Security Group

Security Group ์ž์„ธ-ํžˆ ์•Œ์•„๋ณด๊ธฐ ์‹ค๋ฌด ver.

Before getting started

  • ๊ธฐ์กด์— Firewall (๋ฐฉํ™”๋ฒฝ)์ด๋ผ๊ณ  ๋ถ€๋ฅด๋Š” ๊ฒƒ์„ AWS๊ฐ€ Security Group ์ด๋ผ๊ณ  ์ด๋ฆ„์„ ์ง€์Œ

  • ๋ฌผ๋ฆฌ server๋Š” ํ•„์š”ํ•  ๋•Œ๋งˆ๋‹ค ์ฆ์„คํ•˜๋Š” ๊ฒƒ์ด ๋ฌผ๋ฆฌ์ ์œผ๋กœ ์‹œ๊ฐ„์ด ์˜ค๋ž˜ ๊ฑธ๋ฆฐ๋‹ค

    • Data center์˜ VM ํ™˜๊ฒฝ, OpenStack, VM Ware ๋“ฑ์€ ์–ด๋Š ์ •๋„๋Š” ๋น ๋ฅธ ์†๋„๋กœ ๊ฐ€๋Šฅํ•˜๋‹ค

      • but, ๊ทธ๋ž˜๋„ Public Cloud 3์‚ฌ๋งŒํผ ๋น ๋ฅธ ์†๋„๋ฅผ ๊ฐ–์ง€๋Š” ์•Š๋Š”๋‹ค

  • Security Group ์ด๋ผ๋Š” ๊ฐœ๋… ์ž์ฒด๊ฐ€ on-premise ํ™˜๊ฒฝ์˜ ๋ฐฉํ™”๋ฒฝ ์„ค์ •์˜ ๊ฐœ๋…๊ณผ๋Š” ์ฐจ์ด๊ฐ€ ๋‚œ๋‹ค

    • ๋ฐฉํ™”๋ฒฝ group์„ ๋…ผ๋ฆฌ mapping ํ•˜๊ธฐ ์œ„ํ•ด security group ์ด๋ผ๋Š” ์ด๋ฆ„์„ ๊ฐ–๊ฒŒ ๋˜์—ˆ๋‹ค!

Security Group Rule Set

Security group rule set ์ž์ฒด๊ฐ€ EC2๋ฅผ ๊ฐ์‹ธ๋Š” ํ˜•์‹์ด๊ธฐ ๋•Œ๋ฌธ์— (EC2 ๋ฐ”๊นฅ์—์„œ ์ œ์–ด) ์ ‘๊ทผ์ด ์™œ ์•ˆ๋˜๋Š”์ง€ ํ™•์ธํ•  ๋•Œ EC2์— ์ ‘์†ํ•ด์„œ ํ™•์ธํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ rule set์„ ๋ณด๊ณ  ํ™•์ธํ•ด์•ผ ํ•œ๋‹ค

Rule Set ์„ค์ •ํ•˜๊ธฐ

  • Security Group 1๊ฐœ๋‹น ์ตœ๋Œ€ ๊ทœ์น™ (Rule Set) ์ˆ˜ == 200๊ฐœ

  • EC2 1๊ฐœ ์ตœ๋Œ€ ํ• ๋‹น SG ์ˆ˜ == 5๊ฐœ

    • ์ฆ‰, EC2 1๋Œ€๋‹น ์„ค์ • ๊ฐ€๋Šฅํ•œ ์ตœ๋Œ€ ๊ทœ์น™ (rule set) ์ˆ˜ == 1000๊ฐœ

  • ex) EC2 1๊ฐœ๋‹น SG์„ 10๊ฐœ๊นŒ์ง€ ํ• ๋‹นํ•˜๊ณ  ์‹ถ์–ด!

    • SG 1๊ฐœ๋‹น ๊ทœ์น™ (Rule set)์„ ์ค„์—ฌ์•ผํ•œ๋‹ค

Inbound Rules

  • ์ ‘๊ทผ์„ ํ—ˆ์šฉํ• ์ง€ ๋ง์ง€๋ฅผ ์„ค์ •ํ•˜๋Š” ๊ฒƒ์ด Inbound rule์ด๋‹ค

  • (์šฐ๋ฆฌ๋Š”) Inbound ์ „์ฒด๋ฅผ ๋‹ซ์•„๋†“๊ณ  ํ•„์š”ํ•œ ๊ทœ์น™๋งŒ ์—ด์–ด์ฃผ๋Š” ํ˜•์‹์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋‹ค

    • ๊ถŒํ•œ์„ ํ• ๋‹นํ•  ๋•Œ๋Š” ์ž‘์€ ๊ถŒํ•œ์„ ์ฃผ๊ณ , ๋„“ํ˜€ ๋‚˜๊ฐ€๋Š” ๋ฐฉ์‹์œผ๋กœ ํ•ด์•ผํ•œ๋‹ค!

      • why?

        • ๊ณผ๋„ํ•˜๊ฒŒ ์ฃผ์–ด์ง„ ๊ถŒํ•œ ํ• ๋‹น์„ ์ค„์ด๋Š” ๊ฒƒ์€ ์ ์šฉ๋˜๋Š” ๊ฒƒ๋“ค์„ ๋ชจ๋‘ ์ฐพ์•„๋‚ด์•ผ ํ•˜๋ฏ€๋กœ ์–ด๋ ต๋‹ค

Outbound Rules

  • Outbound rule ๋งˆ์ €๋„ Inbound rule ์ฒ˜๋Ÿผ tight ํ•˜๊ฒŒ ๋ง‰์•„๋ฒ„๋ฆฌ๋ฉด inbound๋„ ๋ด์•ผํ•˜๊ณ  outbound๋„ ๋ด์•ผํ•˜๋ฏ€๋กœ ๋ณต์žก๋„๊ฐ€ ์ฆ๊ฐ€ํ•œ๋‹ค

  • ๋‚ด๋ถ€์—์„œ ๋‚˜๊ฐ€๋Š” traffic์„ ์ œ์–ดํ•  ๊ฒƒ์ธ๊ฐ€๋Š” ๊ณ ๋ฏผํ•ด์•ผํ•  ๋ถ€๋ถ„์ด๋‹ค

    • ์•„๋ฌด ๊ณณ์—๋‚˜ ์š”์ฒญ์„ ๋ณด๋‚ด๋„ ๋˜๋„๋ก ํ—ˆ์šฉํ•  ๊ฒƒ์ธ๊ฐ€?

      • ์—ฌ๊ธฐ์„œ ์•„๋ฌด๊ณณ์€ NAT Gateway๋ฅผ ๋œปํ•œ๋‹ค!

Last updated