3587 ๋‹จ์–ด
18 ๋ถ„
๐ŸŒ AWS Networking โ€” VPC

๐ŸŒ AWS Networking โ€” VPC#

CIDR ยท VPC ยท Subnet ยท IGW ยท NAT ยท NACL ยท Security Group

VPC Peering ยท Endpoints ยท VPN ยท Direct Connect ยท Transit Gateway ยท Network Firewall


๋ชฉ์ฐจ#

  1. CIDR โ€” IPv4 ์ฃผ์†Œ ์ฒด๊ณ„
  2. VPC (Virtual Private Cloud)
  3. Subnet (์„œ๋ธŒ๋„ท)
  4. Internet Gateway (IGW)
  5. Bastion Host
  6. NAT Gateway vs. NAT Instance
  7. Security Groups vs. NACLs
  8. VPC Flow Logs
  9. VPC Peering
  10. VPC Endpoints (AWS PrivateLink)
  11. Site-to-Site VPN
  12. AWS Direct Connect (DX)
  13. Transit Gateway
  14. VPC Traffic Mirroring
  15. IPv6 & Egress-only Internet Gateway
  16. AWS Network Firewall
  17. ๋„คํŠธ์›Œํ‚น ๋น„์šฉ (Networking Costs)
  18. AWS ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ๊ณ„์ธต
  19. VPC ์ „์ฒด ์š”์•ฝ
  20. ๐Ÿ“Œ ์‹œํ—˜ ์ž์ฃผ ์ถœ์ œ ํฌ์ธํŠธ
  21. ๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

CIDR โ€” IPv4 ์ฃผ์†Œ ์ฒด๊ณ„#

CIDR (Classless Inter-Domain Routing)#

IP ์ฃผ์†Œ ๋ฒ”์œ„๋ฅผ ์ •์˜ํ•˜๋Š” ๋ฐฉ๋ฒ•. Security Group ๊ทœ์น™ ๋ฐ AWS ๋„คํŠธ์›Œํ‚น ์ „๋ฐ˜์— ์‚ฌ์šฉ.

WW.XX.YY.ZZ/32 โ†’ ๋‹จ 1๊ฐœ์˜ IP
0.0.0.0/0 โ†’ ๋ชจ๋“  IP
192.168.0.0/26 โ†’ 192.168.0.0 ~ 192.168.0.63 (64๊ฐœ IP)

Subnet Mask ๋น ๋ฅธ ๊ณ„์‚ฐ:

CIDR์‚ฌ์šฉ ๊ฐ€๋Šฅ IP ์ˆ˜Subnet Mask
/321255.255.255.255
/312-
/304-
/2816-
/24256255.255.255.0
/1665,536255.255.0.0
/816,777,216255.0.0.0

๐Ÿ“Œ ๊ณต์‹: ์‚ฌ์šฉ ๊ฐ€๋Šฅ IP ์ˆ˜ = 2^(32 - mask ์ˆซ์ž)


Private IP ๋ฒ”์œ„ (IANA ์ง€์ •)#

๋ฒ”์œ„CIDR์šฉ๋„
10.0.0.0 ~ 10.255.255.25510.0.0.0**/8**๋Œ€๊ทœ๋ชจ ๋„คํŠธ์›Œํฌ
172.16.0.0 ~ 172.31.255.255172.16.0.0**/12**AWS Default VPC ๋ฒ”์œ„
192.168.0.0 ~ 192.168.255.255192.168.0.0**/16**ํ™ˆ ๋„คํŠธ์›Œํฌ

๋‚˜๋จธ์ง€ IP๋Š” ๋ชจ๋‘ Public IP.


VPC (Virtual Private Cloud)#

ํ•ญ๋ชฉ๋‚ด์šฉ
๋ฆฌ์ „๋‹น ์ตœ๋Œ€ VPC ์ˆ˜5๊ฐœ (Soft limit, ์ฆ๊ฐ€ ์š”์ฒญ ๊ฐ€๋Šฅ)
VPC๋‹น ์ตœ๋Œ€ CIDR ์ˆ˜5๊ฐœ
CIDR ์ตœ์†Œ ํฌ๊ธฐ/28 (16 IP)
CIDR ์ตœ๋Œ€ ํฌ๊ธฐ/16 (65,536 IP)
ํ—ˆ์šฉ IP ๋ฒ”์œ„Private IP ๋ฒ”์œ„๋งŒ (10.x, 172.16-31.x, 192.168.x)
WARNING

โš ๏ธ VPC CIDR์€ ๊ธฐ์—… ๋„คํŠธ์›Œํฌ์™€ ๊ฒน์น˜๋ฉด ์•ˆ ๋จ (VPN/Direct Connect ์—ฐ๊ฒฐ ์‹œ ๋ผ์šฐํŒ… ์ถฉ๋Œ)

Default VPC#

  • ๋ชจ๋“  ์‹ ๊ทœ AWS ๊ณ„์ •์— ์ž๋™ ์ƒ์„ฑ
  • EC2 ์ธ์Šคํ„ด์Šค ์ƒ์„ฑ ์‹œ Subnet ๋ฏธ์ง€์ • ์‹œ Default VPC์— ๋ฐฐ์น˜
  • ๊ธฐ๋ณธ์ ์œผ๋กœ Internet Connectivity + Public IPv4 ์ฃผ์†Œ ๋ถ€์—ฌ
  • Public/Private IPv4 DNS ์ด๋ฆ„ ๋ชจ๋‘ ์ œ๊ณต

