Skip to content

非公式本サイトは非公式の日本語ドキュメントであり、Cloudflare 公式サイトではありません。最新情報はdevelopers.cloudflare.comをご確認ください。

リファレンス

最終更新 Markdown で表示Agent セットアップ

Cloudflare がクラウドネットワークへの VPN 接続をどのようにオーケストレーションするか、このページで確認できます。

クラウドオンランプ

AWS

Cloudflare が AWS 向けオンランプを作成する流れの図

注: この画像のラベルは、以前の製品名を使っている場合があります。

Cloudflare One Multi-Cloud Networking(旧 Magic Cloud Networking)(ベータ)で AWS アカウントへのオンランプを自動作成する場合、Cloudflare が代わって行う次の設定変更を把握してください。

  • Cloudflare は、Cloudflare WAN and Cloudflare Edge という顧客管理のプレフィックスリストを新規作成します。中身は Cloudflare WAN Address Space のプレフィックスと、Cloudflare グローバルネットワークサーバーの IPv4 アドレス範囲です(後者は、Cloudflare の L7 処理機能を使う場合に必要です)。Cloudflare WAN(旧 Magic WAN)との接続を確立するには、このプレフィックスリストとの送受信を許可するルールを Network Security Groups(NSG)に作成してください。(プレフィックスリストは約 15〜25 件になり、それぞれが AWS アカウントの NSG におけるセキュリティグループあたりのルール数クォータにカウントされます。)
  • Cloudflare は Virtual Private Gateway を作成し、Virtual Private Cloud(VPC)にアタッチします。既存の Virtual Private Gateway がすでに VPC にアタッチされている場合、オンランプ作成は失敗します。
  • Cloudflare は、Virtual Private Gateway から VPC 内のすべてのルートテーブルへルート伝播を有効にします。その結果、Cloudflare WAN Address Space の各プレフィックスに、ゲートウェイをターゲットとするルートが追加されます。
  • Cloudflare は、VPC 内の各 IPv4 CIDR(Classless Inter-Domain Routing)ブロックに対して、Cloudflare WAN にルートを追加します。

Azure

Cloudflare が Azure 向けオンランプを作成する流れの図

注: この画像のラベルは、以前の製品名を使っている場合があります。

Multi-Cloud Networking(ベータ)で Azure アカウントへのオンランプを自動作成する場合、Cloudflare が代わって行う次の設定変更を把握してください。

  • Cloudflare は、Virtual Network(VNet)内に Virtual Network Gateway を作成します。Azure の Virtual Network Gateway には、GatewaySubnet という名前のサブネットが必要です。VNet にまだない場合、Cloudflare は GatewaySubnet を作成します。GatewaySubnet 用の /27 サブネットを作る空きアドレス空間が VNet にない場合、または GatewaySubnet はあるが Virtual Network Gateway に十分な空きアドレス空間がない場合、オンランプ作成は失敗します。
  • Cloudflare は、VNet 内のすべてのルートテーブルでゲートウェイのルート伝播を有効にします。その結果、Cloudflare WAN Address Space の各プレフィックスに、ゲートウェイを指すルートが追加されます。VNet にほかの Virtual Network Gateway がある場合、それらのルートもルートテーブルへ伝播します。オンランプを削除しても、ルート伝播は無効になりません。
  • 既定では、Azure の Network Security Groups には、VirtualNetwork サービスタグとの送受信を許可する Allow ルールが含まれます。このサービスタグには Virtual Network Gateway のアドレス空間(したがって Cloudflare WAN Address Space)も含まれます。VNet 内のすべてのリソースを Cloudflare WAN から到達可能にしたくない場合は、適切な Deny ルールを Network Security Groups(NSG)に追加してください。
  • Cloudflare は、VNet 内の各 IPv4 アドレス範囲に対して、Cloudflare WAN にルートを追加します。

GCP

Cloudflare が GCP 向けオンランプを作成する流れの図

注: この画像のラベルは、以前の製品名を使っている場合があります。

Multi-Cloud Networking(ベータ)で Google Cloud Platform(GCP)アカウントへのオンランプを自動作成する場合、Cloudflare が代わって行う次の設定変更を把握してください。

  • Cloudflare は、GCP からインターネットへルーティング可能なパブリック IP アドレスを予約します。
  • Cloudflare は、指定したリージョンに VPN Gateway と 2 本の VPN Tunnel を作成します。
  • Cloudflare は、VPC 内の Cloudflare WAN Address Space の各プレフィックスに対して、VPN Tunnel を指すルートを作成します。
  • Cloudflare は、VPC 内のすべてのサブネット CIDR プレフィックスに対して、Cloudflare WAN にルートを追加します。これには VPC 内のすべてのリージョンが含まれます。VPN Gateway があるリージョン以外へ向かうトラフィックには、GCP の Inter-region Pricing が適用されます。
  • VPN Tunnel 経由で VM インスタンスとのあいだに送受信されるトラフィックは、引き続き VPC ファイアウォールルールの対象です。追加の設定が必要 な場合があります。

対応リソース

Multi-Cloud Networking(ベータ)は、クラウド環境で次のリソースタイプを検出します。これらのリソースは、クラウドネットワークのトポロジーと接続を包括的に把握するために使います。

AWS

  • AWS Customer Gateway
  • AWS EC2 Managed Prefix List
  • AWS EC2 Transit Gateway
  • AWS EC2 Transit Gateway Prefix List
  • AWS EC2 Transit Gateway VPC Attachment
  • AWS Egress Only Internet Gateway
  • AWS Internet Gateway
  • AWS Instance
  • AWS Network Interface
  • AWS Route Table
  • AWS Route Table Association
  • AWS Security Group
  • AWS Subnet
  • AWS VPC
  • AWS VPC IPv4 CIDR Block Association
  • AWS VPC Security Group Egress Rule
  • AWS VPC Security Group Ingress Rule
  • AWS VPN Connection
  • AWS VPN Connection Route
  • AWS VPN Gateway

Azure

  • Azure Application Security Group
  • Azure Load Balancer
  • Azure Load Balancer Backend Address Pool
  • Azure Load Balancer NAT Pool
  • Azure Load Balancer NAT Rule
  • Azure Load Balancer Rule
  • Azure Local Network Gateway
  • Azure Network Interface
  • Azure Network Interface Application Security Group Association
  • Azure Network Interface Backend Address Pool Association
  • Azure Network Interface Security Group Association
  • Azure Network Security Group
  • Azure Public IP
  • Azure Route
  • Azure Route Table
  • Azure Subnet
  • Azure Subnet Route Table Association
  • Azure Virtual Machine
  • Azure Virtual Machine Gateway Connection
  • Azure Virtual Network
  • Azure Virtual Network Gateway
  • Azure Virtual Network Gateway Connection

GCP

  • Google Compute Address
  • Google Compute Forwarding Rule
  • Google Compute Global Address
  • Google Compute HA VPN Gateway
  • Google Compute Interconnect Attachment
  • Google Compute Network
  • Google Compute Network Firewall Policy
  • Google Compute Network Firewall Policy Rule
  • Google Compute Route
  • Google Compute Router
  • Google Compute Subnetwork
  • Google Compute VPN Gateway
  • Google Compute VPN Tunnel

役に立ちましたか?