Amazon Web Services ããã°
Amazon VPC Block Public Access ã«ãã VPC ã»ãã¥ãªãã£ã®åŒ·å
åœåãã客æ§ã«å¿ èŠãª Amazon Virtual Private Cloud (Amazon VPC) ã¯1ã€ã ãã ãšèããŠããŸããããå€ãã®ããšãåŠãã§ããã仿¥ãAWS Well-Architected Frameworkã§ã¯ãåäžã® VPC ãæã€åäžã®ã¢ã«ãŠã³ããã¢ã³ããã¿ãŒã³ãšããŠèšè¿°ããŠããŸããAWS ã¯ã©ãŠãå ã®ã¢ã«ãŠã³ããšãããã¯ãŒã¯ãã¹ã®æ°ãå¢å ããã«ã€ããã客æ§ãããŒãããŒã®çæ§ãããå€§èŠæš¡ãªã¯ã©ãŠãç°å¢ãçè§£ããã»ãã¥ãªãã£ã確ä¿ããããã«åœ¹ç«ã€ã·ã³ãã«ãªããŒã«ã欲ãããšããèŠæããããŸããã
AWSã¯ãã客æ§ãçºèŠççµ±å¶ãäºé²çã³ã³ãããŒã«ãããã¢ã¯ãã£ãã³ã³ãããŒã«ãããã³ã¬ã¹ãã³ã·ãã³ã³ãããŒã«ã®å®è£ ãå¯èœã«ãããµãŒãã¹ãæ©èœãæäŸããŠããŸããäŸãã°ãèªåæšè«ãšèšŒæå¯èœã»ãã¥ãªãã£ãžã®æè³ã«ããããããªãã¯ã«å ¬éããã Amazon Simple Storage Service (Amazon S3) ãã±ãããæ€åºããåçŽãªãã¹ã誀解ããçããäºæãã¬ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãç¹å®ããããšãå¯èœãšãªããŸãããå€§èŠæš¡ãªäºé²çã³ã³ãããŒã«ã®ããã«ãAmazon S3 ãããã¯ãããªãã¯ã¢ã¯ã»ã¹ã®ãããªæ©èœãæäŸããS3 ãªããžã§ã¯ãããã©ã€ããŒãã§ããããšãç°¡åã«ä¿èšŒã§ããããã«ããŠããŸãã
Amazon VPC ã«å¯Ÿãã Block Public Access ã®å®è£
2024幎11æ19æ¥ã«ãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹å¶åŸ¡ãç°¡çŽ åãã匷åãªæ°æ©èœãçºè¡šã§ããããšãå¬ããæããŸããAmazon VPC Block Public Access ã¯ãAWS ãæäŸããã€ã³ã¿ãŒãããçµè·¯ãéããŠå ¥ã£ãŠãã (ã€ã³ããŠã³ã) ããã³åºãŠãã (ã¢ãŠãããŠã³ã) VPC ãã©ãã£ãã¯ã確å®ã«ãããã¯ããã·ã³ãã«ã§å®£èšçãªå¶åŸ¡æ©èœã§ããAmazon VPC Block Public Access ã«ããã VPC å ã®ãªãœãŒã¹ã«å¯Ÿãã AWS æäŸã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãäžå çã«ãããã¯ããããšã§ãã客æ§ã¯çµç¹ã®ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãžã®æºæ ã確ä¿ã§ããŸããåæ¹åãããã¯ã«èšå®ãããšãå šãŠã®ã€ã³ããŠã³ãããã³ã¢ãŠãããŠã³ã VPC ãã©ãã£ãã¯ãæåŠãããŸããAmazon VPC Block Public Access ã¯ãInternet Gateway (IGW) ã Egress-Only Internet Gateway (EIGW) ãªã©ã®çµè·¯ãéããŠã€ã³ã¿ãŒãããã«å ¬éãããå šãŠã®ãã©ãã£ãã¯ã鮿ããããã«ãæ¢åã® VPC èšå®ãããåªå ãããŸãã
ããããVPC ããã®ãã©ãã£ãã¯ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããå¿ èŠãããå Žåã¯ã©ãã§ãããã?
