ã¯ããã«
ãre:Invent 2024ãè¿ä»ãä¸ã§ãä»å¹´ãæ§ã
ãªãããã¯ã¼ã¯ã«ããããã¢ãããã¼ããçºè¡¨ããã¾ãããããã®ä¸ã§ã2024å¹´11æ25æ¥ã«æ稿ããããAWS Cloud WAN ã AWS Direct Connect ã«ãããªã³ãã¬ãã¹æ¥ç¶ãç°¡ç´ åãã¨ããã¢ãããã¼ãã«ã¤ãã¦ãç´¹ä»ãã¾ãã
ãæ¬è¨äºã¯ã2024å¹´12æ16æ¥ã«éå¬ããããNW-JAWS #14 ï½re:Invent 2024 re:Cap ãããã¯ã¼ã¯ã«ã¤ãã¦èªããï½ãã§ã®çºè¡¨å
容ã«å½æ¥ã話ãã§ããªãã£ãå
容ãä»ãå ãã¦ãããã®ã®ãæ¬çã®ã話ã¯å¤ãããªãæ¨ãæ¿ç¥ããé ãã¾ãã¨å¹¸ãã§ãã
- ã¯ããã«
- Cloud WANã¨ã¯
- ã¢ãããã¼ãã®æ¦è¦
- ã¢ãããã¼ãã®æ¤è¨¼ã»èª¿æ»
- ä»å¾ã®ã°ãã¼ãã«ãããã¯ã¼ã¯
- ã¾ã¨ã
- ãããã«
Cloud WANã¨ã¯
ãã°ãã¼ãã«ãããã¯ã¼ã¯ã«ããã¦ããªã³ãã¬ãã¹æ ç¹éãAWSã¨ç¸äºæ¥ç¶ããããã®ããã¼ã¸ããµã¼ãã¹ã§ããããªã·ã¼ã«ããæ¥ç¶ã¿ã¹ã¯èªååãã»ã°ã¡ã³ãåé¢ã«ãããã©ãã£ãã¯å¶å¾¡ãä¸å¤®ä¸å
管çã¨ç£è¦ãªã©ã®ç¹å¾´ãããã¾ãã
ãï¼åãªãç¸äºæ¥ç¶ãµã¼ãã¹ã¨æããããã¡ã§ãããçã®åã¯ãããç¹å¾´ã§çºæ®ã§ãã¾ããæ®å¿µãªããæ¬è¨äºã¯ç¸äºæ¥ç¶ã«é¢ãããã¼ãã®ãããå¥è¨äºã§ç¹å¾´ã«é¢ãããã¼ããåãä¸ãããã¨æãã¾ããï¼
ãä¸ã®å³ã¯Cloud WANã®æ§æä¾ã§ãããCloud WANã¯ãªã¼ã¸ã§ã³æ¨ªæçãªä½ç½®ä»ãã§ãåãªã¼ã¸ã§ã³ã®VPCã«å ãã¦ãDirect Connect/Site-to-Site VPN/SD-WAN Applianceãªã©ã®å¤æ§ãªæ¹å¼ã§ãªã³ãã¬ãã¹ã¸æ¥ç¶ããã¦ãããã¨ã確èªã§ãã¾ãã
ãã¡ãªã¿ã«ãCloud WANã¯Transit Gatewayã¨ããæ¯è¼ããã¾ãããããããã®ã¡ãªããã»ãã¡ãªããã¯ä»¥ä¸ã®è¨äºã§æ´çãã¦ã¾ãã®ã§ããèå³ã®ããæ¹ã¯ãã¡ããã覧ä¸ããã
ã¢ãããã¼ãã®æ¦è¦
ãCloud WANï½Direct ConnectéãTransit Gatewayçµç±ã§ãªãç´æ¥æ¥ç¶ã§ããããã«ãªã£ãã¨ãã大å¤ã·ã³ãã«ãªã¢ãããã¼ãå
容ã¨ãªãã¾ãã
ãä¸ã®å³ã¯AWSï½ãªã³ãã¬ãã¹éãDirect Connectæ¥ç¶ã§åé·åãããæ§æä¾ã§ãããã¢ãããã¼ãã«ãã£ã¦Cloud WANã¨DXGWéãTransit Gatewayçµç±ã§ãªãç´æ¥æ¥ç¶ããã¦ãã¾ãã
ã¢ãããã¼ãã®æ¤è¨¼ã»èª¿æ»
