
ãã¡ã€ã¢ãŠã©ãŒã«ã®èšå®ãèŠããšãIP ã¢ãã¬ã¹ãããŒãããããã³ã«ããµããããã倿°èšèŒãããã·ãŒãã衚瀺ãããã¯ãã§ããããã¯ããªãœãŒã¹ãžã®ãŠãŒã¶ãŒ ã¢ã¯ã»ã¹ã«é¢ãããããã¯ãŒã¯ ã»ãã¥ãªã㣠ããªã·ãŒãåŸæ¥å®è£
ãããæ¹æ³ã§ããæåã¯æ§æã®ç§©åºãç¶æããããšããŸããããã®åŸãåŸæ¥å¡ãéšééãç§»åãå§ãããµãŒããŒãå¢å ããŠåœ¹å²ãå€ãããéåžžã¯èš±å¯ãããŠããªãããŸããŸãªãããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãçºçããäœçŸãã®æªç¥ã®ã€ã®ãã¹ãååŸãããŸãã
éãè¯ããã°ãããã€ãã®ã«ãŒã«ã®è¿ãã«ãVasya ããããããããã«é Œãã ããããã㯠DMZ ãžã®éè·¯ã§ãããªã©ã®ã³ã¡ã³ãããããŸãããããã¯ãŒã¯ç®¡çè ãèŸããŠããŸãããã¹ãŠãå®å šã«äžæçã«ãªããŸãããã®åŸã誰ãã Vasya ããæ§æãæ¶å»ããããšã決å®ããSAP ãã¯ã©ãã·ã¥ããŸãããããã¯ãVasya ãæŠé SAP ã§åäœããããã«ãã®ã¢ã¯ã»ã¹ãèŠæ±ããããã§ãã

仿¥ã¯ããã¡ã€ã¢ãŠã©ãŒã«æ§æã®æ··ä¹±ãªãã«ãããã¯ãŒã¯ãšã»ãã¥ãªã㣠ããªã·ãŒãæ£ç¢ºã«é©çšããã®ã«åœ¹ç«ã€ VMware NSX ãœãªã¥ãŒã·ã§ã³ã«ã€ããŠèª¬æããŸãããã®åéã§ VMware ããããŸã§æäŸããŠããæ©èœãšæ¯èŒããŠãã©ã®ãããªæ°æ©èœãç»å Žãããã玹ä»ããŸãã
VMWare NSX ã¯ããããã¯ãŒã¯ ãµãŒãã¹ã®ä»®æ³åãšã»ãã¥ãªãã£ã®ããã®ãã©ãããã©ãŒã ã§ãã NSX ã¯ãã«ãŒãã£ã³ã°ãã¹ã€ããã³ã°ãè² è·åæ£ããã¡ã€ã¢ãŠã©ãŒã«ã®åé¡ã解決ãããã®ä»å€ãã®è峿·±ãããšãè¡ãããšãã§ããŸãã
NSX ã¯ãVMware ç¬èªã® vCloud Networking and Security (vCNS) 補åãš Nicira è²·åã«ãã NVP ã®åŸç¶ã§ãã
vCNSããNSXãž
以åã顧客㯠VMware vCloud äžã«æ§ç¯ãããã¯ã©ãŠãå ã«å¥ã® vCNS vShield Edge ä»®æ³ãã·ã³ãææããŠããŸãããããã¯ãNATãDHCPããã¡ã€ã¢ãŠã©ãŒã«ãVPNãããŒã ãã©ã³ãµãªã©ã®å€ãã®ãããã¯ãŒã¯æ©èœãæ§æã§ããå¢çã²ãŒããŠã§ã€ãšããŠæ©èœããŸãããvShield Edge ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãš NAT ã§æå®ãããã«ãŒã«ã«åŸã£ãŠãä»®æ³ãã·ã³ãšå€éšãšã®ããåããå¶éããŸããããããã¯ãŒã¯å ã§ã¯ãä»®æ³ãã·ã³ã¯ãµããããå ã§èªç±ã«çžäºã«éä¿¡ããŸããããã©ãã£ãã¯ãåå²ããŠå¶åŸ¡ãããå Žåã¯ãã¢ããªã±ãŒã·ã§ã³ã®åã ã®éšå (ç°ãªãä»®æ³ãã·ã³) ããšã«åå¥ã®ãããã¯ãŒã¯ãäœæãããã¡ã€ã¢ãŠã©ãŒã«ã§ãããã®ãããã¯ãŒã¯çžäºäœçšã«å¯Ÿå¿ããã«ãŒã«ãèšè¿°ããããšãã§ããŸããããããç¹ã«æ°åå°ã®ä»®æ³ãã·ã³ãããå Žåãããã¯é·ããŠè€éã§é¢çœããããŸããã
NSX ã§ã¯ãVMware ã¯ãã€ããŒãã€ã¶ãŒ ã«ãŒãã«ã«çµã¿èŸŒãŸãã忣ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã®æŠå¿µãå®è£ ããŸããã IP ã¢ãã¬ã¹ãš MAC ã¢ãã¬ã¹ã ãã§ãªããä»®æ³ãã·ã³ãã¢ããªã±ãŒã·ã§ã³ãªã©ã®ä»ã®ãªããžã§ã¯ãã«å¯ŸããŠãã»ãã¥ãªãã£ãšãããã¯ãŒã¯çžäºäœçšã®ããªã·ãŒãæå®ããŸãã NSX ãçµç¹å ã«å±éãããŠããå Žåããããã®ãªããžã§ã¯ã㯠Active Directory ã®ãŠãŒã¶ãŒãŸãã¯ãŠãŒã¶ãŒ ã°ã«ãŒãã«ãªããŸãããã®ãããªåãªããžã§ã¯ãã¯ãç¬èªã®ã»ãã¥ãªã㣠ã³ã³ã¿ãŒãå¿ èŠãªãµãããããç¬èªã®å¿«é©ãª DMZ ãæã€ãã€ã¯ã ã»ã°ã¡ã³ãã«ãªããŸã :)ã

