Network ACLS

Network ACL ์ž์„ธ-ํžˆ ์•Œ์•„๋ณด๊ธฐ ์‹ค๋ฌด ver.

Before getting started

๋ฐฉํ™”๋ฒฝ ์™ธ์— Network๋ฅผ ์ œ์–ดํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ

  • Routing Table

    • Packet์„ ์–ด๋””๋กœ ๋ณด๋‚ผ์ง€ ์ œ์–ด

  • Network ACL

    • ๊ทœ์น™์— ๋”ฐ๋ผ packet์„ ์ „์†ก or ์ฐจ๋‹จ

What are Network ACLS?

  • ์–ด๋–ค packet์„ ์ฐจ๋‹จํ• ์ง€ ๋ง์ง€์— ๋Œ€ํ•œ ๊ทœ์น™

  • ์„ค์ •ํ•œ ๊ทœ์น™์€ ๋ชจ๋“  resource์— ์ ์šฉ๋˜๋ฏ€๋กœ ๋งŽ์ด ์„ค์ •ํ•  ์ˆ˜ ์—†๋‹ค

    • ํ•ด๋‹น subnet์˜ ๋ชจ๋“  resource์— ์ ์šฉ๋œ๋‹ค

      • ๊ทธ๋ ‡๊ธฐ ๋•Œ๋ฌธ์—, Network ACL์„ ์ž˜ ์„ค๊ณ„ํ•ด์•ผํ•œ๋‹ค

        • why? ๋ฐฉํ™”๋ฒฝ(SG)์€ ์ œ๋Œ€๋กœ ์„ค์ •ํ–ˆ๋Š”๋ฐ Network ACL์— Deny Rule์ด ์žˆ์–ด์„œ ์ ‘๊ทผ ๋ถˆ๊ฐ€์ผ ์ˆ˜๋„ ์žˆ๋‹ค

  • Network ACL ๊ทœ์น™์ด ๋งŽ์•„์งˆ ์ˆ˜๋ก ๋ฐฉํ™”๋ฒฝ ์„ค์ •์— ์žˆ์–ด์„œ ํ—ท๊ฐˆ๋ฆฌ๊ฒŒ ๋˜๋ฏ€๋กœ Network ACL์€ ์ตœ๋Œ€ํ•œ ๊ฐ„๊ฒฐํ•œ ๊ทœ์น™์œผ๋กœ ๊ฐ€์ ธ๊ฐ€๋Š” ๊ฒƒ์ด ์ข‹๋‹ค

    • ๋ฐฉํ™”๋ฒฝ ์„ค์ •์„ ์ž˜ํ•˜๋ฉด Network ACL ์„ ๋”ฐ๋กœ ์„ค์ •ํ•˜์ง€ ์•Š์•„๋„ ๋œ๋‹ค!

Rule number in Network ACLs

  • Network ACL ๊ทœ์น™์—๋Š” ์šฐ์„ ์ˆœ์œ„๊ฐ€ ์žˆ๋‹ค

    • ์šฐ์„ ์ˆœ์œ„ (Rule number)๊ฐ€ ๋†’์€ ์ˆœ์„œ๋กœ ์ ์šฉ ๋ฐ›๋Š”๋‹ค!

Network ACL๊ณผ Well known Port

  • Network Inbound rule์—์„œ Port Range์— 1024 - 65535๋ฅผ ํ—ˆ์šฉํ•ด๋†“๋Š” ์ด์œ 

Last updated