すべてのプロダクト
Search
ドキュメントセンター

Cloud Firewall:VPCファイアウォールを作成して、Express Connect回路を使用して接続されている2つのVPC間のトラフィックを保護する

最終更新日:Aug 14, 2024

このトピックでは、Express Connect回路を使用して接続されている2つのVPC間のトラフィックを保護するために、仮想プライベートクラウド (VPC) ファイアウォールを作成する方法について説明します。

使用上の注意

  • Terraformランタイム環境: Alibaba Cloud Shell

  • Terraformバージョン: 0.12

  • alicloudバージョン: 1.203.0

  • リソース定義: cloud_firewall_vpc_firewall

前提条件

  • Alibaba CloudアカウントとAccessKeyペアが作成されます。 詳細については、「AccessKey の作成」をご参照ください。

  • Terraformがインストールされ、設定されます。

手順

  1. Terraformの実行ディレクトリで、terraform.tfファイルを設定します。

    以下にコードの例を示します。

    provider "alicloud" {
      version = "~> 1.203.0"
    }
    
    resource "alicloud_cloud_firewall_vpc_firewall" "default" {
      vpc_firewall_name = "tf-test"
      member_uid        = "141518928482****"
      local_vpc {
        vpc_id    = "vpc-bp1d065m6hzn1xbw8****"
        region_no = "cn-hangzhou"
        local_vpc_cidr_table_list {
          local_route_table_id = "vtb-bp1lj0ddg846856ch****"
          local_route_entry_list {
            local_next_hop_instance_id = "ri-bp1uobww3aputjlww****"
            local_destination_cidr     = "10.XX.XX.0/16"
          }
        }
      }
      peer_vpc {
        vpc_id    = "vpc-bp1gcmm64o3caox84****"
        region_no = "cn-hangzhou"
        peer_vpc_cidr_table_list {
          peer_route_table_id = "vtb-bp1f516f2hh4sok1i****"
          peer_route_entry_list {
            peer_destination_cidr     = "10.XX.XX.0/16"
            peer_next_hop_instance_id = "ri-bp1thhtgf6ydr2or5****"
          }
        }
      }
      status = "open"
    }
  2. terraform initコマンドを実行して、環境を初期化します。

    以下にコードの例を示します。

    Initializing the backend...
    
    Initializing provider plugins...
    - Checking for available provider plugins...
    - Downloading plugin for provider "alicloud" (hashicorp/alicloud) 1.203.0...
    
    
    Warning: registry.terraform.io: For users on Terraform 0.13 or greater, this provider has moved to aliyun/alicloud. Please update your source in required_providers.
    
    
    Terraform has been successfully initialized!
    
    You may now begin working with Terraform. Try running "terraform plan" to see
    any changes that are required for your infrastructure. All Terraform commands
    should now work.
    
    If you ever set or change modules or backend configuration for Terraform,
    rerun this command to reinitialize your working directory. If you forget, other
    commands will detect it and remind you to do so if necessary.

  1. terraform applyコマンドを実行します。 次の情報が表示されたら、情報を確認し、はいと入力してVPCファイアウォールを作成します。

    次のコードは例を提供します。 コードが実行されると、IDがvfw-d7b8ce273791475b **** のVPCファイアウォールが作成されます。

    An execution plan has been generated and is shown below.
    Resource actions are indicated with the following symbols:
      + create
    
    Terraform will perform the following actions:
    
      # alicloud_cloud_firewall_vpc_firewall.default will be created
      + resource "alicloud_cloud_firewall_vpc_firewall" "default" {
          + bandwidth         = (known after apply)
          + connect_type      = (known after apply)
          + id                = (known after apply)
          + lang              = (known after apply)
          + member_uid        = "141518928482****"
          + region_status     = (known after apply)
          + status            = "open"
          + vpc_firewall_id   = (known after apply)
          + vpc_firewall_name = "tf-test"
    
          + local_vpc {
              + eni_id                 = (known after apply)
              + eni_private_ip_address = (known after apply)
              + region_no              = "cn-hangzhou"
              + router_interface_id    = (known after apply)
              + vpc_id                 = "vpc-bp1d065m6hzn1xbw8****"
              + vpc_name               = (known after apply)
    
