VPC Gateway ์ข…๋ฅ˜
AWS

VPC Gateway ์ข…๋ฅ˜

1. Internet Gateway

์ธํ„ฐ๋„ท๊ณผ ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•œ Gateway

Instance๊ฐ€ ์ธํ„ฐ๋„ท์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— 0.0.0.0/0 - Internet Gateway๋กœ ๋ผ์šฐํŒ… ํ•„์š”(์ธํ„ฐ๋„ท์—์„œ Insatance๋กœ ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์ถ”๊ฐ€๋กœ Instance์— ๊ณต์ธ IP ํ• ๋‹น ํ•„์š”)

 

2. NAT Gateway

Private Subnet์ด ์ธํ„ฐ๋„ท๊ณผ ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•œ Gateway

NAT Gateway๋Š” Private IP๋ฅผ ๊ฐ€์ง€๋ฉฐ Public Subnet์— ์œ„์น˜์‹œ์ผœ Source๋ฅผ NAT ์‹œ์ผœ Internet Gateway๋ฅผ ํ†ตํ•ด ์ธํ„ฐ๋„ท ์ ‘์†์ด ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ด์คŒ

Instance๊ฐ€ ์ธํ„ฐ๋„ท์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— 0.0.0.0/0 - NAT Gateway๋กœ ๋ผ์šฐํŒ… ํ•„์š”

 

3. VPN Gateway

Data Center์˜ Gateway์™€ IPsec VPN์„ ๋งบ์–ด ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•œ Gateway

On Premise ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— Data Center IP ๋Œ€์—ญ - VPN Gateway๋กœ ๋ผ์šฐํŒ… ํ•„์š”

IPsec VPN โ–ถ๏ธ https://eunhyee.tistory.com/225

 

IPsec VPN

1. IPsec VPN - Site to Site๋กœ ๋งบ๋Š” VPN์ž…๋‹ˆ๋‹ค. - IETF์—์„œ ๊ถŒ๊ณ ํ•˜๋Š” IPsec ๊ธฐ์ˆ ์„ ์ค€์ˆ˜ํ•˜์—ฌ ๋งŒ๋“  VPN์ž…๋‹ˆ๋‹ค. - ๊ฐ Site์˜ ๊ฒŒ์ดํŠธ์›จ์ด ์žฅ๋น„๋ผ๋ฆฌ ์–ด๋– ํ•œ ๋ฐฉ์‹์œผ๋กœ ์•”ํ˜ธํ™”๋ฅผ ํ• ์ง€ ๊ฒฐ์ •ํ•˜์—ฌ ๋™์ผํ•˜๊ฒŒ ์„ค์ •ํ•ด์•ผ ํ•ฉ

eunhyee.tistory.com

 

4. VPC Peering

VPC ๋ผ๋ฆฌ ์—ฐ๊ฒฐ(VPC๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ VPC๋‚ด๋ถ€์—์„œ๋Š” ํ†ต์‹  ๊ฐ€๋Šฅํ•˜์ง€๋งŒ VPC ๋ผ๋ฆฌ๋Š” ํ†ต์‹  ๋ถˆ๊ฐ€๋Šฅ)ํ•˜๊ธฐ ์œ„ํ•œ Gateway

๋‹ค๋ฅธ ์ง€์—ญ, ๋‹ค๋ฅธ ๊ณ„์ •์— ์žˆ๋Š” VPC์™€๋„ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅ

Remote VPC์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— Remote VPC IP ๋Œ€์—ญ - VPN Peering์œผ๋กœ ๋ผ์šฐํŒ… ํ•„์š”

 

5. DX(Direct Connect)

์ „์šฉ ํšŒ์„ ์œผ๋กœ ์—ฐ๊ฒฐ๋œ Gateway

์ผ๋ฐ˜ ํšŒ์„ ์ด ์•„๋‹ˆ ๋ณ„๋„ ํšŒ์„ ์œผ๋กœ Site to Site ํ†ต์‹ ํ•˜๊ฒŒ ๋˜๋ฉฐ ์š”๊ธˆ์ด ๋น„์‹ธ IPsec VPN(์ธํ„ฐ๋„ท์œผ๋กœ ํ†ต์‹ ํ•˜๋Š” ๋Œ€์‹  ๋ณด์•ˆ ํ„ฐ๋„ ์ƒ์„ฑ)์„ ๋งบ์–ด ์‚ฌ์šฉํ•˜๊ณ ๋Š” ํ•จ