Subnet (์„œ๋ธŒ๋„ท)#

  • VPC ๋‚ด IPv4 ์ฃผ์†Œ์˜ ํ•˜์œ„ ๋ฒ”์œ„, ํŠน์ • AZ์— ์ข…์†
  • AWS๋Š” ๊ฐ Subnet์—์„œ 5๊ฐœ์˜ IP๋ฅผ ์˜ˆ์•ฝ (์‚ฌ์šฉ ๋ถˆ๊ฐ€)

์˜ˆ์‹œ: 10.0.0.0/24 Subnet

์ฃผ์†Œ์šฉ๋„
10.0.0.0Network Address
10.0.0.1VPC Router์šฉ (AWS ์˜ˆ์•ฝ)
10.0.0.2Amazon-provided DNS์šฉ (AWS ์˜ˆ์•ฝ)
10.0.0.3๋ฏธ๋ž˜ ์šฉ๋„ (AWS ์˜ˆ์•ฝ)
10.0.0.255Network Broadcast Address (AWS๋Š” VPC์—์„œ Broadcast ๋ฏธ์ง€์›, ์˜ˆ์•ฝ)
TIP

29๊ฐœ์˜ IP๊ฐ€ ํ•„์š”ํ•˜๋‹ค๋ฉด /27 (32 IP - 5 = 27 < 29) ๋ถˆ๊ฐ€ โ†’ /26 (64 - 5 = 59) ํ•„์š”


Internet Gateway (IGW)#

  • VPC ๋‚ด ๋ฆฌ์†Œ์Šค๊ฐ€ ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋˜๋„๋ก ํ•˜๋Š” ๊ฒŒ์ดํŠธ์›จ์ด
  • ์ˆ˜ํ‰ ํ™•์žฅ, ๊ณ ๊ฐ€์šฉ์„ฑ, ์ด์ค‘ํ™” ์ง€์›
  • VPC์™€ ๋ณ„๋„๋กœ ์ƒ์„ฑ ํ›„ ์—ฐ๊ฒฐ (1 VPC : 1 IGW)
  • IGW ์ž์ฒด๋งŒ์œผ๋กœ๋Š” ์ธํ„ฐ๋„ท ์ ‘๊ทผ ๋ถˆ๊ฐ€ โ†’ Route Table ์ˆ˜์ • ํ•„์ˆ˜
[EC2] โ†’ Route Table โ†’ Router โ†’ IGW โ†’ Internet

Bastion Host#

  • Public Subnet์— ์œ„์น˜ํ•œ EC2 ์ธ์Šคํ„ด์Šค
  • Private Subnet์˜ EC2 ์ธ์Šคํ„ด์Šค์— SSH ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•œ Jump Server ์—ญํ• 

๋ณด์•ˆ ์„ค์ •:

Bastion Host Security Group:
Inbound: Port 22 ํ—ˆ์šฉ โ€” ํšŒ์‚ฌ ๊ณต์ธ IP(CIDR)์—์„œ๋งŒ
Private EC2 Security Group:
Inbound: Port 22 ํ—ˆ์šฉ โ€” Bastion Host์˜ Security Group ๋˜๋Š” Private IP์—์„œ๋งŒ

NAT Gateway vs. NAT Instance#

๋ชฉ์ : Private Subnet์˜ EC2๊ฐ€ ์ธํ„ฐ๋„ท(์™ธ๋ถ€)์— ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๋„๋ก (๋ฐ˜๋Œ€ ๋ฐฉํ–ฅ์€ ์ฐจ๋‹จ)

ํ•ญ๋ชฉNAT GatewayNAT Instance
๊ด€๋ฆฌAWS ์™„์ „ ๊ด€๋ฆฌํ˜•์ง์ ‘ ๊ด€๋ฆฌ (OS ํŒจ์น˜ ๋“ฑ)
๊ฐ€์šฉ์„ฑAZ ๋‚ด ๊ณ ๊ฐ€์šฉ์„ฑ์Šคํฌ๋ฆฝํŠธ๋กœ Failover ๊ตฌํ˜„
๋Œ€์—ญํญ์ตœ๋Œ€ 100 Gbps (5 Gbps ๊ธฐ๋ณธ, ์ž๋™ ํ™•์žฅ)EC2 Instance Type์— ๋”ฐ๋ฆ„
๋ณด์•ˆ ๊ทธ๋ฃนโŒ ๋ถˆํ•„์š”โœ… ์ง์ ‘ ๊ด€๋ฆฌ
Bastion HostโŒ ๋ถˆ๊ฐ€โœ… ๊ฐ€๋Šฅ
๋น„์šฉ์‹œ๊ฐ„๋‹น + ์ „์†ก๋Ÿ‰EC2 ๋น„์šฉ + ๋„คํŠธ์›Œํฌ ๋น„์šฉ
์ƒํƒœํ˜„์žฌ ๊ถŒ์žฅ๊ตฌ์‹ (2020๋…„ ์ง€์› ์ข…๋ฃŒ)

NAT Instance ํ•„์ˆ˜ ์„ค์ •:

  • Public Subnet์— ๋ฐฐ์น˜
  • Source/Destination Check ๋น„ํ™œ์„ฑํ™”
  • Elastic IP ์—ฐ๊ฒฐ
  • Route Table์—์„œ Private Subnet โ†’ NAT Instance๋กœ ๋ผ์šฐํŒ…

NAT Gateway ๊ณ ๊ฐ€์šฉ์„ฑ ๊ตฌ์„ฑ#

[AZ1: Private Subnet] โ†’ [NAT-GW-1 (AZ1)] โ†’ IGW โ†’ Internet
[AZ2: Private Subnet] โ†’ [NAT-GW-2 (AZ2)] โ†’ IGW โ†’ Internet
  • NAT GW๋Š” ๋‹จ์ผ AZ ๋‚ด์—์„œ๋งŒ ๊ณ ๊ฐ€์šฉ์„ฑ
  • Multi-AZ ๊ตฌ์„ฑ: AZ๋ณ„๋กœ ๋ณ„๋„ NAT GW ์ƒ์„ฑ (AZ ์žฅ์•  ์‹œ ํฌ๋กœ์Šค AZ Failover ๋ถˆํ•„์š”)

