Contents

28. AWS Virtual Private Cloud(VPC)

AWS Certified SAA-C02 ์‹œํ—˜์ค€๋น„

CIDR - IPv4

  • Classless Inter-Domain Routing : IP ์ฃผ์†Œ ํ• ๋‹น ๋ฐฉ๋ฒ•
  • Security Groups : ๊ทœ์น™ ๋ฐ AWS ๋„คํŠธ์›Œํ‚น์— ์ผ๋ฐ˜์ ์œผ๋กœ ์‚ฌ์šฉ
  • Base IP : ๋ฒ”์œ„์— ํฌํ•จ๋œ IP๋ฅผ ๋‚˜ํƒ€๋ƒ„ (e.g., 10.0.0.0, 192.168.0.0 …)
  • Subnet Mask
    • IP์—์„œ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ๋Š” ๋น„ํŠธ ์ˆ˜๋ฅผ ์ •์˜ (e.g., /0, /24, /32)
    • /8 : 255.0.0.0
    • /16 : 255.255.0.0
    • /24 : 255.255.255.0
    • /32 : 255.255.255.255
Subnet Mask

Subnet Mask ์‚ฌ์šฉํ•˜๋ฉด ๊ธฐ๋ณธ์ ์œผ๋กœ ๊ธฐ๋ณธIP์—์„œ ๋‹ค์Œ ๊ฐ’์„ ์ถ”๊ฐ€๋กœ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์žˆ๋‹ค.

IP/Subnet Mask
192.168.0.0/32 allows for 1 IP(20) 192.168.0.0
192.168.0.0/31 allows for 2 IP(21) 192.168.0.0 ~ 192.168.0.1
192.168.0.0/30 allows for 4 IP(22) 192.168.0.0 ~ 192.168.0.3
192.168.0.0/29 allows for 8 IP(23) 192.168.0.0 ~ 192.168.0.7
192.168.0.0/28 allows for 16 IP(24) 192.168.0.0 ~ 192.168.0.15
192.168.0.0/27 allows for 32 IP(25) 192.168.0.0 ~ 192.168.0.31
192.168.0.0/26 allows for 64 IP(26) 192.168.0.0 ~ 192.168.0.65
192.168.0.0/25 allows for 128 IP(27) 192.168.0.0 ~ 192.168.0.127
192.168.0.0/24 allows for 256 IP(28) 192.168.0.0 ~ 192.168.0.255
192.168.0.0/16 allows for 65,536IP(216) 192.168.0.0 ~ 192.168.255.255
192.168.0.0/0 allows for All IP 0.0.0.0 ~ 255.255.255.255

Public vs Private IP (IPv4)

  • IANA(Internet Assigned Number Authority) ์€ ๊ฐœ์ธ(LAN) ๋ฐ ๊ณต์šฉ(Internet) ์ฃผ์†Œ ์‚ฌ์šฉ์„ ์œ„ํ•ด IPv4 ์ฃผ์†Œ์˜ ํŠน์ • ๋ธ”๋ก์„ ์„ค์ •ํ•จ
  • Private IP๋Š” ํŠน์ • ๊ฐ’๋งŒ ํ—ˆ์šฉ ๊ฐ€๋Šฅ
    • 10.0.0.0 โ€“ 10.255.255.255 (10.0.0.0/8) : big networks
    • 172.16.0.0 โ€“ 172.31.255.255 (172.16.0.0/12) : AWS defaultVPC in that range
    • 192.168.0.0 โ€“ 192.168.255.255 (192.168.0.0/16) : e.g., home networks
  • ์ธํ„ฐ๋„ท์— ์žˆ๋Š” ๋‚˜๋จธ์ง€ IP๋Š” ๋ชจ๋‘ public IP

Default VPC

  • ๋ชจ๋“  AWS ๊ณ„์ •์€ default VPC๋ฅผ ๊ฐ–๋Š”๋‹ค.
  • ์ƒˆ๋กœ์šด EC2 ์ธ์Šคํ„ด์Šค๋Š” subnet์„ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ๊ธฐ๋ณธ VPC๋กœ ์‹œ์ž‘ํ•œ๋‹ค.
  • ๊ธฐ๋ณธ VPC๋Š” ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๊ณ  public IPv4 ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ์Œ
  • public ๋ฐ private IPv4 ์™€ DNS ์ด๋ฆ„์„ ์–ป์„ ์ˆ˜ ์žˆ์Œ