NAT Gateway ãš EIGW ã¯äžè¬çã«ãVPC å ã®ãªãœãŒã¹ã«ã€ã³ããŠã³ãã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ã«ãããããšãªããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæäŸããããã«äœ¿çšãããŠããŸããã客æ§ãããAmazon VPC Block Public Access ã䜿çšããéã«ããã®ãããªäžè¬çãªã¢ãŒããã¯ãã£ããµããŒãããã·ã³ãã«ã§ä¿¡é Œæ§ã®é«ãäžè²«ããã¢ãããŒããæ±ããããŠããŸãããåæ¹åãããã¯ã®ä»£æ¿ãšããŠãAmazon VPC Block Public Access ã¯ãããã®ãŠãŒã¹ã±ãŒã¹ã«å¯ŸããŠã€ã³ã°ã¬ã¹æ¹åã®ã¿ã®ãããã¯ããµããŒãããŠããŸããã€ã³ã°ã¬ã¹æ¹åã®ã¿ã®ãããã¯ã§ã¯ãã€ã³ã¿ãŒãããããã®ã€ã³ããŠã³ããã©ãã£ãã¯ã確å®ã«ãããã¯ãããVPC ããã®ã¢ãŠãããŠã³ããã©ãã£ãã¯ã¯ NAT Gateway ãš EIGW ãéããŠã®ã¿èš±å¯ãããŸãã
Amazon VPC Block Public Access ã¯ãAWS ã¢ã«ãŠã³ãå ããªãŒãžã§ã³åäœã§æå¹ã«ã§ããè¿æ¥äžã« AWS Organizations ã®ãµããŒããäºå®ãããŠããŸãã
é€å€ã«ãããã现ãããªå¶åŸ¡
VPC å ã®äžéšãªãœãŒã¹ã§ã¯ãåæ¹åã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãå¿ èŠã«ãªãå Žåãããããšãçè§£ããŠããŸãããããã¯ãAmazon VPC Block Public Access ã®åæ¹åãããã¯ãŸãã¯ã€ã³ã°ã¬ã¹æ¹åã®ã¿ã®ãããã¯ã§ã¯æåŠããããããªããšã°ã¬ã¹æ¹åã®ã¿ã®ã€ã³ã¿ãŒããããã¹ãå¿ èŠã«ãªããšãã£ãéäžåã®ãã©ãã£ãã¯æ€æ»ã®ãããªãŠãŒã¹ã±ãŒã¹ããããŸãããã®èŠä»¶ã«å¯Ÿå¿ããããã«ãAmazon VPC Block Public Access ã«ã¯çްããªé€å€æ©èœãå«ãŸããŠããŸãã管çè ã¯ãAmazon VPC Block Public Access ã®é©çšããé€å€ãã VPC ãŸãã¯ãµãããããåå¥ã«æå®ã§ããå¿ èŠã«å¿ããŠã¿ãŒã²ãããçµã£ãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãèš±å¯ã§ããŸãã
ãããã®é€å€ãèšå®ããããšã§ãå šãŠ (åæ¹å) ãŸãã¯ã¢ãŠãããŠã³ã (ãšã°ã¬ã¹æ¹åã®ã¿) ã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãèš±å¯ã§ããŸããã€ã³ã°ã¬ã¹æ¹åã®ã¿ã®ãããã¯ãšåæ§ã«ããšã°ã¬ã¹æ¹åã®ã¿ã®é€å€ãèš±å¯ãããšãVPC ãŸãã¯ãµããããããã®ãšã°ã¬ã¹ãã©ãã£ãã¯ã¯ NAT Gateway ãš EIGW ãéããŠã®ã¿èš±å¯ãããŸãã
Amazon VPC Block Public Access ã®åäœæ¹æ³ãšäž»èŠæ©èœã«ã€ããŠãããæ·±ãæãäžããŠãããŸãã
Amazon VPC Block Public Access ãçè§£ãã
