๐Ÿ“‚ AWS/Advanced Networking - Specialty

[AWS] Networking Specialty #1 VPC ๊ธฐ์ดˆ์™€ ์‹ฌํ™”

dhyuck 2025. 1. 6. 19:08
๋ฐ˜์‘ํ˜•

VPC(Virtual Private Cloud)๋ž€?

  • VPC(Virtual Private Cloud)๋ž€ AWS ๋‚ด์— ๋…ผ๋ฆฌ์ ์œผ๋กœ ๊ฒฉ๋ฆฌ๋œ ์‚ฌ์šฉ์ž ์ „์šฉ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ์ž…๋‹ˆ๋‹ค.
  • VPC๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์ง€์ •ํ•œ IP ์ฃผ์†Œ ๋ฒ”์œ„๋ฅผ ์‚ฌ์šฉํ•˜๊ณ , VPC์˜ IP ์ฃผ์†Œ๋Š” CIDR๋กœ ํ‘œํ˜„๋˜๋ฉฐ RFC 1918์— ๋ช…์‹œ๋œ ํ”„๋ผ์ด๋น— IP ๋Œ€์—ญ ์‚ฌ์šฉ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.
  • VPC์˜ IP ์ฃผ์†Œ๋กœ ๊ณต์ธ IP CIDR ๋ธ”๋ก์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋‚˜, AWS๋Š” VPC CIDR ๋ธ”๋ก์˜ IP ์ฃผ์†Œ๋ฅผ ์ ˆ๋Œ€๋กœ ์ธํ„ฐ๋„ท์— ์ง์ ‘ ๋…ธ์ถœํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
    ๊ทธ๋ ‡๊ธฐ ๋•Œ๋ฌธ์— VPC์˜ CIDR ๋ธ”๋ก์ด ๊ณต์ธIP ๋Œ€์—ญ์ด๋”๋ผ๋„ ์ธํ„ฐ๋„ท๊ณผ ์ง์ ‘ ํ†ต์‹ ์€ ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
  • ๊ฐ VPC ๊ฐ„์—๋Š” IP ๋Œ€์—ญ์„ ๊ฒน์น˜์ง€ ์•Š๊ฒŒ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.
  • VPC๋Š” IPv4์— ๋Œ€ํ•ด 5๊ฐœ์˜ IP ๋Œ€์—ญ(Primary 1๊ฐœ, Secondary 4๊ฐœ)๊นŒ์ง€ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ ๋Œ€์—ญ์˜ ํฌ๊ธฐ๋Š” /16์—์„œ /28 ์‚ฌ์ด๊ฐ€ ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • VPC Primary CIDR ๋ธ”๋ก์˜ ํฌ๊ธฐ๋ฅผ ๋Š˜๋ฆฌ๊ฑฐ๋‚˜ ์ค„์ผ์ˆ˜ ์—†๊ณ , VPC Secondary CIDR์€ ๊ธฐ์กด์˜ CIDR ๋ธ”๋ก๊ณผ ๊ฒน์น˜์ง€ ์•Š์•„์•ผํ•ฉ๋‹ˆ๋‹ค.
  • VPC์— Secondary CIDR ๋ธ”๋ก์„ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒฝ์šฐ์— Route table์— Destination์ด Secondary CIDR ๋ธ”๋ก์ด๊ณ  Target์ด local์ธ ๊ฒฝ๋กœ๊ฐ€ ์ž๋™์œผ๋กœ ์ถ”๊ฐ€๋ฉ๋‹ˆ๋‹ค.
  • AWS๋Š” ๊ฐ ๋ฆฌ์ „๋งˆ๋‹ค ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋˜๋Š” Default VPC๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. Default VPC์—๋Š” ํผ๋ธ”๋ฆญ ์„œ๋ธŒ๋„ท, ์ธํ„ฐ๋„ท ๊ฒŒ์ดํŠธ์›จ์ด ๋“ฑ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • ๊ธฐ๋ณธ VPC์—๋Š” 172.31.0.0/16์ด ํ• ๋‹น๋˜๊ณ , ๊ธฐ๋ณธ VPC๋Š” ๋ฆฌ์ „์— ์กด์žฌํ•˜๋Š” Availability Zone์˜ ์ˆ˜๋งŒํผ ํผ๋ธ”๋ฆญ ์„œ๋ธŒ๋„ท์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ํผ๋ธ”๋ฆญ ์„œ๋ธŒ๋„ท์€ /20์ด ํ• ๋‹น๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • VPC๋Š” IPv4์™€ IPv6 ์ฃผ์†Œ๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

AWS Account์™€ Region, AZ(Availability Zone)

