Upgrade to Pro — share decks privately, control downloads, hide ads and more …

基礎から応用までじっくり学ぶ「AWSでのネットワークの作り方」

 基礎から応用までじっくり学ぶ「AWSでのネットワークの作り方」

Hiroyuki Kaji

October 05, 2018
Tweet

More Decks by Hiroyuki Kaji

Other Decks in Technology

Transcript

  1. Φεεϝ   ϓϥΠϕʔτωοτϫʔΫΞυϨε͸3'$͔Β 3'$  QSFpY   QSFpY

      QSFpY  ʻҾ༻ʼϓϥΠϕʔτ໢ͷΞυϨεׂ౰3'$+1/*$ IUUQTXXXOJDBEKQKBUSBOTMBUJPOSGDIUNM
  2. 8FC"QQ%#ͷߏ੒ͳΒ૚ߏ଄   w 'SPOUFOE w ෛՙ෼ࢄ૷ஔɺ/"5ήʔτ΢ΣΠɺ౿Έ୆ αʔό w "QQMJDBUJPO

    w 8FCαʔό΍ɺΞϓϦέʔγϣϯαʔό w %BUBTUPSF w ಺෦௨৴ͷΈڐՄ w %#αʔό΍3%4ɺ&MBTUJ$BDIFͳͲΛ഑ஔ
  3. ཧ༝   w εέʔϧΞοϓΛߟྀ͠ w &-# &MBTUJD-PBE#BMBODJOH ͸ࣗಈεέʔϧΞοϓ w

    ΦʔτεέʔϦϯάઃఆͨ͠&$ʢԾ૝αʔόʣ w &MBTUJ$BDIF&.3ͳͲ͸ɺΫϥελͷϊʔυ਺ʹߟྀ *1ΞυϨεফඅ ʙͷ޿ΊͷωοτϫʔΫΞυϨεͰׂΓ౰ͯΔ
  4. ࢲݸਓͷ޷ΈͰ͕͢ɾɾɾ   PSJHJO CBTF ͕Θ͔Γ΍͍͢ɻ ͷҐʢ੨จࣈʣͰɺ֊૚͕Θ͔Δ αϒωοτෆ଍࣌͸࿈൪Ͱ௥Ճ 'SPOUFOEαϒωοτ 

     "QQMJDBUJPOαϒωοτ   %BUBTUPSFαϒωοτ  
  5. ֊૚ຖʹϧʔτςʔϒϧ࡞੒   w 'SPOUFOE35 w 71$಺ʢMPDBMʣͱ*(8ܦ༝Πϯλʔωοτ઀ଓ w "QQMJDBUJPO35 w

    71$಺ʢMPDBMʣͱ/"5ήʔτ΢ΣΠܦ༝ͷΠϯλʔωοτ઀ଓ w "QQMJDBUJPO35 w 71$಺ʢMPDBMʣͱ/"5ήʔτ΢ΣΠܦ༝ͷΠϯλʔωοτ઀ଓ w %BUBTUPSF35 w 71$಺ʢMPDBMʣͷΈ
  6. τϥϑΟοΫ੍ޚ   ໊শ ωοτϫʔΫ"$- ηΩϡϦςΟάϧʔϓ ར༻཰ ΄ͱΜͲ࢖Θͳ͍ جຊతʹར༻ ద༻৔ॴ

    αϒωοτ αϒωοτʹଘࡏ͢Δ΋ͷ͢΂ͯʹద༻ Πϯελϯεຖ &$ʢαʔόʣɺ&-#ɺ3%4ͳͲɾɾɾ ಛੑ ϒϥοΫϦετܕ ʢ%FOZ"MMPXΛ*O0VUͰࢦఆՄೳʣ εςʔτϨεͰߦ͖΋໭Γ΋ڐՄඞཁ ϗϫΠτϦετܕ ʢ"MMPXͷΈΛ*O0VUͰࢦఆՄೳʣ εςʔτϑϧͳͷͰɺ໭Γͷύέοτ͸ߟྀෆཁ ධՁॱ Ϧετॱʹద༻ ͢΂ͯͷϧʔϧΛద༻ ͦͷଞ ಛఆ*1ΞυϨε͔Βͷෆਖ਼߈ܸΛःஅ͢Δͷʹ ศརɻ ૹ৴ݩͷࢦఆͰηΩϡϦςΟʔάϧʔϓ*%ΛࢦఆՄೳ ಉҰ71$ʹݕূ؀ڥͱຊ൪؀ڥ͕ଘࡏ͢Δͱ͖ʹศརɻ
  7. &MBTUJD-PBE#BMBODFSʢ&-#ʣ   w "QQMJDBUJPO-PBE#BMBODFS w ௨শɿ"-# w ߴػೳ-ϩʔυόϥϯαʔ w