ãããŸã§ãã»ãã¥ãªãã£å¢çã¯ãªãœãŒã¹ ããŒã«å
šäœã«å¯Ÿã㊠1 ã€ã§ããããšããž ã¹ã€ããã«ãã£ãŠä¿è·ãããŠããŸããããNSX ã䜿çšãããšãåããããã¯ãŒã¯å
ã§ãåã
ã®ä»®æ³ãã·ã³ãäžèŠãªçžäºäœçšããä¿è·ã§ããŸãã
ãªããžã§ã¯ããå¥ã®ãããã¯ãŒã¯ã«ç§»åãããšãã»ãã¥ãªãã£ãšãããã¯ãŒã¯ ããªã·ãŒãé©å¿ãããŸããããšãã°ãããŒã¿ããŒã¹ãå«ããã·ã³ãå¥ã®ãããã¯ãŒã¯ ã»ã°ã¡ã³ãã«ç§»åããããæ¥ç¶ãããå¥ã®ä»®æ³ããŒã¿ ã»ã³ã¿ãŒã«ç§»åããããããšããã®ä»®æ³ãã·ã³ã«å®çŸ©ãããã«ãŒã«ã¯ãæ°ããå Žæã«é¢ä¿ãªãåŒãç¶ãé©çšãããŸããã¢ããªã±ãŒã·ã§ã³ ãµãŒããŒã¯åŒãç¶ãããŒã¿ããŒã¹ãšå¯Ÿè©±ã§ããŸãã
vCNS vShield Edge ãšããž ã²ãŒããŠã§ã€èªäœã¯ NSX Edge ã«çœ®ãæããããŸãããæ§ Edge ã®ãã¹ãŠã®æ©èœã«å ããããã€ãã®äŸ¿å©ãªæ°æ©èœãåãã£ãŠããŸãããããã«ã€ããŠã¯åŸã»ã©ã話ãããŸãã
NSX Edge ã®æ°æ©èœã¯äœã§ãã?
NSX Edgeã®æ©èœã¯ä»¥äžã«äŸåããŸã NSXããããã¯ãStandardãProfessionalãAdvancedãEnterpriseãPlus Remote Branch Office ã® 5 ã€ã§ããæ°ããè峿·±ããã®ã¯ãã¹ãŠãAdvanced ããã®ã¿èŠãããšãã§ããŸããæ°ããã€ã³ã¿ãŒãã§ã€ã¹ãå«ãŸããŠãããvCloud ã HTML2019 ã«å®å šã«åãæ¿ãããŸã§ (VMware 㯠XNUMX 幎å€ã«äºå®)ãæ°ããã¿ãã§éããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ã ã«ãŒã«ãé©çšãããªããžã§ã¯ããšããŠãIP ã¢ãã¬ã¹ããããã¯ãŒã¯ãã²ãŒããŠã§ã€ ã€ã³ã¿ãŒãã§ã€ã¹ãä»®æ³ãã·ã³ãéžæã§ããŸãã


