ããã«ã¡ã¯ãTIG/DXãŠãããã®äŒè€å€ªæã§ããããŠãã€ãã«ã¯ãªã¹ãã¹åœæ¥ã§ãããä»äºãããã ããã®ã¯éåžžã«ãããããããšã§ãããçŽ æµã§ãã
ããŠãç§ã¯ãã¥ãŒãã£ãŒã§ã¯ã©ãŠããšã³ãžãã¢ãšããŠGCPãAWSã䜿ã£ãŠã€ã³ãã©ãæ§ç¯ããŠããŸãããã³ããŒããšã«è¯ããšãããæªããšãããåãã£ãŠããŸãããåã°ããããšã§ããæ¯æ¥äœ¿ãç¶ããŠãããšããã®åãããããšãå€ããæ¯æ¥éåã®äžãæ©ããŠãæ°æã¡ã«ãªããŸããããŠãïŒïŒïŒïŒå¹Žä»äºãããŠããäžã§ãããã¯å¿ããããªãããããã©ãããäŸé€ããŠãããŸããèªåã®åŒ·ã¿ã§ãããã
- AWS
- GCP
ã®äž¡æ¹ãããã§ã¯ãããŠãããŸãã
AWS
ããŒããã©ã³ãµãŒãšã¿ãŒã²ããã°ã«ãŒãã®å¶åŸ¡
AWSã®ããŒããã©ã³ãµãŒã¯ã¢ããªã±ãŒã·ã§ã³åãã®ALBãTCPãUDPãããã³ã«ã®å©çšåãã®NLBãšïŒçš®é¡ååšããŸããåã ã
- LBãã®ãã®ã®èšå®
- ã¿ãŒã²ããã°ã«ãŒãã®èšå®
- ãªã¹ããŒã®èšå®
ã®ïŒç¹ãèšå®ããããšã§å©çšåºæ¥ãŸãïŒããå°ããããšãã¿ãŒã²ããã°ã«ãŒããšLBã®çŽä»ãã®èšå®ããããŸãïŒãåäžVPCå ã§å©çšããå Žåã§ããã°ç¹æ®µæ°ã«ãã䜿ãããšãåºæ¥ãŸãããããã以äžã®ãããªæ§æã ãšã©ãã§ããããïŒ
ãã®ãã¿ãŒã³ã¯ALBã眮ããµãããããVPCãŸã§ãDMZãšããŠæ±ã£ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ãšåŸ¹åºçã«åãããå Žåã«äœ¿ãã¢ãŒããã¯ãã£ã®äžéšã§ãããŸããTransit Gatewayçµç±ã§VPC Aãã£ãŠãããã©ãã£ãã¯ã¯ãããã«ãã¢ãªã³ã°ã§æ¥ç¶ãããŠããVPC Bã«ãã©ãã£ãã¯ã¯æµããŸããããããã£ãŠãã®åé¡ã解決ããããã«ãå©çšãããŸãã
ããŠããã®ã¢ãŒããã¯ãã£ãå©çšããæã«ãALBãšã¿ãŒã²ããå
ã«ãªããªãœãŒã¹ãå¥ã®VPCã§äœæããå Žåã«ãã¿ãŒã²ããã°ã«ãŒããã©ã¡ãã«çœ®ããæ©ããã€ã³ãã ãšæããŸããããã§ã®æ£è§£ã¯ãALBåŽã®VPCã®ãªãœãŒã¹ãšããŠæ±ãã®ãæ£è§£ã§ãããããã£ãŠã以äžã®é
眮ã«ãªããŸãã
ç§ã®äžã§ã®ã¿ãŒã²ããã°ã«ãŒãã®è§£éã¯ãããŒããã©ã³ãµãŒã®Egressãå¶åŸ¡ãããã¡ã€ã¢ãŠã©ãŒã«çžåœã®ãã®ãªã®ã§ã¯ãšæã£ãŠããŸãããªã®ã§ãã¿ãŒã²ããã°ã«ãŒãããªãœãŒã¹ãšããŠçŽã¥ããŠããã®ã¯VPCåäœã«ãªã£ãŠããã®ã¯ãããã£ãæåãè£ã§ãªãããŠããã®ã§ã¯ãšæããŸããã
泚æç¹ãšããŠããã®èšèšã§ã¯ã¿ãŒã²ããã°ã«ãŒãã®èšå®ãã
- ID
- ã€ã³ã¹ã¿ã³ã¹
- IP
ã®ïŒã€ããæå®ã§ããŸãããVPCãè¶ãæã«ã¯IPæå®ã®ã¿ãå©çšã§ããŸãããããã¯ãŒã¯ã¬ãã«ã®äžçã®è©±ãªã®ã§èšãããŠã¿ãã°çŽåŸã§ããŸãã䟿å©ããããšãããšããæãæ©ã¿ãŸããã
GCP
ãã¡ã€ã¢ãŠã©ãŒã«ã®å¶åŸ¡ã«ã€ããŠ
åçš®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ãä¿è·ããããã«ããã¡ã€ã¢ãŠã©ãŒã«ã¯å¿