    $MBTTJD-PBE#BMBODFS w ௨শɿ$-# w ੲ͔Β͋Δ--ϩʔυόϥϯαʔ w /FUXPSL-PBE#BMBODFS w ௨শɿ/-# w ΞʔϜߏ੒ͬΆ͍/"5͋Γ-ϩʔυόϥϯαʔ
  8. &-#ൺֱ   ಛ௃ "QQMJDBUJPO-PBE#BMBODFS /FUXPSL-PBE#BMBODFS $MBTTJD-PBE#BMBODFS ϓϩτίϧ )551ɺ)5514 5$1

    5$1ɺ44-ɺ)551ɺ)5514 ϩάه࿥ ✔ ✔ ˎ4ग़ྗͷΞΫηεϩά͸ແ͍ɻ71$'MPX-PH ✔ ಉ͡ΠϯελϯεͰ ෳ਺ͷϙʔτ΁ͷෛՙ෼ࢄ ✔ ✔ 8FC4PDLFUT ✔ ✔ *1ΞυϨεΛλʔήοτʹઃఆ ✔ ✔ ˎλʔήοτΛ&$Πϯελϯεࢦఆͷ৔߹͸ɺૹ৴ݩ *1͸ΫϥΠΞϯτ*1ɻ*1ࢦఆͷ৔߹͸/-#1SJWBUF*1 ύεϕʔεͷϧʔςΟϯά ✔ ϗετϕʔεͷϧʔςΟϯά ✔ ωΠςΟϒ)551 ✔ 44-ͷΦϑϩʔυ ✔ ✔ όοΫΤϯυαʔόʔ҉߸Խ ✔ ✔ ੩త*1 ✔ ˎ࡞੒࣌ʹ෇༩͞Εͨ΋ͷΛҡ࣋ &MBTUJD*1ΞυϨε ✔ ˎ࡞੒࣌ʹࢦఆՄೳ Ϣʔβೝূ ✔ ϦμΠϨΫτ ✔ ݻఆϨεϙϯε ✔ ্ه͸ൈਮͰ͢ɻৄࡉ͸ʮ&MBTUJD-PBE#BMBODJOH੡඼ͷൺֱʯIUUQTBXTBNB[PODPNKQFMBTUJDMPBECBMBODJOHEFUBJMT
  9. %JSFDU$POOFDUͷ࢖͍ॴ   w ηΩϡϦςΟ͕ݫͯ͘͠ΠϯλʔωοτΞΫηεͤͨ͘͞ͳ͍ w ྫɿݸਓ৘ใΛ֨ೲ͢Δ%#͕ΦϯϓϨʹ͋Δɻ w εϧʔϓοτඞཁ w

    ྫɿΦϯϓϨ͔Β"84ͷαʔϏεʹେྔσʔλΛૹ෇͍ͨ͠ɻ஫ҙɿ 5#ڃͷσʔλͷ৔߹͸4OPXCBMMΛݕ౼͍ͩ͘͞ɻ w ϨΠςϯγඞཁ w ྫɿΦϯϓϨͷ%#ʹ"84͔ΒΞΫηε͍ͤͨ͞ɻ
  10. ੩తϧʔςΟϯάରԠʢൈਮʣ   w $JTDP"4"γϦʔζόʔδϣϯҎ߱ͷιϑτ΢ΣΞ w $JTDP*43*04Ҏ߱ͷιϑτ΢ΣΞΛ࣮ߦ w +VOJQFS439γϦʔζαʔϏεήʔτ΢ΣΠ +VO04Ҏ߱ͷιϑτ΢ΣΞΛ