VPC in AWS

  • Virtual Private Cloud (VPC)
  • AWS ๋ฆฌ์ „์— ์—ฌ๋Ÿฌ VPC๋ฅผ ๋งŒ๋“ค ์ˆ˜ ์žˆ๋‹ค. (๋ฆฌ์ „๋‹น VPC๋Š” ์ตœ๋Œ€ 5๊ฐœ)
  • VPC๋‹น CIDR
    • Min size /28 (16 IP Address)
    • Max Size /16 (65,536 IP Address)
  • VPC ๋น„๊ณต๊ฐœ ์ „์šฉ์ด๋ฏ€๋กœ Private IPv4 ๋ฒ”์œ„๋งŒ ํ—ˆ์šฉ
    • 10.0.0.0 โ€“ 10.255.255.255 (10.0.0.0/8)
    • 172.16.0.0 โ€“ 172.31.255.255 (172.16.0.0/12)
    • 192.168.0.0 โ€“ 192.168.255.255 (192.168.0.0/16)

VPC CIDR๋Š” ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ(e.g., corporate)์™€ ๊ฒน์น˜์ง€ ์•Š์•„์•ผ ํ•œ๋‹ค.

Subnet

  • AWS๋Š” ๊ฐ ์„œ๋ธŒ๋„ท์— 5๊ฐœ์˜ IP ์ฃผ์†Œ๋ฅผ ์˜ˆ์•ฝ(์ฒ˜์Œ 4๊ฐœ & ๋งˆ์ง€๋ง‰ 1๊ฐœ)
  • ์œ„ IP๋Š” ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์œผ๋ฉฐ EC ์ธ์Šคํ„ด์Šค ํ• ๋‹น ๋ถˆ๊ฐ€
์„œ๋ธŒ๋„ท ์˜ˆ์•ฝ IP
  • 10.0.0.0 โ€“ Network Address
  • 10.0.0.1 โ€“ AWS์— ์˜ํ•ด VPC Router ์šฉ์œผ๋กœ ์˜ˆ์•ฝ
  • 10.0.0.2 โ€“ Amazon๊ฐ€ ์ œ๊ณตํ•˜๋Š” DNS์— ๋งคํ•‘ํ•˜๊ธฐ ์œ„ํ•ด AWS์— ์˜ํ•ด ์˜ˆ์•ฝ
  • 10.0.0.3 โ€“ ๋‚˜์ค‘์— ์‚ฌ์šฉ์„ ์œ„ํ•œ
  • 10.0.0.255 - Network Broadcast Address. AWS๋Š” VPC์—์„œ ๋ธŒ๋กœ๋“œ์บ์Šค๋“œ๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š์œผ๋ฏ€๋กœ ํ•ด๋‹น ์ฃผ์†Œ๊ฐ€ ์˜ˆ์•ฝ๋˜์–ด์žˆ์Œ
Exam Tip: EC2 ์ธ์Šคํ„ด์Šค์— 29๊ฐœ์˜ IP ์ฃผ์†Œ๊ฐ€ ํ•„์š”ํ•œ ๊ฒฝ์šฐ
  • ํฌ๊ธฐ๊ฐ€ /27์ธ ์„œ๋ธŒ๋„ท์€ ์„ ํƒํ•  ์ˆ˜ ์—†๋‹ค (/27 -> 25=32 - 5 = 27 -> 27 < 29)
  • ํฌ๊ธฐ๊ฐ€ /26์ธ ์„œ๋ธŒ๋„ท์„ ์„ ํƒํ•ด์•ผ ํ•œ๋‹ค. (/26 -> 26=64 - 5 = 59 -> 59 > 29)

Internet Gateway (IGW)

