MACsec for Cloud Interconnect ๊ฐœ์š”

MACsec for Cloud Interconnect๋Š” ํŠนํžˆ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ์™€ Google์˜ ์—์ง€ ๋ผ์šฐํ„ฐ ๊ฐ„์˜ Cloud Interconnect ์—ฐ๊ฒฐ์—์„œ ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋ฉ๋‹ˆ๋‹ค. MACsec for Cloud Interconnect๋Š” IEEE ํ‘œ์ค€ 802.1AE Media Access Control Security(MACsec)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ์™€ Google ์—์ง€ ๋ผ์šฐํ„ฐ ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค.

MACsec for Cloud Interconnect๋Š” Google ๋‚ด์—์„œ ์ „์†ก ์ค‘์ธ ๋ฐ์ดํ„ฐ ์•”ํ˜ธํ™”๋ฅผ ์ œ๊ณตํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•ด ์ธํ„ฐ๋„ท ๋ณด์•ˆ ํ”„๋กœํ† ์ฝœ(IPsec) ๋ฐ ์ „์†ก ๊ณ„์ธต ๋ณด์•ˆ(TLS)๊ณผ ๊ฐ™์€ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ํ”„๋กœํ† ์ฝœ๊ณผ ํ•จ๊ป˜ MACsec๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. IPsec๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Google Cloud๋กœ์˜ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ Cloud Interconnect๋ฅผ ํ†ตํ•œ HA VPN ๊ฐœ์š”๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”. ๊ต์ฐจ ์‚ฌ์ดํŠธ Interconnect์˜ ์•”ํ˜ธํ™”์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์•”ํ˜ธํ™” ์˜ต์…˜์„ ์ฐธ์กฐํ•˜์„ธ์š”.

MACsec for Cloud Interconnect๋Š” 10Gbps ๋ฐ 100Gbps ํšŒ์„ ์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ 10Gbps ํšŒ์„ ์˜ MACsec for Cloud Interconnect๋ฅผ ์ฃผ๋ฌธํ•˜๋ ค๋ฉด ๊ณ„์ • ๊ด€๋ฆฌ์ž์—๊ฒŒ ๋ฌธ์˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

MACsec for Cloud Interconnect๋Š” IPv4, IPv6, IPsec์„ ํฌํ•จํ•œ ๋ชจ๋“  VLAN ์—ฐ๊ฒฐ ๊ธฐ๋Šฅ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ ๋‹ค์ด์–ด๊ทธ๋žจ์—์„œ๋Š” MACsec๊ฐ€ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

  • ๊ทธ๋ฆผ 1์—์„œ๋Š” Dedicated Interconnect์—์„œ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•˜๋Š” MACsec๋ฅผ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค. ์ด ๋‹ค์ด์–ด๊ทธ๋žจ์— ํ‘œ์‹œ๋œ ์•”ํ˜ธํ™”๋Š” ๊ต์ฐจ ์‚ฌ์ดํŠธ Interconnect์—๋„ ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.
  • ๊ทธ๋ฆผ 2์—์„œ๋Š” Partner Interconnect์—์„œ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•˜๋Š” MACsec๋ฅผ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.
MACsec๋Š” Google์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ์™€ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ ๊ฐ„์˜ Dedicated Interconnect์—์„œ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค.
๊ทธ๋ฆผ 1. MACsec๋Š” Google์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ์™€ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ ๊ฐ„์— Dedicated Interconnect์˜ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค(ํ™•๋Œ€ํ•˜๋ ค๋ฉด ํด๋ฆญ).


MACsec๋Š” Google์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ์™€ ์„œ๋น„์Šค ์ œ๊ณต์—…์ฒด์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ ๊ฐ„์— Partner Interconnect์˜ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค.
๊ทธ๋ฆผ 2. MACsec๋Š” Google์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ์™€ ์„œ๋น„์Šค ์ œ๊ณต์—…์ฒด์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ ๊ฐ„์— Partner Interconnect์˜ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค (ํ™•๋Œ€ํ•˜๋ ค๋ฉด ํด๋ฆญ).