ãã¢ãããã¼ãã«ãã£ã¦ãã©ã®ãããªå½±é¿ããããã©ã®ãããªå¯¾å¿ããã¹ãããå®éã®Direct Connectæ¥ç¶ã§æ¤è¨¼ã»èª¿æ»ããçµæããã¨ã«æ´çãã¦ã¾ãã
ãæ°ãããªãã¬ã¼ã·ã§ã³ã¯ãCloud WANï½Direct Connect Gatewayéã®ã¢ã¿ããã¡ã³ãä½æã®ã¿ã§ããCloud WANã®ã¢ã¿ããã¡ã³ãã®è¨å®ã§ãã¢ã¿ããã¡ã³ãã¿ã¤ã(=Direct Connect)ãã¨ãã¸ãã±ã¼ã·ã§ã³(=ãªã¼ã¸ã§ã³)ãDirect Connect gateway attachment(=DXGW ID)ãå
¥åããã ãã§ä½æã§ãã¾ãã
ãã¡ãªã¿ã«ãTransit Gatewayã¯çµç±ããªããã®ã®ãå¾æ¥ã©ããDirect Connectãä½æããå ´åã¯TransitVIFãä½æãã¦ãã ãããVPC attachmentã®ENIã®ã¤ã³ã¿ã¼ãã§ã¼ã¹ã¿ã¤ããTranit Gatewayã¨è¡¨ç¤ºããããªã©ãCloud WANãTransit Gatewayã®ããã«åãæ±ããããã¨ã¯æã
ããã¾ãã
ããªã¼ã¸ã§ã³ãã«ã¼ãã£ã³ã°ãVPNã¸ã®å¯¾å¿ãå°ãç©è¶³ããªããããä»å¾ã®ã¢ãããã¼ãã¸æå¾ ã§ããç´è¿ã§ã客æ§è¦ä»¶ãå 足ã§ããªãå ´åã¯ãå¾æ¥ã®æ§æãæ¤è¨ãã¾ãããã
- ãªã¼ã¸ã§ã³ã対å¿ãã¦ãªã
- æ±äº¬ã大éªãªã¼ã¸ã§ã³ã¯æªå¯¾å¿ï¼2024/11/25æç¹ã§ã¯ãã¼ã¸ãã¢åé¨ããªãã¤ãªããªã¬ã´ã³ãã«ã«ã¬ãªã¼ããã©ã³ã¯ãã«ããã¹ããã¯ãã«ã ãã¢ã¤ã«ã©ã³ãããã³ãã³ãã·ã³ã¬ãã¼ã«ãã·ããã¼ããã«ã¢ãããªã¼ã¸ã§ã³ã®ã¿å¯¾å¿ï¼ã
- ã«ã¼ãã£ã³ã°ãå¶å¾¡ã§ããªã
- DXGWã®ã²ã¼ãã¦ã§ã¤é¢é£ä»ãã«ã¦ããªã³ãã¬ãã¹ã«ã¢ããã¿ã¤ãºãããã«ã¼ããè¨å®ã§ããããCloud WANãé¢é£ä»ããå ´åã¯ã«ã¼ããè¨å®ã§ããªãï¼è¨å®ãã¿ã³ã表示ãããï¼ã
- Cloud WANã®ããªã·ã¼ã®ã»ã°ã¡ã³ããªãã·ã§ã³ã«ã¦ãéçã«ã¼ããè¨å®ã§ããããDXGWãã¿ã¼ã²ããã¨ããéçã«ã¼ãã¯è¨å®ã§ããªãï¼ã¨ã©ã¼ã表示ãããï¼ã
- ã«ã¼ãã£ã³ã°ãå¶å¾¡ã§ããªããªããã¨ã§ãAWSï½ãªã³ãã¬ãã¹éã®ãã£ãªã¢å¶ç´äºé ã¸æµè§¦ããªãã注æãã¾ãããï¼ã«ã¼ãä¸éæ°ã¸éãããªã©ï¼ã
- VPNã確ç«ã§ããªã
ãæ§æãç°¡ç´ åããããã¨ã§ãéç¨è² è·ãã³ã¹ãã軽æ¸ããã¾ããä¸æ¹ãéç¨ãä¸é¨ã®æ©è½ãç¡ããªããã代æ¿æ段ãèãã¦ããã¾ãããã
- éç¨è² è·ã軽æ¸
- ãªã½ã¼ã¹ã¯Transit Gatewayãç¡ããªãã¢ã¿ããã¡ã³ããæ¸ãããããã©ã¡ã¼ã¿ã»ã¹ãã¼ã¿ã¹ã®ç®¡çã»ç¢ºèªãªã©ã®éç¨è² è·ã¯è»½æ¸ã§ãã¾ãã
