã£ã³ã°(è¦BGP)ã使ã£ãVPNæ¥ç¶ãããã¾ãã
ä»åã¯ã(大æãããªãã®ã§ããªãã®ã§)éçã«ã¼ãã£ã³ã°ãè¨å®ãã¦ä½¿ããã¨ã«ãã¾ãã(以éãéçã«ã¼ãã£ã³ã°ã§ã®è¨å®ã«çµã£ã¦æ¸ãã¾ãã)
ãã®éããã¡ãå´ã§VPCã¸æ¥ç¶ããããã«å¿ è¦ã¨ãªãã«ã¼ã¿ã¼(ã«ã¹ã¿ãã¼ã²ãã¦ã§ã¤)ã®è¦ä»¶ã¯ä»¥ä¸ã¨ãªãã¿ããã§ãã
http://aws.amazon.com/jp/vpc/faqs/#C8
- Pre-shared ãã¼ã使ç¨ãã¦ãIKE ã»ãã¥ãªãã£æ¥ç¶ã確ç«ãã
- ãã³ãã«ã¢ã¼ãã§ãIPsec ã»ãã¥ãªãã£æ¥ç¶ã確ç«ãã
- AES 128ãããæå·åæ©è½ãå©ç¨ãã
- SHA-1 ããã·ã¥æ©è½ãå©ç¨ãã
- ãã°ã«ã¼ã2ãã¢ã¼ãã§ãDiffie-Hellman Perfect Forward Secrecy ãå©ç¨ãã
- æå·åã®åã«ãã±ããã®æçåãå®è¡ãã
å°ã(ç¾æç¹ã§)以ä¸ã®ããã¤ã¹ã«ã¤ãã¦ã¯ãVPNæ¥ç¶ã«å¿
è¦ãª(ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã§ã®)è¨å®ãã¡ã¤ã«ããAWSå´ã§èªåçæãã¦ããã¾ãã
http://aws.amazon.com/jp/vpc/faqs/#C9
- Cisco ASA 5500 ã·ãªã¼ãºãã¼ã¸ã§ã³ 8.2 以éã®ã½ããã¦ã§ã¢
- Cisco ISRï¼IOS 12.4 以éã®ã½ããã¦ã§ã¢ãå®è¡ï¼
- Juniper J ã·ãªã¼ãºãµã¼ãã¹ã«ã¼ã¿ã¼ï¼JunOS 9.5 以éã®ã½ããã¦ã§ã¢ãå®è¡ï¼
- Juniper SRX ã·ãªã¼ãºãµã¼ãã¹ã²ã¼ãã¦ã§ã¤ï¼JunOS 9.5 以éã®ã½ããã¦ã§ã¢ãå®è¡ï¼
- ScreenOS 6.1 ããã㯠6.2ï¼ã¾ãã¯ãã以éï¼ãå®è¡ãã Juniper SSG
- ScreenOS 6.1 ããã㯠6.2ï¼ã¾ãã¯ãã以éï¼ãå®è¡ãã Juniper ISG
- Microsoft Windows Server 2008 R2 以éã®ã½ããã¦ã§ã¢
- ã¤ãã RTX1200 ã«ã¼ã¿ã¼
VPCã®ä½æ
ã§ã¯ãæ©éVPCãä½æãã¦ã¿ã¾ãããã
GUIã§ç°¡åã«ãªãã¬ã¼ã·ã§ã³ããã¹ããã¾ãã¯AWS Management Consoleã«ã¢ã¯ã»ã¹(ãã°ã¤ã³)ãã¦ããµã¼ãã¹ä¸è¦§ã®ã¨ãããã"VPC"ãé¸æãã¾ãã
ãªã¼ã¸ã§ã³ã«ã¤ãã¦ã¯ãæ¥ç¶ããã(VPCãä½æããã)ãªã¼ã¸ã§ã³ãé¸ãã§ããã¦ãã ããã
ã¾ããæåã®æ®µéã§ã¯ãå ¨ãVPCã®è¨å®ãããã¦ããªãã¯ãã§ãã®ã§ãâã®ãããªã¦ã£ã¶ã¼ãã¸èªå°ãããæãã«ãªã£ã¦ãã¾ãã"Get started creating a VPC"ãã¯ãªãã¯ãã¾ãããã
次ã«ãæ§æãã¿ã¼ã³ã¨ãã¦4éãã®å ã1ã¤ã ãé¸ã³ã¾ããå ã»ã©ãæ¸ãã¾ãããã以ä¸ã®4ã¤ã§ãã
http://aws.amazon.com/jp/vpc/faqs/#G4
- 1ã¤ã®ãããªã㯠ãµããããã®ã¿ãæ㤠VPC
- ãããªãã¯ã¨ãã©ã¤ãã¼ã ãµãããããæ㤠VPC