Partner Interconnect์—์„œ MACsec๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ œ๊ณต์—…์ฒด์™€ ํ˜‘๋ ฅํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์ด ์ œ๊ณต์—…์ฒด ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ์•”ํ˜ธํ™”๋˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

Cloud Interconnect์šฉ MACsec ์‚ฌ์šฉ์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ๋น„์šฉ์€ ์—†์Šต๋‹ˆ๋‹ค.

MACsec for Cloud Interconnect ์ž‘๋™ ๋ฐฉ์‹

Cloud Interconnect์šฉ MACsec๋Š” ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ์™€ Google์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋ฉ๋‹ˆ๋‹ค. Google Cloud CLI(gcloud CLI) ๋˜๋Š” Google Cloud ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜์—ฌ GCM-AES-256 ์—ฐ๊ฒฐ ํ‚ค(CAK)์™€ ์—ฐ๊ฒฐ ํ‚ค ์ด๋ฆ„(CKN) ๊ฐ’์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. CAK ๋ฐ CKN ๊ฐ’์„ ์‚ฌ์šฉํ•˜์—ฌ MACsec๋ฅผ ๊ตฌ์„ฑํ•˜๋„๋ก ๋ผ์šฐํ„ฐ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ๋ผ์šฐํ„ฐ์™€ Cloud Interconnect์—์„œ MACsec๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜๋ฉด MACsec์—์„œ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ์™€ Google์˜ ํ”ผ์–ด๋ง ์—์ง€ ๋ผ์šฐํ„ฐ ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค.

์•”ํ˜ธํ™”์—๋Š” ๊ณ„์ธตํ™”๋œ ๋ณด์•ˆ ์ ‘๊ทผ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. ๋ ˆ์ด์–ด 2์—์„œ MACsec๋Š” ์ธ์ ‘ํ•œ ๋ผ์šฐํ„ฐ ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์„ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค. ๋ ˆ์ด์–ด 3์—์„œ IPsec๋Š” ๊ณ ๊ฐ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ์™€ VPC ๋„คํŠธ์›Œํฌ ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ์„ ๋ณดํ˜ธํ•ฉ๋‹ˆ๋‹ค. ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ˆ˜์ค€ ๋ณด์•ˆ ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜์—ฌ ์ถ”๊ฐ€ ๋ณดํ˜ธ๋ฅผ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ง€์›๋˜๋Š” ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ

๋‹ค์Œ ํ‘œ์— ๋‚˜์—ด๋œ MACsec ์‚ฌ์–‘์„ ์ง€์›ํ•˜๋Š” MACsec for Cloud Interconnect์™€ ํ•จ๊ป˜ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์„ค์ • ๊ฐ’
MACsec ์•”ํ˜ธํ™” ์Šค์œ„ํŠธ
  • GCM-AES-256-XPN
  • GCM-AES-256
CAK ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ AES_256_CMAC
ํ‚ค ์„œ๋ฒ„ ์šฐ์„ ์ˆœ์œ„ 15
๋ณด์•ˆ ์—ฐ๊ฒฐ ํ‚ค(SAK) ํ‚ค ๊ฐฑ์‹  ๊ฐ„๊ฒฉ 28800์ดˆ
MACsec ๋น„๋ฐ€์œ ์ง€ ์˜คํ”„์…‹ 0
์ฐฝ ํฌ๊ธฐ 64
๋ฌด๊ฒฐ์„ฑ ๊ฒ€์‚ฌ ๊ฐ’(ICV) ํ‘œ์‹œ๊ธฐ ์˜ˆ
๋ณด์•ˆ ์ฑ„๋„ ์‹๋ณ„์ž(SCI) ์‚ฌ์šฉ ์„ค์ •๋จ

MACsec for Cloud Interconnect๋Š” ์ตœ๋Œ€ 5๊ฐœ์˜ ํ‚ค์— ๋Œ€ํ•ด ์ž๋™ ํ‚ค ์ˆœํ™˜์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

Cisco, Juniper, Arista์—์„œ ์ œ์กฐํ•œ ์—ฌ๋Ÿฌ ๋ผ์šฐํ„ฐ๊ฐ€ ์‚ฌ์–‘์„ ์ถฉ์กฑํ•ฉ๋‹ˆ๋‹ค. Google์—์„œ๋Š” ํŠน์ • ๋ผ์šฐํ„ฐ๋ฅผ ๊ถŒ์žฅํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋ผ์šฐํ„ฐ ๊ณต๊ธ‰์—…์ฒด์— ๋ฌธ์˜ํ•˜์—ฌ ๋‹ˆ์ฆˆ์— ๊ฐ€์žฅ ์ ํ•ฉํ•œ ๋ชจ๋ธ์„ ๊ฒฐ์ •ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