Direct Connect Gateway๋ฅผ ์ƒ์„ฑํ•˜๊ณ  VPN Gateway์— ์—ฐ๊ฒฐํ•ด์•ผ ํ•จ

Remote์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— Remote IP ๋Œ€์—ญ - VPN Gateway๋กœ ๋ผ์šฐํŒ… ํ•„์š”

 

 

6. Transit Gateway

VPC ๊ฐ„ ํ†ต์‹ ์„ ์œ„ํ•ด์„œ๋Š” VPC Peering์„ ๋งบ์–ด์•ผํ•˜๋ฉฐ ๋ฐ์ด์ง€ ์ฒด์ธ ๋ฐฉ์‹์ด ๋ถˆ๊ฐ€๋Šฅํ•˜์—ฌ ํ’€๋งค์‹œ๋กœ ๋งบ์–ด์•ผ ํ•˜๋Š” ๋ฌธ์ œ์ ์ด ์žˆ์Œ

On Premise์™€ DX, VPN Gateway๋ฅผ ๋งบ์„ ๊ฒฝ์šฐ ํ†ตํ•ฉ ๊ด€๋ฆฌ๊ฐ€ ๋ถˆํŽธํ•œ ๋ฌธ์ œ์ ์ด ์žˆ์Œ

์œ„ ๋‘ ๋ฌธ์ œ์ ์„ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด VPC(Subnet ๋‹จ์œ„๋กœ ๊ฐ€๋Šฅ), DX, VPN Gateway์— ์—ฐ๊ฒฐํ•˜์—ฌ ํ•œ๋ฒˆ์— ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” Transit Gateway ๋“ฑ์žฅ(Transit Gateway์™€๋„ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅ)

 

7. VPC Endpoint

Interface Endpoint

- Interface Endpoint๋Š” ์„œ๋ธŒ๋„ท์— ์ƒ์„ฑ๋˜๋ฉฐ ENI(Endpoint Network Interface)์— Private IP๊ฐ€ ํ• ๋‹น๋˜์–ด ์„œ๋น„์Šค์™€ ์—ฐ๊ฒฐ

- ์ธํ„ฐ๋„ท์„ ํ†ตํ•ด ํ†ต์‹ ํ•˜๋˜ ์„œ๋น„์Šค๋ฅผ ํ”„๋ผ์ด๋น— ํ†ต์‹ ์„ ํ†ตํ•ด ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ฃผ๋ฉฐ ์ •์ฑ…์„ ํ†ตํ•ด ์ ‘๊ทผ ๊ด€๋ฆฌ ๊ฐ€๋Šฅ

- Private DNS๋ฅผ ํ™œ์„ฑํ™”ํ•˜์—ฌ DNS name, Endpoint hostname๋ฅผ ํ†ตํ•ด Endpoint์— ์ ‘์† ๊ฐ€๋Šฅ(์„œ๋น„์Šค์— ๋”ฐ๋ผ Private DNS ํ™œ์„ฑํ™”๋˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Œ)

- VPC ๋‚ด๋ถ€๋Š” Local๋กœ ์ ‘์† ํ—ˆ์šฉ๋˜๊ธฐ ๋•Œ๋ฌธ์— Route Table์— ์ถ”๊ฐ€ ์ž‘์—… ํ•„์š” ์—†์Œ

 

์ดˆ๋ก์ƒ‰ : VPC Interface Endpoint ์„ค์ • ์ „ / ํŒŒ๋ž€์ƒ‰ : VPC Interface Endpoint ์„ค์ • ํ›„ / Public DNS ์‚ฌ์šฉ
์ดˆ๋ก์ƒ‰ : VPC Interface Endpoint ์„ค์ • ์ „ / ํŒŒ๋ž€์ƒ‰ : VPC Interface Endpoint ์„ค์ • ํ›„ / Private DNS ์‚ฌ์šฉ

 

Gateway Endpoint

- S3์™€ Dynamo DB๋งŒ ์‚ฌ์šฉ ๊ฐ€๋Šฅ

- ์ธํ„ฐ๋„ท์„ ํ†ตํ•ด ํ†ต์‹ ํ•˜๋˜ S3, Dynamo DB๋ฅผ Gateway Endpoint๋ฅผ ๋งŒ๋“ค์–ด ํ”„๋ผ์ด๋น— ํ†ต์‹ ์„ ํ†ตํ•ด ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ฃผ๋ฉฐ ์ •์ฑ…์„ ํ†ตํ•ด - ์ ‘๊ทผ(S3 ๋ฒ„ํ‚ท ์ด๋ฆ„, action ๋“ฑ) ๊ด€๋ฆฌ ๊ฐ€๋Šฅ