- Cloud WANã¯ã«ã¼ããã¤ãã³ããã°ã®ç¢ºèªã¯åãã§ãããTransit Gatewayãç¡ããªãããVPCããã¼ãã°ã確èªã§ããããã©ãã«æã«ããã代æ¿æ段ã¯è¦æ¤è¨ã§ãã
- ã³ã¹ããåæ¸
- ãªã½ã¼ã¹ã¯Transit Gatewayãç¡ããªãã¢ã¿ããã¡ã³ããæ¸ããããæéããã³ãã¼ã¿ãããã®æéã¯è»½æ¸ã§ãã¾ãã
- Transit Gatewayã¢ã¿ããã¡ã³ãã¯åéãé«ããåãªã¼ã¸ã§ã³ã§DirectConnectæ¥ç¶ãã¦ããå ´åã¯ã³ã¹ãå¹æã大ããã§ãã
ãæ¬è¨äºã§ã¯ãã¤ã³ãã¯ãã大ããã¨èªãæããå½±é¿ã®ã¿ããã¯ã¢ãããã¦ã¾ããããã¹ã¦ã®å¶éäºé
ã網ç¾
çã«ç¢ºèªãããå ´å㯠AWS Cloud WANã¦ã¼ã¶ã¬ã¤ãããåç
§ä¸ããã
ä»å¾ã®ã°ãã¼ãã«ãããã¯ã¼ã¯
ãCloud WANã¯æ¥ç¶æ¹æ³ã®å¤æ§å/ç°¡ç´ åã«ããããªã³ãã¬ãã¹æ ç¹ãæ¥ç¶ãããããªãããã®æ ç¹æ°ãå¢ãããã®ã¨èãããã¾ããããããå ´åããªã³ãã¬ãã¹æ ç¹ééä¿¡ãAWSãããã¯ã¼ã¯çµç±ã§éä¿¡ããã±ã¼ã¹ãå¢ãããã®ã¨èãããã¾ãã
ããã®ããã«AWSãããã¯ã¼ã¯ãã°ãã¼ãã«ãããã¯ã¼ã¯ããã¯ãã¼ã³ã¨ãã¦å©ç¨ãããã¨ã§ãå質ã¯AWSãããã¯ã¼ã¯æ°´æºãç¶æããªãããã³ã¹ãã¯æµ·å¤æ ç¹éãIP-VPNæ¥ç¶ããã±ã¼ã¹ã¨æ¯ã¹ã¦æããå¹æãæå¾
ã§ããã®ã§ã¯ãªããã¨èãããã¾ãã
ãâ»Direct Connectæ ç¹å士ã§éä¿¡ããå ´åã¯Cloud WANã§ãªãSiteLinkã§ã®DXGWæãè¿ãã¨ãªããããã·ã³ãã«ãªã«ã¼ããå®ç¾ã§ãã¾ãã
ã¾ã¨ã
ããAWS Cloud WAN ã AWS Direct Connect ã«ãããªã³ãã¬ãã¹æ¥ç¶ãç°¡ç´ åãããç´¹ä»ãã¾ããã
- æ°ãããªãã¬ã¼ã·ã§ã³ã¯Cloud WANã§DXGWã¢ã¿ããã¡ã³ããä½æããã ãã§OK
- ãªã¼ã¸ã§ã³ãã«ã¼ãã£ã³ã°ãVPNã¸ã®å¯¾å¿ãå°ãç©è¶³ããªããããä»å¾ã®ã¢ãããã¼ãã¸æå¾
- æ§æç°¡ç´ åã§éç¨è² è·ãã³ã¹ãã¯è»½æ¸ãããããä¸é¨æ©è½ç¸®å°ã®å½±é¿ã¨å¯¾å¿ã¯è¦æ³¨æ
ãä»å¾ã®ã°ãã¼ãã«ãããã¯ã¼ã¯ã«é¢ããå人ã®è¦è§£ããç´¹ä»ãã¾ããã
- ãªã³ãã¬ãã¹æ ç¹ééä¿¡ã«ããã¦AWSãããã¯ã¼ã¯ãããã¯ãã¼ã³ã¨ãã¦å©ç¨æ¡å¤§
ãããã«
ãCloud WANã¯Transit Gatewayã¨æ¯ã¹ãã¨ãã¾ã ã¾ã ç¥å度ã®ä½ããµã¼ãã¹ã§ãããã¢ãããã¼ãã®å¢ãã¯å¼·ã¾ã£ã¦ãã¾ãã®ã§ãä»å¾æ´ãªãå©ç¨ã·ã¼ã³æ¡å¤§ãæå¾ ã§ãããã¨èãããã¾ãã