Amazon VPC Block Public Access ã宿Œããããã«ãã·ã³ãã«ãªãã¥ã¢ã«ã¹ã¿ã㯠(IPv4ãšIPv6) ã® VPC ã¢ãŒããã¯ãã£ãäœæããŸããã2ã€ã®ãããªãã¯ãµããããã2ã€ã®ãã©ã€ããŒããµããããã2ã€ã® NAT GatewayãEIGWãIGW ããããŸãããããªãã¯ãµããããã«ã¯ãIGW ãžã®ããã©ã«ãã«ãŒãããããŸãããã©ã€ããŒããµããããã«ã¯ãåãã¢ãã€ã©ããªãã£ãŒãŸãŒã³å ã® NAT Gateway ãžã® IPv4 ããã©ã«ãã«ãŒããšãEIGW ãžã® IPv6 ããã©ã«ãã«ãŒãããããŸãããããªãã¯ãµããããã«ã¯ãHTTP ãåãä»ããã€ã³ã¿ãŒãããåã Application Load Balancer (ALB) ããããã€ããŸãããALB ã¯ã€ã³ã¿ãŒãããããã®ã€ã³ããŠã³ããã©ãã£ãã¯ããã©ã€ããŒããµããããå ã® Web ãµãŒããŒã«æž¡ããŸãã
Amazon VPC Block Public Access ãæå¹ã«ããåã¯ãALB ãéããŠã€ã³ã¿ãŒããããã Web ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããŸãããŸããWeb ãµãŒããŒã«ãã°ã€ã³ããŠããéãIPv4 çšã® NAT Gateway ãšIPv6 çšã® EIGW ãéããŠã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããAWS ããŒã ããŒãžã« ping ãå®è¡ããããšãã§ããŸãã
Amazon VPC Block Public Access ãèšå®ããŠããããªãã¯ãµããããã®ã¿ãšã®åæ¹åã®å šãã©ãã£ãã¯ãèš±å¯ããããšæããŸããããããAmazon VPC Block Public Access ã®æå¹ååŸã«ãWeb ãµã€ããå©çšã§ããªããªãããšã¯é¿ãããã§ãããã®ãããAmazon VPC Block Public Access ãæå¹åããåã«ããããã®ãµããããã«å¯Ÿããé€å€èšå®ãè¡ããŸãã
VPC ã³ã³ãœãŒã«ã«ç§»åããæ¬¡ã®ããšãè¡ããŸãã
- èšå®ãéžæããŸãã
- 次ã«ããããªãã¯ã¢ã¯ã»ã¹ããããã¯ã¿ããéžæããŸãã
次ã«ã以äžãè¡ããŸãã
- é€å€ãäœæãã¯ãªãã¯ãã2ã€ã®ãããªãã¯ãµãããããå šãŠã®ã€ã³ã¿ãŒããããã©ãã£ã㯠(åæ¹åéä¿¡) ãèš±å¯ããããã«æå®ããŠãã ããã
- 次ã«ãé€å€ãäœæãã¯ãªãã¯ããŸãã
æ°ååŸãé€å€ã Active ã«ãªããŸãã
ããŠãAmazon VPC Block Public Access ãæå¹åããæºåãã§ããŸããããã®æ©èœãæå¹ã«ããéã«äœãèµ·ããã®ãã確å®ã«çè§£ããŠãããããšæããŸããNetwork Access Scope ãäœæãã¯ãªãã¯ããNetwork Access Analyzer ã䜿çšããŠãçŸåšèš±å¯ãããŠãã AWS æäŸã®ã€ã³ã¿ãŒããããã¹ãç¹å®ããŸãã2 ã€ã®é€å€æ¡ä»¶ã䜿çšããŠããããªãã¯ãµãããããã€ã³ã¿ãŒããããã©ãã£ãã¯ã®éä¿¡å ãŸãã¯å®å ãšããŠãã£ã«ã¿ãªã³ã°ããŸãããããã®ãµãããããžã®ãã©ãã£ãã¯ã¯ãé€å€ã«ãã£ãŠèš±å¯ãããŠããããšãããããŸãã
åæã«ãããšãWeb ãµãŒããŒã§ã¯ ALB ãä»ããã€ã³ã¿ãŒããããã©ãã£ãã¯ã®åãå ¥ããå¿çãèš±å¯ãããŠããããŸããNAT Gateway ãä»ããŠã¢ãŠãããŠã³ã (ãšã°ã¬ã¹) ã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ãéå§ããããšãã§ããŸãããã©ã€ããŒããµããããã«ã¯ EIGW ãžã® IPv6 ããã©ã«ãã«ãŒããããããšãããã©ã€ããŒããµããããã«å¯Ÿã㊠Amazon VPC Block Public Access ã®é€å€ãè¡ã£ãŠããªãããšãæãåºããŠãã ããããã®çµæãAmazon VPC Block Public Access ãWeb ãµãŒããŒããã®ãšã°ã¬ã¹ IPv6 ãã©ãã£ãã¯ãæåŠãããšäºæ³ãããŸãã
