13. Tokyo Region
VPC@MGR
Public SubnetPrivate Subnet
VPC@DEV
Public SubnetPrivate Subnet
VPC@STG
Public SubnetPrivate Subnet
Oregon Region
AWS Cloud
VPC@OR
Private SubnetPublic Subnet
Verginia Region
VPC@VA
Private SubnetPublic Subnet
Ireland Region
VPC@IE
Private SubnetPublic Subnet
マルチリージョン構成
VyOS
VyOS
VyOS
VGW
15. Configダウンロード
Vyattaを選択し、ダウンロード
Config編集はここだけ!
あとは、Configを流し込む!
set vpn ipsec site-to-site peer xxx.xxx.xxx.xxx local-address ‘xxx.xxx.xxx.xxx'
set vpn ipsec site-to-site peer xxx.xxx.xxx.xxx local-address ‘xxx.xxx.xxx.xxx'
set protocols bgp 65000 network xxx.xxx.xxx.xxx/xx
vyos@VyOS-AMI:~$ configure
vyos@VyOS-AMI# set vpn ipsec ike-group AWS lifetime '28800''
vyos@VyOS-AMI# set vpn ipsec ike-group AWS proposal 1 dh-group ‘x'
・
・
・
vyos@VyOS-AMI# set protocols bgp 65000 network xxx.xxx.xxx.xxx/xx
vyos@VyOS-AMI# commit
vyos@VyOS-AMI# save
16. vyos@VyOS-AMI:~$ show vpn ipsec sa
Peer ID / IP Local ID / IP
------------------ ------------------
xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
Description: VPC tunnel 1
Tunnel State Bytes Out/In Encrypt Hash NAT-T A-Time L-Time Proto
------ ----- ------------- ------- ---- ----- ------ ------ -----
vti up 19.9K/19.7K aes128 sha1 no 1023 3600 all
Peer ID / IP Local ID / IP
------------------ ------------------
xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
Description: VPC tunnel 2
Tunnel State Bytes Out/In Encrypt Hash NAT-T A-Time L-Time Proto
------ ----- ------------- ------- ---- ----- ------ ------ -----
vti up 1.1K/905.0 aes128 sha1 no 698 3600 all
コネクション確認
VPN Connectionsからコネクション確認@Tokyo
VyOSサーバからコネクション確認@OR