MACsec for Cloud Interconnect๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์ „์—

๋‹ค์Œ ์š”๊ตฌ์‚ฌํ•ญ์„ ์ถฉ์กฑํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  • ๋„คํŠธ์›Œํฌ ํšŒ์„ ์„ ์ •๋ ฌํ•˜๊ณ  ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ธฐ๋ณธ ๋„คํŠธ์›Œํฌ ์ƒํ˜ธ ์—ฐ๊ฒฐ์„ ์ดํ•ดํ•ฉ๋‹ˆ๋‹ค.

  • Dedicated Interconnect์™€ Partner Interconnect์˜ ์ฐจ์ด์ ๊ณผ ์š”๊ตฌ์‚ฌํ•ญ์„ ์ดํ•ดํ•ฉ๋‹ˆ๋‹ค.

  • ์˜จํ”„๋ ˆ๋ฏธ์Šค ์—์ง€ ๋ผ์šฐํ„ฐ์— ๋Œ€ํ•œ ๊ด€๋ฆฌ์ž ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  • ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ MACsec๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

MACsec for Cloud Interconnect ์„ค์ • ๋‹จ๊ณ„

MACsec for Cloud Interconnect๋ฅผ ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•œ ํ›„ MACsec ์ง€์› Cloud Interconnect ์—ฐ๊ฒฐ์ด ์ด๋ฏธ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด MACsec ์ง€์› Cloud Interconnect ์—ฐ๊ฒฐ์„ ์ฃผ๋ฌธํ•ฉ๋‹ˆ๋‹ค. ๊ต์ฐจ ์‚ฌ์ดํŠธ Interconnect๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์—ฐ๊ฒฐ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ MACsec๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

Cloud Interconnect ์—ฐ๊ฒฐ์—์„œ ํ…Œ์ŠคํŠธ๋ฅผ ์™„๋ฃŒํ•˜๊ณ  ์ด ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•  ์ค€๋น„๊ฐ€ ๋˜๋ฉด MACsec ์‚ฌ์ „ ๊ณต์œ  ํ‚ค๋ฅผ ๋งŒ๋“ค๊ณ  ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋ผ์šฐํ„ฐ๋ฅผ ๊ตฌ์„ฑํ•˜์—ฌ MACsec๋ฅผ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ MACsec๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜์—ฌ ๋งํฌ์— ์‚ฌ์šฉ ์„ค์ •๋˜์–ด ์žˆ๊ณ  ๋งํฌ๊ฐ€ ์ž‘๋™๋˜๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋งˆ์ง€๋ง‰์œผ๋กœ MACsec ์—ฐ๊ฒฐ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ž‘๋™ํ•˜๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

MACsec ๊ฐ€์šฉ์„ฑ

MACsec for Cloud Interconnect๋Š” ์œ„์น˜์— ๊ด€๊ณ„์—†์ด ๋ชจ๋“  Cloud Interconnect 100Gbps ์—ฐ๊ฒฐ์—์„œ ์ง€์›๋ฉ๋‹ˆ๋‹ค.

10Gbps ํšŒ์„ ์˜ ๋ชจ๋“  ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ MACsec for Cloud Interconnect๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์—ฐ๊ฒฐ ์œ ํ˜•์— ๋”ฐ๋ผ ๋‹ค์Œ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

MACsec for Cloud Interconnect๋ฅผ ์ง€์›ํ•˜๋Š” 10Gbps ํšŒ์„ ์˜ ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์„ ํ™•์ธํ•˜๋ ค๋ฉด ๋‹ค์Œ์„ ์ˆ˜ํ–‰ํ•˜์„ธ์š”. 10Gbps ํšŒ์„ ์˜ MACsec ๊ฐ€์šฉ์„ฑ์€ ํ—ˆ์šฉ ๋ชฉ๋ก์— ํฌํ•จ๋œ ํ”„๋กœ์ ํŠธ์—๋งŒ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. 10Gbps ํšŒ์„ ์˜ MACsec for Cloud Interconnect๋ฅผ ์ฃผ๋ฌธํ•˜๋ ค๋ฉด ๊ณ„์ • ๊ด€๋ฆฌ์ž์—๊ฒŒ ๋ฌธ์˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ฝ˜์†”

