๐Ÿ“‚ AWS

[AWS] Verified Access

dhyuck 2023. 3. 20. 23:21
๋ฐ˜์‘ํ˜•

Verified Access ๋“ฑ์žฅ ๋ฐฐ๊ฒฝ

  • ๋Œ€๋ถ€๋ถ„์˜ ๊ธฐ์—… ๊ณ ๊ฐ์ด AWS ๋‚ด์˜ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ ‘๊ทผํ•˜๋ ค๋ฉด VPN๊ณผ ๊ธฐ์—…์—์„œ ๊ด€๋ฆฌํ•˜๋Š” ์žฅ๋น„๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ์ด๋Š” ๊ฒฐ๊ตญ ์—ฌ๋Ÿฌ๊ฐ€์ง€ ์ •์ฑ…์„ ์—ฌ๋Ÿฌ ํŒ€์—์„œ ๊ด€๋ฆฌํ•˜๊ฒŒ ๋งŒ๋“ค๊ณ , ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ ‘๊ทผํ•˜์ง€ ๋ชปํ•˜๋Š” ๋ฌธ์ œ๋ฅผ ์—ฌ๋Ÿฌ ํฌ์ธํŠธ์—์„œ ์ฐพ๊ฒŒ๋” ๋งŒ๋“ญ๋‹ˆ๋‹ค.
  • Verified Access๋Š” Zero Trust์— ๊ธฐ๋ฐ˜ํ•˜์—ฌ VPN ์—†์ด ์›น๋ธŒ๋ผ์šฐ์ €๋กœ๋งŒ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ ‘๊ทผ ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ค๋‹ˆ๋‹ค.

  • AVA(AWS Verified Access)๋Š” ์œ ์ €๊ฐ€ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ ‘๊ทผํ•  ๋•Œ Trust Provider์—์„œ ๊ฐ€์ ธ์˜จ ์ •๋ณด์™€ ์ •์ฑ…์„ ๋น„๊ตํ•˜์—ฌ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.
  • AVA๋Š” ๋ชจ๋“  ์•ก์„ธ์Šค ์‹œ๋„๋ฅผ ๋กœ๊น…ํ•ฉ๋‹ˆ๋‹ค.

์‚ฌ์šฉ ์˜ˆ์‹œ


์ฃผ์š” ์ปดํฌ๋„ŒํŠธ

  • VA instance
    • ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์•ก์„ธ์Šค ์š”์ฒญ์„ ํ‰๊ฐ€ํ•˜๊ณ  ๋ณด์•ˆ ์š”๊ตฌ์‚ฌํ•ญ์ด ์ถฉ์กฑ๋˜๋Š” ๊ฒฝ์šฐ์—๋งŒ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ์ฃผ์ฒด์ž…๋‹ˆ๋‹ค.
    • ์ตœ์†Œ 1๊ฐœ ์ด์ƒ์˜ Trust provider์™€ ์—ฐ๊ฒฐํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.
  • VA endpoints
    • VA ์—”๋“œํฌ์ธํŠธ๋Š” ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜๋กœ ์—ฐ๊ฒฐ๋˜๋Š” ๋์ ์ž…๋‹ˆ๋‹ค.
    • LB ์—”๋“œํฌ์ธํŠธ, ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ์—”๋“œํฌ์ธํŠธ๋กœ ์ƒ์„ฑ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
    • hyperplane ENI๊ฐ€ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์กด์žฌํ•˜๋Š” ์„œ๋ธŒ๋„ท์— ์œ„์น˜ํ•˜์—ฌ point-to-point๋กœ ํŠธ๋ž˜ํ”ฝ์„ ์ „๋‹ฌํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.
  • VA groups
    • ๋ณด์•ˆ ์š”๊ตฌ ์‚ฌํ•ญ์ด ์œ ์‚ฌํ•œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋ชจ์Œ์ž…๋‹ˆ๋‹ค.
    • ๊ทธ๋ฃน ๋‚ด์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์€ ๊ทธ๋ฃน์˜ ์ •์ฑ…์„ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค.
  • Access policies
    • ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ์ •์ฑ…์ž…๋‹ˆ๋‹ค.
    • ๊ทธ๋ฃน์— ํ• ๋‹นํ•˜๊ฑฐ๋‚˜ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ์—”๋“œํฌ์ธํŠธ๋กœ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
    • AWS์—์„œ ์ƒˆ๋กœ ๋งŒ๋“  ์ •์ฑ… ์–ธ์–ด์ธ Cedar๋กœ ์ž‘์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Trust providers
    • ์‚ฌ์šฉ์ž ์ •๋ณด์™€ ๋””๋ฐ”์ด์Šค ์ •๋ณด๋ฅผ ์œ ์ง€ํ•˜๊ณ  ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.
    • AWS IAM Identity Center์™€ OIDC Provider๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.
    • ์—ฌ๋Ÿฌ ๊ฐœ์˜ VA ์ธ์Šคํ„ด์Šค์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ฐธ๊ณ ์ž๋ฃŒ

AWS re:Invent 2022 - Advanced VPC design and new Amazon VPC capabilities (NET302)

AWS re:Invent 2022 - [NEW] Introducing AWS Verified Access: Secure connections to your apps (NET214)

How Verified Access works

๋ฐ˜์‘ํ˜•