              + local_vpc_cidr_table_list {
                  + local_route_table_id = "vtb-bp1lj0ddg846856ch****"
    
                  + local_route_entry_list {
                      + local_destination_cidr     = "10.XX.XX.0/16"
                      + local_next_hop_instance_id = "ri-bp1uobww3aputjlww****"
                    }
                }
            }
    
          + peer_vpc {
              + eni_id                 = (known after apply)
              + eni_private_ip_address = (known after apply)
              + region_no              = "cn-hangzhou"
              + router_interface_id    = (known after apply)
              + vpc_id                 = "vpc-bp1gcmm64o3caox84****"
              + vpc_name               = (known after apply)
    
              + peer_vpc_cidr_table_list {
                  + peer_route_table_id = "vtb-bp1f516f2hh4sok1i****"
    
                  + peer_route_entry_list {
                      + peer_destination_cidr     = "10.XX.XX.0/16"
                      + peer_next_hop_instance_id = "ri-bp1thhtgf6ydr2or5****"
                    }
                }
            }
        }
    
    Plan: 1 to add, 0 to change, 0 to destroy.
    
    Do you want to perform these actions?
      Terraform will perform the actions described above.
      Only 'yes' will be accepted to approve.
    
      Enter a value: yes
    
    alicloud_cloud_firewall_vpc_firewall.default: Creating...
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [10s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [20s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [30s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [40s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [50s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [1m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [1m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [1m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [1m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [1m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [1m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [2m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [2m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [2m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [2m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [2m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [2m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [3m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [3m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [3m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [3m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [3m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [3m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [4m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [4m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [4m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [4m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [4m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [4m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [5m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [5m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Still creating... [5m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall.default: Creation complete after 5m26s [id=vfw-d7b8ce273791475b****]
    
    Apply complete! Resources: 1 added, 0 changed, 0 destroyed.

  2. 結果を表示します。

    • terraform showコマンドを実行して、VPCファイアウォールの詳細を表示します。

      # alicloud_cloud_firewall_vpc_firewall.default:
      resource "alicloud_cloud_firewall_vpc_firewall" "default" {
          bandwidth         = 100
          connect_type      = "expressconnect"
          id                = "vfw-d7b8ce273791475b****"
          member_uid        = "141518928482****"
          status            = "open"
          vpc_firewall_id   = "vfw-d7b8ce273791475b****"
          vpc_firewall_name = "tf-test"
      
          local_vpc {
              eni_id                 = "eni-bp1ho0xiqvydpl74****"
              eni_private_ip_address = "10.XX.XX.173"
              region_no              = "cn-hangzhou"
              router_interface_id    = "ri-bp1uobww3aputjlww****"
              vpc_id                 = "vpc-bp1d065m6hzn1xbw8****"
              vpc_name               = "aihan_test_vpc01"
      
              local_vpc_cidr_table_list {
                  local_route_table_id = "vtb-bp1lj0ddg846856ch****"
      
                  local_route_entry_list {
                      local_destination_cidr     = "10.XX.XX.0/16"
                      local_next_hop_instance_id = "ri-bp1uobww3aputjlww****"
                  }
              }
          }
      
          peer_vpc {
              eni_id                 = "eni-bp19qja9ze9zq7gh****"
              eni_private_ip_address = "10.XX.XX.12"
              region_no              = "cn-hangzhou"
              router_interface_id    = "ri-bp1thhtgf6ydr2or5****"
              vpc_id                 = "vpc-bp1gcmm64o3caox84****"
              vpc_name               = "aihan_test_vpc02"
      
              peer_vpc_cidr_table_list {
                  peer_route_table_id = "vtb-bp1f516f2hh4sok1i****"
      
                  peer_route_entry_list {
                      peer_destination_cidr     = "10.XX.XX.0/16"
                      peer_next_hop_instance_id = "ri-bp1thhtgf6ydr2or5****"
                  }
              }
          }
      }
    • [クラウドファイアウォールコンソール] にログインし、[ファイアウォールの設定] ページに移動し、[VPCファイアウォール] タブをクリックします。 次に、ファイアウォールIDを使用してVPCファイアウォールを検索し、VPCファイアウォールの詳細を表示します。