๐Ÿ™‚โ˜๏ธ0620 [AWS,OPENSTACK]

๋ง์ง€ยท2022๋…„ 6์›” 20์ผ
0
post-custom-banner

๐Ÿ“Œ ์„ธ๋ฏธํ”„๋กœ์ ํŠธ 2

  1. Hybrid cloud(Public์™€ Private cloud ์—ฐ๊ฒฐ) - AWS storage ํ™œ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ• (main)
    AWS(EFS) <- VPN -> Openstack(on-prem)
    AWS(S3) <- Storage Gateway -> ESXi(On-Prem)
  1. route53 (GSLB : Cross Region , VRRP:์ด์ค‘ํ™” , Failover: Active, Passive(Inactive,standby)

์„ธ๋ฏธํ”„๋กœ์ ํŠธ ๋ง๋„ - ์ง€๋‚œ ๊ทธ๋ฆผ๋“ค์ฒ˜๋Ÿผ route53์„ ํ†ต๊ณผํ•ด์„œ๊ฐ€๋Š” ๊ฒƒ์ด ์•„๋‹˜. ์ธํ„ฐ๋„ท ํŠธ๋ž˜ํ”ฝ์„ ๋„์™€์ฃผ๋Š” ์—ญํ• .

https://aws.amazon.com/ko/blogs/korea/amazon-route-53-application-recovery-controller/


์›นํŽ˜์ด์ง€ ์ด๋ฏธ์ง€ ํด๋ผ์šฐ๋“œ ํ”„๋ก ํŠธ๋กœ ๋ฐฐํฌ ๊ฐ€๋Šฅ. ๋ฌด๊ฑฐ์šด jpg, ๋™์˜์ƒ..์— cloudfront๋กœ ํ•  ์ˆ˜ ์žˆ๋‹ค.

<img src= *.jpg(ํด๋ผ์šฐ๋“œ ํ”„๋ก ํŠธ ์ฃผ์†Œ) >

์ง์›๋“ค์˜ password, ์ฃผ์†Œ ๋ณด์•ˆ์ ‘์†. openstack
vpn.

https://docs.aws.amazon.com/ko_kr/vpn/latest/s2svpn/how_it_works.html

https://www.alibabacloud.com/ko/knowledge/what-is-vpn

๐Ÿ“Œ AWS-GSLB

๐Ÿ“™ ์ƒํƒœ๊ฒ€์‚ฌ ์ƒ์„ฑ (seoul,tokyo 2๊ฐœ ์ƒ์„ฑ)

โœ”๏ธroute53 - ์ƒํƒœ๊ฒ€์‚ฌ - ์ƒํƒœ๊ฒ€์‚ฌ ์ƒ์„ฑ
โœ”๏ธ์ด๋ฆ„ : active / passive - ๋ชจ๋‹ˆํ„ฐ๋ง ๋Œ€์ƒ : ์—”๋“œํฌ์ธํŠธ - ์ง€์ •๊ธฐ์ค€ : ๋„๋ฉ”์ธ ์ด๋ฆ„ - ํ”„๋กœํ† ์ฝœ :HTTPS - ๋„๋ฉ”์ธ ์ด๋ฆ„ : seoul.lovemj.shop / tokyo.lovemj.shop - ๊ณ ๊ธ‰๊ตฌ์„ฑ

โœ”๏ธ ๊ณ ๊ธ‰๊ตฌ์„ฑ : ๋น ๋ฆ„ - ์‹คํŒจ ์ž„๊ณ„๊ฐ’ : 1 - ๋‹ค์Œ - ๊ฒฝ๋ณด์ƒ์„ฑ : ์•„๋‹ˆ์˜ค - ์ƒํƒœ ๊ฒ€์‚ฌ ์ƒ์„ฑ