- ãããªãã¯ã¨ãã©ã¤ãã¼ã ãµããããããã³ãã¼ãã¦ã§ã¢ VPN ã¢ã¯ã»ã¹ãæ㤠VPC
- 1ã¤ã®ãã©ã¤ãã¼ã ãµããããã®ã¿ãããã³ãã¼ãã¦ã§ã¢ VPN ã¢ã¯ã»ã¹ãæ㤠VPC
ä»åã¯ã3ã¤ç®ã®Public/Private Subnetã®ä¸¡æ¹ãä½æããPrivate Subnetã«ã¯VPNã§ã¤ãªããã¿ã¼ã³ãé¸æãã¦ã¿ã¾ããã
ãã¦ãããããã¯ãããã¯ã¼ã¯ã®è¨å®ã§ãã
1ã¤ç®ã¯ãã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã¨ãªããVPNãã³ãã«ãæãã«ã¼ã¿ã¼ã®IPã¢ãã¬ã¹ãå
¥åãã¾ãã
2ã¤ç®ãä»åã¯éçã«ã¼ãã£ã³ã°ã§ã®æ¥ç¶ãªã®ã§ã"Use static routing"ãé¸æããä¸é¨ã®ããã¹ãããã¯ã¹ã«ã¯ãVPCå´ãããèªãããã¯ã¼ã¯å´ã¸ã®ã«ã¼ãã£ã³ã°ãè¨è¼ãã¾ããã¤ã¾ããèªãããã¯ã¼ã¯ãããAWSã®VPC網ã«ã¢ã¯ã»ã¹ãããããµã¼ãçã®ãããã¯ã¼ã¯ã»ã°ã¡ã³ãã§ãã£ãããAWSã®VPC網å
ã®ãµã¼ã(EC2ã¤ã³ã¹ã¿ã³ã¹)ããã¢ã¯ã»ã¹ããããå
(èªãããã¯ã¼ã¯ã®ã»ã°ã¡ã³ã)ã®ãããã¯ã¼ã¯ãè¨è¼ãã¾ãã
ããã¯ããããã¯ã¼ã¯ã¢ãã¬ã¹/ãµãããããã¹ã¯ãå
¥åãã¦ã"Add"ãã¯ãªãã¯ãããã¨ã§è¤æ°è¿½å ã§ãã¾ãã
å ¨ã¦å ¥åã§ãããã"Continue"ãã¯ãªãã¯ãã¾ãããã
ãã®é¨åã¯å¿
è¦ãããã°ãç·¨éãã¾ãããã
"One VPC with an Internet Gateway"ã®é¨åã¯ãVPCå´ã§ä»ä¸ããããããã¯ã¼ã¯ã®ã»ã°ã¡ã³ããæå®ãã¾ããç¹ã«ãã ããããªã(æ¢åã®èªãããã¯ã¼ã¯ã§ä½¿ã£ã¦ããªã)ã®ã§ããã°ãããã©ã«ãã®ã¾ã¾ã§ãããã¨æãã¾ãã
"Two Subnets"ã®ã¨ããã§ã¯ãVPCãããã¯ã¼ã¯å
ã§åå²ãã¹ããµããããã®æå®ããã¾ãããã®è¾ºãã¢ã¯ã»ã¹ã³ã³ããã¼ã«ãããåä½ã¨ãã§ãé©å®ãããã¯ã¼ã¯ãåºåãã¾ããããã¾ããåãµãããããã©ã®Availability Zoneã«é
ç½®ããããæå®ã§ãã¾ãã
"One VPN Connection"ã®ã¨ããã¯ãå
ã»ã©ã®ç»é¢ã§è¨å®ãããã®ãå
¥ã£ã¦ããã¯ãã
"Hardware Tenancy"ã¯ãVPC網å
ã§åããAmazon EC2ã¤ã³ã¹ã¿ã³ã¹ã§Dedicated Instance(ãã¼ãã¦ã§ã¢å æã¤ã³ã¹ã¿ã³ã¹)ãå©ç¨ãããã©ããã®é¸æã¨ãªãã¾ãã
å
¨ã¦ç¢ºèª(ç·¨é)ããå¾ã"Create VPC"ãã¯ãªãã¯ãã¾ãã
VPCä½æä¸ã®ãã¤ã¢ãã°ãåºã¾ãããã°ãå¾ ã¤ã
ç¡äºãVPCãä½æããã¾ãããããã§"Download Configuration"ãã¯ãªãã¯ããã¨ãã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ã®ããã¤ã¹ã«ããããè¨å®ãã¡ã¤ã«ããã¦ã³ãã¼ãã§ãã¾ãã(ã®ã§ãã¯ãªãã¯ãã¾ãã)