é ã§ãããé©åãªç²åºŠã§å®ãããšãå¿
é ã§ããäŸãã°ãèžã¿å°ãµãŒããŒã§ãã£ãŠãã0.0.0.0/0
ã§éãããªããŠããšãããã«ãäŒç€Ÿããã®åºå£ã«ãªã£ãŠããGlobal IPã ããèš±å¯ããããCloud IAPïŒIdentity Aware ProxyïŒãå©çšãããªã©ããŠãIngressã¯æ¥µåçµãã¹ãã§ãã
æ¬é¡ã«å
¥ããŸãããGCPã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯
- IP
- ã¿ã°
- ãµãŒãã¹ã¢ã«ãŠã³ã
ã®ïŒã€ã§ãœãŒã¹ãå¶åŸ¡ã§ããŸãïŒã¿ãŒã²ããã«æå®ã§ããã®ã¯ã¿ã°ãšãµãŒãã¹ã¢ã«ãŠã³ãã®ã¿ïŒãã¿ã°ã«ã€ããŠã¯æ±çšæ§ãé«ããã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ã容æã«ä¿è·ã§ããããã«ããŠããæ©èœãªã®ã§ç§ãšããŠã¯ãšãŠã奜ã¿ã®æ©èœã§ããã§ããããã®ãã¡ãã¿ã°ãšãµãŒãã¹ã¢ã«ãŠã³ãã§ã¯ãç°ãªãVPCéã®å¶åŸ¡ãå¹ããªããšããããšãåŠã³ã§ãããä»åãå³ã§ç€ºããŸãã以äžã®ãããªãã¿ãŒã³ã§ãã
äžã®å³ã§Egressã¯çããŠããŸãããGCEã®éä¿¡ãå¶åŸ¡ããããã«åäžVPCå ãç°ãªãVPCéã«ãããããã¡ã€ã¢ãŠã©ãŒã«ããããŸãããã®ãšãVPC Aã®èžã¿å°ããVPC Bã®ã€ã³ã¹ã¿ã³ã¹ã«sshããããšãããšåŒŸãããŸãã念ã®ãããæ€èšŒãšããŠãNetwork Intelligence Centerã®Conectivity Testãå©çšããŠã¿ãŸãããããœãŒã¹ãèžã¿å°ãµãŒããŒãã¿ãŒã²ãããVPC Bã®ã€ã³ã¹ã¿ã³ã¹ãšããŠèšå®ããŠãã¹ãããŠã¿ãŸãããçµæã¯ãã¡ããVPC Bã®ãã¡ã€ã¢ãŠã©ãŒã«ãããŸãå¹ããŠããªãããšãåãããŸãã
ãã¡ããšãã¡ã€ã¢ãŠã©ãŒã«ãäœçšããããã«ãVPC Bã®ã«ãŒã«ãã¿ã°ããèžã¿å°ã®å¶åŸ¡ã«å€ããŠã¿ãŸãã
ãã®ããã«ãVPC Bã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãé©çšãããŠãªãŒãã£ããªãã£ã確çãããŸãããå®éã«èžã¿å°ããpingãå©ããŠãã¬ã¹ãã³ã¹è¿ã£ãŠããŸãã
Connectivity Testèªäœã¯ã«ãŒã«ã確èªããŠãªãŒãã£ããªãã£ããããåŠããèŠãŠããã®ã§ãå®éã«ã¯ãã©ã€ã©ã³ã§ãã
ãŸãšã
ã¯ã©ãŠãã®äžçã§ãããã¯ãŒã¯ã®è«žã
ãå¶åŸ¡ãããšãã¯åã¯ã©ãŠãããšã«äŸ¿å©ãªæ©èœãå®è£
ãããŠãããäºæ
é²æ¢ã®ããã«ãç解ãæ·±ããŠãæ倧éå©çšããã¹ãã ãšæã£ãŠããŸããããããèªåãä»ãããããã¯ãŒã¯ã®äžçããå¥ã®äžçã«ãããšããçµå±ã®ãšããIPå¶åŸ¡ãåå§çãªãããã以äžã®ããšã¯ãŸã åºæ¥ãªãã®ã ãªããšããã®ãä»å¹Žã®ææ³ã§ãã
䟿å©ãªãã®ã¯ã©ãã©ã䜿ããã§ãè£ã®æåã«ä»®èª¬ããã£ãããããããã®åçååèªäœã«ç®ãåããªããšãããªããšæ¹ããŠæããŸããã
ðððððã¿ãªãããçŽ æµãªã¯ãªã¹ãã¹ããéãããã ãããððððð