Security Groups vs. NACLs#

ํŠธ๋ž˜ํ”ฝ ํ๋ฆ„#

Inbound: Internet โ†’ [NACL Inbound] โ†’ [Security Group Inbound] โ†’ EC2
Outbound: EC2 โ†’ [Security Group Outbound] โ†’ [NACL Outbound] โ†’ Internet

๋น„๊ต#

ํ•ญ๋ชฉSecurity GroupNACL
์ ์šฉ ๋ ˆ๋ฒจEC2 ์ธ์Šคํ„ด์Šค ๋ ˆ๋ฒจ์„œ๋ธŒ๋„ท ๋ ˆ๋ฒจ
๊ทœ์น™ ์œ ํ˜•Allow๋งŒAllow + Deny ๋ชจ๋‘
์ƒํƒœStateful (Inbound ํ—ˆ์šฉ ์‹œ Outbound ์ž๋™ ํ—ˆ์šฉ)Stateless (Inbound/Outbound ๊ฐ๊ฐ ๋ช…์‹œ ํ•„์š”)
๊ทœ์น™ ํ‰๊ฐ€๋ชจ๋“  ๊ทœ์น™ ํ‰๊ฐ€ ํ›„ ๊ฒฐ์ •๋‚ฎ์€ ๋ฒˆํ˜ธ๋ถ€ํ„ฐ ์ˆœ์„œ๋Œ€๋กœ ํ‰๊ฐ€, ์ฒซ ๋งค์นญ ์ ์šฉ
์ž๋™ ์ ์šฉ๋ช…์‹œ์ ์œผ๋กœ ์ง€์ •ํ•ด์•ผ ํ•จ์„œ๋ธŒ๋„ท ๋‚ด ๋ชจ๋“  EC2์— ์ž๋™ ์ ์šฉ

NACL ๊ทœ์น™ ํŠน์„ฑ#

  • ๊ทœ์น™ ๋ฒˆํ˜ธ: 1 ~ 32766 (๋‚ฎ์€ ๋ฒˆํ˜ธ๊ฐ€ ๋†’์€ ์šฐ์„ ์ˆœ์œ„)
  • ๋งˆ์ง€๋ง‰ ๊ทœ์น™: (asterisk) โ€” ์ผ์น˜ํ•˜๋Š” ๊ทœ์น™ ์—†์œผ๋ฉด Deny
  • ์ƒˆ๋กœ ์ƒ์„ฑ๋œ NACL: ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ Deny
  • Default NACL: ๋ชจ๋“  Inbound/Outbound ํ—ˆ์šฉ โ†’ ์ˆ˜์ • ๊ธˆ์ง€, Custom NACL ์‚ฌ์šฉ ๊ถŒ์žฅ
  • ํŠน์ • IP ์ฐจ๋‹จ์— ์ ํ•ฉ (Security Group์€ Deny ๋ถˆ๊ฐ€)
  • ๊ทœ์น™ ์ถ”๊ฐ€ ์‹œ 100 ๋‹จ์œ„ ์ฆ๋ถ„ ๊ถŒ์žฅ

Ephemeral Ports (์ž„์‹œ ํฌํŠธ)#

  • ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์— ์—ฐ๊ฒฐํ•  ๋•Œ ์‘๋‹ต์„ ๋ฐ›์„ ์ž„์‹œ ํฌํŠธ๋ฅผ ๋ฌด์ž‘์œ„๋กœ ํ• ๋‹น
  • ์šด์˜์ฒด์ œ๋ณ„ ์ž„์‹œ ํฌํŠธ ๋ฒ”์œ„:
    • IANA/Windows 10: 49152 ~ 65535
    • Linux Kernel: 32768 ~ 60999

NACL์—์„œ Ephemeral Port ๊ณ ๋ ค ์˜ˆ์‹œ (Web โ†’ DB ํ†ต์‹ ):

Web-NACL Outbound: TCP 3306 โ†’ DB Subnet CIDR ํ—ˆ์šฉ
DB-NACL Inbound: TCP 3306 โ† Web Subnet CIDR ํ—ˆ์šฉ
DB-NACL Outbound: TCP 1024-65535 โ†’ Web Subnet CIDR ํ—ˆ์šฉ โ† ์ž„์‹œ ํฌํŠธ!
Web-NACL Inbound: TCP 1024-65535 โ† DB Subnet CIDR ํ—ˆ์šฉ โ† ์ž„์‹œ ํฌํŠธ!

VPC Flow Logs๋กœ SG/NACL ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…#

Flow Log Action์›์ธ
Inbound REJECTNACL ๋˜๋Š” Security Group ์ฐจ๋‹จ
Inbound ACCEPT + Outbound REJECTNACL ์ฐจ๋‹จ (Stateless)

๐Ÿ’ก Security Group์€ Stateful์ด๋ฏ€๋กœ Inbound ACCEPT ์‹œ Outbound๋Š” ์ž๋™ ํ—ˆ์šฉ๋จ.