  • VPC ๋ฆฌ์†Œ์Šค(e.g., EC2 ์ธ์Šคํ„ด์Šค)๋ฅผ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ์ˆ˜ํ‰์œผ๋กœ ํ™•์žฅ ๊ฐ€๋Šฅํ•˜๋ฉฐ ๋†’์€ ๊ฐ€์šฉ์„ฑ๊ณผ ์ด์ค‘ํ™”redundant ์ œ๊ณต
  • VPC์™€ ๋ณ„๋„๋กœ ์ƒ์„ฑํ•ด์•ผ ํ•œ๋‹ค.
  • ํ•˜๋‚˜์˜ VPC๋Š” ํ•˜๋‚˜์˜ IGW์—๋งŒ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค. (๊ทธ ๋ฐ˜๋Œ€์˜ ๊ฒฝ์šฐ๋„ ๋งˆ์ฐฌ๊ฐ€์ง€)
  • ์ธํ„ฐ๋„ท ๊ฒŒ์ดํŠธ ์›จ์ด ์ž์ฒด์—์„œ๋„ ์ธํ„ฐ๋„ท ์•ก์„ธ์Šค๋ฅผ ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š”๋‹ค - Route Tables์„ ๋ฐ˜๋“œ์‹œ ์ˆ˜์ •ํ•ด์•ผ ํ•œ๋‹ค.

Bastion Hosts

  • Bastion Host๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Private EC2 ์ธ์Šคํ„ด์Šค๋กœ SSH ํ•  ์ˆ˜ ์žˆ๋‹ค.
  • Bastion์€ public ์„œ๋ธŒ๋„ท์— ์œ„์น˜ํ•˜๋ฉฐ ๋‹ค๋ฅธ ๋ชจ๋“  private ์„œ๋ธŒ๋„ท๊ณผ ์—ฐ๊ฒฐ ๋œ๋‹ค.
  • Bastion Host์˜ security group์€ ๋งค์šฐ ์—„๊ฒฉํ•ด์•ผํ•œ๋‹ค
Exam Tip
  • ๋‹ค๋ฅธ EC2 ์ธ์Šคํ„ด์Šค Security Group์ด ์•„๋‹Œ ์‚ฌ์šฉ์ž๊ฐ€ ํ•„์š”ํ•œ IP ์ฃผ์†Œ์˜ ํฌํŠธ 22๋งŒ Bastion host์—์„œ ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

NAT Instance (outdated, ์‹œํ—˜์—๋Š” ๋‚˜์˜ด)

  • NAT (Network Address Translation)
  • private ์„œ๋ธŒ๋„ท์˜ EC2 ์ธ์Šคํ„ด์Šค๋ฅผ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐํ•˜๊ฒŒ ํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ๋ฐ˜๋“œ์‹œ public ์„œ๋ธŒ๋„ท์—์„œ ์‹คํ–‰
  • ๋ฐ˜๋“œ์‹œ NAT EC2 ์ƒ์„ฑ ์‹œ ํ•ด๋‹น ์ฒดํฌ ํ•ด์ œ -> Source/destination
  • Elastic IP๊ฐ€ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค.
  • private ์„œ๋ธŒ๋„ท์—์„œ NAT ์ธ์Šคํ„ด์Šค๋กœ ๋ผ์šฐํŒ…ํ•˜๋„๋ก Route Tables ๊ตฌ์„ฑํ•ด์•ผ ํ•œ๋‹ค.
  • ๋ฏธ๋ฆฌ ๊ตฌ์„ฑ๋œ Amazon Linux AMI๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Œ
  • 2020๋…„ 12์›” 31์ผ ์ง€์› ์ข…๋ฃŒ
  • ๊ฐ€์šฉ์„ฑ์ด ๋†’์ง€ ์•Š๊ณ  ์ดˆ๊ธฐํ™” ์„ค์ •์œผ๋กœ ๋ณต์› ๋ถˆ๊ฐ€๋Šฅ
    • Multi AZ์— ๋Œ€ํ•œ ASG ์ƒ์„ฑ + ๋ณต์›๋˜๋Š” ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ ์Šคํฌ๋ฆฝํŠธ ํ•„์š”
  • ์ธํ„ฐ๋„ท ํŠธ๋ž˜ํ”ฝ ๋Œ€์—ญํญ์€ EC2 ์ธ์Šคํ„ด์Šค ์œ ํ˜•์— ๋”ฐ๋ผ ๋‹ค๋ฆ„
  • Security Group & rules ๊ด€๋ฆฌ
    • ์ธ๋ฐ”์šด๋“œ
      • HTTP/HTTPS: Private Subnet ํ—ˆ์šฉ
      • SSH: ํ™ˆ ๋„คํŠธ์›Œํฌ(Internet Gateway๋ฅผ ํ†ตํ•ด ์•ก์„ธ์Šค ์ œ๊ณต)
    • ์•„์›ƒ๋ฐ”์šด๋“œ
      • ์ธํ„ฐ๋„ท์— ๋Œ€ํ•œ ๋ชจ๋“  HTTP/HTTPS ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ

NAT Gateway

  • AWS์—์„œ ๊ด€๋ฆฌ๋˜๋ฉฐ ๋†’์€ ๋Œ€์—ญํญ, ๋†’์€ ๊ฐ€์šฉ์„ฑ, ๊ด€๋ฆฌ๊ฐ€ ํ•„์š”์—†์Œ
  • ์‚ฌ์šฉ๋Ÿ‰ ๋ฐ ๋Œ€์—ญํญ์— ๋”ฐ๋ผ ์‹œ๊ฐ„๋‹น ๋น„์šฉ์ง€๋ถˆ
  • NATGW๋Š” ํŠน์ • AZ์— ์ƒ์„ฑ๋˜๋ฉฐ Elastic IP๋ฅผ ์‚ฌ์šฉ
  • ๋™์ผํ•œ ์„œ๋ธŒ๋„ท์˜ EC2 ์ธ์Šคํ„ด์Šค์—์„œ๋Š” ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Œ (์˜ค์ง ๋‹ค๋ฅธ ์„œ๋ธŒ๋„ท์—์„œ๋งŒ)
  • Internet Gateway๊ฐ€ ํ•„์š” (Private subnet => NAT Gateway => Internet Gateway)
  • 5Gpbs ๋Œ€์—ญํญ ์ตœ๋Œ€ 45Gbps ๊นŒ์ง€ ์ž๋™ ํ™•์žฅ
  • Security Groups ๊ด€๋ฆฌ๊ฐ€ ํ•„์š” ์—†์Œ

NAT Gateway with High Availability

  • NAT Gateway๋Š” ๋‹จ์ผ AZ๋‚ด์—์„œ ํƒ„๋ ฅ์ ์ž„
  • fault-tolerance์„ ์œ„ํ•ด multiple AZ์— multiple NAT Gateways๋ฅผ ๊ตฌ์„ฑ
  • AZ๊ฐ€ ์ค‘๋‹จ๋  ๊ฒฝ์šฐ NAT๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์œผ๋ฏ€๋กœ AZ failover๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์Œ

NAT Gateway vs NAT Instance

NAT Gateway NAT Instance
Availability
๊ฐ€์šฉ์„ฑ
AZ๋‚ด ๋†’์€ ๊ฐ€์šฉ์„ฑ(๋‹ค๋ฅธ AZ์ƒ์„ฑ) ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์Šคํ„ด์Šค๊ฐ„ failover ๊ด€๋ฆฌ(๊ฐ€์šฉ์„ฑ์ด ๋†’์ง„์•Š์Œ)
Bandwidth Up to 45 Gbps EC2 ํƒ€์ž…์— ์˜์กด
Maintenance AWS์—์„œ ๊ด€๋ฆฌ ์‚ฌ์šฉ์ž๊ฐ€ ๊ด€๋ฆฌ (e.g., software, OS patches …)
Cost ์‹œ๊ฐ„ ๋‹น & ์ „์†ก๋œ ๋ฐ์ดํ„ฐ ์–‘ ์‹œ๊ฐ„ ๋‹น, ์ธ์Šคํ„ด์Šค ํƒ€์ž…์— ๋”ฐ๋ฅธ ์‚ฌ์ด์ฆˆ + ๋„คํŠธ์›Œํฌ $
Public IPv4 O O
Private IPv4 O O
Security Groups X O
Use as Bastion Host? X O

DNS Resolution in VPC

DNS Resolution (enableDnsSupport)

  • VPC์— ๋Œ€ํ•ด Route 53 Resolver server์˜ DNS ํ™•์ธ(DNS Resolution)์ด ์ง€์›๋˜๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ •
  • ๊ธฐ๋ณธ๊ฐ’ : True
    • Amazon์ด ์ œ๊ณตํ•˜๋Š” DNS ์„œ๋ฒ„(169.254.169.253) ๋˜๋Š” VPC IPv4 reserved IP (x.x.x.2)๋ฅผ ์ฟผ๋ฆฌํ•˜๊ฒŒ ๋œ๋‹ค.