ããã¨ãâã®ãããªã¦ã£ã³ãã¦ãåºãã®ã§ãããã¤ã¹ã®ãã³ãã¼ãæ©ç¨®(ã·ãªã¼ãº)ãã½ããã¦ã§ã¢(OS)çãé¸æãã¦ã"Yes, Download"ãã¯ãªãã¯ããã¨ãè¨å®ãã¡ã¤ã«ããã¦ã³ãã¼ãã§ãã¾ãã
VPNã«ã¼ã¿ã¼ã«è¨å®ãæå ¥
VPCãä½æãããã次ã¯ã«ã¹ã¿ãã¼ã²ãã¦ã§ã¤ã¨ãªãã«ã¼ã¿ã¼ã«ãå
ã»ã©ãã¦ã³ãã¼ãããè¨å®ãæå
¥ãã¦ããã¾ãã
ã«ã¹ã¿ãã¼ã²ã¼ãã¦ã§ã¤ããã¯ãAWSå´ã®ã²ã¼ãã¦ã§ã¤ã«2æ¬åã®IPsecãã³ãã«ãã¯ããã¨ã«ãªãã¾ãããã³ãã«1æ¬åã®è¨å®ã¨ãã¦ã¯ããµã³ãã«ã§ã¯ããã¾ããå®éã«ã¯ã(ã¡ãã£ã¨é·ãã§ãã)以ä¸ã®ãããªãã³ãã¬ã¼ãã«ãªã£ã¦ãã¾ãã(Cisco IOSåããè¥å¹²ãã¹ãã³ã°ãã¦ãã¾ã)
crypto isakmp policy 200 encryption aes 128 authentication pre-share group 2 lifetime 28800 hash sha exit ! crypto keyring keyring-vpn-xxxxxxxx-x local-address xxx.xxx.xxx.xxx pre-shared-key address 27.0.1.xx key xyzxyzxyzxyzxyzxyzxyzxyzxyzxyzxy exit ! crypto isakmp profile isakmp-vpn-xxxxxxxx-x local-address xxx.xxx.xxx.xxx match identity address 27.0.1.xx keyring keyring-vpn-xxxxxxxx-x exit ! crypto ipsec transform-set ipsec-prop-vpn-xxxxxxxx-x esp-aes 128 esp-sha-hmac mode tunnel exit ! crypto ipsec profile ipsec-vpn-xxxxxxxx-x set pfs group2 set security-association lifetime seconds 3600 set transform-set ipsec-prop-vpn-xxxxxxxx-x exit ! crypto ipsec df-bit clear ! crypto isakmp keepalive 10 10 on-demand ! crypto ipsec security-association replay window-size 128 ! crypto ipsec fragmentation before-encryption ! interface Tunnel1 ip address 169.254.252.2 255.255.255.252 ip virtual-reassembly tunnel source xxx.xxx.xxx.xxx tunnel destination 27.0.1.xx tunnel mode ipsec ipv4 tunnel protection ipsec profile ipsec-vpn-xxxxxxxx-x ip tcp adjust-mss 1387 no shutdown exit ! ip route 10.96.0.0 255.255.0.0 Tunnel1 track 100 ! ip sla 100 icmp-echo 169.254.252.1 source-interface Tunnel1 timeout 1000 frequency 5 exit ! ip sla schedule 100 life forever start-time now ! track 100 ip sla 100 reachability