  • AWS Account(๊ณ„์ •)๋Š” ๋ชจ๋“  ๋ฆฌ์†Œ์Šค(S3 ๋ฒ„ํ‚ท, EC2 ์ธ์Šคํ„ด์Šค ๋“ฑ)์„ ๋‹ด๋Š” ๊ธฐ๋ณธ ์ปจํ…Œ์ด๋„ˆ ์—ญํ• ๋กœ ๊ณ„์ • ์•ˆ์˜ ๋ฆฌ์†Œ์Šค๋Š” ๋‹ค๋ฅธ ๊ณ„์ •์˜ ๋ฆฌ์†Œ์Šค์™€ ๋…ผ๋ฆฌ์ ์œผ๋กœ ๊ฒฉ๋ฆฌ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • AWS Account์€ ๋‹ค๋ฅธ AWS Account์™€ ๊ตฌ๋ถ„๋˜๋Š” ๊ณ ์œ ํ•œ ID๋ฅผ ๊ฐ–์Šต๋‹ˆ๋‹ค.
  • ์‚ฌ์šฉ์ž๋Š” AWS Account ๋‚ด์˜ ์—ฌ๋Ÿฌ Region์—์„œ ๋ฆฌ์†Œ์Šค๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Region์€ ์ง€๋ฆฌ์ ์œผ๋กœ ๋ถ„๋ฆฌ๋œ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ํด๋Ÿฌ์Šคํ„ฐ๋กœ Region์€ ์—ฌ๋Ÿฌ ๊ฐœ์˜ AZ(Availability Zone)๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • AZ๋Š” 1๊ฐœ ์ด์ƒ์˜ ๊ฐœ๋ณ„ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ๋กœ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค. AZ ๊ฐ„ ๊ฑฐ๋ฆฌ๋Š” ์ˆ˜ ํ‚ฌ๋กœ๋ฏธํ„ฐ์ด๋ฉฐ, ๋ชจ๋‘ 100km ์ด๋‚ด์— ์œ„์น˜ํ•ฉ๋‹ˆ๋‹ค.
  • VPC๋Š” ํŠน์ • Region ๋‚ด์— ์ƒ์„ฑ๋˜์–ด Account์™€ Region์— ์ข…์†๋ฉ๋‹ˆ๋‹ค.

VPC Subnet๊ณผ Route table

  • VPC Subnet์€ VPC ๋‚ด์—์„œ IP ์ฃผ์†Œ ๋ฒ”์œ„๋ฅผ ์ •์˜ํ•˜๋ฉฐ ํŠน์ • AZ์— ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. VPC Subnet์—์„œ EC2 ์ธ์Šคํ„ด์Šค์™€ ๊ฐ™์€ AWS ๋ฆฌ์†Œ์Šค๋ฅผ ๋งŒ๋“ค ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Route table์€ Destination(๋ชฉ์ ์ง€)์™€ Target(๋Œ€์ƒ)์„ ์ •์˜ํ•˜๋Š” Route(๊ฒฝ๋กœ)๋กœ ๊ตฌ์„ฑ๋˜์–ด Subnet์ด๋‚˜ Gateway์—์„œ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์ด ์–ด๋””๋กœ ์ „์†กํ•ด์•ผํ•˜๋Š”์ง€ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.
  • ๊ฐ Subnet์€ Route table๊ณผ ์—ฐ๊ฒฐ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. 1๊ฐœ์˜ Subnet์€ 1๊ฐœ์˜ Route table๋งŒ ๊ฐ€์งˆ์ˆ˜ ์žˆ๊ณ  1๊ฐœ์˜ Route table์€ ์—ฌ๋Ÿฌ ๊ฐœ์˜ Subnet๊ณผ ์—ฐ๊ฒฐ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Subnet ์œ ํ˜•์€ Route๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋”ฐ๋ผ ๊ฒฐ์ •๋˜๋ฉฐ Public subnet, Private subnet, Isolated subnet, VPN-only subnet์ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • Public subnet์€ Internet gateway๋กœ ๊ฐ€๋Š” ์ง์ ‘์ ์ธ ๊ฒฝ๋กœ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. Public subnet์˜ ๋ฆฌ์†Œ์Šค๋Š” ์ธํ„ฐ๋„ท์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Private subnet์€ Internet gateway๋กœ ๊ฐ€๋Š” ์ง์ ‘์ ์ธ ๊ฒฝ๋กœ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. Private subnet์˜ ๋ฆฌ์†Œ์Šค๊ฐ€ ์ธํ„ฐ๋„ท์— ์•ก์„ธ์Šคํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” NAT ์žฅ์น˜๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
  • Isolated subnet์€ VPC ์™ธ๋ถ€๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. Isolated subnet์˜ ๋ฆฌ์†Œ์Šค๋Š” ๋™์ผํ•œ VPC์˜ ๋‹ค๋ฅธ ๋ฆฌ์†Œ์Šค์—๋งŒ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • VPN-only subnet์€ Internet gateway๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ๊ฐ€ ์—†๊ณ  VGW(Virtual private gateway, Site-to-Site VPN)๋กœ ๊ฐ€๋Š” ๊ฒฝ๋กœ๋งŒ ์žˆ๋Š” Subnet์ž…๋‹ˆ๋‹ค.
  • ๊ธฐ๋ณธ์ ์œผ๋กœ VPC ๋‚ด์˜ ๋ชจ๋“  Subnet๋“ค์€ local(VPC ๋‚ด๋ถ€)์„ ๋ชฉ์ ์ง€๋กœํ•˜๋Š” ๊ฒฝ๋กœ๊ฐ€ ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

Private IP์™€ Public IP, Elastic IP (IPv4)

