๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๐Ÿ”ฅ IT 8๊ฐœ ์ง๋ฌด ๊ธฐ์ดˆ์ฒดํ—˜

๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ

๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ VPC, Subnet, Route Table, Internet Gateway ๊ตฌ์ถ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์ž.

 

1. ๋„คํŠธ์›Œํฌ ๊ตฌ์„ฑ

์•„๋ž˜ ํ‘œ์™€ ๊ทธ๋ฆผ์€ ๋„คํŠธ์›Œํฌ๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ์š”์†Œ๋“ค์„ ์ง‘์„ ๊ตฌ์„ฑํ•˜๋Š” ์š”์†Œ๋“ค๋กœ ๋น„์œ ํ•˜์—ฌ ๋‚˜ํƒ€๋‚ด์—ˆ๋‹ค.

 

2. AWS์—์„œ ์ œ๊ณตํ•˜๋Š” VPC์™€ Subnet์˜ ๊ฐœ๋…

1) VPC (Virtual Private Cloud) ๋ž€?

  • AWS  Cloud ๋‚ด๋ถ€์—์„œ ๊ตฌ์„ฑ๋˜๋Š” ์‚ฌ์šฉ์ž์˜ AWS ๊ณ„์ • ์ „์šฉ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ๋กœ ์ด๊ณณ์—์„œ AWS ๋ฆฌ์†Œ์Šค๋ฅผ ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ๋‹ค.  AWS์—์„œ๋Š” ๋””ํดํŠธ๋กœ Amazon EC2-VPC๋ฅผ ์ œ๊ณตํ•˜์ง€๋งŒ Amazon VPC๋Š” AWS์˜ ํ™•์žฅ ๊ฐ€๋Šฅํ•œ ์ธํ”„๋ผ๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค๋Š” ์ด์ ๊ณผ ํ•จ๊ป˜ ๊ณ ๊ฐ์˜ ์ž์ฒด ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์—์„œ ์šด์˜ํ•˜๋Š” ๊ธฐ์กด ๋„คํŠธ์›Œํฌ์™€ ๋งค์šฐ ์œ ์‚ฌํ•˜๋‹ค.
  • ๋˜ํ•œ AWS VPC๋Š” AWS ํด๋ผ์šฐ๋“œ์—์„œ ๋‹ค๋ฅธ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ์™€ ๋…ผ๋ฆฌ์ ์œผ๋กœ ๋ถ„๋ฆฌ๋˜์–ด ์žˆ๋‹ค. IP ์ฃผ์†Œ ๋ฒ”์œ„์™€ VPC ๋ฒ”์œ„๋ฅผ ์„ค์ •ํ•˜๊ณ  ์„œ๋ธŒ๋„ท์„ ์ถ”๊ฐ€ํ•˜๊ณ  ๋ณด์•ˆ ๊ทธ๋ฃน์„ ์—ฐ๊ฒฐํ•œ ๋‹ค์Œ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์„ ๊ตฌ์„ฑํ•œ๋‹ค.
  • VPC๋Š” Amazon ์ฝ˜์†”์—์„œ ์ƒ์„ฑ๋œ๋‹ค. ๋˜ํ•œ ํ•˜๋‚˜์˜ VPC๋Š” ํ•˜๋‚˜์˜ Region๋‚ด์—์„œ๋งŒ ์ƒ์„ฑ์ด ๊ฐ€๋Šฅํ•˜์ง€๋งŒ ๋‘๊ฐœ ์ด์ƒ์˜ ๋ฆฌ์ „์— ๊ฑธ์น˜๋Š” ๊ฒƒ์€ ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค. ๊ทธ๋ ‡์ง€๋งŒ  ํ•˜๋‚˜์˜ VPC๋Š” ์—ฌ๋Ÿฌ๊ฐœ์˜ Amazon Availability Zone (์ดํ•˜ AZ) ์— ๊ฑธ์ณ์„œ ์ƒ์„ฑ๋  ์ˆ˜ ์žˆ๋‹ค. ๋˜ํ•œ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋Š” IP ์ฃผ์†Œ์˜ Range๋Š” 2^16 = 65535๋กœ ์ œํ•œ๋œ๋‹ค.

 

2) Public Subnet & Private Subnet ์ด๋ž€? 

VPC๋‚ด์—๋Š” ๋ณดํ†ต Public Subnet๊ณผ Private Subnet์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ๋‹ค.

  • Public Subnet: Public Subnet์˜ ํŠน์ง•์€ Internet Gateway, ELB, ๊ทธ๋ฆฌ๊ณ  Public IP/Elastic IP๋ฅผ ๊ฐ€์ง„ ์ธ์Šคํ„ด์Šค๋ฅผ ๋‚ด๋ถ€์— ๊ฐ€์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ํŠนํžˆ, Public Subnet ๋‚ด์— ์žˆ๋Š” Nat Instance๋ฅผ ํ†ตํ•˜์—ฌ Private Subnet๋‚ด์— ์žˆ๋Š” instances์ด ์ธํ„ฐ๋„ท์ด ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.
  • Private Subnet: ๊ธฐ๋ณธ์ ์œผ๋กœ ์™ธ๋ถ€์™€ ์ฐจ๋‹จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. Private Subnet๋‚ด์˜ ์ธ์Šคํ„ด์Šค๋“ค์€ private ip๋งŒ์„ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉฐinternet inbound/outbound๊ฐ€ ๋ถˆ๊ฐ€๋Šฅ ํ•˜๊ณ  ์˜ค์ง ๋‹ค๋ฅธ ์„œ๋ธŒ๋„ท๊ณผ์˜ ์—ฐ๊ฒฐ๋งŒ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

์—ฌ๊ธฐ ์‚ฌ์šฉ๋˜๋Š” VPC ๋Œ€์—ญ๋Œ€๋Š” 172.16.0.0/24 ์ด๋ฉฐ ์„œ๋ธŒ๋„คํŒ…์€ public/private ๋ชจ๋‘ 6๊ฐœ์˜ ์„œ๋ธŒ๋„ท์œผ๋กœ ๋‚˜๋ˆ„์—ˆ๊ณ (public subnet ๋‘๊ฐœ, private subnet 4๊ฐœ) ๊ฐ subnet๋‹น 27๊ฐœ์˜ ๋„คํŠธ์›Œํฌ ip๋ฅผ ํ• ๋‹นํ•˜์˜€๋‹ค.

๋‹ค์‹œ ์ •๋ฆฌํ•˜์ž๋ฉด,

  • VPC ๋Œ€์—ญ๋Œ€: 172.16.0.0/24
  • public subnet1: 172.16.0.0/27
  • public subnet2: 172.16.0.32/27
  • private subnet1 : 172.16.0.64/27
  • private subnet2: 172.16.0.96/27
  • private subnet3: 172.16.0.128/27
  • private subnet4: 172.16.0.160/27

VPC ๋Œ€์—ญ๋Œ€๋ฅผ 6๊ฐœ์˜ ์„œ๋ธŒ๋„ท์œผ๋กœ ๋‚˜๋ˆ„์—ˆ๊ณ  ๊ฐ ์„œ๋ธŒ๋„ท์€ 27๊ฐœ์˜ ๋„คํŠธ์›Œํฌ ip๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ค.