DNS Hostname (enableDnsHostnames)

  • ๊ธฐ๋ณธ์ ์œผ๋กœ
    • True : default VPC
    • False : ์ƒˆ๋กœ ์ƒ์„ฑ๋œ VPC
  • enableDnsSupport=true : ์•„๋ฌด๊ฒƒ๋„ ํ•˜์ง€ ์•Š์Œ
  • enableDnsHostnames=true : EC2 ์ธ์Šคํ„ด์Šค์— ๊ณต์šฉ IPv4๊ฐ€ ์žˆ๋Š” ๊ฒฝ์šฐ ๊ณต์šฉ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์„ ํ• ๋‹น
Tip
Route 53์˜ Private Hosted Zone์—์„œ ์‚ฌ์šฉ์ž ์ง€์ • DNS ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ๋‘๋ชจ๋“  ์†์„ฑ์„ true๋กœ ์ง€์ • enableDnsSupport=true & enableDnsHostname=true

Security Groups & NACLs

Network Access Control List (NACL)

  • NACL์€ ์„œ๋ธŒ๋„ท์—์„œ ์†ก์ˆ˜์‹ ๋˜๋Š” ํŠธ๋ž˜ํ”ฝ์„ ์ œ์–ดํ•˜๋Š” ๋ฐฉํ™”๋ฒฝ๊ณผ ๊ฐ™๋‹ค.
  • ์„œ๋ธŒ๋„ท ๋‹น ํ•˜๋‚˜์˜ NACL, ์ƒˆ๋กœ์šด ์„œ๋ธŒ๋„ท์€ Default NACL์— ํ• ๋‹น๋œ๋‹ค.
  • ์ƒˆ๋กœ ์ƒ์„ฑ๋œ NACL์€ ๋ชจ๋“  ๊ฒƒ์„ ๊ฑฐ๋ถ€
  • NACL์€ ์„œ๋ธŒ๋„ท ์ˆ˜์ค€์—์„œ ํŠน์ • IP ์ฃผ์†Œ๋ฅผ ์ฐจ๋‹จํ•˜๋Š” ์ข‹์€ ๋ฐฉ๋ฒ•

NACL ๊ทœ์น™

  • ๊ทœ์น™์—๋Š” ์ˆซ์ž(1-32766). ๋‚ฎ์€ ์ˆซ์ž๊ฐ€ ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’๋‹ค.
    Tip

    10.0.0.10 ํ•ด๋‹น ์ฃผ์†Œ๋Š” ALLOW

    • #100 ALLOW 10.0.0.10/32
    • #200 DENY 10.0.0.10/32
  • ๋งˆ์ง€๋ง‰ ๊ทœ์น™์€ asterisk(*)์ด๋ฉฐ ๊ทœ์น™์ด ๋งค์นญ๋˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ ์š”์ฒญ์„ ๊ฑฐ๋ถ€
  • AWS๋Š” 100 ๋‹จ์œ„๋กœ ๊ทœ์น™์„ ์ฆ๊ฐ€ํ•˜๋Š” ๊ฒƒ์„ ์ถ”์ฒœ

Default NACL

  • ์—ฐ๊ฒฐ๋œ ์„œ๋ธŒ๋„ท๊ณผ ํ•จ๊ป˜ ๋ชจ๋“  ์ธ๋ฐ”์šด๋“œ/์•„์›ƒ๋ฐ”์šด๋“œ๋ฅผ ์ˆ˜๋ฝ
  • ์ ˆ๋Œ€ Default NACL์„ ์ˆ˜์ •ํ•˜์ง€ ๋ง๊ณ  ์‚ฌ์šฉ์ž ์ •์˜ NACL์„ ์ž‘์„ฑํ•  ๊ฒƒ