๐Ÿ“™ ๋ ˆ์ฝ”๋“œ ์ƒ์„ฑ์œผ๋กœ GSLB

โœ”๏ธ route53-ํ˜ธ์ŠคํŒ…์˜์—ญ(lovemj.shop) - ๋ ˆ์ฝ”๋“œ ์ƒ์„ฑ - ์ด๋ฆ„ : gslb - ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ… ๋Œ€์ƒ ์ •๋ณด - ๋ณ„์นญ; ALB - ๋ฆฌ์ „ ; ์„œ์šธ - ์ƒ์„ฑ๋˜์–ด์žˆ๋Š” ALB ์„ ํƒ - ๋ผ์šฐํŒ… ์ •์ฑ… : ์žฅ์• ์กฐ์น˜ - ์žฅ์• ์กฐ์น˜ ๋ ˆ์ฝ”๋“œ ์œ ํ˜• : ๊ธฐ๋ณธ;primary ( active) - ์ƒํƒœํ™•์ธ ID : active - ๋ ˆ์ฝ”๋“œ ID : seoul - ๋‹ค๋ฅธ ๋ ˆ์ฝ”๋“œ ์ถ”๊ฐ€

โœ”๏ธ ์ด๋ฆ„ : gslb - ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ… ๋Œ€์ƒ ์ •๋ณด - ๋ณ„์นญ; ALB - ๋ฆฌ์ „ ; ๋„์ฟ„ - ์ƒ์„ฑ๋˜์–ด์žˆ๋Š” ALB ์„ ํƒ - ๋ผ์šฐํŒ… ์ •์ฑ… : ์žฅ์• ์กฐ์น˜ - ์žฅ์• ์กฐ์น˜ ๋ ˆ์ฝ”๋“œ ์œ ํ˜• : ๋ณด์กฐ;secondary ( passive) - ์ƒํƒœํ™•์ธ ID : passive - ๋ ˆ์ฝ”๋“œ ID : tokyo - ๋ ˆ์ฝ”๋“œ ์ƒ์„ฑ

๐Ÿ“™ GSLB ํ™•์ธ

seoul haproxy ์„œ๋ฒ„ ์ง„์ž…ํ•ด์„œ ์•„๋ž˜ ๋ช…๋ น์–ด ์ž…๋ ฅ (haproxy์ค‘๋‹จ)


[ec2-user@ip-10-14-47-144 ~]$ sudo systemctl stop haproxy
[ec2-user@ip-10-14-47-144 ~]$


[ec2-user@ip-172-31-4-224 ~]$ sudo systemctl stop haproxy
[ec2-user@ip-172-31-4-224 ~]$



[ec2-user@ip-10-14-47-144 ~]$ sudo systemctl enable --now haproxy



๐Ÿ“Œ openstack - AWS VPN ์—ฐ๊ฒฐ

๐Ÿ“™ ๋™์ผ ๋„คํŠธ์›Œํฌ(๊ฐ•์˜์‹ค) ๋‚ด ๋‹ค๋ฅธ ์„œ๋ฒ„์™€ ๋‚ด๋ถ€ IP๋กœ ํ†ต์‹ ํ•˜๊ธฐ

โœ”๏ธ ์ธ์Šคํ„ด์Šค์— ์œ ๋™ IP์—ฐ๊ฒฐ ํ›„ mobaxterm์œผ๋กœ ์ง„์ž…


โœ”๏ธ ์ง๊ฟ์ด๋ž‘ ์„œ๋กœ ์œ ๋™ IP๋กœ ping์ณ๋ณด๊ณ , ์•„๋ž˜์™€ ๊ฐ™์ด ๋ผ์šฐํ„ฐ ์ •์ ๊ฒฝ๋กœ ์ถ”๊ฐ€.

์ง๊ฟ 9.216 ๋ผ์šฐํ„ฐ extnernal IP
10.124.0.0/24

โœ”๏ธ ์ง๊ฟ ๋‚ด๋ถ€ ip๋กœ ping๋‚˜๊ฐ.