  • Private IP๋ž€ ์ธํ„ฐ๋„ท ํ†ต์‹ ์ด ๋ถˆ๊ฐ€๋Šฅํ•œ IP ์ฃผ์†Œ๋กœ VPC ๋‚ด๋ถ€์˜ ํ†ต์‹  ๋˜๋Š” VPC ์™ธ๋ถ€์˜ ํ”„๋ผ์ด๋น— ํ†ต์‹ (VPC Peering, VPN ๋“ฑ)์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
  • Private IP๋Š” ๋ฆฌ์†Œ์Šค๊ฐ€ ์ƒ์„ฑ๋œ ์„œ๋ธŒ๋„ท์˜ CIDR ๋Œ€์—ญ ๋‚ด์— ์žˆ๋Š” IP ์ฃผ์†Œ๊ฐ€ ๋ฉ๋‹ˆ๋‹ค.
  • Public IP๋ž€ ์ธํ„ฐ๋„ท ํ†ต์‹ ์ด ๊ฐ€๋Šฅํ•œ IP ์ฃผ์†Œ๋กœ ENI์— ์ž„์‹œ๋กœ ํ• ๋‹น๋˜๋Š” Dynamic ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
  • Public IP๋Š” AWS์˜ Public IPv4 ์ฃผ์†Œ ํ’€์—์„œ ์ œ๊ณต๋˜๋ฉฐ ์ธ์Šคํ„ด์Šค๊ฐ€ ์ค‘์ง€ ํ›„ ์žฌ์‹œ์ž‘ํ•˜๋ฉด ์ƒˆ๋กœ์šด ํผ๋ธ”๋ฆญ IP๊ฐ€ ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
  • Elastic IP๋Š” Static Public IPv4 ์ฃผ์†Œ๋กœ AWS ๊ณ„์ •์— ํ• ๋‹น๋˜์–ด ์ธ์Šคํ„ด์Šค๋ฅผ ์ค‘์ง€ ํ›„ ์žฌ์‹œ์ž‘ ์‹œ์—๋„ ๋™์ผํ•œ IP ์ฃผ์†Œ๋ฅผ ์œ ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Elastic IP๋Š” AWS์˜ Public IPv4 ์ฃผ์†Œ ํ’€์—์„œ ์ œ๊ณต๋˜๋ฉฐ ํ•œ ๋ฒˆ์— ํ•˜๋‚˜์˜ ๋ฆฌ์†Œ์Šค์—๋งŒ ์—ฐ๊ฒฐ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Elastic IP๋Š” ๋ฐฉํ™”๋ฒฝ ๊ทœ์น™์ด๋‚˜ DNS ์„ค์ •๊ณผ ๊ฐ™์€ ์™ธ๋ถ€์— ๊ณ ์ •๋œ IP๋ฅผ ์ œ๊ณตํ•ด์•ผํ•˜๋Š” ๊ฒฝ์šฐ์— ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
  • AWS๋Š” Elastic LoadBalancer, CloudFront, NAT Gateway ๋“ฑ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ๋ชจ๋“  Public IPv4 ์ฃผ์†Œ์— ๋Œ€ํ•ด ์‹œ๊ฐ„๋‹น $0.005์˜ ์š”๊ธˆ์ด ๋ถ€๊ณผํ•ฉ๋‹ˆ๋‹ค. (BYOIP๋Š” ํฌํ•จ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.)
  • Bring Your Own IP (BYOIP)๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ๋ณด์œ ํ•œ IP ์ฃผ์†Œ๋ฅผ AWS์— ๊ฐ€์ ธ์™€์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์œผ๋กœ ์ฃผ๋กœ ๊ธฐ์กด ๋„คํŠธ์›Œํฌ ์ธํ”„๋ผ์™€ ์—ฐ์†์„ฑ์„ ์œ ์ง€ํ•˜๊ฑฐ๋‚˜ ํŠน์ • IP ์ฃผ์†Œ์— ์˜์กดํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด๋‚˜ ํŒŒํŠธ๋„ˆ๋“ค์˜ ํ˜ธํ™˜์„ฑ์„ ์œ„ํ•ด ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