AWS Management Consoleãããã¦ã³ãã¼ãããè¨å®ãã¡ã¤ã«ã«ã¯ãIPsecãã³ãã«2æ¬åã®è¨å®ãå
¥ã£ã¦ãã(ä¸è¨ãµã³ãã«ã¯1æ¬å)ã®ã§ã2æ¬åè¨å®ãã¡ããã¾ãã
(AWSå´ã®ã²ã¼ãã¦ã§ã¤ã«çéã§ãããããèªãããã¯ã¼ã¯æ§æã«å¿ãã¦ã«ã¼ãã£ã³ã°ã®è¨å®ã¯ç¢ºèªãã¦ãã ããã)
#show crypto isakmp sa IPv4 Crypto ISAKMP SA dst src state conn-id status 27.0.1.xx xxx.xxx.xxx.xxx QM_IDLE 1001 ACTIVE 27.0.1.yy xxx.xxx.xxx.xxx QM_IDLE 1002 ACTIVE
"show crypto isakmp sa"ã³ãã³ããå®è¡ãã¦ãåé¡ãªãè¨å®ãããã°ãã¾ãä¸è¨ã®ããã«ISAKMP(éµäº¤æ)ã®ã¹ãã¼ã¿ã¹ãæ£å¸¸ã«ãªã£ã¦ãããã¨æãã¾ããä»åã®ä¾ã ã¨stateãQM_IDLEãstatusãACTIVEã«ãªã£ã¦ããã°OKã§ãã
#show crypto ipsec sa interface: Tunnel1 ãããããçç¥ããããã inbound esp sas: spi: 0x2F74367A(796145274) transform: esp-aes esp-sha-hmac , in use settings ={Tunnel, } conn id: 2687, flow_id: Onboard VPN:687, sibling_flags 80000040, crypto map: Tunnel1-head-0 sa timing: remaining key lifetime (k/sec): (4281963/1734) IV size: 16 bytes replay detection support: Y replay window size: 128 Status: ACTIVE(ACTIVE) ãããããçç¥ããããã outbound esp sas: spi: 0xE7B8E672(3887654514) transform: esp-aes esp-sha-hmac , in use settings ={Tunnel, } conn id: 2688, flow_id: Onboard VPN:688, sibling_flags 80000040, crypto map: Tunnel1-head-0 sa timing: remaining key lifetime (k/sec): (4281963/1734) IV size: 16 bytes replay detection support: Y replay window size: 128 Status: ACTIVE(ACTIVE) ãããããçç¥ããããã
次ã«"show crypto ipsec sa"ã³ãã³ããå®è¡ããIPsecãã³ãã«ã®ç¶æ
ã確èªãã¾ãã
ä¸è¨ã®ããã«inbound/outbound esp sasã®é¨åã«ä½ãããã¹ãã¼ã¿ã¹ã表示ããã¦ããã°ãIPsecãã³ãã«ã確ç«ããã¦ãããã¨ã«ãªãã¾ãã
AWS Management Consoleã®[Amazon VPC] - [VPN Connections]ã§ãä¸å³ã®ããã«VPNã®æ¥ç¶ç¶æ³ã確èªã§ãã¾ãã