[centos@centos7 ~]$ ping 10.124.0.59
PING 10.124.0.59 (10.124.0.59) 56(84) bytes of data.
64 bytes from 10.124.0.59: icmp_seq=1 ttl=62 time=2.82 ms
64 bytes from 10.124.0.59: icmp_seq=2 ttl=62 time=3.59 ms
64 bytes from 10.124.0.59: icmp_seq=3 ttl=62 time=2.46 ms

๐Ÿ“™ AWS VPN - G/W

โœ”๏ธ aws vpc - vpn - ๊ณ ๊ฐ ๊ฒŒ์ดํŠธ์›จ์ด(์ƒ์„ฑ๋˜์–ด์žˆ์Œ
-> [custom G/W]

โœ”๏ธ aws vpc - vpn - ๊ฐ€์ƒ ํ”„๋ผ์ด๋น— ๊ฒŒ์ดํŠธ์›จ์ด(MY-VGW ์ƒ์„ฑ๋˜์–ด์žˆ์œผ๋‚˜ detached) - ์„ ํƒ - ์ž‘์—… - VPC์— ์—ฐ๊ฒฐ - ์‚ฌ์šฉ๊ฐ€๋Šฅํ•œ VPC: MY-VPC - VPC์— ์—ฐ๊ฒฐ

-> [VP G/W]

๐Ÿ“™ openstack libreswan

Libreswan์€ "IPsec" ๋ฐ ์ธํ„ฐ๋„ท ํ‚ค ๊ตํ™˜ ( "IKE" ) ์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ€์žฅ ๋„๋ฆฌ ์ง€์›๋˜๊ณ  ํ‘œ์ค€ํ™”๋œ VPN ํ”„๋กœํ† ์ฝœ์˜ ๋ฌด๋ฃŒ ์†Œํ”„ํŠธ์›จ์–ด ๊ตฌํ˜„์ž…๋‹ˆ๋‹ค . ์ด๋Ÿฌํ•œ ํ‘œ์ค€์€ IETF ( Internet Engineering Task Force )์—์„œ ์ƒ์„ฑ ๋ฐ ์œ ์ง€ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

openstack ์„œ๋ฒ„ IP๋กœ mobaxterm ์ ‘์†

# dnf install -y libreswan
# systemctl enable --now ipsec


# vi /etc/sysctl.conf
//์›๋ž˜ ์žˆ๋Š” ๊ฒƒ์— ์ถ”๊ฐ€ํ•˜๊ธฐ
net.ipv4.ip_forward = 1
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.rp_filter = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.icmp_ignore_bogus_error_responses = 1
net.ipv6.conf.all.disable_ipv6 = 1
net.ipv6.conf.default.disable_ipv6 = 1
:wq

//๋„ค ์ค„ ํ•œ๋ฒˆ์— ๋ณต์‚ฌํ•ด์„œ ๋„ฃ๊ธฐ
#for vpn in /proc/sys/net/ipv4/conf/*;
do echo 0 > $vpn/accept_redirects;
echo 0 > $vpn/send_redirects;
done


# sysctl -p

๐Ÿ“™ AWS VPN - VPN CONNECTION

โœ”๏ธ 0. aws vpc - vpn - site to stie VPN ์—ฐ๊ฒฐ - VPN์—ฐ๊ฒฐ ์ƒ์„ฑ ํด๋ฆญ

โœ”๏ธ 1. ์ด๋ฆ„ : MY-VPN - ์œ ํ˜• : ๊ฐ€์ƒ ํ”„๋ผ์ด๋น— ๊ฒŒ์ดํŠธ์›จ์ด ; MY-VGW [VPGW ์™€ VPNconnection์„ ์ž‡๋Š” ๋ผ์ธ ์—ฐ๊ฒฐ] - ๊ณ ๊ฐ๊ฒŒ์ดํŠธ ์›จ์ด : ๊ธฐ์กด - ๊ณ ๊ฐ ๊ฒŒ์ดํŠธ์›จ์ด ID : MY-CGW [ VPNconnectionr๊ณผ customGW์„ ์ž‡๋Š” ๋ผ์ธ ์—ฐ๊ฒฐ]