Security group๊ณผ Network ACL

  • VPC๋Š” Firewall(๋ฐฉํ™”๋ฒฝ)์œผ๋กœ Security group๊ณผ Network Access Control List(NACL)์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  • VPC์— ๋Œ€ํ•œ Network Access๋ฅผ ์ œ์–ดํ•  ๋•Œ ๊ธฐ๋ณธ ๋ฉ”์ปค๋‹ˆ์ฆ˜์œผ๋กœ Security group์„ ์‚ฌ์šฉํ•˜๊ณ , ํ•„์š”ํ•œ ๊ฒฝ์šฐ Network ACL์„ ์ด์šฉํ•ด ์ถ”๊ฐ€์ ์ธ ์ œ์–ด๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  • Security group(๋ณด์•ˆ ๊ทธ๋ฃน)์€ ์ธ์Šคํ„ด์Šค ์ˆ˜์ค€์—์„œ ์ธ๋ฐ”์šด๋“œ ๋ฐ ์•„์šด๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. ๋ณด์•ˆ๊ทธ๋ฃน์€ ํ—ˆ์šฉ ๊ทœ์น™๋งŒ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
  • Network ACL์€ ์„œ๋ธŒ๋„ท ์ˆ˜์ค€์—์„œ ์ธ๋ฐ”์šด๋“œ ๋ฐ ์•„์›ƒ๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๊ฑฐ๋‚˜ ๊ฑฐ๋ถ€ํ•ฉ๋‹ˆ๋‹ค. Network ACL์€ ํ—ˆ์šฉ ๋ฐ ๊ฑฐ๋ถ€ ๊ทœ์น™์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
  • Security group์€ ์ธ์Šคํ„ด์Šค ๋‹จ์œ„๋กœ ์ ์šฉ๋˜๊ณ  Network ACL์€ ์„œ๋ธŒ๋„ท์— ์กด์žฌํ•˜๋Š” ๋ชจ๋“  ์ธ์Šคํ„ด์Šค์— ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.
  • Security group์€ Statefulํ•œ ๋ฐฉํ™”๋ฒฝ์œผ๋กœ ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์œผ๋กœ ํ—ˆ์šฉ๋œ ํŠธ๋ž˜ํ”ฝ์€ ์•„์›ƒ๋ฐ”์šด๋“œ ๊ทœ์น™์˜ ์˜ํ–ฅ์„ ๋ฐ›์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
    Network ACL์€ Statelessํ•œ ๋ฐฉํ™”๋ฒฝ์œผ๋กœ ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์œผ๋กœ ํ—ˆ์šฉ๋œ ํŠธ๋ž˜ํ”ฝ๋„ ์•„์›ƒ๋ฐ”์šด๋“œ ๊ทœ์น™์˜ ํ‰๊ฐ€๋ฅผ ๋ฐ›์Šต๋‹ˆ๋‹ค.
  • Security group์€ ๋ชจ๋“  ๊ทœ์น™์„ ํ‰๊ฐ€ํ•˜์—ฌ ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.
    Network ACL์€ ๊ฐ€์žฅ ๋‚ฎ์€ ๋ฒˆํ˜ธ์˜ ๊ทœ์น™๋ถ€ํ„ฐ ์ˆœ์„œ๋Œ€๋กœ ํ‰๊ฐ€ํ•˜์—ฌ ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.
  • EC2 ์ธ์Šคํ„ด์Šค๋กœ ์ธ๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ์ด ๋“ค์–ด์˜ค๋Š” ๊ฒฝ์šฐ Network ACL์ด ๋จผ์ € ํ‰๊ฐ€๋œ ํ›„ Security group์ด ์ดํ›„์— ํ‰๊ฐ€๋ฉ๋‹ˆ๋‹ค.
    ๋ฐ˜๋Œ€๋กœ EC2 ์ธ์Šคํ„ด์Šค์—์„œ ์•„์›ƒ๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ์ด ๋‚˜๊ฐ€๋Š” ๊ฒฝ์šฐ Security group์ด ๋จผ์ € ํ‰๊ฐ€๋œ ํ›„ Network ACL์ด ์ดํ›„์— ํ‰๊ฐ€๋ฉ๋‹ˆ๋‹ค.
  • Network ACL์€ ์„œ๋ธŒ๋„ท์— ๋“ค์–ด์˜ค๊ณ  ๋‚˜๊ฐˆ ๋•Œ ํ‰๊ฐ€๋ฉ๋‹ˆ๋‹ค. ์„œ๋ธŒ๋„ท ๋‚ด์—์„œ ๋ผ์šฐํŒ…๋  ๋•Œ๋Š” ํ‰๊ฐ€๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • Security group์€ ๋‹ค๋ฅธ Security group์„ Soure ๋˜๋Š” Destination์œผ๋กœ ํ•˜๋Š” ๋ฃฐ์„ ๋งŒ๋“ค ์ˆ˜ ์žˆ๋Š”๋ฐ ์ด๋ฅผ Security group referencing์ด๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค.
    Security group referencing์€ ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ์„ ์œ ์—ฐํ•˜๊ณ  ๋™์ ์œผ๋กœ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๋„๊ตฌ๋กœ Security group์— ์—ฐ๊ฒฐ๋œ ๋ชจ๋“  ์ธ์Šคํ„ด์Šค์— ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค.
    ์˜ˆ๋ฅผ ๋“ค์–ด ALB-WEB-DB๋กœ ๊ตฌ์„ฑ๋œ ๊ฒฝ์šฐ, WEB ์„œ๋ฒ„์˜ ๋ณด์•ˆ ๊ทธ๋ฃน์— ALB์˜ ๋ณด์•ˆ ๊ทธ๋ฃน์„ Source๋กœ ํ•˜๋Š” ๊ทœ์น™์„ ์ถ”๊ฐ€ํ•˜๊ณ , DB ์„œ๋ฒ„์˜ ๋ณด์•ˆ ๊ทธ๋ฃน์— WEB ์„œ๋ฒ„์˜ ๋ณด์•ˆ ๊ทธ๋ฃน์„ Source๋กœ ํ•˜๋Š” ๊ทœ์น™์„ ์ถ”๊ฐ€ํ•˜์—ฌ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Security group referencing์€ ๊ฐœ๋ณ„ ์ธ์Šคํ„ด์Šค์˜ IP ์ฃผ์†Œ๋‚˜ CIDR ๋Œ€์—ญ์œผ๋กœ ๊ด€๋ฆฌํ•  ํ•„์š” ์—†์ด ๋ณด์•ˆ ๊ทธ๋ฃน ๋‹จ์œ„๋กœ ํŠธ๋ž˜ํ”ฝ๊ณผ ๋ณด์•ˆ ์ •์ฑ…์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Network ACL์€ ์„œ๋ธŒ๋„ท ์ˆ˜์ค€์˜ ๋ฐฉํ™”๋ฒฝ์œผ๋กœ Security group์˜ ๊ทœ์น™์ด ๊ด€๋Œ€ํ•œ ๊ฒฝ์šฐ ์ƒ์œ„ ์ˆ˜์ค€์˜ ์ถ”๊ฐ€์ ์ธ ๋ณด์•ˆ ๊ณ„์ธต์œผ๋กœ ๋™์ž‘ํ•˜์—ฌ ์˜๋„ํ•˜์ง€ ์•Š์€ ํŠธ๋ž˜ํ”ฝ ์œ ์ž…์„ ๋ง‰์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Network ACL์€ ํŠน์ • IP ์ฃผ์†Œ์— ๋Œ€ํ•œ ๋ช…์‹œ์ ์ธ ๊ฑฐ๋ถ€ ๊ทœ์น™์„ ์„ค์ •ํ•˜์—ฌ ์•…์˜์ ์ธ ํŠธ๋ž˜ํ”ฝ์„ ์ฐจ๋‹จํ•จ์œผ๋กœ์จ ๋„คํŠธ์›Œํฌ ๊ณต๊ฒฉ์— ๋Œ€ํ•œ ๋ฐฉ์–ด ์ˆ˜๋‹จ์œผ๋กœ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