ãããªãã¯ã¢ã¯ã»ã¹ããããã¯ã®ã¿ãã«æ»ãã以äžãè¡ããŸãã
- ãããªãã¯ã¢ã¯ã»ã¹èšå®ãç·šéãã¯ãªãã¯ããŸãã
- [ãããªãã¯ã¢ã¯ã»ã¹ããããã¯ãã]ããªã³ã«ããã®ããã¯ã¹ããã§ãã¯ãããã¹ãŠã®ã€ã³ã¿ãŒããããã©ãã£ã㯠(åæ¹å) ããããã¯ããåäœãèšå®ããŸãã
- 倿Žãä¿åãã¯ãªãã¯ããŸãã
æ°ååŸããããªãã¯ã¢ã¯ã»ã¹èšå®ã®ã¹ããŒã¿ã¹ããªã³ãšè¡šç€ºãããŸãã
確èªã®ãããã€ã³ã¿ãŒããããã ALB ãéã㊠Web ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ãããã©ããã確èªããŸããâHello, World!â ããŒãžãæ£åžžã«è¡šç€ºãããŸãããWeb ãµãŒããŒã«æ»ããšãNetwork Access Analyzer ã®çµæã§ç¢ºèªããããã«ãNAT Gateway ãš IGW ãä»ã㊠IPv4 ã§ AWS ããŒã ããŒãžã« ping ãéãããšãã§ããŸããäºæ³éããIPv6 ã§ã¯ AWS ããŒã ããŒãžã« ping ãéãããšã¯ã§ããŸããã
å³10. IPv4ã§ã®ã¢ãŠãããŠã³ãã® ping ã¯æåããIPv6 ã§ã®ã¢ãŠãããŠã³ãã® ping ã¯å€±æ
ãã©ã€ããŒããµããããã§æå¹åãããŠãã VPCãããŒãã° ãèŠããšãIPv6 ãã©ãã£ãã¯ãæåŠãããŠããã®ãåãããŸããæåã®è¡ (ACCEPT) ã¯ããã±ããããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹ã®ã»ãã¥ãªãã£ã°ã«ãŒããšãµããããã®ãããã¯ãŒã¯ ACL ã«ãã£ãŠèš±å¯ãããããšã瀺ããŠããŸããããããAmazon VPC Block Public Access ããã©ãã£ãã¯ããããã¯ããŠããŸã (REJECT)ãVPC ãããŒãã°ã§ã«ã¹ã¿ã ãã©ãŒããããèšå®ããŠããã°ãreject-reason ãã£ãŒã«ããå«ããããšãã§ãããã©ãã£ãã¯ããããã¯ããçç±ã BPA ã§ããããšã衚瀺ãããã¯ãã§ãã
ãã©ã€ããŒããµããããããã® EIGW ãä»ãã IPv6 ã¢ãŠãããŠã³ããã©ãã£ãã¯ãæå¹ã«ããããã«ãæ°ããé€å€ã远å ããŸãããã®é€å€ã¯ãEIGW ãééãããã©ãã£ãã¯ãæµããæ¹åã«äžèŽããããšã°ã¬ã¹æ¹åã®ã¿ã§ãã
æ°ååŸãé€å€ã Active ã«ãªããŸããWeb ãµãŒããŒã«æ»ããšãEIGW ãä»ã㊠IPv6 çµç±ã§ AWS ããŒã ããŒãžã«åã³ ping ãéãããšãã§ããŸãã
æåŸã®æäœãšããŠããã¹ãŠã®é€å€ãåé€ããŸããé€å€ããªãç¶æ ã§ã¯ããã® VPC ã®ãã¹ãŠã®ã€ã³ã¿ãŒããããã©ãã£ãã¯ããããã¯ãããŸãã
äºæ³éããALB ã«ã¯ã¢ã¯ã»ã¹ã§ããªããªããWeb ãµãŒããŒããã®ã¢ãŠãããŠã³ããã©ãã£ãã¯ãéå§ã§ããªããªããŸããã
å³15. ãã©ãŠã¶ãŠã£ã³ããŠã« âæ¥ç¶ãã¿ã€ã ã¢ãŠãããŸããâ ãšè¡šç€ºãããŠãã
