å°ãäŒæ©ããåŸãNSXã«æ»ããŸãã ä»åã¯NATãšãã¡ã€ã¢ãŠã©ãŒã«ã®èšå®æ¹æ³ã玹ä»ããŸãã
ã¿ãå
管çéšé ä»®æ³ããŒã¿ã»ã³ã¿ãŒã«ç§»åããŸã â ã¯ã©ãŠã ãªãœãŒã¹ â ä»®æ³ããŒã¿ã»ã³ã¿ãŒ.
ã¿ããéžæããŸã ãšããžã²ãŒããŠã§ã€ ãã¯ãªãã¯ããç®çã® NSX Edge ãå³ã¯ãªãã¯ããŸãã 衚瀺ãããã¡ãã¥ãŒã§ãªãã·ã§ã³ãéžæããŸã ãšããžã²ãŒããŠã§ã€ãµãŒãã¹ã NSX Edge ã³ã³ãããŒã« ããã«ãå¥ã®ã¿ãã§éããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®èšå®
ããã©ã«ãã§ã¯é ç®å ã«ãããŸã ã€ã³ã°ã¬ã¹ãã©ãã£ãã¯ã®ããã©ã«ãã«ãŒã« [æåŠ] ãªãã·ã§ã³ãéžæãããŠããŸããã€ãŸãããã¡ã€ã¢ãŠã©ãŒã«ã¯ãã¹ãŠã®ãã©ãã£ãã¯ããããã¯ããŸãã
æ°ããã«ãŒã«ãè¿œå ããã«ã¯ã+ ãã¯ãªãã¯ããŸãã æ°ãããšã³ããªã次ã®ååã§è¡šç€ºãããŸãã æ°ããã«ãŒã«ã èŠä»¶ã«å¿ããŠãã£ãŒã«ããç·šéããŸãã
ãã£ãŒã«ã㧠åå ã«ãŒã«ã«ã€ã³ã¿ãŒããããªã©ã®ååãä»ããŸãã
ãã£ãŒã«ã㧠ãœãŒã¹ å¿
èŠãªéä¿¡å
ã¢ãã¬ã¹ãå
¥åããŸãã [IP] ãã¿ã³ã䜿çšãããšãåäžã® IP ã¢ãã¬ã¹ãIP ã¢ãã¬ã¹ã®ç¯å²ãCIDR ãèšå®ã§ããŸãã
+ ãã¿ã³ã䜿çšãããšãä»ã®ãªããžã§ã¯ããæå®ã§ããŸãã
- ã²ãŒããŠã§ã€ã€ã³ã¿ãŒãã§ã€ã¹ã ãã¹ãŠã®å éšãããã¯ãŒã¯ (å éš)ããã¹ãŠã®å€éšãããã¯ãŒã¯ (å€éš)ããŸã㯠[ä»»æ]ã
- ä»®æ³ãã·ã³ã ã«ãŒã«ãç¹å®ã®ä»®æ³ãã·ã³ã«ãã€ã³ãããŸãã
- OrgVdcãããã¯ãŒã¯ã çµç¹ã¬ãã«ã®ãããã¯ãŒã¯ã
- IP ã»ããã äºåã«äœæããã IP ã¢ãã¬ã¹ã®ãŠãŒã¶ãŒ ã°ã«ãŒã (ã°ã«ãŒãåãªããžã§ã¯ãã§äœæ)ã
ãã£ãŒã«ã㧠éå¬å Žæ åä¿¡è
ã®ã¢ãã¬ã¹ã瀺ããŸãã ããã§ã®ãªãã·ã§ã³ã¯ãããœãŒã¹ããã£ãŒã«ãã®ãªãã·ã§ã³ãšåãã§ãã
ãã£ãŒã«ã㧠ã«ã¹ã¿ããŒãµãŒãã¹ å®å
ããŒã (Destination Port)ãå¿
èŠãªãããã³ã« (Protocol)ãããã³éä¿¡åŽããŒã (Source Port) ãéžæãŸãã¯æåã§æå®ã§ããŸãã ãä¿æããã¯ãªãã¯ããŸãã
ãã£ãŒã«ã㧠Action å¿
èŠãªã¢ã¯ã·ã§ã³ãéžæããŸãããã®ã«ãŒã«ã«äžèŽãããã©ãã£ãã¯ãèš±å¯ãŸãã¯æåŠããŸãã
ãéžæããŠãå
¥åããæ§æãé©çšããŸãã å€æŽãä¿åããŸã.