NAT Gateway์™€ NAT Instance

  • AWS๋Š” NAT Device๋กœ NAT Gateway์™€ NAT Instance๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  • NAT Gateway๋Š” AWS Managed Service๋กœ ๊ฐ€์šฉ์„ฑ๊ณผ ๋Œ€์—ญํญ์ด ๋ณด์žฅ๋˜์ง€๋งŒ, NAT Instance๋Š” Customer Managed๋กœ EC2๋ฅผ ์ด์šฉํ•˜์—ฌ ์ง์ ‘ ๊ตฌ์ถ•ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • NAT Device๋Š” ํ†ต์‹  ์š”์ฒญ์„ ๋ณด๋‚ผ์ˆ˜๋งŒ ์žˆ์œผ๋ฉฐ, ์™ธ๋ถ€์—์„œ ์ง์ ‘ ์š”์ฒญ์„ ๋ฐ›์•„ ํ†ต์‹ ์„ ์‹œ์ž‘ํ•˜์ง€๋Š” ์•Š์Šต๋‹ˆ๋‹ค. ์ฆ‰, ์•„์›ƒ๋ฐ”์šด๋“œ ํ†ต์‹ ๋งŒ ๊ฐ€๋Šฅํ•˜๊ณ  ์ธ๋ฐ”์šด๋“œ ํ†ต์‹ ์€ ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
  • AWS์—์„œ์˜ NAT device๋Š” ์‹ค์ œ๋กœ๋Š” Network Address Translation(NAT) ๋ฟ๋งŒ์•„๋‹ˆ๋ผ Port Address Translation(PAT)๋„ ํ•จ๊ป˜ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  • NAT Gateway๋Š” Connectivity type์— ๋”ฐ๋ผ Public NAT Gateway์™€ Private NAT Gateway์œผ๋กœ ๋ถ„๋ฅ˜๋ฉ๋‹ˆ๋‹ค.
  • Public NAT Gateway๋Š” Private subnet์— ์กด์žฌํ•˜๋Š” ๋ฆฌ์†Œ์Šค๊ฐ€ ์ธํ„ฐ๋„ท์— ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
    Public NAT Gateway๋Š” Public ์„œ๋ธŒ๋„ท์— ์ƒ์„ฑ๋˜๋ฉฐ, Elastic IP๊ฐ€ ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค.
  • Private NAT Gateway๋Š” ์ธํ„ฐ๋„ท ์—ฐ๊ฒฐ์ด ์•„๋‹Œ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ ํ†ต์‹ ์ด๋‚˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ์™€์˜ ์—ฐ๊ฒฐ์„ ์œ„ํ•ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
    Private NAT Gateway๋Š” Private ์„œ๋ธŒ๋„ท์— ์ƒ์„ฑ๋˜๋ฉฐ, Elastic IP๊ฐ€ ์—ฐ๊ฒฐ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • Public NAT Gateway๋ฅผ ํ†ตํ•ด ํ†ต์‹ ํ•˜๋Š” ๊ฒฝ์šฐ, ์ธ์Šคํ„ด์Šค์˜ Private IP๋Š” Public NAT Gateway์— ์—ฐ๊ฒฐ๋œ Elastic IP๋กœ NAT๋˜๊ณ ,
    Private NAT Gateway๋ฅผ ํ†ตํ•ด ํ†ต์‹ ํ•˜๋Š” ๊ฒฝ์šฐ, ์ธ์Šคํ„ด์Šค์˜ Private IP๋Š” Private NAT Gateway์˜ Private IP๋กœ NAT๋ฉ๋‹ˆ๋‹ค.
  • NAT Instance๋Š” ์ž์ฒด EC2 AMI๋ฅผ ๋งŒ๋“ค์–ด ๊ตฌ์ถ•ํ•ด์•ผํ•˜๊ณ  ์ธ์Šคํ„ด์Šค ์œ ํ˜•์— ๋”ฐ๋ผ ๋Œ€์—ญํญ์ด ๋‹ฌ๋ผ์ง‘๋‹ˆ๋‹ค.
  • NAT Gateway๋Š” NAT Instance์— ๋น„ํ•ด ๋” ๋‚˜์€ ๊ฐ€์šฉ์„ฑ๊ณผ ๋Œ€์—ญํญ์„ ์ œ๊ณตํ•˜๋ฏ€๋กœ ๋Œ€๋ถ€๋ถ„์˜ ๊ฒฝ์šฐ NAT Gateway๋ฅผ ์‚ฌ์šฉํ•  ๊ฒƒ์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.
  • NAT Gateway๋Š” ๋ณด์•ˆ ๊ทธ๋ฃน์„ ์ ์šฉํ•  ์ˆ˜ ์—†๊ณ  NACL๋งŒ ์ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
    NAT Instance๋Š” ๋ณด์•ˆ ๊ทธ๋ฃน๊ณผ NACL์„ ๋ชจ๋‘ ์ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • NAT Gateway๋Š” Bastion server๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์ง€๋งŒ NAT Inatnace๋Š” Bastion server๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ENI(Elastic Network Interface)๋ž€?