ãµã¼ãããçé確èª
ãã¦ããã³ãã«ã確ç«ãããã¨ããã§ãèªãããã¯ã¼ã¯ã®ãµã¼ãã¨AWSå´ã®ãµã¼ã(EC2)ã®çé確èªããã¦ã¿ã¾ãã
ã¾ããAmazon EC2ã®ã¤ã³ã¹ã¿ã³ã¹ãèµ·åãã¦ã¿ã¾ããã¤ã³ã¹ã¿ã³ã¹ã®èµ·åæ¹æ³ã«ã¤ãã¦ã¯ãå¤ãã®è§£èª¬ãµã¤ããåå¨ããã®ã§ã詳ããã¯å²æãã¾ãããã¤ã³ã¹ã¿ã³ã¹èµ·åã®éã«ãVPCã¾ãããé¢é£ããé¨åã®è¨å®ã¯ä»¥ä¸ã®éãã
EC2ã¤ã³ã¹ã¿ã³ã¹èµ·åæã«ããã®ã¤ã³ã¹ã¿ã³ã¹ãVPCã®ã©ã®ãµããããã«æå±ãããããé¸æãã¾ãã(å²ãå½ã¦å¯è½ãªæ®ãIPã¢ãã¬ã¹æ°ã¨ãã表示ããã¦ãã¾ããã)
ä¸çªä¸é¨ã«ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¼ã¹ã®è¨å®ãããé¨åãããã¾ãã
ã¤ã³ã¿ã¼ãã§ã¼ã¹ã®æ°ããå²ãæ¯ãIPã¢ãã¬ã¹ã®æå®(ããã©ã«ãã§ã¯èªåã§å²ãæ¯ã)ãPublic IPãæ¯ããã©ããããã¨ã¤ãªã¢ã¹ã®æå®ãªã©ã
ã¨ã主ãªã¨ããã¯ããããªã¨ããã§ããããã
EC2ã¤ã³ã¹ã¿ã³ã¹ãèµ·åããããèªãããã¯ã¼ã¯å
ã®ãµã¼ãããã¢ã¯ã»ã¹ãã¦ã¿ã¾ããããæ£ããè¨å®ããã¦ããããéä¿¡ã§ããã¯ãã§ãã
ãã¾ãçéã§ããªãå ´å
以ä¸ã®ã«ã¼ãã£ã³ã°ã¾ããã¨ãã確èªãã¦ã¿ãã¨ããããã
- èªãããã¯ã¼ã¯ãããVPC(ããã³ãã®ãµãããã)ã®ãããã¯ã¼ã¯ã»ã°ã¡ã³ãã¸ã®éä¿¡
- VPCã®ãããã¯ã¼ã¯ãããèªãããã¯ã¼ã¯ã»ã°ã¡ã³ãã¸ã®éä¿¡
- VPNã²ã¼ãã¦ã§ã¤(VPN Connectionsã®Static Routesã§è¨å®)
- VPCã®ãµãããã(Route Tablesã§è¨å®)
ãã¨ã¯ããã¿ã«ãNetwork ACLãSecurity Groupsã§ãã£ã«ã¿ããã¦ããªããã確èªããããããã§ããããã
ã¡ãã£ã¨é·ããªã£ãã®ã§ãä»æ¥ã¯ãã®è¾ºã¾ã§ã(ç¶ãã¯å¥ã®ã¨ã³ããªã«ãã¾ãã)
ããã§ã¯ï¼=͟͟͞͞(๑•̀=͟͟͞͞(๑•̀д•́=͟͟͞͞(๑•̀д•́๑)=͟͟͞͞(๑•̀д•́
ãããã¦èªã¿ãã
AWSå ¬å¼ã®ãã¬ã¼ã³è³æããæ¦ç¥ãæ´ãè³æã¨ãã¦ã¯ããããããã¦ãªã¹ã¹ã¡ã§ãããã¾ãã
追è¨
ç¶ããæ¸ãã¾ããã
ã¾ã¨ã
ã¯ã©ã¦ãAMAZON EC2/S3ã®ãã¹ã¦ (ITpro BOOKs)
- ä½è : 並河ç¥è²´,å®éè¼é,ITpro/æ¥çµSYSTEMS
- åºç社/ã¡ã¼ã«ã¼: æ¥çµBP社
- çºå£²æ¥: 2009/11/05
- ã¡ãã£ã¢: åè¡æ¬
- è³¼å ¥: 4人 ã¯ãªãã¯: 372å
- ãã®ååãå«ãããã° (18件) ãè¦ã
- ä½è : 'ã·ã¹ã³ã·ã¹ãã ãºæ ªå¼ä¼ç¤¾,次ä¸ä»£ã«ã¼ã¿ã¯ã¼ãã³ã°ã°ã«ã¼ã
- åºç社/ã¡ã¼ã«ã¼: ã¤ã³ãã¬ã¹
- çºå£²æ¥: 2006/02/23
- ã¡ãã£ã¢: 大åæ¬
- è³¼å ¥: 1人 ã¯ãªãã¯: 21å
- ãã®ååãå«ãããã° (6件) ãè¦ã