    ࣮ߦ  w 'PSUJOFU'PSUJHBUF γϦʔζ'PSUJ04Ҏ߱·ͨ͸Ҏ߱ͷιϑτ΢Σ ΞΛ࣮ߦ w 1BMP"MUP/FUXPSLT1"/04Ҏ߱·ͨ͸Ҏ߱ͷιϑτ΢ΣΞΛ࣮ߦ w :BNBIB3593PVUFST3FWҎ߱ͷιϑτ΢ΣΞ ͳͲͳͲɾɾɾ
  11. ಈతϧʔςΟϯάରԠ #(1ඞཁ ൈਮ   w $JTDP*43*04Ҏ߱ͷιϑτ΢ΣΞΛ࣮ߦ w +VOJQFS439γϦʔζαʔϏεήʔτ΢ΣΠ +VO04Ҏ߱ͷιϑ

    τ΢ΣΞΛ࣮ߦ  w 'PSUJOFU'PSUJHBUF γϦʔζ'PSUJ04Ҏ߱·ͨ͸Ҏ ߱ͷιϑτ΢ΣΞΛ࣮ߦ w 1BMP"MUP/FUXPSLT1"/04Ҏ߱·ͨ͸Ҏ߱ͷιϑτ΢Σ ΞΛ࣮ߦ w :BNBIB3593PVUFST3FWҎ߱ͷιϑτ΢ΣΞ ͳͲͳͲɾɾɾ
  12. αϯϓϧίϯϑΟάͷ஫ҙ఺   ಈతϧʔςΟϯάͷ৔߹ ͦͷ··ઃఆ͢Δͱϧʔλʹઃఆ͞ΕͨσϑΥϧτϧʔτ͕ 7(8ʹΞυόλΠζͷͰ஫ҙʢҎԼ͸$JTDPϧʔλͷ৔߹ʣ router bgp 65000 neighbor

    169.254.27.xxx remote-as 10124 neighbor 169.254.27.xxx activate neighbor 169.254.27.xxx timers 10 30 30 address-family ipv4 unicast neighbor 169.254.27.xxx remote-as 10124 neighbor 169.254.27.xxx timers 10 30 30 neighbor 169.254.27.xxx default-originate →ෆཁͰ͋Ε͹࡟আ neighbor 169.254.27.xxx activate neighbor 169.254.27.xxx soft-reconfiguration inbound ! To advertise additional prefixes to Amazon VPC, copy the 'network' statement ! and identify the prefix you wish to advertise. Make sure the prefix is present ! in the routing table of the device with a valid next-hop. network 0.0.0.0 →ΞυόλΠζ͢ΔϧʔτΛࢦఆʢྫɿnetwork 192.168.1.0 mask 255.255.255.0ʣ
  13. ιϑτ΢ΣΞ71/ͷ"84ߏஙͷྲྀΕ   71$্ʹιϑτ΢ΣΞ71/&$ΠϯελϯεΛߏங ر๬ϝʔΧʔͷ".*ʢԾ૝ϧʔλΠϝʔδʣΛબ୒ ηΩϡϦςΟάϧʔϓϧʔϧͰɺ71/ʹར༻͢ΔϓϩτίϧڐՄ *1ʢ&41*1TFDʣɺ6%1ϙʔτ *4",.1 ͓Αͼ *1TFD/"55SBWFSTBM

    ౳ ͱɺϧʔλ؅ཧ௨৴༻ͷड৴τϥϑΟοΫΛڐՄ &MBTUJD*1ΞυϨεʢ"84؅ཧͷݻఆάϩʔόϧ*1ʣΛׂΓ౰ͯ 71$ϧʔτςʔϒϧʹઃఆ 71/௨৴ઌωοτϫʔΫ΁ͷϧʔτΛιϑτ΢ΣΞ71/&$Πϯελϯεͷ&/*Λࢦఆ ιϑτ΢ΣΞ71/&$Πϯελϯεʹͯʮૹ৴ݩૹ৴ઌνΣοΫΛແޮʯ͠ɺύ έοτసૹڐՄ