  • ENI(Elastic Network Interface)๋ž€ VPC ๋‚ด์—์„œ ๋„คํŠธ์›Œํฌ ํ†ต์‹ ์„ ๋‹ด๋‹นํ•˜๋Š” ๊ฐ€์ƒ์˜ ๋„คํŠธ์›Œํฌ ์นด๋“œ๋กœ EC2, RDS, Lambda ๋“ฑ์˜ ์„œ๋น„์Šค์— ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  • ENI๋Š” Subnet์— ์ƒ์„ฑ๋˜๊ณ  Subnet์˜ CIDR ๋Œ€์—ญ์— ํ•ด๋‹นํ•˜๋Š” Private IP ์ฃผ์†Œ๋ฅผ ๊ฐ–์Šต๋‹ˆ๋‹ค.
  • ENI๋Š” Primary IP ์ฃผ์†Œ(๊ธฐ๋ณธ Private IP ์ฃผ์†Œ), Secondary IP ์ฃผ์†Œ(๋ณด์กฐ Private IP ์ฃผ์†Œ), Public IP ์ฃผ์†Œ ๋˜๋Š” Elastic IP, MAC ์ฃผ์†Œ, Security Group, Subnet ๋“ฑ์„ ์†์„ฑ์œผ๋กœ ๊ฐ–์Šต๋‹ˆ๋‹ค.
  • EC2 ๋˜๋Š” RDS Instance์— ์ ์šฉ๋˜๋Š” Security Group์€ Instance๊ฐ€ ์‚ฌ์šฉํ•˜๋Š” ENI์— ์—ฐ๊ฒฐ๋˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
  • EC2 Instance type์— ๋”ฐ๋ผ ์ตœ๋Œ€๋กœ ์ง€์›ํ•˜๋Š” ENI์˜ ๊ฐœ์ˆ˜๊ฐ€ ๋‹ค๋ฆ…๋‹ˆ๋‹ค.
  • ENI๋Š” NIC teaming์„ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. NIC teaming์€ ์—ฌ๋Ÿฌ ๊ฐœ์˜ NIC๋ฅผ ๋ฌถ์–ด์„œ ๋Œ€์—ญํญ์„ ๋Š˜๋ฆฌ๋Š” ๊ธฐ์ˆ ์ž…๋‹ˆ๋‹ค.

VPC Peering

  • VPC Peering์€ ๋‘ ๊ฐœ์˜ VPC๋ฅผ ํ•˜๋‚˜์˜ ๋„คํŠธ์›Œํฌ์ฒ˜๋Ÿผ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ๋„๋ก ์—ฐ๊ฒฐํ•˜๋Š” ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.
  • VPC Peering Connection์€ 2๊ฐœ์˜ VPC ๊ฐ„์˜ ์—ฐ๊ฒฐ๋กœ Private IP ์ฃผ์†Œ๋ฅผ ์‚ฌ์šฉํ•ด ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • VPC Peering Connection์„ ํ†ตํ•œ ํŠธ๋ž˜ํ”ฝ์€ ์ธํ„ฐ๋„ท์„ ๊ฑฐ์น˜์ง€ ์•Š๊ณ  AWS Backbone Network ๋‚ด์—์„œ ํ†ต์‹ ๋˜๋ฏ€๋กœ ์ผ๋ฐ˜์ ์ธ Exploit ๋ฐ DDoS ๊ณต๊ฒฉ๊ณผ ๊ฐ™์€ ์œ„ํ˜‘์ด ์ค„์–ด๋“ญ๋‹ˆ๋‹ค.
  • VPC Peering์€ SPOF์™€ ๋Œ€์—ญํญ ์ œํ•œ์ด ์—†์œผ๋ฉฐ Cross Region ๋ฐ Cross Account VPC ๊ฐ„์—๋„ Peering์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
  • VPC Peering์„ ๊ตฌ์„ฑํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” CIDR ๋ธ”๋ก์ด ๊ฒน์น˜์ง€ ์•Š์•„์•ผ ํ•˜๊ณ , ์–‘์ชฝ VPC์˜ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์„ ์ˆ˜๋™์œผ๋กœ ์—…๋ฐ์ดํŠธํ•˜์—ฌ ํŠธ๋ž˜ํ”ฝ์ด ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ „๋‹ฌ๋˜๋„๋ก ํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.
  • VPC Peering์€ Transitive Peering์„ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
    A์™€ B, A์™€ C๊ฐ€ ํ”ผ์–ด๋ง๋˜์–ด ์žˆ๋‹ค๊ณ  ํ•˜๋”๋ผ๋„ B์™€ C ๊ฐ„์˜ ํ†ต์‹ ์„ ์œ„ํ•ด์„œ๋Š” ๋ณ„๋„์˜ ํ”ผ์–ด๋ง ์—ฐ๊ฒฐ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
  • VPC Peering์€ ๋‹จ์ˆœํžˆ Connection์ด ๋งบ์–ด์ง„ 2๊ฐœ์˜ VPC ๊ฐ„ ์ง์ ‘ ๋ผ์šฐํŒ…๋งŒ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
    A์™€ B๊ฐ€ ํ”ผ์–ด๋ง๋˜์–ด ์žˆ๊ณ , B๊ฐ€ DX/VPN์œผ๋กœ On-premise์™€ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ์— A์—์„œ B๋ฅผ ๊ฒฝ์œ (Transit)ํ•˜์—ฌ On-Premise๋กœ ์ ‘๊ทผํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
    ๋™์ผํ•˜๊ฒŒ A์™€ B๊ฐ€ ํ”ผ์–ด๋ง ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ์— A๊ฐ€ B์— ์กด์žฌํ•˜๋Š” NAT Gateway๋‚˜ VPC Endpoint๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

