Slide 16
Slide 16 text
IAMで何ができる?上級編 その1
ConditionのNotIpAddressで設定!
{ "Statement": [
{ "Effect": "Deny"
"Deny"
"Deny"
"Deny",
"Action": "*",
"Resource": "*",
"Condition": {
"
"
"
"NotIpAddress
NotIpAddress
NotIpAddress
NotIpAddress"
"
"
": {"aws:SourceIp":"192.0.2.1" }
}
}
]
}
EffectはDeny
Conditionは
NotIpAddressで設定
Allowで設定した場合、
別の権限を追加すると
アクセスできてしまう。
EffectはDeny
Conditionは
NotIpAddressで設定
http://docs.aws.amazon.com/ja_jp/IAM/latest/UserGuide/AccessPolicyLa
nguage_ElementDescriptions.html#Conditions_IPAddress