- S3, Dynamo DB์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ pi-id(๊ด€๋ฆฌํ˜• ์ ‘๋‘์‚ฌ) Gateway Endpoint๋กœ ๋ผ์šฐํŒ… ํ•„์š”

์ดˆ๋ก์ƒ‰ : VPC Gateway Endpoint ์„ค์ • ์ „ / ํŒŒ๋ž€์ƒ‰ : VPC Gateway Endpoint ์„ค์ • ํ›„

 

8. VPC Endpoint Service

Service Provider VPC์™€ Service Consumer VPC๊ฐ€ ํ”„๋ผ์ด๋น— ํ†ต์‹ ์„ ํ•˜๊ธฐ ์œ„ํ•จ

๋ชฉ์ ์— ๋”ฐ๋ผ Network/Gateway Load Balancer ๊ฐ€๋Šฅ

 

Network Load Balancer

- NLB์™€ Endpoint Service์™€ ์—ฐ๊ฒฐ ํ›„ Enpoint Service์™€ Interface Endpoint ์—ฐ๊ฒฐ

 

Gateway Load Balancer

- ๋ฐฉํ™”๋ฒฝ, ์นจ์ž… ํƒ์ง€ ๋ฐ ๋ฐฉ์ง€ ์‹œ์Šคํ…œ, ์‹ฌ์ธต ํŒจํ‚ท ๊ฒ€์‚ฌ ์‹œ์Šคํ…œ ๊ฐ™์€ ๊ฐ€์ƒ ์–ดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ๋ฐฐํฌ, ํ™•์žฅ ๋ฐ ๊ด€๋ฆฌ ๊ฐ€๋Šฅ

- GLB์™€ Endpoint Service์™€ ์—ฐ๊ฒฐ ํ›„ Enpoint Service์™€ GLB Endpoint ์—ฐ๊ฒฐ

- GLB Endpoint๋Š” Interface Endpoint๋กœ ์„œ๋ธŒ๋„ท์— ์ƒ์„ฑ๋˜๋ฉฐ ENI(Endpoint Network Interface)์— Private IP๊ฐ€ ํ• ๋‹น๋˜์–ด ์„œ๋น„์Šค์™€ ์—ฐ๊ฒฐ

- Subnet1์€ Application Servers๊ฐ€ Security Appliances์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— 0.0.0.0/0 - GLB Endpoint๋กœ ๋ผ์šฐํŒ… ํ•„์š”

- ์ธํ„ฐ๋„ท ๊ฒŒ์ดํŠธ์›จ์ด๋Š” Application Servers๋กœ ํ–ฅํ•˜๋Š” ํŠธ๋ž˜ํ”ฝ์ด GLB Endpoint๋ฅผ ํ†ตํ•ด ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— Subnet1 ๋Œ€์—ญ - GLB Endpoint๋กœ ๋ผ์šฐํŒ… ํ•„์š”

- Subnet2๋Š” ์ธํ„ฐ๋„ท์œผ๋กœ ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ Route Table์— 0.0.0.0/0 - Internet Gateway๋กœ ๋ผ์šฐํŒ… ํ•„์š”

 

9. VPC Flowlogs

VPC ๋‹จ์œ„๋กœ ํ•„ํ„ฐ/์ตœ๋Œ€ ์ง‘๊ณ„ ๊ฐ„๊ฒฉ/๋กœ๊ทธ ๋ ˆ์ฝ”๋“œ๋ฅผ ์„ค์ •ํ•˜์—ฌ CloudWatch Logs or S3 ๋ฒ„ํ‚ท์œผ๋กœ ์ „์†ก

 

๋‹ค์–‘ํ•œ VPC Architecture โ–ถ๏ธ https://docs.aws.amazon.com/ko_kr/whitepapers/latest/aws-vpc-connectivity-options/network-to-amazon-vpc-connectivity-options.html

 

Network-to-Amazon VPC connectivity options - Amazon Virtual Private Cloud Connectivity Options

Network-to-Amazon VPC connectivity options This section provides design patterns for connecting remote networks with your Amazon VPC environment. These options are useful for integrating AWS resources with your existing on-site services (for example, monit

docs.aws.amazon.com