Managed Prefix Lists

  • Managed Prefix Lists๋ž€ ๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ ๋ฐ ๊ด€๋ฆฌ๋ฅผ ๊ฐ„์†Œํ™”ํ•˜๊ธฐ ์œ„ํ•ด ์—ฌ๋Ÿฌ CIDR ๋ธ”๋ก์„ ํ•˜๋‚˜์˜ ๋ฆฌ์ŠคํŠธ๋กœ ๋‹จ์œ„๋กœ ๊ด€๋ฆฌํ•˜๋Š” ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.
  • Managed Prefix Lists๋Š” ๊ฐœ๋ณ„ CIDR ๋ธ”๋ก์„ ํ•˜๋‚˜์˜ ๋ฆฌ์ŠคํŠธ๋กœ ์ฐธ์กฐํ•  ์ˆ˜ ์žˆ์–ด ๋ณด์•ˆ ๊ทธ๋ฃน์ด๋‚˜ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์—์„œ์˜ ๋„คํŠธ์›Œํฌ ๊ทœ์น™์„ ๋‹จ์ˆœํ™”์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • AWS๋Š” Managed Prefix Lists๋กœ AWS-Managed Prefix Lists์™€ Customer-Managed Prefix Lists๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  • AWS-Managed Prefix Lists๋Š” S3, DynamoDB ๋“ฑ์˜ AWS ์„œ๋น„์Šค์— ์‚ฌ์šฉ๋˜๋Š” IP ์ฃผ์†Œ ๋ฒ”์œ„์ž…๋‹ˆ๋‹ค.
  • AWS-Managed Prefix Lists๋Š” AWS๊ฐ€ ์ง์ ‘ ์ƒ์„ฑํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ๋ฆฌ์ŠคํŠธ๋กœ ์‚ฌ์šฉ์ž๊ฐ€ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •, ์‚ญ์ œํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
  • Customer-Managed Prefix Lists๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์ง์ ‘ ์ •์˜ํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ๋ฆฌ์ŠคํŠธ๋กœ ์‚ฌ์šฉ์ž๊ฐ€ ํ•ญ๋ชฉ์„ ์ถ”๊ฐ€ํ•˜๊ฑฐ๋‚˜ ์ œ๊ฑฐํ•  ๋•Œ๋งˆ๋‹ค ์ƒˆ๋กœ์šด ๋ฒ„์ „์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

VPC DNS Server - Route 53 Resolver

  • Route 53 Resolver๋Š” VPC ๋‚ด์—์„œ ์ƒ์„ฑ๋œ DNS ์ฟผ๋ฆฌ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ์„œ๋น„์Šค๋กœ Amazon DNS Server, AmazonProvidedDNS๋ผ๊ณ ๋„ ํ•ฉ๋‹ˆ๋‹ค.
  • Route 53 Resolver๋Š” AWS Managed Network์— ์กด์žฌํ•˜๋ฉฐ VPC ๋‚ด๋ถ€์˜ ๋ฆฌ์†Œ์Šค๋Š” VPC+2 IP Address๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Resolver์™€ ํ†ต์‹ ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.
    ์˜ˆ๋ฅผ ๋“ค์–ด, VPC์˜ CIDR ๊ฐ’์ด 10.0.0.0/16์ด๋ผ๋ฉด 10.0.0.2๋Š” Route 53 Resolver์™€ ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•ด ์˜ˆ์•ฝ๋œ ์ฃผ์†Œ๋กœ ๋‹ค๋ฅธ ๋ฆฌ์†Œ์Šค๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
  • ์˜จํ”„๋ ˆ๋ฏธ์Šค DNS ์„œ๋ฒ„์—์„œ VPC+2 IP Address๋กœ DNS ์ฟผ๋ฆฌ๋ฅผ ์ „๋‹ฌํ•˜๋Š” ๊ฒƒ์€ ์ง€์›๋˜์ง€ ์•Š์œผ๋ฉฐ Resolver Inbound Endpoint๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.
  • Route 53 Resolver๋Š” 169.254.169.253(IPv4), fd00:ec2::253 (IPv6)๋ฅผ ์‚ฌ์šฉํ•ด์„œ๋„ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
    169.254.169.253(IPv4), fd00:ec2::253 (IPv6)๋Š” Link-Local Address๋กœ ๋„คํŠธ์›Œํฌ ์„ธ๊ทธ๋จผํŠธ ๋‚ด์—์„œ๋งŒ ์œ ํšจํ•œ ํŠน์ˆ˜ ๋ชฉ์  IP์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
  • Route 53 Resolver๋Š” Route 53 private hosted zone, Amazon VPC-specific DNS name, Public record์— ๋Œ€ํ•œ DNS ์ฟผ๋ฆฌ๋ฅผ ์žฌ๊ท€์ ์œผ๋กœ ์‘๋‹ตํ•ฉ๋‹ˆ๋‹ค.
  • EC2 ์ธ์Šคํ„ด์Šค๋ฅผ ์‹œ์ž‘ํ•˜๋ฉด ํ•ญ์ƒ Private IPv4 ์ฃผ์†Œ์™€ ๊ทธ์— ํ•ด๋‹นํ•˜๋Š” Private DNS hostname์ด ํ• ๋‹น๋ฉ๋‹ˆ๋‹ค.
    ๋งŒ์•ฝ ์ธ์Šคํ„ด์Šค๊ฐ€ Public IPv4 ์ฃผ์†Œ๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค๋ฉด VPC์˜ DNS์˜ ์†์„ฑ์— ๋”ฐ๋ผ Public DNS hostname๊ฐ€ ๊ฒฐ์ •๋ฉ๋‹ˆ๋‹ค.
  • VPC๋Š” DNS ์†์„ฑ์œผ๋กœ DNS resolution๊ณผ DNS hostnames๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
    DNS resolution์„ Enableํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” Route 53 Resolver๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ณธ ๊ฐ’์€ Enable์ž…๋‹ˆ๋‹ค.
    DNS hostnames๋ฅผ Enableํ•˜๋ฉด ๊ฒฝ์šฐ์—๋Š” EC2 ์ธ์Šคํ„ด์Šค๊ฐ€ Public IP ์ฃผ์†Œ์— ๋Œ€์‘ํ•˜๋Š” Public DNS hostname์„ ํ• ๋‹นํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.๊ธฐ๋ณธ VPC๋Š” Enable ๋˜์–ด ์žˆ์ง€๋งŒ ์ƒˆ๋กœ ์ƒ์„ฑํ•œ VPC๋Š” Disable๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