ã«ãŒã«ã®äŸ
ãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã« 1 (ã€ã³ã¿ãŒããã) IP 192.168.1.10 ãæã€ãµãŒããŒãžã®ä»»æã®ãããã³ã«ãä»ããã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã« 2 (Web ãµãŒããŒ) å€éšã¢ãã¬ã¹ãä»ã㊠(TCP ãããã³ã«ãããŒã 80) çµç±ã§ã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ããããã«ããŸãã ãã®å Žå - 185.148.83.16:80ã
NATèšå®
NATïŒãããã¯ãŒã¯ã¢ãã¬ã¹å€æïŒ â ãã©ã€ããŒã (ã°ã¬ãŒ) IP ã¢ãã¬ã¹ããå€éš (çœ) IP ã¢ãã¬ã¹ãžã®å€æããŸãã¯ãã®éã®å€æã ãã®ããã»ã¹ãéããŠãä»®æ³ãã·ã³ã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã ãã®ã¡ã«ããºã ãæ§æããã«ã¯ãSNAT ã«ãŒã«ãš DNAT ã«ãŒã«ãæ§æããå¿
èŠããããŸãã
éèŠïŒ NAT ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãæå¹ã§ãé©åãªèš±å¯ã«ãŒã«ãèšå®ãããŠããå Žåã«ã®ã¿æ©èœããŸãã
SNAT ã«ãŒã«ãäœæããŸãã SNAT (Source Network Address Translation) ã¯ããã±ããéä¿¡æã«éä¿¡å ã¢ãã¬ã¹ã眮ãæããã¡ã«ããºã ã§ãã
ãŸãã䜿çšå¯èœãªå€éš IP ã¢ãã¬ã¹ãŸã㯠IP ã¢ãã¬ã¹ã®ç¯å²ã確èªããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãã»ã¯ã·ã§ã³ã«ç§»åããŠãã ãã 管çéšé ä»®æ³ããŒã¿ã»ã³ã¿ãŒãããã«ã¯ãªãã¯ããŸãã 衚瀺ãããèšå®ã¡ãã¥ãŒã§ãã¿ãã«ç§»åããŸã ãšããžã²ãŒããŠã§ã€s. ç®çã® NSX Edge ãéžæããå³ã¯ãªãã¯ããŸãã éžæè¢äžã€ãéžæããŠãã ãã ããããã£.
衚瀺ããããŠã£ã³ããŠã®ã¿ã㧠IP ããŒã«ã®ãµãå²ãåœãŠ å€éš IP ã¢ãã¬ã¹ãŸã㯠IP ã¢ãã¬ã¹ã®ç¯å²ã衚瀺ã§ããŸãã æžãçããããèŠããŠãããŠãã ããã
次ã«ãNSX Edge ãå³ã¯ãªãã¯ããŸãã 衚瀺ãããã¡ãã¥ãŒã§ãªãã·ã§ã³ãéžæããŸã ãšããžã²ãŒããŠã§ã€ãµãŒãã¹ã ãããŠãNSX Edge ã³ã³ãããŒã« ããã«ã«æ»ããŸããã
衚瀺ããããŠã£ã³ããŠã§ã[NAT] ã¿ããéãã[SNAT ã®è¿œå ] ãã¯ãªãã¯ããŸãã
æ°ãããŠã£ã³ããŠã§ã¯ã次ã®ããšã瀺ããŸãã
- [é©çšå¯Ÿè±¡] ãã£ãŒã«ã â å€éšãããã¯ãŒã¯ (çµç¹ã¬ãã«ã®ãããã¯ãŒã¯ã§ã¯ãããŸãã!)ã
- å ã®éä¿¡å IP/ç¯å² - å éšã¢ãã¬ã¹ç¯å² (äŸ: 192.168.1.0/24)ã
- å€æããããœãŒã¹ IP/ç¯å² â ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ã«äœ¿çšãããå€éšã¢ãã¬ã¹ã[IP ããŒã«ã®ãµãå²ãåœãŠ] ã¿ãã§ç¢ºèªãããã®ã§ãã
ãä¿æããã¯ãªãã¯ããŸãã
DNAT ã«ãŒã«ãäœæããŸãã DNAT ã¯ããã±ããã®å®å
ã¢ãã¬ã¹ãšå®å
ããŒããå€æŽããã¡ã«ããºã ã§ãã å€éšã¢ãã¬ã¹/ããŒãããã®åä¿¡ãã±ããããã©ã€ããŒã ãããã¯ãŒã¯å
ã®ãã©ã€ããŒã IP ã¢ãã¬ã¹/ããŒãã«ãªãã€ã¬ã¯ãããããã«äœ¿çšãããŸãã
[NAT] ã¿ããéžæãã[DNAT ã®è¿œå ] ãã¯ãªãã¯ããŸãã
衚瀺ããããŠã£ã³ããŠã§ã次ã®ããã«æå®ããŸãã
â [é©çšå
] ãã£ãŒã«ã â å€éšãããã¯ãŒã¯ (çµç¹ã¬ãã«ã®ãããã¯ãŒã¯ã§ã¯ãããŸãã!)ã
â å
ã® IP/ç¯å² â å€éšã¢ãã¬ã¹ ([IP ããŒã«ã®ãµãå²ãåœãŠ] ã¿ãããã®ã¢ãã¬ã¹)ã
â ãããã³ã« â ãããã³ã«ã
â å
ã®ããŒã â å€éšã¢ãã¬ã¹çšã®ããŒãã
â å€æããã IP/ç¯å² â å
éš IP ã¢ãã¬ã¹ãããšãã° 192.168.1.10
â å€ææžã¿ããŒã â å€éšã¢ãã¬ã¹ã®ããŒããå€æãããå
éšã¢ãã¬ã¹ã®ããŒãã
ãä¿æããã¯ãªãã¯ããŸãã
ãéžæããŠãå
¥åããæ§æãé©çšããŸãã å€æŽãä¿åããŸã.
å®äºããŸããã
次ã«ãDHCP ãã€ã³ãã£ã³ã°ããªã¬ãŒã®èšå®ãªã©ãDHCP ã«é¢ããæé ãèšèŒãããŠããŸãã
åºæïŒ habr.com