Upgrade to Pro — share decks privately, control downloads, hide ads and more …

20180920 セキュリティグループとNACL

20180920 セキュリティグループとNACL

2018/9/20のSapporo.awsの発表資料です。

Masaru Ogura

September 20, 2018
Tweet

More Decks by Masaru Ogura

Other Decks in Technology

Transcript

  1. • 小倉 大 (おぐら まさる) Facebook : https://www.facebook.com/masaru.ogura.71 Twitter :

    @MasaruOgura • 株式会社サーバーワークス • 札幌在住 • 以前はデータセンターネットワーク運用 • AWS歴 2年10か月 自己紹介
  2. セキュリティグループの上限 セキュリティグループの上限緩和は可能だが、 以下の条件がある (SGルール数) × (ENIあたりのSG) ≦ 300 SG :

    セキュリティグループ ENI : ネットワークインターフェイス 例) (SGルール数)100 × (ENIあたりのSG) 3 = 300 ≦ 300
  3. クイズ Rule # Type Protocol Port Range Source Allow/De ny

    100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source ALL Traffic ALL ALL 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  4. クイズ1 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source ALL Traffic ALL ALL 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  5. クイズ1 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source ALL Traffic ALL ALL 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  6. クイズ2 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  7. クイズ2 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  8. クイズ3 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  9. クイズ3 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 ALL Traffic ALL ALL 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  10. クイズ4 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  11. クイズ4 Rule # Type Protocol Port Range Source Allow/De ny

    100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny 100 HTTP(80) TCP(6) 80 0.0.0.0/0 ALLOW * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG1 Outbound Rules
  12. クイズ5 Rule # Type Protocol Port Range Source Allow/De ny

    * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG2 Outbound Rules
  13. クイズ5 Rule # Type Protocol Port Range Source Allow/De ny

    * ALL Traffic ALL ALL 0.0.0.0/0 DENY Rule # Type Protocol Port Range Destinati on Allow/De ny * ALL Traffic ALL ALL 0.0.0.0/0 DENY Type Protocol Port Range Source HTTP(80) TCP(6) 80 0.0.0.0/0 Type Protocol Port Range Destination ALL Traffic ALL ALL 0.0.0.0/0 NACL Inbound Rules NACL Outbound Rules SG1 Inbound Rules SG2 Outbound Rules
  14. 参考資料 • 20180418 AWS Black Belt Online Seminar Amazon VPC

    https://www.slideshare.net/AmazonWebServicesJapan/20 180418-aws-black-belt-online-seminar-amazon-vpc • AWS サービス制限 https://docs.aws.amazon.com/ja_jp/general/latest/gr/aw s_service_limits.html • AWS Service Limits https://docs.aws.amazon.com/general/latest/gr/aws_serv ice_limits.html
  15. 参考資料 • AWS ドキュメント » Amazon VPC » ユーザーガイド »

    セキュ リティ https://docs.aws.amazon.com/ja_jp/vpc/latest/userguide /VPC_Security.html