DHCPã ãã®ãããã¯ãŒã¯äžã®ä»®æ³ãã·ã³ã«èªåçã«å²ãåœãŠãããIPã¢ãã¬ã¹ã®ç¯å²ãèšå®ããããšã«å ããŠãNSX Edgeã«ã¯æ¬¡ã®ãããªæ©èœã远å ãããŸããã ãã€ã³ãã£ã³ã° О ãªã¬ãŒ.
ã¿ãå ãã€ã³ãã£ã³ã° IP ã¢ãã¬ã¹ã倿Žããªãå Žåã¯ãä»®æ³ãã·ã³ã® MAC ã¢ãã¬ã¹ã IP ã¢ãã¬ã¹ã«ãã€ã³ãã§ããŸããéèŠãªã®ã¯ããã® IP ã¢ãã¬ã¹ã DHCP ããŒã«ã«å«ãŸããŠããªãããšã§ãã

ã¿ãå
ãªã¬ãŒ ç©çã€ã³ãã©ã¹ãã©ã¯ãã£äžã® DHCP ãµãŒããŒãå«ããvCloud Director çµç¹ã®å€éšã«ãã DHCP ãµãŒããŒãžã® DHCP ã¡ãã»ãŒãžã®ãªã¬ãŒãæ§æããŸãã

ã«ãŒãã£ã³ã°ã vShield Edge ã§ã¯éçã«ãŒãã£ã³ã°ã®ã¿ãæ§æã§ããŸãã OSPF ããã³ BGP ãããã³ã«ããµããŒãããåçã«ãŒãã£ã³ã°ãããã«ç»å ŽããŸãããç©çã«ãŒã¿ãŒäžã§ã®ã¢ã¯ãã£ã-ã¢ã¯ãã£ã ãã§ã€ã«ãªãŒããŒãæå³ãã ECMP (ã¢ã¯ãã£ã-ã¢ã¯ãã£ã) èšå®ãå©çšå¯èœã«ãªããŸããã

OSPFã®èšå®

BGP ã®èšå®
ããäžã€ã®æ°æ©èœã¯ãç°ãªããããã³ã«éã®ã«ãŒãäŒéã®æ§æã§ãã
ã«ãŒãã®åé
åžã

L4/L7 ããŒã ãã©ã³ãµãŒã HTTPs ããããŒã« X-Forwarded-For ãå°å
¥ãããŸããã圌ãããªããã°ã誰ããæ³£ããŠããŸããããšãã°ããã©ã³ã¹èª¿æŽãè¡ã£ãŠãããµã€ãããããšããŸãããã®ããããŒã転éããªããŠãããã¹ãŠã¯æ©èœããŸãããWeb ãµãŒããŒã®çµ±èšæ
å ±ã«ã¯ã蚪åè
ã® IP ã§ã¯ãªãããã©ã³ãµãŒã® IP ã衚瀺ãããŸããä»ã¯ãã¹ãŠæ£åžžã§ãã
ãŸãã[ã¢ããªã±ãŒã·ã§ã³ ã«ãŒã«] ã¿ãã§ã¯ããã©ãã£ã㯠ãã©ã³ã·ã³ã°ãçŽæ¥å¶åŸ¡ããã¹ã¯ãªããã远å ã§ããããã«ãªããŸããã