Ephemeral Ports

  • ๋‘ endpoint ์—ฐ๊ฒฐ์„ ์„ค์ •ํ•˜๋ ค๋ฉด ํฌํŠธ๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•œ๋‹ค.
  • ํด๋ผ์ด์–ธํŠธ๋Š” ์ •์˜๋œ ํฌํŠธ์— ์—ฐ๊ฒฐํ•˜๊ณ  ephemeral port๋กœ ์‘๋‹ต๊ฐ’์„ ๋ฐ›๊ธฐ๋ฅผ ์›ํ•œ๋‹ค.
  • ์šด์˜์ฒด์ œ์— ๋”ฐ๋ผ ํฌํŠธ๋ฒ”์œ„๊ฐ€ ๋‹ค๋ฅด๋‹ค
    • IANA & MSWindows10 : 49152 - 65535
    • Many Linux Kernels : 32768 - 60999

Security Group vs. NACLs

Security Group NACL
์ธ์Šคํ„ด์Šค ์ˆ˜์ค€์—์„œ ์ž‘๋™ ์„œ๋ธŒ๋„ท ์ˆ˜์ค€์—์„œ ์ž‘๋™
ํ—ˆ์šฉ ๊ทœ์น™๋งŒ ์ง€์› allow, deny ๊ทœ์น™ ์ง€์›
Stateful:๋ฐ˜ํ™˜ ํŠธ๋ž˜ํ”ฝ์€ ๊ทœ์น™๊ณผ ๊ด€๊ณ„์—†์ด ์ž๋™์œผ๋กœ ํ—ˆ์šฉ Stateless:๋ฐ˜ํ™˜ ํŠธ๋ž˜ํ”ฝ์€ ๊ทœ์น™์— ์˜ํ•ด ๋ณ‘์‹œ์ ์œผ๋กœ ํ—ˆ์šฉ - think of ephemeral ports
ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ• ์ง€ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ •ํ•˜๊ธฐ ์ „์— ๋ชจ๋“  ๊ทœ์น™ ํ‰๊ฐ€ ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ •ํ•  ๋•Œ ๊ทœ์น™์„ ์ˆœ์„œ๋Œ€๋กœ ํ‰๊ฐ€(์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’์€ ์ฒซ๋ฒˆ์งธ ์ผ์น˜๊ฐ€ ์ ์šฉ)
๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๊ฐ€ ์ง€์ •ํ•œ ๊ฒฝ์šฐ EC2 ์ธ์Šคํ„ด์Šค์— ์ ์šฉ ์—ฐ๊ฒฐ๋œ ์„œ๋ธŒ๋„ท์˜ ๋ชจ๋“  EC2 ์ธ์Šคํ„ด์Šค์— ์ž๋™์œผ๋กœ ์ ์šฉ

VPC โ€“ Reachability Analyzer

  • VPC ๋‘ endpoint ๊ฐ„ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ๋„คํŠธ์›Œํฌ ์ง„๋‹จ ๋„๊ตฌ
  • ๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ์˜ ๋ชจ๋ธ์„ ๋งŒ๋“  ๋‹ค์Œ ์ด๋Ÿฌํ•œ ๊ตฌ์„ฑ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ๋„๋‹ฌ ๊ฐ€๋Šฅ์„ฑ์„ ํ™•์ธ (ํŒจํ‚ท ์ „์†ก์€ ํ•˜์ง€ ์•Š์Œ)
  • ์‚ฌ์šฉ ์‚ฌ๋ก€ : ์—ฐ๊ฒฐ๋ฌธ์ œ ํ•ด๊ฒฐ, ๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ์ด ์˜๋„๋Œ€๋กœ์ธ์ง€ ํ™•์ธ ๋“ฑ…

๋Œ€์ƒ์— ๋”ฐ๋ฅธ ๋ถ„์„

  • Reachable : ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ ๊ฒฝ๋กœ์— ๋Œ€ํ•œ hop-by-hop ์„ธ๋ถ€ ์ •๋ณด ์ƒ์„ฑ
  • Not reachable : ์ฐจ๋‹จ ๊ตฌ์„ฑ์š”์†Œ (e.g., SG, NACL, Route Tables ๊ตฌ์„ฑ ๋ฌธ์ œ)๋ฅผ ์‹๋ณ„