Diese Präsentation wurde erfolgreich gemeldet.
Wir verwenden Ihre LinkedIn Profilangaben und Informationen zu Ihren Aktivitäten, um Anzeigen zu personalisieren und Ihnen relevantere Inhalte anzuzeigen. Sie können Ihre Anzeigeneinstellungen jederzeit ändern.

20191016 AWS Black Belt Online Seminar Amazon Route 53 Resolver

AWS 公式オンラインセミナー: https://amzn.to/JPWebinar
過去資料: https://amzn.to/JPArchive

Ähnliche Bücher

Kostenlos mit einer 30-tägigen Testversion von Scribd

Alle anzeigen

Ähnliche Hörbücher

Kostenlos mit einer 30-tägigen Testversion von Scribd

Alle anzeigen
  • Loggen Sie sich ein, um Kommentare anzuzeigen.

20191016 AWS Black Belt Online Seminar Amazon Route 53 Resolver

  1. 1. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Webinar https://amzn.to/JPWebinar https://amzn.to/JPArchive
  2. 2. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  3. 3. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • ① 吹き出しをクリック ② 質問を入力 ③ Sendをクリック Twitter #awsblackbelt
  4. 4. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • • •
  5. 5. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  6. 6. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  7. 7. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Webinar https://amzn.to/JPWebinar https://amzn.to/JPArchive
  8. 8. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. www1 FQDN www1.sub.example.com. ip-private-ipv4-address.ec2.internal.
  9. 9. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • •
  10. 10. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DNS 4
  11. 11. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • •
  12. 12. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • •
  13. 13. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • •
  14. 14. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • •
  15. 15. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  16. 16. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • • .( example.internal Internet example.internal example.com
  17. 17. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. example.com example.com • • example.com Internal Name Server Hostname Type Value www @ MX 10 mai.example.com. mail Hostname Type Value www @ MX 10 mai.intra.example.com. mail.intra
  18. 18. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. V DNS • • Internet .( example.internal example.internal example.com
  19. 19. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • •
  20. 20. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Webinar https://amzn.to/JPWebinar https://amzn.to/JPArchive
  21. 21. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Route 53 Amazon Route 53 Resolver Amazon Route 53 Resolver for Hybrid Clouds
  22. 22. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. for On-premisefor Amazon VPCfor Internet Amazon Route 53 Public Hosted Zone Amazon Route 53 Private Hosted Zone Amazon-provided private DNS hostnames User-managed DNS Private Hosted Zone Internet Public DNS Zone DNS VPC DNS DNS
  23. 23. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • Amazon VPC VPC Instance Route 53 Resolver Internet VPC DNS DNS Amazon Route 53 Public Hosted Zone Amazon Route 53 Private Hosted Zone
  24. 24. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. for Internet • • VPC Availability Zone Instance Amazon Route 53 Resolver Amazon Route 53 Public Hosted Zone Internet Public DNS Zone for Amazon VPC Amazon-provided private DNS hostnames Amazon Route 53 Private Hosted Zone Instance example.com ec2.internal
  25. 25. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • Outbound Endpoint Inbound Endpoint
  26. 26. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. https://aws.amazon.com/jp/blogs/security/how-to-set-up-dns-resolution-between-on-premises-networks-and- aws-using-aws-directory-service-and-amazon-route-53/ これが必要でした
  27. 27. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VPC Availability Zone Instance Client Amazon Route 53 Resolver for Internet Amazon Route 53 Public Hosted Zone Internet Public DNS Zone for Amazon VPC Amazon-provided private DNS hostnames Amazon Route 53 Private Hosted Zone for On-premise User-managed DNS Private Hosted Zone Inbound Endpoint Outbound Endpoint
  28. 28. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VPC Inbound Endpoint VPC Availability Zone Client for Internet Amazon Route 53 Public Hosted Zone Internet Public DNS Zone for Amazon VPC Amazon Route 53 Resolver xxx.ec2.internal Amazon-provided private DNS hostnames Amazon Route 53 Private Hosted Zone ec2.internal
  29. 29. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Route 53 Resolver Inbound Endpoint VPC Availability Zone Client for Internet Amazon Route 53 Public Hosted Zone Internet Public DNS Zone for Amazon VPC Amazon Route 53 Resolver example.com www.example.com Amazon-provided private DNS hostnames Amazon Route 53 Private Hosted Zone