VPN NSX Edge ã¯ãIPSec VPN ã«å ããŠã以äžããµããŒãããŸãã
- å°ççã«åæ£ãããµã€ãéã§ãããã¯ãŒã¯ãæ¡åŒµã§ãã L2 VPNããã®ãã㪠VPN ã¯ãããšãã°ãå¥ã®ãµã€ãã«ç§»åãããšãã«ä»®æ³ãã·ã³ãåããµããããå ã«çãŸããIP ã¢ãã¬ã¹ãä¿æããå Žåã«å¿ èŠã§ãã

- SSL VPN Plus ã䜿çšãããšããŠãŒã¶ãŒã¯äŒæ¥ãããã¯ãŒã¯ã«ãªã¢ãŒãã§æ¥ç¶ã§ããŸãã vSphere ã¬ãã«ã§ã¯ãã®ãããªæ©èœãååšããŠããŸããããvCloud Director ã§ã¯ããã¯æ°ããæ©èœã§ãã

SSL èšŒææžã NSX Edge ãèšŒææžã䜿çšããŠããããžã§ãã³ã°ã§ããããã«ãªããŸãããããã¯åã³ãhttps ã®èšŒææžã®ãªããã©ã³ãµãŒã誰ãå¿
èŠãšããããšããçåã«æ»ããŸãã

ãªããžã§ã¯ãã®ã°ã«ãŒãåã ãã®ã¿ãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãªã©ãç¹å®ã®ãããã¯ãŒã¯çžäºäœçšã«ãŒã«ãé©çšããããªããžã§ã¯ã ã°ã«ãŒããæå®ããŸãã
ãããã®ãªããžã§ã¯ã㯠IP ã¢ãã¬ã¹ãš MAC ã¢ãã¬ã¹ã«ãªããŸãã


ãŸãããã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ãäœæãããšãã«äœ¿çšã§ãããµãŒãã¹ (ãããã³ã«ãšããŒãã®çµã¿åãã) ãšã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ããæäŸããŸããæ°ãããµãŒãã¹ãšã¢ããªã±ãŒã·ã§ã³ã远å ã§ããã®ã¯ãvCD ããŒã¿ã«ç®¡çè
ã ãã§ãã


çµ±èš æ¥ç¶çµ±èš: ã²ãŒããŠã§ã€ããã¡ã€ã¢ãŠã©ãŒã«ããã©ã³ãµãŒãééãããã©ãã£ãã¯ã
å IPSEC VPN ããã³ L2 VPN ãã³ãã«ã®ã¹ããŒã¿ã¹ãšçµ±èšã

ãã°èšé²ã ããšããžèšå®ãã¿ãã§ã¯ããã°ãèšé²ãããµãŒããŒãèšå®ã§ããŸãããã°èšé²ã¯ãDNAT/SNATãDHCPããã¡ã€ã¢ãŠã©ãŒã«ãã«ãŒãã£ã³ã°ããã©ã³ãµãŒãIPsec VPNãSSL VPN Plus ã§æ©èœããŸãã
åãªããžã§ã¯ã/ãµãŒãã¹ã«ã¯æ¬¡ã®çš®é¡ã®éç¥ãå©çšã§ããŸãã
â ãããã°
â èŠå
- èŽåœç
- ãšã©ãŒ
- èŠå
- ç¥ãã
- æ
å ±