  1. Google Cloud ์ฝ˜์†”์—์„œ Cloud Interconnect ์‹ค์ œ ์—ฐ๊ฒฐ ํƒญ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

    ์‹ค์ œ ์—ฐ๊ฒฐ๋กœ ์ด๋™

  2. ์‹ค์ œ ์—ฐ๊ฒฐ ์„ค์ •์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. Dedicated Interconnect๋ฅผ ์„ ํƒํ•˜๊ณ  ๊ณ„์†์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  4. ์ƒˆ Dedicated Interconnect ์ฃผ๋ฌธ์„ ์„ ํƒํ•˜๊ณ  ๊ณ„์†์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  5. Google Cloud ์œ„์น˜ ํ•„๋“œ์—์„œ ์„ ํƒ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  6. ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค ์„ ํƒ ์ฐฝ์—์„œ Cloud Interconnect ์—ฐ๊ฒฐ์„ ์„ค์ •ํ•  ๋„์‹œ๋ฅผ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ง€๋ฆฌ์  ์œ„์น˜ ํ•„๋“œ์—์„œ ์ง€๋ฆฌ์  ์ง€์—ญ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ ํ”„๋กœ์ ํŠธ์— ๋Œ€ํ•œ MACsec ์ง€์› ์—ด์—๋Š” Cloud Interconnect์šฉ MACsec์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ํšŒ์„  ํฌ๊ธฐ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

gcloud

  1. Google Cloud CLI์— ์ธ์ฆํ•ฉ๋‹ˆ๋‹ค.

    gcloud auth login
    
  2. ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์ด MACsec for Cloud Interconnect๋ฅผ ์ง€์›ํ•˜๋Š”์ง€ ํ™•์ธํ•˜๋ ค๋ฉด ๋‹ค์Œ ์ค‘ ํ•˜๋‚˜๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    • ํŠน์ • ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์ด MACsec for Cloud Interconnect๋ฅผ ์ง€์›ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

      gcloud compute interconnects locations describe COLOCATION_FACILITY
      

      COLOCATION_FACILITY๋ฅผ ์œ„์น˜ ํ‘œ์— ๋‚˜์—ด๋œ ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

      ์ถœ๋ ฅ์€ ๋‹ค์Œ ์ƒ˜ํ”Œ๊ณผ ๋น„์Šทํ•ฉ๋‹ˆ๋‹ค. availableFeatures ์„น์…˜์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. MACsec ์ง€์› ์—ฐ๊ฒฐ์—์„œ ๋‹ค์Œ์„ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.

      • 10Gbps ๋งํฌ: linkType: LINK_TYPE_ETHERNET_10G_LR ๋ฐ availableFeatures: IF_MACSEC
      • 100Gbps ๋งํฌ: linkType: LINK_TYPE_ETHERNET_100G_LR, MACsec์—์„œ ์ง€์›ํ•˜๋Š” ๋ชจ๋“  100Gbps
      address: |-
        Equinix
        47 Bourke Road
        Alexandria
        Sydney, New South Wales 2015
        Australia
      availabilityZone: zone1
      availableFeatures:
      - IF_MACSEC
      availableLinkTypes:
      - LINK_TYPE_ETHERNET_10G_LR
      - LINK_TYPE_ETHERNET_100G_LR
      city: Sydney
      continent: C_ASIA_PAC
      creationTimestamp: '2019-12-05T12:56:15.000-08:00'
      description: Equinix Sydney (SY3)
      facilityProvider: Equinix
      facilityProviderFacilityId: SY3
      id: '1173'
      kind: compute#interconnectLocation
      name: syd-zone1-1605
      peeringdbFacilityId: '1605'
      regionInfos:
      - region: https://www.googleapis.com/compute/v1/projects/my-project/regions/australia-southeast1
      - region: https://www.googleapis.com/compute/v1/projects/my-project/regions/australia-southeast2
      - region: https://www.googleapis.com/compute/v1/projects/my-project/regions/us-east7
      selfLink: https://www.googleapis.com/compute/v1/projects/my-project/global/interconnectLocations/syd-zone1-1605
      status: AVAILABLE
      