โœ”๏ธ 1-1. ๋ผ์šฐํŒ… ์˜ต์…˜ ; ์ •์  (์‹ค์Šต์ด ์•„๋‹Œ ๊ฒฝ์šฐ์— ๋™์ ) - ๊ณ ์ • IP์ ‘๋‘์‚ฌ : 192.168.0.0/20 ํ•™์› ๊ณต์œ ๊ธฐ IP ๋ฒ”์œ„ - ๋กœ์ปฌ(ํ•™์›) IPv4 ๋„คํŠธ์›Œํฌ CIDR : 192.168.0.0/20(์ ์ง€ ์•Š์œผ๋ฉด anywhere) - ์›๊ฒฉ(aws) IPv4 ๋„คํŠธ์›Œํฌ CIDR : 10.14.0.0/16 - VPN์—ฐ๊ฒฐ ์ƒ์„ฑ ํด๋ฆญ

โœ”๏ธ2. MY-VPN์ฒดํฌ - ๊ตฌ์„ฑ ๋‹ค์šด๋กœ๋“œ ํด๋ฆญ - ๊ณต๊ธ‰ ์—…์ฒด : openswan - ํ”Œ๋žซํผ : openswan - ์†Œํ”„ํŠธ์›จ์–ด : openswan 2.6.38+ - ๋‹ค์šด๋กœ๋“œ

=> ๋‹ค์šด๋กœ๋“œ ๋œ ํ…์ŠคํŠธ ํŒŒ์ผ ์ฐธ๊ณ ํ•˜์—ฌ ์˜คํ”ˆ์Šคํƒ๊ณผ vpn์—ฐ๊ฒฐ

๐Ÿ“™ openstack ์—ฐ๊ฒฐ(mobaxterm)



# vi /etc/ipsec.d/aws.conf
conn Tunnel1
        authby=secret
        auto=start
        left=%defaultroute
	leftid=123.142.252.25 //ํ•™์› public IP
	right=13.209.79.101 // ๋‚ด๋ ค๋ฐ›์€txt์— ์žˆ๋Š” right ๊ฐ’
        type=tunnel
        ikelifetime=8h
        keylife=1h
        phase2alg=aes128-sha1;modp1024
        ike=aes128-sha1;modp1024
        keyingtries=%forever
        keyexchange=ike
	leftsubnet=192.168.0.0/20 // ํ•™์›๋‚ด๋ถ€
	rightsubnet=10.14.0.0/16 // aws
        dpddelay=10
        dpdtimeout=30
        dpdaction=restart_by_peer
        overlapip=yes

conn Tunnel2
        authby=secret
        auto=start
        left=%defaultroute
	leftid=123.142.252.25
	right=15.165.154.217 // ๋‚ด๋ ค๋ฐ›์€txt์— ์žˆ๋Š” tunnel2 right๊ฐ’ 
        type=tunnel
        ikelifetime=8h
        keylife=1h
        phase2alg=aes128-sha1;modp1024
        ike=aes128-sha1;modp1024
        keyingtries=%forever
        keyexchange=ike
	leftsubnet=192.168.0.0/20
	rightsubnet=10.14.0.0/16
        dpddelay=10
        dpdtimeout=30
        dpdaction=restart_by_peer
        overlapip=yes



# vi /etc/ipsec.d/aws.secrets
123.142.252.25 13.209.79.101: PSK "kAXaCKxlWfIhKtF.5Aj7adS4SE0PfOVo"
123.142.252.25 15.165.154.217: PSK "kxt1MKcPn3m0kc3BwLddBIyPaj7LSMYy"


systemctl restart ipsec
[root@localhost ~]# systemctl status ipsec

โœ”๏ธ ํ„ฐ๋„ ์ƒํƒœ ํ™•์ธ

๐Ÿ“™ AWS EC2- ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”

โœ”๏ธ MY PUBLIC SUBNET RTB - ๋ผ์šฐํŒ… - ๋ผ์šฐํŒ… ํŽธ์ง‘ - ๋ผ์šฐํŒ… ์ถ”๊ฐ€ - ๋Œ€์ƒ : 192.168.0.0/20- ๊ฐ€์ƒํ”„๋ผ์ด๋น—๊ฒŒ์ดํŠธ์›จ์ด(MY-VGW) - ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์ €์žฅ