ãããªãã¯ã¢ã¯ã»ã¹ããããã¯ã®ã¿ãã«æ»ãããããªãã¯ã¢ã¯ã»ã¹èšå®ãç·šéãã¯ãªãã¯ããŸãã[ãããªãã¯ã¢ã¯ã»ã¹ããããã¯ãã]ããªã³ã«ããã®ãããã¯ã®ãã§ãã¯ãå€ãã倿Žãä¿åãã¯ãªãã¯ããŸããæ°ååŸããããªãã¯ã¢ã¯ã»ã¹èšå®ã®ã¹ããŒã¿ã¹ããªããšè¡šç€ºãããŸããåã³ ALB ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããIPv4 ãš IPv6 ã䜿çšã㊠AWS ããŒã ããŒãžã« ping ãéãããšãã§ããããã«ãªããŸãã
ç¥ã£ãŠããã¹ããã€ã³ã
- Amazon VPC Block Public Access ã¯ãã€ã³ã°ã¬ã¹æ¹åã®ã¿ã®ãããã¯ããŸãã¯ãšã°ã¬ã¹æ¹åã®ã¿ã®é€å€ãèš±å¯ããå Žåãã¹ããŒããã«ã§ããèš±å¯ãããæ¥ç¶ã®æ»ãã®ãã©ãã£ãã¯ã¯èªåçã«èš±å¯ãããŸãããã®åäœã¯ã»ãã¥ãªãã£ã°ã«ãŒããšé¡äŒŒããŠããŸãã
- æå¹ã«ãããšãAmazon VPC Block Public Access ã¯æ°èŠããã³æ¢åã®ãããã¯ãŒã¯æ¥ç¶ã«åœ±é¿ããŸãã
- Amazon VPC Block Public Accessã«ã¯ãããã©ã«ãã§50åã®é€å€ãŸã§ãšãã£ãã¯ã©ãŒã¿ããããŸããã¯ã©ãŒã¿ã®åŒãäžãã¯å¯èœã§ãã
- ã€ã³ã°ã¬ã¹æ¹åã®ã¿ã®ãããã¯ãæå¹ã«ãªã£ãŠãããããšã°ã¬ã¹æ¹åã®ã¿ã®é€å€ãèš±å¯ãããŠããå ŽåãNAT Gateway ãš EIGW ã®ã¿ã VPC ããåºãããšãèš±å¯ããŸãã
- Amazon VPC Block Public Access ã¯ãElastic Load Balancing ã AWS Global Accelerator ãªã©ã®ä»ã®ãµãŒãã¹ãšçµ±åãããŠããŸãã
- AWS Client VPN ãšAWS Site-to-Site VPN ã¯å®å šãªéä¿¡ãšã¿ãªãããŠããããAmazon VPC Block Public Access ããé€å€ãããŠããŸãã
çµè«
æ¬çš¿ã§ã¯ãã客æ§ã VPC ã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ã管çããããã®å®£èšçãªã³ã³ãããŒã«ãæ±ããŠããããšã«ã€ããŠè°è«ããŸãããAmazon VPC Block Public Access ã䜿çšããããšã§ãã客æ§ã¯ã©ã® VPC ããµããããã Amazon ãæäŸããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ãããã管çããããšãã§ããŸããããã«ãããVPC å ã®ãªãœãŒã¹ãžã® AWS æäŸã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãäžå çã«ãããã¯ããããšã§ãçµç¹ã®ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãžã®æºæ ã確ä¿ã§ããŸããNetwork Access Analyzer ãš VPC ãããŒãã°ã掻çšããŠãã©ãã£ãã¯ãã¿ãŒã³ãçè§£ããAmazon VPC Block Public Access ãæå¹ã«ããããšã§ãä»ããå§ããããšãã§ããŸãã詳现ã«ã€ããŠã¯ãAmazon VPC Block Public Access ã®ããã¥ã¡ã³ããã芧ãã ããã
æ¬çš¿ã¯ã2024幎11æ19æ¥ã« Networking & Content Delivery ã§å ¬éããã âEnhancing VPC Security with Amazon VPC Block Public Accessâ ã翻蚳ãããã®ã§ãã翻蚳㯠Solutions Architect ã®æŠæŸãæ åœããŸããã

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.