VPC Flow Logs#

  • VPC / Subnet / ENI ๋ ˆ๋ฒจ์—์„œ IP ํŠธ๋ž˜ํ”ฝ ์ •๋ณด ์บก์ฒ˜
  • AWS ๊ด€๋ฆฌํ˜• ์ธํ„ฐํŽ˜์ด์Šค(ELB, RDS, ElastiCache, NAT GW ๋“ฑ)๋„ ์บก์ฒ˜ ๊ฐ€๋Šฅ
  • ๋Œ€์ƒ: S3, CloudWatch Logs, Kinesis Data Firehose

Flow Log ํ•„๋“œ:

version account-id interface-id srcaddr dstaddr srcport dstport protocol packets bytes start end action log-status

๋ถ„์„ ์•„ํ‚คํ…์ฒ˜:

VPC Flow Logs โ†’ CloudWatch Logs โ†’ Contributor Insights โ†’ Top-10 IP
VPC Flow Logs โ†’ CloudWatch Logs โ†’ Metric Filter โ†’ Alarm โ†’ SNS
VPC Flow Logs โ†’ S3 โ†’ Athena โ†’ QuickSight
IMPORTANT

โš ๏ธ CloudWatch Logs๋กœ ์ „์†ก ์‹œ IAM Role์— logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents ๊ถŒํ•œ ํ•„์š”


VPC Peering#

  • AWS ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ๋กœ ๋‘ VPC๋ฅผ ํ”„๋ผ์ด๋น— ์—ฐ๊ฒฐ
  • ๊ฐ™์€ ๋„คํŠธ์›Œํฌ์ฒ˜๋Ÿผ ๋™์ž‘

์ œ์•ฝ ์กฐ๊ฑด:

  • CIDR ๋ฒ”์œ„ ๊ฒน์น˜๋ฉด ์•ˆ ๋จ
  • Non-transitive: A-B, B-C ํ”ผ์–ด๋ง์ด ์žˆ์–ด๋„ A-C ์ง์ ‘ ์—ฐ๊ฒฐ ์•ˆ ๋จ โ†’ A-C ํ”ผ์–ด๋ง ๋ณ„๋„ ์ƒ์„ฑ ํ•„์š”
  • ์—ฐ๊ฒฐ ํ›„ ์–‘์ชฝ VPC์˜ Route Table ๋ชจ๋‘ ์—…๋ฐ์ดํŠธ ํ•„์š”
  • ์„œ๋กœ ๋‹ค๋ฅธ ๊ณ„์ •/๋ฆฌ์ „ ๊ฐ„ VPC Peering ๊ฐ€๋Šฅ
  • ํ”ผ์–ด๋ง๋œ VPC์˜ Security Group ์ฐธ์กฐ ๊ฐ€๋Šฅ (๊ฐ™์€ ๋ฆฌ์ „, ๋‹ค๋ฅธ ๊ณ„์ • ๊ฐ„)
VPC-A โ†โ†’ VPC-B โ†โ†’ VPC-C
A์™€ C๊ฐ€ ํ†ต์‹ ํ•˜๋ ค๋ฉด ๋ณ„๋„ A-C ํ”ผ์–ด๋ง ํ•„์š” (B๋ฅผ ํ†ตํ•œ ์ „์ด ์—†์Œ)

  • Public Internet์„ ๊ฑฐ์น˜์ง€ ์•Š๊ณ  AWS ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ๋กœ AWS ์„œ๋น„์Šค์— ์ ‘๊ทผ
  • IGW, NAT GW ์—†์ด AWS ์„œ๋น„์Šค ์ ‘๊ทผ ๊ฐ€๋Šฅ
  • ์ˆ˜ํ‰ ํ™•์žฅ, ์ด์ค‘ํ™”

Endpoint ์œ ํ˜•#

ํ•ญ๋ชฉInterface EndpointGateway Endpoint
๊ตฌํ˜„ENI (Private IP) ์ƒ์„ฑRoute Table์— Gateway ์ถ”๊ฐ€
Security Groupโœ… ํ•„์š”โŒ ๋ถˆํ•„์š”
์ง€์› ์„œ๋น„์Šค๋Œ€๋ถ€๋ถ„์˜ AWS ์„œ๋น„์ŠคS3, DynamoDB๋งŒ
๋น„์šฉ์‹œ๊ฐ„๋‹น + GB๋‹น๋ฌด๋ฃŒ
ํ™•์žฅENI ๊ธฐ๋ฐ˜Route Table ๊ธฐ๋ฐ˜ (์ž๋™ ํ™•์žฅ)

S3 Endpoint ์„ ํƒ ๊ธฐ์ค€:

์ผ๋ฐ˜์ ์œผ๋กœ โ†’ Gateway Endpoint ๊ถŒ์žฅ (๋ฌด๋ฃŒ, Route Table๋งŒ ์ˆ˜์ •)
On-premises (VPN/Direct Connect), ๋‹ค๋ฅธ VPC, ๋‹ค๋ฅธ ๋ฆฌ์ „์—์„œ ์ ‘๊ทผ
โ†’ Interface Endpoint ํ•„์š”

Site-to-Site VPN#

  • On-premises โ†” AWS VPC ๊ฐ„ ์•”ํ˜ธํ™”๋œ VPN ํ„ฐ๋„ (๊ณต์šฉ ์ธํ„ฐ๋„ท ๊ฒฝ์œ )

๊ตฌ์„ฑ ์š”์†Œ:

๊ตฌ์„ฑ์š”์†Œ์„ค๋ช…
VGW (Virtual Private Gateway)AWS ์ธก VPN Concentrator, VPC์— ์—ฐ๊ฒฐ
CGW (Customer Gateway)๊ณ ๊ฐ ์ธก ์†Œํ”„ํŠธ์›จ์–ด ์•ฑ ๋˜๋Š” ๋ฌผ๋ฆฌ ์žฅ๋น„

์„ค์ • ํ•„์ˆ˜ ์‚ฌํ•ญ:

  • CGW ๋””๋ฐ”์ด์Šค์˜ ๊ณต์ธ IP ์‚ฌ์šฉ (NAT ๋’ค์— ์žˆ์œผ๋ฉด NAT์˜ Public IP)
  • ์„œ๋ธŒ๋„ท Route Table์—์„œ VGW Route Propagation ํ™œ์„ฑํ™”
  • On-premises โ†’ EC2 Ping ํ•„์š” ์‹œ Security Group์— ICMP ํ”„๋กœํ† ์ฝœ Inbound ํ—ˆ์šฉ

AWS VPN CloudHub#

  • ์—ฌ๋Ÿฌ Site์™€ VPN ์—ฐ๊ฒฐ์„ ํ•˜๋‚˜์˜ VGW์— ์—ฐ๊ฒฐ โ†’ Hub-and-Spoke ๊ตฌ์„ฑ
  • ๊ฐ Site ๊ฐ„ ๋ณด์•ˆ ํ†ต์‹  (์ €๋น„์šฉ)
  • ๊ณต์šฉ ์ธํ„ฐ๋„ท ๊ฒฝ์œ  (์•”ํ˜ธํ™”๋จ)
  • ๋™์  ๋ผ์šฐํŒ… + Route Table ์„ค์ • ํ•„์š”

AWS Direct Connect (DX)#

  • On-premises โ†” AWS ๊ฐ„ ์ „์šฉ ๋ฌผ๋ฆฌ Private ์—ฐ๊ฒฐ (์ธํ„ฐ๋„ท ๋ฏธ๊ฒฝ์œ )
  • DC โ†’ AWS Direct Connect Location โ†’ VGW โ†’ VPC
  • IPv4, IPv6 ๋ชจ๋‘ ์ง€์›

Use Cases:

  • ๋Œ€์šฉ๋Ÿ‰ ๋ฐ์ดํ„ฐ์…‹ ์ฒ˜๋ฆฌ (๋†’์€ ๋Œ€์—ญํญ, ๋‚ฎ์€ ๋น„์šฉ)
  • ์‹ค์‹œ๊ฐ„ ๋ฐ์ดํ„ฐ ํ”ผ๋“œ (์ผ๊ด€๋œ ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ)
  • Hybrid ํ™˜๊ฒฝ (์˜จํ”„๋ ˆ๋ฏธ์Šค + ํด๋ผ์šฐ๋“œ)

Direct Connect ์—ฐ๊ฒฐ ์œ ํ˜•#

์œ ํ˜•์šฉ๋Ÿ‰ํŠน์ง•
Dedicated Connections1/10/100 Gbps๋ฌผ๋ฆฌ์  Ethernet ํฌํŠธ ์ „์šฉ
Hosted Connections50 Mbps ~ 10 GbpsAWS Direct Connect Partner ํ†ตํ•ด ์š”์ฒญ, ์˜จ๋””๋งจ๋“œ ์šฉ๋Ÿ‰ ์กฐ์ • ๊ฐ€๋Šฅ
IMPORTANT

โš ๏ธ ์‹ ๊ทœ ์—ฐ๊ฒฐ ๊ตฌ์ถ• ๋ฆฌ๋“œ ํƒ€์ž„: ๋ณดํ†ต 1๊ฐœ์›” ์ด์ƒ

Direct Connect ์•”ํ˜ธํ™”#

  • ๋ฐ์ดํ„ฐ ์ „์†ก ์ค‘ ์•”ํ˜ธํ™” ๊ธฐ๋ณธ ์—†์Œ (Private ์—ฐ๊ฒฐ์ด์ง€๋งŒ ๋น„์•”ํ˜ธํ™”)
  • ์•”ํ˜ธํ™” ํ•„์š” ์‹œ: Direct Connect + Site-to-Site VPN ์กฐํ•ฉ โ†’ IPsec ์•”ํ˜ธํ™”

Direct Connect Gateway#

  • ์—ฌ๋Ÿฌ ๋ฆฌ์ „์˜ ์—ฌ๋Ÿฌ VPC์— Direct Connect๋ฅผ ์—ฐ๊ฒฐํ•  ๋•Œ ์‚ฌ์šฉ
  • ๋‹จ์ผ Direct Connect๋กœ ์—ฌ๋Ÿฌ ๋ฆฌ์ „์˜ VPC์— ์ ‘๊ทผ

Direct Connect ์ด์ค‘ํ™” (Resiliency)#

์ˆ˜์ค€๊ตฌ์„ฑ
High Resiliency์—ฌ๋Ÿฌ ์œ„์น˜(Location)์— ๊ฐ 1๊ฐœ DX ์—ฐ๊ฒฐ
Maximum Resiliency์—ฌ๋Ÿฌ ์œ„์น˜์—์„œ ๊ฐ๊ฐ ๋ณ„๋„ ๋””๋ฐ”์ด์Šค์— 2๊ฐœ ์ด์ƒ DX ์—ฐ๊ฒฐ

Direct Connect ์žฅ์•  ์‹œ Backup#

  • DX ์žฅ์•  ๋Œ€๋น„ Backup์œผ๋กœ Site-to-Site VPN ์—ฐ๊ฒฐ ์„ค์ • ๊ฐ€๋Šฅ

Transit Gateway#

  • ์ˆ˜์ฒœ ๊ฐœ์˜ VPC + On-premises๋ฅผ Hub-and-Spoke(Star) ๋ฐฉ์‹์œผ๋กœ ์—ฐ๊ฒฐ
  • VPC Peering์˜ Non-transitive ๋ฌธ์ œ ํ•ด๊ฒฐ (Transit GW๋Š” Transitive)
ํ•ญ๋ชฉ๋‚ด์šฉ
์—ฐ๊ฒฐ ๊ฐ€๋Šฅ ๋Œ€์ƒVPC, Direct Connect Gateway, VPN Connection (CGW)
๋ฒ”์œ„Regional Resource (ํฌ๋กœ์Šค ๋ฆฌ์ „ ์ง€์›, ๋ฆฌ์ „ ๊ฐ„ TGW Peering)
๊ณ„์ • ๊ณต์œ AWS Resource Access Manager (RAM) ์‚ฌ์šฉ
Route TablesVPC ๊ฐ„ ํ†ต์‹  ์ œ์–ด ๊ฐ€๋Šฅ
ํŠน์ด ๊ธฐ๋ŠฅIP Multicast ์ง€์› (๋‹ค๋ฅธ AWS ์„œ๋น„์Šค ๋ฏธ์ง€์›)