โœ”๏ธ MY PRIVATE SUBNET RTB - ๋ผ์šฐํŒ… - ๋ผ์šฐํŒ… ํŽธ์ง‘ - ๋ผ์šฐํŒ… ์ถ”๊ฐ€ -๋Œ€์ƒ : 192.168.0.0/20- ๊ฐ€์ƒํ”„๋ผ์ด๋น—๊ฒŒ์ดํŠธ์›จ์ด(MY-VGW) - ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์ €์žฅ

๐Ÿ“™ openstack ๋Œ€์‹œ๋ณด๋“œ

ํ”„๋กœ์ ํŠธ - ๋„คํŠธ์›Œํฌ - ๋ผ์šฐํ„ฐ - router - ์ •์  ๊ฒฝ๋กœ - ์ •์  ๊ฒฝ๋กœ ์ถ”๊ฐ€ - ๋Œ€์ƒ: 10.14.0.0/16 - ๋‹ค์Œ ํ™‰ : OPENSTACK IP ( libreswan์„ ์„ค์น˜ํ•œ ์„œ๋ฒ„์˜ IP)

์˜คํ”ˆ์Šคํƒ CLI์—์„œ

[root@localhost ~]# iptables -F
[root@localhost ~]# systemctl restart ipsec

๐Ÿ“™ VPN์—ฐ๊ฒฐ ํ™•์ธ

โœ”๏ธaws ๋ณด์•ˆ๊ทธ๋ฃน SG-WEB์— ICMPipv4 ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™ ํ™•์ธ. ( ์•ˆ๋˜์–ด์žˆ์œผ๋ฉด ์ถ”๊ฐ€ํ•˜๊ธฐ)
โœ”๏ธaws seoul(HA-seoul ์•„๋‹˜) ํผ๋ธ”๋ฆญ IP ๋ณต์‚ฌํ•˜์—ฌ mobaxterm์ ‘์†

โœ”๏ธseoul ์„œ๋ฒ„์—์„œ openstack์—์„œ ์ƒ์„ฑํ•œ server(centos7)์ธ์Šคํ„ด์Šค ํ”Œ๋กœํŒ… IP(์™ธ๋ถ€IP)๋กœ ํ•‘ ์ณ๋ณด๊ณ ,
sever์—์„œ seoul ๋‚ด๋ถ€ IP๋กœ ping ๋‚˜๊ฐ€๋Š”์ง€ ํ™•์ธ.

[ec2-user@ip-10-14-1-91 ~]$ ping 192.168.4.158
PING 192.168.4.158 (192.168.4.158) 56(84) bytes of data.
64 bytes from 192.168.4.158: icmp_seq=14 ttl=62 time=5.51 ms
64 bytes from 192.168.4.158: icmp_seq=15 ttl=62 time=5.27 ms
64 bytes from 192.168.4.158: icmp_seq=16 ttl=62 time=5.36 ms


[centos@centos7 ~]$ ping 10.14.1.91
PING 10.14.1.91 (10.14.1.91) 56(84) bytes of data.
64 bytes from 10.14.1.91: icmp_seq=1 ttl=252 time=5.55 ms
64 bytes from 10.14.1.91: icmp_seq=2 ttl=252 time=6.42 ms
64 bytes from 10.14.1.91: icmp_seq=3 ttl=252 time=5.78 ms

๐Ÿ“™โœ”๏ธโœ๏ธ๐Ÿ“ขโญ๏ธ๐Ÿ“Œ

๐Ÿ“Œ ๊ธฐํƒ€

โญ๏ธ openswan ; libre swan

โญ๏ธ PSK pre share key

openstack VPN์ ‘์†์‹œ ํ•„์š”ํ•œ key

profile
๊พธ์ค€ํžˆ, ์ฐจ๊ทผ์ฐจ๊ทผ
post-custom-banner

0๊ฐœ์˜ ๋Œ“๊ธ€