DHCP Option Sets

  • DHCP Option Set์€ EC2 ์ธ์Šคํ„ด์Šค์™€ ๊ฐ™์€ VPC์˜ ๋ฆฌ์†Œ์Šค๊ฐ€ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ํ†ต์‹ ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•˜๋Š” ๋„คํŠธ์›Œํฌ ์„ค์ • ๊ทธ๋ฃน์ž…๋‹ˆ๋‹ค.
  • DHCP Option Set๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด VPC์˜ DNS ์„œ๋ฒ„๋ฅผ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ๊ธฐ๋ณธ DHCP Option Set๋Š” Domain name servers, Domain name๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๊ณ , ๊ธฐ๋ณธ Domain name servers๋Š” AmazonProvidedDNS์ž…๋‹ˆ๋‹ค.
  • 1๊ฐœ์˜ DHCP Option Set์€ ์—ฌ๋Ÿฌ๊ฐœ์˜ VPC์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์ง€๋งŒ, 1๊ฐœ์˜ VPC๋Š” 1๊ฐœ์˜ DHCP Option Set๋งŒ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • DHCP Option Set๋Š” ์ƒ์„ฑ ํ›„ ์ˆ˜์ •ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. VPC์˜ DHCP Option์„ ์—…๋ฐ์ดํŠธํ•˜๋ ค๋ฉด ์ƒˆ๋กœ์šด DHCP Option Set๋ฅผ ์ƒ์„ฑํ•˜๊ณ  VPC์™€ ์—ฐ๊ฒฐํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • DHCP Option Set๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒฝ์šฐ์— ์ธ์Šคํ„ด์Šค๋ฅผ ์žฌ์‹œ์ž‘ํ•  ํ•„์š”๋Š” ์—†์ง€๋งŒ DHCP ๊ฐฑ์‹  ์‹œ๊ฐ„์— ๋”ฐ๋ผ ๋ช‡์‹œ๊ฐ„์ด ๊ฑธ๋ฆด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
    ์ด ๊ฒฝ์šฐ ์ธ์Šคํ„ด์Šค์˜ OS์—์„œ ์ˆ˜๋™ ๊ฐฑ์‹ ํ•˜์—ฌ DHCP Option์„ ์ฆ‰์‹œ ์ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

MTU์™€ Jumbo Frame

  • MTU๋ž€ Network๋ฅผ ํ†ตํ•ด ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ท์˜ ์ตœ๋Œ€ ํฌ๊ธฐ๋กœ ๋Œ€๋ถ€๋ถ„์˜ ์ธํ„ฐ๋„ท์—์„œ ์ง€์›ํ•˜๋Š” MTU๋Š” 1500๋ฐ”์ดํŠธ์ž…๋‹ˆ๋‹ค.
  • MTU๊ฐ€ ์ปค์ง€๋ฉด ๋” ์ ์€ ์ˆ˜์˜ ํŒจํ‚ท์œผ๋กœ ๋™์ผํ•œ ์–‘์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•  ์ˆ˜ ์žˆ์–ด์„œ ์ฒ˜๋ฆฌ๋Ÿ‰์ด ์ฆ๊ฐ€ํ•˜๊ณ  ๋‚ฎ์€ PPS์˜ ํ˜ธ์ŠคํŠธ์—์„œ๋„ ๋” ๋งŽ์€ ์–‘์˜ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Jumbo Frame์€ ์ผ๋ฐ˜์ ์ธ MTU ํฌ๊ธฐ๋ฅผ ๋„˜์–ด์„œ๋Š” 1501~9000๋ฐ”์ดํŠธ ๋ฒ”์œ„์˜ ํ”„๋ ˆ์ž„์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.
  • AWS์—์„œ๋Š” 1500 ๋ฐ”์ดํŠธ๊ฐ€ ๋„˜๋Š” Jubmo Frame์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
  • ๋„คํŠธ์›Œํฌ ๊ฒฝ๋กœ์ƒ์˜ ๋ชจ๋“  ์žฅ๋น„๊ฐ€ Jumbo Frame์„ ์ง€์›ํ•ด์•ผ Jumbo Frame์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
    ๋„คํŠธ์›Œํฌ ๊ฒฝ๋กœ์ƒ์— Jumbo Frame์„ ์ง€์›ํ•˜์ง€ ์•Š๋Š” ์žฅ๋น„๊ฐ€ ์žˆ๋‹ค๋ฉด Jumbo Frame์€ ๋‹จํŽธํ™”๋˜์–ด ํŠธ๋ž˜ํ”ฝ์ด ๋Š๋ ค์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Path MTU๋ž€ ์ถœ๋ฐœ์ง€์—์„œ ๋ชฉ์ ์ง€๊นŒ์ง€์˜ ๋„คํŠธ์›Œํฌ ๊ฒฝ๋กœ์—์„œ ์ง€์›๋˜๋Š” ์ตœ๋Œ€ ํŒจํ‚ท ์‚ฌ์ด์ฆˆ์ž…๋‹ˆ๋‹ค.
  • PMTUD(Path MTU Discovery)๋ž€ Path MTU๋ฅผ ์ฐพ๋Š” ๊ณผ์ •์œผ๋กœ ๋ถˆํ•„์š”ํ•œ ํŒจํ‚ท ๋‹จํŽธํ™”๋ฅผ ๋ฐฉ์ง€ํ•˜๊ณ  ํŒจํ‚ท ์†์‹ค์ด ๋ฐœ์ƒํ•˜์ง€ ์•Š๋„๋ก ํ•˜๋Š” ๊ณผ์ •์ž…๋‹ˆ๋‹ค.
๋ฐ˜์‘ํ˜•

'๐Ÿ“‚ AWS > Advanced Networking - Specialty' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[AWS] Networking Specialty #3 VPC Endpoint์™€ PrivateLink  (0) 2025.01.06