    • 10Gbps ํšŒ์„ ์—์„œ MACsec for Cloud Interconnect๋ฅผ ์ง€์›ํ•˜๋Š” ๋ชจ๋“  ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.

      gcloud compute interconnects locations list \
          --filter "availableFeatures: (IF_MACSEC)"
      

      ์ถœ๋ ฅ์€ ๋‹ค์Œ๊ณผ ๋น„์Šทํ•ฉ๋‹ˆ๋‹ค.

      NAME                  DESCRIPTION              FACILITY_PROVIDER
      ... <stripped>
      syd-zone1-1605        Equinix Sydney (SY3)     Equinix
      ... <stripped>
      
    • 100Gbps ๋งํฌ๊ฐ€ ์žˆ๋Š” ๋ชจ๋“  ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์„ ๋‚˜์—ดํ•˜๋ฏ€๋กœ ๊ธฐ๋ณธ์ ์œผ๋กœ MACsec๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

      gcloud compute interconnects locations list \
          --filter "availableLinkTypes: (LINK_TYPE_ETHERNET_100G_LR)"
      

      ์ถœ๋ ฅ์€ ๋‹ค์Œ๊ณผ ๋น„์Šทํ•ฉ๋‹ˆ๋‹ค.

      NAME                  DESCRIPTION              FACILITY_PROVIDER
      ... <stripped>
      syd-zone1-1605        Equinix Sydney (SY3)     Equinix
      ... <stripped>
      

๊ธฐ์กด Cloud Interconnect ์—ฐ๊ฒฐ์— MACsec ์ง€์›

MACsec for Cloud Interconnect๋Š” ๊ธฐ์กด 100Gbps Cloud Interconnect ์—ฐ๊ฒฐ์—์„œ ์ง€์›๋ฉ๋‹ˆ๋‹ค.

10Gbps ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ MACsec ๊ฐ€์šฉ์„ฑ์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ MACsec ์ง€์›์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ, Cloud Interconnect๊ฐ€ MACsec๋ฅผ ์ง€์›ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ์กด Cloud Interconnect ์—ฐ๊ฒฐ์—์„œ MACsec๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ MACsec๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‚˜์š”?

์ฝ”๋กœ์ผ€์ด์…˜ ์‹œ์„ค์—์„œ MACsec๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š์œผ๋ฉด ๋‹ค์Œ ์ค‘ ํ•˜๋‚˜๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • ์ƒˆ Cloud Interconnect ์—ฐ๊ฒฐ์„ ์š”์ฒญํ•˜๊ณ  MACsec๋ฅผ ํ•„์ˆ˜ ๊ธฐ๋Šฅ์œผ๋กœ ์š”์ฒญํ•ฉ๋‹ˆ๋‹ค.

  • Google Cloud ๊ณ„์ • ๊ด€๋ฆฌ์ž์—๊ฒŒ ๋ฌธ์˜ํ•˜์—ฌ ๊ธฐ์กด Cloud Interconnect ์—ฐ๊ฒฐ์„ MACsec ์ง€์› ํฌํŠธ๋กœ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ํ•˜๋Š” ์ž‘์—…์„ ์˜ˆ์•ฝํ•ฉ๋‹ˆ๋‹ค.

์˜ˆ์•ฝ ์ œ์•ฝ์กฐ๊ฑด์œผ๋กœ ์ธํ•ด ๋ฌผ๋ฆฌ์ ์œผ๋กœ ์—ฐ๊ฒฐ์„ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ํ•˜๋Š” ๋ฐ ๋ช‡ ์ฃผ ์ •๋„ ๊ฑธ๋ฆด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ํ•˜๋ ค๋ฉด Cloud Interconnect ์—ฐ๊ฒฐ์— ํ”„๋กœ๋•์…˜ ํŠธ๋ž˜ํ”ฝ์ด ์—†๋Š” ์œ ์ง€๋ณด์ˆ˜ ๊ธฐ๊ฐ„์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ ๋‹จ๊ณ„