NSX ãšããžã®å¯žæ³
解決ãã¹ãã¿ã¹ã¯ãšVMwareã®ããªã¥ãŒã ã«å¿ã㊠次ã®ãµã€ãºã® NSX Edge ãäœæããŸãã
NSX ãšããž
ïŒã³ã³ãã¯ãïŒ
NSX ãšããž
ïŒå€§ïŒ
NSX ãšããž
(4é¢å€§)
NSX ãšããž
(ç¹å€§)
vCPU
1
2
4
6
ã¡ã¢ãª
512MB
1GB
1GB
8GB
ãã£ã¹ã¯
512MB
512MB
512MB
4.5GB + 4GB
ä»»åœ
1ã€
ã¢ããªã±ãŒã·ã§ã³ããã¹ã
ããŒã¿ã»ã³ã¿ãŒ
å°ãã
ãŸãã¯å¹³å
ããŒã¿ã»ã³ã¿ãŒ
ããŒãæžã¿
ãã¡ã€ã¢ãŠã©ãŒã«
ãã©ã³ã¹èª¿æŽ
L7ã¬ãã«ã®è² è·
以äžã®è¡šã¯ãNSX Edge ã®ãµã€ãºã«åºã¥ãããããã¯ãŒã¯ ãµãŒãã¹ã®ããã©ãŒãã³ã¹ ã¡ããªãã¯ã瀺ããŠããŸãã
NSX ãšããž
ïŒã³ã³ãã¯ãïŒ
NSX ãšããž
ïŒå€§ïŒ
NSX ãšããž
(4é¢å€§)
NSX ãšããž
(ç¹å€§)
ã€ã³ã¿ãŒãã§ãŒã¹
10
10
10
10
ãµãã€ã³ã¿ãŒãã§ãŒã¹ïŒãã©ã³ã¯ïŒ
200
200
200
200
NATã«ãŒã«
2,048
4,096
4,096
8,192
ARPãšã³ããª
äžæžããããŸã§
1,024
2,048
2,048
2,048
FWã«ãŒã«
2000
2000
2000
2000
FWããã©ãŒãã³ã¹
3Gbps
9.7Gbps
9.7Gbps
9.7Gbps
DHCP ããŒã«
20,000
20,000
20,000
20,000
ECMP ãã¹
8
8
8
8
éçã«ãŒã
2,048
2,048
2,048
2,048
LB ããŒã«
64
64
64
1,024
LB ä»®æ³ãµãŒããŒ
64
64
64
1,024
LB ãµãŒã㌠/ ããŒã«
32
32
32
32
LB ãã«ã¹ãã§ãã¯
320
320
320
3,072
LB ã¢ããªã±ãŒã·ã§ã³ã«ãŒã«
4,096
4,096
4,096
4,096
L2VPN ã¯ã©ã€ã¢ã³ã ããããã¹ããŒã¯
5
5
5
5
ã¯ã©ã€ã¢ã³ã/ãµãŒããŒãããã® L2VPN ãããã¯ãŒã¯
200
200
200
200
IPSec ãã³ãã«
512
1,600
4,096
6,000
SSLVPN ãã³ãã«
50
100
100
1,000
SSLVPN ãã©ã€ããŒããããã¯ãŒã¯
16
16
16
16
åæã»ãã·ã§ã³
64,000
1,000,000
1,000,000
1,000,000
ã»ãã·ã§ã³/ç§
8,000
50,000
50,000
50,000
LB ã¹ã«ãŒããã L7 ãããã·)
2.2Gbps
2.2Gbps
3Gbps
LB ã¹ã«ãŒããã L4 ã¢ãŒã)
6Gbps
6Gbps
6Gbps
LB æ¥ç¶æ°/ç§ (L7 ãããã·)
46,000
50,000
50,000
LB åææ¥ç¶ (L7 ãããã·)
8,000
60,000
60,000
LB æ¥ç¶æ°/ç§ (L4 ã¢ãŒã)
50,000
50,000
50,000
LB åææ¥ç¶æ° (L4 ã¢ãŒã)
600,000
1,000,000
1,000,000
BGPã«ãŒã
20,000
50,000
250,000
250,000
BGP ãã€ããŒ
10
20
100
100
BGPã«ãŒãã®åé åž
å¶éãªã
å¶éãªã
å¶éãªã
å¶éãªã
OSPFã«ãŒã
20,000
50,000
100,000
100,000
OSPF LSA ãšã³ããªæå€§ 750 ã¿ã€ã 1
20,000
50,000
100,000
100,000
OSPF飿¥é¢ä¿
10
20
40
40
OSPFã«ãŒãã®åé åž
2000
5000
20,000
20,000
åèšã«ãŒã
20,000
50,000
250,000
250,000
â
衚ã¯ãæ¬çªç°å¢ã®ã·ããªãªã§ã¯ãLarge ãµã€ãºããã®ã¿ NSX Edge ã§ãã©ã³ã¹èª¿æŽãè¡ãããšãæšå¥šãããŠããããšã瀺ããŠããŸãã
仿¥ã¯ããã§çµããã§ããæ¬¡ã®éšåã§ã¯ãå NSX Edge ãããã¯ãŒã¯ ãµãŒãã¹ã®æ§æã«ã€ããŠè©³ãã説æããŸãã
åºæïŒ habr.com