Transit Gateway โ€” ECMP (Equal-Cost Multi-Path)#

  • ECMP: ์—ฌ๋Ÿฌ ์ตœ์  ๊ฒฝ๋กœ๋กœ ํŒจํ‚ท ์ „๋‹ฌํ•˜๋Š” ๋ผ์šฐํŒ… ์ „๋žต
  • VPN โ†’ Transit Gateway ์—ฐ๊ฒฐ ์‹œ ์—ฌ๋Ÿฌ Site-to-Site VPN์œผ๋กœ ๋Œ€์—ญํญ ๋ฐฐ๊ฐ€ ๊ฐ€๋Šฅ
์—ฐ๊ฒฐ ๋ฐฉ์‹์ตœ๋Œ€ ์ฒ˜๋ฆฌ๋Ÿ‰
VPN โ†’ Virtual Private Gateway1.25 Gbps (2๊ฐœ ํ„ฐ๋„)
VPN โ†’ Transit Gateway (ECMP)2.5 Gbps (2 ํ„ฐ๋„ ์‚ฌ์šฉ) โ†’ VPN ์ถ”๊ฐ€๋กœ ๋ฐฐ๊ฐ€ ๊ฐ€๋Šฅ

๐Ÿ’ก Direct Connect๋ฅผ ์—ฌ๋Ÿฌ ๊ณ„์ •๊ณผ ๊ณต์œ ํ•  ๋•Œ๋„ Transit Gateway + RAM ์กฐํ•ฉ ์‚ฌ์šฉ


VPC Traffic Mirroring#

  • VPC ๋‚ด ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์„ ์บก์ฒ˜ํ•˜์—ฌ ๋ถ„์„
  • ์†Œ์Šค: ENI / ๋Œ€์ƒ: ENI ๋˜๋Š” NLB
  • ๊ฐ™์€ VPC ๋˜๋Š” VPC Peering๋œ ๋‹ค๋ฅธ VPC ๊ฐ„์—๋„ ๊ฐ€๋Šฅ
  • Use Cases: ์ฝ˜ํ…์ธ  ๊ฒ€์‚ฌ, ์œ„ํ˜‘ ๋ชจ๋‹ˆํ„ฐ๋ง, ๋„คํŠธ์›Œํฌ ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…

IPv6 & Egress-only Internet Gateway#

  • AWS์˜ ๋ชจ๋“  IPv6 ์ฃผ์†Œ๋Š” Public + ์ธํ„ฐ๋„ท ๋ผ์šฐํŒ… ๊ฐ€๋Šฅ (์‚ฌ์„ค IPv6 ๋ฒ”์œ„ ์—†์Œ)
  • VPC์—์„œ IPv4๋Š” ๋น„ํ™œ์„ฑํ™” ๋ถˆ๊ฐ€, IPv6๋Š” ์„ ํƒ์  ํ™œ์„ฑํ™” (Dual-Stack)
  • EC2๋Š” Private IPv4 + Public IPv6 ๋ชจ๋‘ ๊ฐ€์ง

Egress-only Internet Gateway:

  • IPv6 ์ „์šฉ NAT Gateway ์—ญํ• 
  • VPC ์ธ์Šคํ„ด์Šค์˜ IPv6 ์•„์›ƒ๋ฐ”์šด๋“œ ํ—ˆ์šฉ, ์ธํ„ฐ๋„ท์—์„œ์˜ IPv6 ์ธ๋ฐ”์šด๋“œ ์ฐจ๋‹จ
๋ฐฉํ–ฅIPv4IPv6
Private โ†’ InternetNAT GatewayEgress-only IGW
Internet โ†’ Private์ฐจ๋‹จ์ฐจ๋‹จ
NOTE

๐Ÿ“Œ EC2 ์ธ์Šคํ„ด์Šค ์‹œ์ž‘ ์‹คํŒจ ์‹œ โ€” IPv6 ์ฃผ์†Œ ๊ณต๊ฐ„์€ ๋งค์šฐ ๋„“์œผ๋ฏ€๋กœ ๊ณ ๊ฐˆ ์•„๋‹˜. IPv4 ์ฃผ์†Œ ๊ณ ๊ฐˆ์ด ์›์ธ โ†’ Subnet์— ์ƒˆ IPv4 CIDR ์ถ”๊ฐ€


AWS Network Firewall#

  • VPC ์ „์ฒด๋ฅผ Layer 3 ~ Layer 7๊นŒ์ง€ ๋ณดํ˜ธ
  • ๋‚ด๋ถ€์ ์œผ๋กœ AWS Gateway Load Balancer ์‚ฌ์šฉ
  • AWS Firewall Manager๋กœ Cross-Account ์ค‘์•™ ๊ด€๋ฆฌ

๊ฒ€์‚ฌ ๊ฐ€๋Šฅํ•œ ํŠธ๋ž˜ํ”ฝ:

  • VPC โ†” VPC
  • ์ธํ„ฐ๋„ท Inbound/Outbound
  • Direct Connect & Site-to-Site VPN

์„ธ๋ฐ€ํ•œ ์ œ์–ด (Fine-grained Controls):

  • IP/Port ๊ธฐ๋ฐ˜ ๊ทœ์น™
  • Protocol ๊ธฐ๋ฐ˜
  • Stateful Domain List: .mycorp.com ๋“ฑ ๋„๋ฉ”์ธ ํ—ˆ์šฉ/์ฐจ๋‹จ
  • Regex ํŒจํ„ด ๋งค์นญ
  • Active Flow Inspection (์นจ์ž… ๋ฐฉ์ง€, IPS ๊ธฐ๋Šฅ)
  • ๋กœ๊ทธ ์ „์†ก: S3, CloudWatch Logs, Kinesis Data Firehose

๋„คํŠธ์›Œํ‚น ๋น„์šฉ (Networking Costs)#

EC2 ์ธ์Šคํ„ด์Šค ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ๋น„์šฉ#

๊ฒฝ๋กœ๋น„์šฉ
EC2 ์ธ๋ฐ”์šด๋“œ ํŠธ๋ž˜ํ”ฝ๋ฌด๋ฃŒ
๊ฐ™์€ AZ ๋‚ด EC2 ๊ฐ„ (Private IP)๋ฌด๋ฃŒ
๋‹ค๋ฅธ AZ ๊ฐ„ EC2 (Public/Elastic IP)$0.02/GB
๋‹ค๋ฅธ AZ ๊ฐ„ EC2 (Private IP)$0.01/GB
๋ฆฌ์ „ ๊ฐ„ (Inter-Region)$0.02/GB

๐Ÿ’ก Private IP ์‚ฌ์šฉ ๊ถŒ์žฅ (Public IP ๋Œ€๋น„ ์ ˆ๋ฐ˜ ๋น„์šฉ + ๋” ๋‚˜์€ ์„ฑ๋Šฅ)

S3 ๋ฐ์ดํ„ฐ ์ „์†ก ๋น„์šฉ#

๊ฒฝ๋กœ๋น„์šฉ
S3 Ingress (์—…๋กœ๋“œ)๋ฌด๋ฃŒ
S3 โ†’ ์ธํ„ฐ๋„ท$0.09/GB
S3 Transfer Acceleration+0.04ย 0.04 ~ 0.08/GB
S3 โ†’ CloudFront๋ฌด๋ฃŒ
CloudFront โ†’ ์ธํ„ฐ๋„ท$0.085/GB (S3 ์ง์ ‘๋ณด๋‹ค ์ €๋ ด + ์บ์‹ฑ)
S3 Cross-Region Replication$0.02/GB

NAT Gateway vs. Gateway VPC Endpoint (S3 ์ ‘๊ทผ ๋น„์šฉ)#

๋ฐฉ๋ฒ•๋น„์šฉ
NAT Gateway โ†’ IGW โ†’ S3NAT GW ์‹œ๊ฐ„๋‹น 0.045+์ฒ˜๋ฆฌGB๋‹น0.045 + ์ฒ˜๋ฆฌ GB๋‹น 0.045 + S3 ๋ฐ์ดํ„ฐ ์ „์†ก
Gateway VPC Endpoint โ†’ S3Gateway Endpoint ์‚ฌ์šฉ ๋ฌด๋ฃŒ ($0.01 In/Out ๋™์ผ ๋ฆฌ์ „)

โœ… Private Subnet์—์„œ S3 ์ ‘๊ทผ ์‹œ Gateway VPC Endpoint๊ฐ€ ํ›จ์”ฌ ์ €๋ ด


AWS ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ๊ณ„์ธต#

L3-4 ๋„คํŠธ์›Œํฌ ๋ณดํ˜ธ: NACLs, Security Groups
L3-7 ์™„์ „ ๋ณดํ˜ธ: AWS Network Firewall (Gateway LB ๋‚ด๋ถ€ ์‚ฌ์šฉ)
DDoS ๋ณดํ˜ธ: AWS Shield (Standard/Advanced)
์•…์„ฑ HTTP ์š”์ฒญ ์ฐจ๋‹จ: AWS WAF
๋ฉ€ํ‹ฐ ๊ณ„์ • ๊ด€๋ฆฌ: AWS Firewall Manager