  30. 30. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VPC Outbound Endpoint VPC Availability Zone Instance Amazon Route 53 Resolver on-prem.internal on-prem.internalfor On-premise User-managed DNS Private Hosted Zone
  31. 31. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. for Amazon VPC Amazon-provided private DNS hostnames Amazon Route 53 Private Hosted Zone Outbound Endpoint VPC Availability Zone Instance Amazon Route 53 Resolver example.com for Internet Amazon Route 53 Public Hosted Zone Internet Public DNS Zone example.com x.example.com Instance example.com www.example.com for On-premise User-managed DNS Private Hosted Zone
  32. 32. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DNS DNS https://docs.aws.amazon.com/ja_jp/Route53/latest/DeveloperGuide/resolver-forwarding-outbound-queries.html
  33. 33. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • • •
  34. 34. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Route 53 Amazon Route 53 Resolver Amazon Route 53 Resolver for Hybrid Clouds • • • • • • ※
  35. 35. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Webinar https://amzn.to/JPWebinar https://amzn.to/JPArchive
  36. 36. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VPC Availability Zone Amazon Route 53 Resolver Instance • •
  37. 37. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • VPC Availability Zone 1 Availability Zone 2 Route 53 Resolver Inbound Endpoint Inbound Endpoint Outbound Endpoint Outbound Endpoint VGW CGW
  38. 38. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Endpoint Elastic Network Interfaces (ENIs) UDP 53 TCP 53 ※ TCP Fallback RFC 5966 TCP Inbound Endpoint Outbound Endpoint UDP 53 TCP 53 0.0.0.0/0 0.0.0.0/0
  39. 39. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • • • Resource Access Manager https://docs.aws.amazon.com/ram/latest/userguide/what-is.html
  40. 40. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  41. 41. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  42. 42. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  43. 43. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Inbound Endpoint IP IP
  44. 44. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. IP Outbound Endpoint IP
  45. 45. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 1 1
  46. 46. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • • • •
  47. 47. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. ␣ ␣ ␣ ␣ ␣ FQDN
  48. 48. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Header Question Answer $ dig @172.31.0.2 www.example.com ; <<>> DiG 9.9.4-RedHat-9.9.4-74.amzn2.1.2 <<>> www.example.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 57031 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 4096 ;; QUESTION SECTION: ;www.example.com. IN A ;; ANSWER SECTION: www.example.com. 60 IN A 192.168.0.1 ;; Query time: 758 msec ;; SERVER: 172.31.0.2#53(172.31.0.2) ;; WHEN: 10 14 04:37:26 UTC 2019 ;; MSG SIZE rcvd: 65
  49. 49. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. status NOERROR SERVFAIL DNS REFUSED NXDOMAIN flags qr aa ra tc ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 57031 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1 【参考】初心者のためのDNS運用入門-トラブル事例とその解決のポイント-, 水野貴史, 株式会社日本レジストリサービス, 2014 https://dnsops.jp/event/20140626/dns-beginners-guide2014-mizuno.pdf DNS AWS dig
  50. 50. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • • • • • • • •
  51. 51. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Webinar https://amzn.to/JPWebinar https://amzn.to/JPArchive
  52. 52. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  53. 53. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hybrid Cloud DNS Options for Amazon VPC https://d1.awsstatic.com/whitepapers/hybrid-cloud-dns-options-for-vpc.pdf
  54. 54. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Coming Soon !
  55. 55. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. • • ① 吹き出しをクリック ② 質問を入力 ③ Sendをクリック
  56. 56. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. https://amzn.to/JPArchive
  57. 57. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Well-Architected 個別技術相談会 • •
  58. 58. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Webinar https://amzn.to/JPWebinar https://amzn.to/JPArchive
  59. 59. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. .(root) DNS .(root) VPC DNS AWS .ec2.internal/.compute.internal/.amazonaws.com VPC DNS .(root) Amazon Route 53 Public Hosted Zone Amazon Route 53 Private Hosted Zone Amazon-provided private DNS hostnames User-managed DNS Private Hosted Zone Internet Public DNS Zone

×