Cloudflare がクラウドネットワークへの VPN 接続をどのようにオーケストレーションするか、このページで確認できます。
注: この画像のラベルは、以前の製品名を使っている場合があります。
Cloudflare One Multi-Cloud Networking(旧 Magic Cloud Networking)(ベータ)で AWS アカウントへのオンランプを自動作成する場合、Cloudflare が代わって行う次の設定変更を把握してください。
- Cloudflare は、Cloudflare WAN and Cloudflare Edge という顧客管理のプレフィックスリストを新規作成します。中身は Cloudflare WAN Address Space のプレフィックスと、Cloudflare グローバルネットワークサーバーの IPv4 アドレス範囲です(後者は、Cloudflare の L7 処理機能を使う場合に必要です)。Cloudflare WAN(旧 Magic WAN)との接続を確立するには、このプレフィックスリストとの送受信を許可するルールを Network Security Groups(NSG)に作成してください。(プレフィックスリストは約 15〜25 件になり、それぞれが AWS アカウントの NSG におけるセキュリティグループあたりのルール数クォータにカウントされます。)
- Cloudflare は Virtual Private Gateway を作成し、Virtual Private Cloud(VPC)にアタッチします。既存の Virtual Private Gateway がすでに VPC にアタッチされている場合、オンランプ作成は失敗します。
- Cloudflare は、Virtual Private Gateway から VPC 内のすべてのルートテーブルへルート伝播を有効にします。その結果、Cloudflare WAN Address Space の各プレフィックスに、ゲートウェイをターゲットとするルートが追加されます。
- Cloudflare は、VPC 内の各 IPv4 CIDR(Classless Inter-Domain Routing)ブロックに対して、Cloudflare WAN にルートを追加します。
注: この画像のラベルは、以前の製品名を使っている場合があります。
Multi-Cloud Networking(ベータ)で Azure アカウントへのオンランプを自動作成する場合、Cloudflare が代わって行う次の設定変更を把握してください。
- Cloudflare は、Virtual Network(VNet)内に Virtual Network Gateway を作成します。Azure の Virtual Network Gateway には、
GatewaySubnetという名前のサブネットが必要です。VNet にまだない場合、Cloudflare はGatewaySubnetを作成します。GatewaySubnet用の/27サブネットを作る空きアドレス空間が VNet にない場合、またはGatewaySubnetはあるが Virtual Network Gateway に十分な空きアドレス空間がない場合、オンランプ作成は失敗します。 - Cloudflare は、VNet 内のすべてのルートテーブルでゲートウェイのルート伝播を有効にします。その結果、Cloudflare WAN Address Space の各プレフィックスに、ゲートウェイを指すルートが追加されます。VNet にほかの Virtual Network Gateway がある場合、それらのルートもルートテーブルへ伝播します。オンランプを削除しても、ルート伝播は無効になりません。
- 既定では、Azure の Network Security Groups には、
VirtualNetworkサービスタグとの送受信を許可する Allow ルールが含まれます。このサービスタグには Virtual Network Gateway のアドレス空間(したがって Cloudflare WAN Address Space)も含まれます。VNet 内のすべてのリソースを Cloudflare WAN から到達可能にしたくない場合は、適切な Deny ルールを Network Security Groups(NSG)に追加してください。 - Cloudflare は、VNet 内の各 IPv4 アドレス範囲に対して、Cloudflare WAN にルートを追加します。
注: この画像のラベルは、以前の製品名を使っている場合があります。
Multi-Cloud Networking(ベータ)で Google Cloud Platform(GCP)アカウントへのオンランプを自動作成する場合、Cloudflare が代わって行う次の設定変更を把握してください。
- Cloudflare は、GCP からインターネットへルーティング可能なパブリック IP アドレスを予約します。
- Cloudflare は、指定したリージョンに VPN Gateway と 2 本の VPN Tunnel を作成します。
- Cloudflare は、VPC 内の Cloudflare WAN Address Space の各プレフィックスに対して、VPN Tunnel を指すルートを作成します。
- Cloudflare は、VPC 内のすべてのサブネット CIDR プレフィックスに対して、Cloudflare WAN にルートを追加します。これには VPC 内のすべてのリージョンが含まれます。VPN Gateway があるリージョン以外へ向かうトラフィックには、GCP の Inter-region Pricing ↗ が適用されます。
- VPN Tunnel 経由で VM インスタンスとのあいだに送受信されるトラフィックは、引き続き VPC ファイアウォールルールの対象です。追加の設定が必要 ↗ な場合があります。
Multi-Cloud Networking(ベータ)は、クラウド環境で次のリソースタイプを検出します。これらのリソースは、クラウドネットワークのトポロジーと接続を包括的に把握するために使います。
- AWS Customer Gateway
- AWS EC2 Managed Prefix List
- AWS EC2 Transit Gateway
- AWS EC2 Transit Gateway Prefix List
- AWS EC2 Transit Gateway VPC Attachment
- AWS Egress Only Internet Gateway
- AWS Internet Gateway
- AWS Instance
- AWS Network Interface
- AWS Route Table
- AWS Route Table Association
- AWS Security Group
- AWS Subnet
- AWS VPC
- AWS VPC IPv4 CIDR Block Association
- AWS VPC Security Group Egress Rule
- AWS VPC Security Group Ingress Rule
- AWS VPN Connection
- AWS VPN Connection Route
- AWS VPN Gateway
- Azure Application Security Group
- Azure Load Balancer
- Azure Load Balancer Backend Address Pool
- Azure Load Balancer NAT Pool
- Azure Load Balancer NAT Rule
- Azure Load Balancer Rule
- Azure Local Network Gateway
- Azure Network Interface
- Azure Network Interface Application Security Group Association
- Azure Network Interface Backend Address Pool Association
- Azure Network Interface Security Group Association
- Azure Network Security Group
- Azure Public IP
- Azure Route
- Azure Route Table
- Azure Subnet
- Azure Subnet Route Table Association
- Azure Virtual Machine
- Azure Virtual Machine Gateway Connection
- Azure Virtual Network
- Azure Virtual Network Gateway
- Azure Virtual Network Gateway Connection
- Google Compute Address
- Google Compute Forwarding Rule
- Google Compute Global Address
- Google Compute HA VPN Gateway
- Google Compute Interconnect Attachment
- Google Compute Network
- Google Compute Network Firewall Policy
- Google Compute Network Firewall Policy Rule
- Google Compute Route
- Google Compute Router
- Google Compute Subnetwork
- Google Compute VPN Gateway
- Google Compute VPN Tunnel