VPC ์ „์ฒด ์š”์•ฝ#

CIDR : IP ๋ฒ”์œ„ ์ •์˜
VPC : ๋ฆฌ์ „ ๋‚ด ๊ฒฉ๋ฆฌ๋œ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ (์ตœ๋Œ€ 5๊ฐœ/๋ฆฌ์ „)
Subnet : AZ์— ์ข…์†๋œ IP ๋ฒ”์œ„ (5๊ฐœ IP AWS ์˜ˆ์•ฝ)
IGW : VPC โ†’ Internet (Route Table ์ˆ˜์ • ํ•„์š”)
Bastion Host : Public EC2 โ†’ Private EC2 SSH Jump ์„œ๋ฒ„
NAT Instance : ๊ตฌ์‹, Source/Dest Check ๋น„ํ™œ์„ฑํ™” ํ•„์š”
NAT Gateway : AWS ๊ด€๋ฆฌํ˜•, Private โ†’ Internet (IPv4)
NACL : Stateless, Subnet ๋ ˆ๋ฒจ, Allow + Deny
Security Group : Stateful, EC2 ๋ ˆ๋ฒจ, Allow๋งŒ
VPC Peering : Non-transitive, CIDR ๋น„์ค‘๋ณต ํ•„์ˆ˜, Route Table ์—…๋ฐ์ดํŠธ
VPC Endpoints : Gateway(S3/DynamoDB, ๋ฌด๋ฃŒ) / Interface(PrivateLink, ์œ ๋ฃŒ)
VPC Flow Logs : IP ํŠธ๋ž˜ํ”ฝ ์บก์ฒ˜ โ†’ S3/CloudWatch/Firehose
Site-to-Site VPN : VGW + CGW, ๊ณต์šฉ ์ธํ„ฐ๋„ท ๊ฒฝ์œ  ์•”ํ˜ธํ™”
VPN CloudHub : Hub-and-Spoke ๋‹ค์ค‘ Site VPN
Direct Connect : ์ „์šฉ ๋ฌผ๋ฆฌ ์—ฐ๊ฒฐ (Private, ์•”ํ˜ธํ™” ์—†์Œ)
DX Gateway : ๋‹จ์ผ DX๋กœ ์—ฌ๋Ÿฌ ๋ฆฌ์ „ VPC ์ ‘๊ทผ
Transit Gateway : ์ˆ˜์ฒœ VPC/VPN/DX Hub-and-Spoke, IP Multicast
Traffic Mirroring : ENI ํŠธ๋ž˜ํ”ฝ ์บก์ฒ˜ ๋ถ„์„
Egress-only IGW : IPv6 ์ „์šฉ NAT GW
Network Firewall : L3-7 ์™„์ „ VPC ๋ณดํ˜ธ

๐Ÿ“Œ ์‹œํ—˜ ์ž์ฃผ ์ถœ์ œ ํฌ์ธํŠธ#

ํฌ์ธํŠธ๋‚ด์šฉ
Subnet ์˜ˆ์•ฝ IP5๊ฐœ (์ฒซ 4๊ฐœ + ๋งˆ์ง€๋ง‰ 1๊ฐœ)
VPC๋‹น ์ตœ๋Œ€ CIDR5๊ฐœ
CIDR ์ตœ์†Œ/์ตœ๋Œ€/28 (16๊ฐœ) ~ /16 (65,536๊ฐœ)
IGW๋งŒ์œผ๋กœ ์ธํ„ฐ๋„ท ์ ‘๊ทผRoute Table ์ˆ˜์ • ํ•„์š”
NAT Instance Source/Dest Check๋ฐ˜๋“œ์‹œ ๋น„ํ™œ์„ฑํ™”
NAT GW ์ตœ๋Œ€ ๋Œ€์—ญํญ100 Gbps (์ž๋™ ํ™•์žฅ)
NAT GW Security Group์—†์Œ (๋ถˆํ•„์š”)
NAT GW Multi-AZ HAAZ๋งˆ๋‹ค ๋ณ„๋„ NAT GW ์ƒ์„ฑ
NACL vs SG ์ƒํƒœNACL: Stateless / SG: Stateful
NACL ๊ทœ์น™ ํ‰๊ฐ€๋‚ฎ์€ ๋ฒˆํ˜ธ๋ถ€ํ„ฐ ์ˆœ์„œ๋Œ€๋กœ, ์ฒซ ๋งค์นญ ์ ์šฉ
Default NACL๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ (์ˆ˜์ • ๊ธˆ์ง€)
ํŠน์ • IP ์ฐจ๋‹จNACL์˜ Deny ๊ทœ์น™ ์‚ฌ์šฉ (SG๋Š” Deny ๋ถˆ๊ฐ€)
VPC Peering Transitive์—†์Œ โ†’ ๊ฐ VPC ์Œ๋งˆ๋‹ค ๋ณ„๋„ Peering
Gateway Endpoint ๋Œ€์ƒS3, DynamoDB๋งŒ
Gateway Endpoint ๋น„์šฉ๋ฌด๋ฃŒ
Interface Endpoint + On-premisesSite-to-Site VPN/DX ๊ฒฝ์œ  ์ ‘๊ทผ ์‹œ Interface Endpoint
Direct Connect ์•”ํ˜ธํ™”๊ธฐ๋ณธ ์—†์Œ โ†’ DX + VPN์œผ๋กœ IPsec ์ถ”๊ฐ€
Direct Connect ์—ฐ๊ฒฐ ๋ฆฌ๋“œ ํƒ€์ž„1๊ฐœ์›” ์ด์ƒ
DX Gateway๋‹จ์ผ DX๋กœ ์—ฌ๋Ÿฌ ๋ฆฌ์ „ VPC ์ ‘๊ทผ
Transit Gateway ํŠน์ด์ IP Multicast ์ง€์› (AWS ์œ ์ผ)
Transit GW ๊ณ„์ • ๊ณต์œ AWS Resource Access Manager (RAM)
VPN โ†’ TGW ๋Œ€์—ญํญ2.5 Gbps (ECMP), VPN ์ถ”๊ฐ€ ์‹œ ๋ฐฐ๊ฐ€ ๊ฐ€๋Šฅ
VPN โ†’ VGW ๋Œ€์—ญํญ1.25 Gbps
EC2 ์‹œ์ž‘ ์‹คํŒจ ์ด์œ IPv6 ์ฃผ์†Œ ๊ณ ๊ฐˆ ์•„๋‹˜ โ†’ IPv4 ์ฃผ์†Œ ๊ณ ๊ฐˆ
Egress-only IGW ๋Œ€์ƒIPv6 ์•„์›ƒ๋ฐ”์šด๋“œ๋งŒ
Private โ†’ S3 ์ตœ์ € ๋น„์šฉGateway VPC Endpoint (๋ฌด๋ฃŒ)
Flow Log Action REJECT (Inbound)NACL ๋˜๋Š” SG ์ฐจ๋‹จ
Flow Log Action ACCEPT+REJECTNACL (Stateless) ์ฐจ๋‹จ

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ#