๋™์  ๋ผ์šฐํŒ…์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ธฐ๋ณธ VPN ๊ฒŒ์ดํŠธ์›จ์ด ๋งŒ๋“ค๊ธฐ

์ด ํŽ˜์ด์ง€์—์„œ๋Š” ๋™์  ๋ผ์šฐํŒ…์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฒฝ๊ณ„ ๊ฒŒ์ดํŠธ์›จ์ด ํ”„๋กœํ† ์ฝœ(BGP)์„ ์‚ฌ์šฉํ•˜๋Š” ํ„ฐ๋„ 1๊ฐœ์™€ ๊ธฐ๋ณธ VPN ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ๋งŒ๋“œ๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

๋™์  ๋ผ์šฐํŒ…์„ ์‚ฌ์šฉํ•  ๋•Œ๋Š” ๋กœ์ปฌ ๋˜๋Š” ์›๊ฒฉ ํŠธ๋ž˜ํ”ฝ ์„ ํƒ๊ธฐ๋ฅผ ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉฐ, ๋Œ€์‹  Cloud Router๋ฅผ ์‚ฌ์šฉํ•˜์„ธ์š”. ๊ฒฝ๋กœ ์ •๋ณด๋Š” ๋™์ ์œผ๋กœ ๊ตํ™˜๋ฉ๋‹ˆ๋‹ค.

Cloud VPN์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋‹ค์Œ ๋ฆฌ์†Œ์Šค๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

  • Cloud VPN ์„ค์ • ์ „์— ๊ณ ๋ คํ•ด์•ผ ํ•  ๊ถŒ์žฅ์‚ฌํ•ญ์€ ๊ถŒ์žฅ์‚ฌํ•ญ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

  • Cloud VPN์— ๋Œ€ํ•œ ์ƒ์„ธ ์„ค๋ช…์€ Cloud VPN ๊ฐœ์š”๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

  • ์ด ํŽ˜์ด์ง€์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์šฉ์–ด์˜ ์ •์˜๋Š” ์ฃผ์š” ์šฉ์–ด๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

์š”๊ตฌ์‚ฌํ•ญ

์ผ๋ฐ˜ ๊ฐ€์ด๋“œ๋ผ์ธ

  • Google Cloud์—์„œ ๋™์  ๋ผ์šฐํŒ…์ด ์ž‘๋™ํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๊ฒ€ํ† ํ•ฉ๋‹ˆ๋‹ค.
  • ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ BGP๋ฅผ ์ง€์›ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • ๊ธฐ๋ณธ VPN ํ† ํด๋กœ์ง€ ์ƒ˜ํ”Œ์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

Compute Engine VM์— ํƒ€์‚ฌ VPN ์†Œํ”„ํŠธ์›จ์–ด ์„ค์น˜

๋™์  ๋ผ์šฐํŒ…์œผ๋กœ ๊ธฐ๋ณธ VPN ํ„ฐ๋„์„ ๋งŒ๋“ค ๋•Œ๋Š” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด ์ธํ„ฐํŽ˜์ด์Šค์— ์ง€์ •ํ•˜๋Š” IP ์ฃผ์†Œ๋ฅผ Compute Engine VM์— ํ• ๋‹นํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ ๊ธฐ๋ณธ VPN ํ„ฐ๋„์„ ๋งŒ๋“ค๋ ค๋ฉด ๋จผ์ € Compute Engine VM์— ํƒ€์‚ฌ VPN ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์„ค์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ณธ VPN ํ„ฐ๋„์„ ๊ตฌ์„ฑํ•  ๋•Œ๋Š” Compute Engine VM์˜ ์™ธ๋ถ€ IP ์ฃผ์†Œ๋ฅผ ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด ์ธํ„ฐํŽ˜์ด์Šค๋กœ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

๋˜ํ•œ Google์ด ์†Œ์œ ํ•œ ๋ฆฌ์ „๋ณ„ ์™ธ๋ถ€ IPv4 ์ฃผ์†Œ ํ’€์—์„œ ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด ์ธํ„ฐํŽ˜์ด์Šค์˜ IP ์ฃผ์†Œ๋ฅผ ํ• ๋‹นํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. IP ์ฃผ์†Œ๋Š” ์ž์ฒด IP ์ฃผ์†Œ ์‚ฌ์šฉ(BYOIP) ๋ฒ”์œ„์— ํฌํ•จ๋  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

Cloud Router ๋งŒ๋“ค๊ธฐ

๊ธฐ๋ณธ VPN์— ๋™์  ๋ผ์šฐํŒ…์„ ์‚ฌ์šฉํ•˜๋Š” ํ„ฐ๋„์„ ๋งŒ๋“ค๋ ค๋ฉด Cloud Router๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ƒˆ Cloud Router๋ฅผ ๋งŒ๋“ค๊ฑฐ๋‚˜ ๊ธฐ์กด Cloud VPN ํ„ฐ๋„ ๋˜๋Š” VLAN ์—ฐ๊ฒฐ์— ๊ธฐ์กด Cloud Router๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ฒจ๋ถ€์˜ ํŠน์ • ASN ์š”๊ตฌ์‚ฌํ•ญ์œผ๋กœ ์ธํ•ด ์‚ฌ์šฉํ•˜๋Š” Cloud Router๊ฐ€ Partner Interconnect ์—ฐ๊ฒฐ๊ณผ ์—ฐ๊ด€๋œ VLAN ์—ฐ๊ฒฐ์— ๋Œ€ํ•œ BGP ์„ธ์…˜์„ ์ด๋ฏธ ๊ด€๋ฆฌํ•˜๊ณ  ์žˆ์ง€ ์•Š์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

Cloud VPN์„ ๋ณด๋‹ค ์‰ฝ๊ฒŒ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ๋„๋ก Google Cloud ์—์„œ ๋‹ค์Œ ํ•ญ๋ชฉ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

  1. Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. Install the Google Cloud CLI.

  5. ์™ธ๋ถ€ ID ๊ณต๊ธ‰์—…์ฒด (IdP)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ๋จผ์ € ์ œํœด ID๋กœ gcloud CLI์— ๋กœ๊ทธ์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  6. gcloud CLI๋ฅผ ์ดˆ๊ธฐํ™”ํ•˜๋ ค๋ฉด, ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    gcloud init
  7. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Go to project selector

  8. Verify that billing is enabled for your Google Cloud project.

  9. Install the Google Cloud CLI.

  10. ์™ธ๋ถ€ ID ๊ณต๊ธ‰์—…์ฒด (IdP)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ๋จผ์ € ์ œํœด ID๋กœ gcloud CLI์— ๋กœ๊ทธ์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

  11. gcloud CLI๋ฅผ ์ดˆ๊ธฐํ™”ํ•˜๋ ค๋ฉด, ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    gcloud init
    1. Google Cloud CLI๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋กœ์ ํŠธ ID๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์ด ํŽ˜์ด์ง€์˜ gcloud ๊ด€๋ จ ์•ˆ๋‚ด์—์„œ๋Š” ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๊ธฐ ์ „์— ํ”„๋กœ์ ํŠธ ID๋ฅผ ์„ค์ •ํ–ˆ๋‹ค๊ณ  ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค.

          gcloud config set project PROJECT_ID
          
    1. ๋˜ํ•œ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ด๋ฏธ ์„ค์ •๋œ ํ”„๋กœ์ ํŠธ ID๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

          gcloud config list --format='text(core.project)'
          

    ์ปค์Šคํ…€ VPC ๋„คํŠธ์›Œํฌ ๋ฐ ์„œ๋ธŒ๋„ท ๋งŒ๋“ค๊ธฐ

    ๊ธฐ๋ณธ VPN ๊ฒŒ์ดํŠธ์›จ์ด ๋ฐ ํ„ฐ๋„์„ ๋งŒ๋“ค๊ธฐ ์ „์— ๊ธฐ๋ณธ VPN ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ์žˆ๋Š” ๋ฆฌ์ „์— ํ•˜๋‚˜์˜ Virtual Private Cloud(VPC) ๋„คํŠธ์›Œํฌ์™€ ํ•˜๋‚˜ ์ด์ƒ์˜ ์„œ๋ธŒ๋„ท์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    ๊ฒŒ์ดํŠธ์›จ์ด ๋ฐ ํ„ฐ๋„ ๋งŒ๋“ค๊ธฐ

    ์ฝ˜์†”

    ๊ฒŒ์ดํŠธ์›จ์ด ๊ตฌ์„ฑ

    1. Google Cloud ์ฝ˜์†”์—์„œ VPN ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
      VPN ํŽ˜์ด์ง€๋กœ ์ด๋™
      1. ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ์ฒ˜์Œ ๋งŒ๋“œ๋Š” ๊ฒฝ์šฐ VPN ์—ฐ๊ฒฐ ๋งŒ๋“ค๊ธฐ ๋ฒ„ํŠผ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
      2. VPN ์„ค์ • ๋งˆ๋ฒ•์‚ฌ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    2. ๊ธฐ๋ณธ VPN ๋ผ๋””์˜ค ๋ฒ„ํŠผ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    3. ๊ณ„์†์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
    4. VPN ์—ฐ๊ฒฐ ๋งŒ๋“ค๊ธฐ ํŽ˜์ด์ง€์—์„œ ๋‹ค์Œ ๊ฒŒ์ดํŠธ์›จ์ด ์„ค์ •์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.
      • ์ด๋ฆ„ - VPN ๊ฒŒ์ดํŠธ์›จ์ด์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์ด๋ฆ„์€ ๋‚˜์ค‘์— ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
      • ์„ค๋ช… - ์›ํ•  ๊ฒฝ์šฐ ์„ค๋ช…์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
      • ๋„คํŠธ์›Œํฌ - VPN ๊ฒŒ์ดํŠธ์›จ์ด์™€ ํ„ฐ๋„์„ ๋งŒ๋“ค ๊ธฐ์กด VPC ๋„คํŠธ์›Œํฌ๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.
      • ๋ฆฌ์ „ - Cloud VPN ๊ฒŒ์ดํŠธ์›จ์ด ๋ฐ ํ„ฐ๋„์€ ๋ฆฌ์ „๋ณ„ ๊ฐœ์ฒด์ž…๋‹ˆ๋‹ค. ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ์œ„์น˜ํ•  Google Cloud๋ฆฌ์ „์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ๋ฆฌ์ „์— ์žˆ๋Š” ์ธ์Šคํ„ด์Šค ๋ฐ ๋‹ค๋ฅธ ๋ฆฌ์†Œ์Šค๋Š” ๊ฒฝ๋กœ ์ˆœ์„œ์— ๋”ฐ๋ผ ์ด๊ทธ๋ ˆ์Šค ํŠธ๋ž˜ํ”ฝ์— ํ„ฐ๋„์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ตœ์ƒ์˜ ์„ฑ๋Šฅ์„ ์›ํ•œ๋‹ค๋ฉด ๊ด€๋ จ Google Cloud ๋ฆฌ์†Œ์Šค์™€ ๋™์ผํ•œ ๋ฆฌ์ „์—์„œ ๊ฒŒ์ดํŠธ์›จ์ด์™€ ํ„ฐ๋„์„ ์ฐพ์œผ์„ธ์š”.
      • IP ์ฃผ์†Œ - ๋ฆฌ์ „๋ณ„ ์™ธ๋ถ€ IP ์ฃผ์†Œ๋ฅผ ๋งŒ๋“ค๊ฑฐ๋‚˜ ๊ธฐ์กด ์ฃผ์†Œ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    ํ„ฐ๋„ ๊ตฌ์„ฑ

    1. ์ƒˆ ํ„ฐ๋„ ํ•ญ๋ชฉ์— ๋Œ€ํ•ด ํ„ฐ๋„ ์„น์…˜์—์„œ ๋‹ค์Œ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

      • ์ด๋ฆ„ - VPN ํ„ฐ๋„์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์ด๋ฆ„์€ ๋‚˜์ค‘์— ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
      • ์„ค๋ช… - ์„ ํƒ์ ์œผ๋กœ ์„ค๋ช…์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
      • ์›๊ฒฉ ํ”ผ์–ด IP ์ฃผ์†Œ โ€” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์˜ ์™ธ๋ถ€ IP ์ฃผ์†Œ๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.
      • IKE ๋ฒ„์ „ - ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ์ง€์›ํ•˜๋Š” ์ ์ ˆํ•œ IKE ๋ฒ„์ „์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ํ”ผ์–ด ๊ธฐ๊ธฐ์—์„œ ์ง€์›๋˜๋Š” ๊ฒฝ์šฐ IKEv2๊ฐ€ ๊ถŒ์žฅ๋ฉ๋‹ˆ๋‹ค.

      • ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ - ์ธ์ฆ์„ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ์‚ฌ์ „ ๊ณต์œ  ํ‚ค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. Cloud VPN ํ„ฐ๋„์˜ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ์ƒ๋Œ€ ํ„ฐ๋„์„ ๊ตฌ์„ฑํ•  ๋•Œ ์‚ฌ์šฉํ•œ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ์™€ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ์ง€์นจ์— ๋”ฐ๋ผ ์•”ํ˜ธ์ ์œผ๋กœ ๊ฐ•๋ ฅํ•œ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

      • ๋ผ์šฐํŒ… ์˜ต์…˜ - ๋™์ (BGP)์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ๋™์  ๋ผ์šฐํŒ…๋งŒ ์‚ฌ์šฉํ•˜์—ฌ Google Cloud VM ์ธ์Šคํ„ด์Šค ๋‚ด์—์„œ ์‹คํ–‰๋˜๋Š” ์„œ๋“œ ํŒŒํ‹ฐ VPN ๊ฒŒ์ดํŠธ์›จ์ด ์†Œํ”„ํŠธ์›จ์–ด์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

      • Cloud Router - ์•„์ง Cloud Router๋ฅผ ๋งŒ๋“ค์ง€ ์•Š์€ ๊ฒฝ์šฐ ์•„๋ž˜์˜ ์„ค๋ช…๋Œ€๋กœ ์˜ต์…˜์„ ์ง€์ •ํ•˜์—ฌ ์ƒˆ Cloud Router๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ๋˜๋Š” Cloud Router๊ฐ€ Partner Interconnect์™€ ์—ฐ๊ฒฐ๋œ Interconnect ์—ฐ๊ฒฐ์— ๋Œ€ํ•œ BGP ์„ธ์…˜์„ ๊ด€๋ฆฌํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ ๊ธฐ์กด Cloud Router๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ธฐ์กด Cloud Router๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ์ƒˆ BGP ์„ธ์…˜์ด ์ƒ์„ฑ๋˜์ง€๋งŒ Google ASN์ด ๋™์ผํ•ฉ๋‹ˆ๋‹ค. ์ƒˆ Cloud Router๋ฅผ ๋งŒ๋“ค๋ ค๋ฉด ๋‹ค์Œ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

        • ์ด๋ฆ„ โ€” Cloud Router ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์ด๋ฆ„์€ ๋‚˜์ค‘์— ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
        • ์„ค๋ช… - ์„ ํƒ์ ์œผ๋กœ ์„ค๋ช…์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
        • Google ASN โ€” ๋น„๊ณต๊ฐœ ASN์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค(64512~65534, 4200000000~4294967294). ์ด Google ASN์€ Cloud Router์—์„œ ๊ด€๋ฆฌ๋˜๋Š” ๋ชจ๋“  BGP ์„ธ์…˜์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ASN์€ ๋‚˜์ค‘์— ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
        • ์ €์žฅ ํ›„ ๊ณ„์†์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
      • BGP ์„ธ์…˜ - ์—ฐํ•„ ์•„์ด์ฝ˜์„ ํด๋ฆญํ•œ ํ›„ ๋‹ค์Œ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค. ์™„๋ฃŒ๋˜์—ˆ์œผ๋ฉด ์ €์žฅ ํ›„ ๊ณ„์†์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

        • ์ด๋ฆ„ - BGP ์„ธ์…˜์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ๋‚˜์ค‘์— ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
        • ํ”ผ์–ด ASN โ€” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ์‚ฌ์šฉํ•˜๋Š” ๊ณต๊ฐœ ๋˜๋Š” ๋น„๊ณต๊ฐœ(64512~65534, 4200000000~4294967294) ASN์ž…๋‹ˆ๋‹ค.
        • ๊ณต์ง€๋œ ๊ฒฝ๋กœ ์šฐ์„ ์ˆœ์œ„ - (์„ ํƒ์‚ฌํ•ญ) 'Google Cloud์— ์—ฐ๊ฒฐ' ๊ฒฝ๋กœ๋ฅผ ๊ณต์ง€ํ•  ๋•Œ Cloud Router๊ฐ€ ์‚ฌ์šฉํ•˜๋Š” ๊ธฐ๋ณธ ์šฐ์„ ์ˆœ์œ„์ž…๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๊ณต์ง€๋œ ํ”„๋ฆฌํ”ฝ์Šค ๋ฐ ์šฐ์„ ์ˆœ์œ„๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”. ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด๋Š” ์ด๋ฅผ MED VPN ๊ฐ’์œผ๋กœ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
        • Cloud Router BGP IP ๋ฐ BGP ํ”ผ์–ด IP - 2๊ฐœ์˜ BGP ์ธํ„ฐํŽ˜์ด์Šค IP ์ฃผ์†Œ๋Š” 169.254.0.0/16 ๋ธ”๋ก์˜ ๊ณตํ†ต /30 CIDR์— ์†ํ•˜๋Š” ๋งํฌ-๋กœ์ปฌ IP ์ฃผ์†Œ์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ BGP IP๋Š” ๊ฒฝ๋กœ ์ •๋ณด ๊ตํ™˜์„ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ํ•ด๋‹น ๋งํฌ-๋กœ์ปฌ IP๋ฅผ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด 169.254.1.1 ๋ฐ 169.254.1.2๋Š” ๊ณตํ†ต /30 ๋ธ”๋ก์— ์†ํ•ฉ๋‹ˆ๋‹ค.
    2. ๋™์ผํ•œ ๊ฒŒ์ดํŠธ์›จ์ด์— ํ„ฐ๋„์„ ๋” ๋งŒ๋“ค์–ด์•ผ ํ•  ๊ฒฝ์šฐ ํ„ฐ๋„ ์ถ”๊ฐ€๋ฅผ ํด๋ฆญํ•˜๊ณ  ์ด์ „ ๋‹จ๊ณ„๋ฅผ ๋ฐ˜๋ณตํ•ฉ๋‹ˆ๋‹ค. ํ„ฐ๋„์€ ๋‚˜์ค‘์— ๋” ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    3. ๋งŒ๋“ค๊ธฐ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    gcloud

    ๋‹ค์Œ ๋ช…๋ น์–ด์—์„œ ๋‹ค์Œ ํ•ญ๋ชฉ์„ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

    • PROJECT_ID๋ฅผ ํ”„๋กœ์ ํŠธ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • NETWORK๋ฅผ Google Cloud ๋„คํŠธ์›Œํฌ ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • REGION์„ Google Cloud๋ฆฌ์ „์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค. ์ด ๋ฆฌ์ „์€ ๊ฒŒ์ดํŠธ์›จ์ด ๋ฐ ํ„ฐ๋„์„ ๋งŒ๋“ค๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
    • (์„ ํƒ์‚ฌํ•ญ) --target-vpn-gateway-region์€ ๊ธฐ๋ณธ VPN ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ์ž‘๋™ํ•  ๋ฆฌ์ „์ž…๋‹ˆ๋‹ค. ๊ฐ’์€ --region๊ณผ ๊ฐ™์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ์ด ์˜ต์…˜์ด ์ž๋™์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ์ด ์˜ต์…˜์€ ์ด ๋ช…๋ น์–ด ํ˜ธ์ถœ์˜ ๊ธฐ๋ณธ compute/region ์†์„ฑ ๊ฐ’์„ ์žฌ์ •์˜ํ•ฉ๋‹ˆ๋‹ค.
    • GW_NAME์„ ๊ฒŒ์ดํŠธ์›จ์ด ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
    • GW_IP_NAME์„ ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์™ธ๋ถ€ IP ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

    ๋‹ค์Œ ๋ช…๋ น์–ด ์‹œํ€€์Šค๋ฅผ ์™„์„ฑํ•˜์—ฌ Google Cloud๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    1. Cloud VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ๋Œ€ํ•œ ๋ฆฌ์†Œ์Šค๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

      1. ๋Œ€์ƒ VPN ๊ฒŒ์ดํŠธ์›จ์ด ๊ฐ์ฒด๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

        gcloud compute target-vpn-gateways create GW_NAME \
            --network NETWORK \
            --region REGION \
            --project PROJECT_ID
        
      2. ๋ฆฌ์ „ ์™ธ๋ถ€(์ •์ ) IP ์ฃผ์†Œ๋ฅผ ์˜ˆ์•ฝํ•ฉ๋‹ˆ๋‹ค.

        gcloud compute addresses create GW_IP_NAME \
            --region REGION \
            --project PROJECT_ID
        
      3. ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ๊ตฌ์„ฑํ•  ๋•Œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก IP ์ฃผ์†Œ๋ฅผ ์ ์–ด ๋‘ก๋‹ˆ๋‹ค.

        gcloud compute addresses describe GW_IP_NAME \
            --region REGION \
            --project PROJECT_ID \
            --format='flattened(address)'
        
      4. 3๊ฐœ์˜ ์ „๋‹ฌ ๊ทœ์น™์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๊ทœ์น™์€ Google Cloud ๊ฐ€ ESP(IPSec), UDP 500, UDP 4500 ํŠธ๋ž˜ํ”ฝ์„ ๊ฒŒ์ดํŠธ์›จ์ด๋กœ ์ „์†กํ•˜๋„๋ก ์ง€์‹œํ•ฉ๋‹ˆ๋‹ค.

         gcloud compute forwarding-rules create fr-GW_NAME-esp \
             --load-balancing-scheme=EXTERNAL \
             --ip-protocol ESP \
             --address GW_IP_NAME \
             --target-vpn-gateway GW_NAME \
             --region REGION \
             --project PROJECT_ID
        
        gcloud compute forwarding-rules create fr-GW_NAME-udp500 \
            --load-balancing-scheme=EXTERNAL \
            --ip-protocol UDP \
            --ports 500 \
            --address GW_IP_NAME \
            --target-vpn-gateway GW_NAME \
            --region REGION \
            --project PROJECT_ID
        
        gcloud compute forwarding-rules create fr-GW_NAME-udp4500 \
            --load-balancing-scheme=EXTERNAL \
            --ip-protocol UDP \
            --ports 4500 \
            --address GW_IP_NAME \
            --target-vpn-gateway GW_NAME \
            --region REGION \
            --project PROJECT_ID
        
    2. ์•„์ง ์™„๋ฃŒ ์ „์ด๋ผ๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์™„๋ฃŒํ•˜์—ฌ Cloud Router๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ์„ค๋ช…๋Œ€๋กœ ์˜ต์…˜์„ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค. ๋˜๋Š” Cloud Router๊ฐ€ Partner Interconnect์™€ ์—ฐ๊ฒฐ๋œ Interconnect ์—ฐ๊ฒฐ์— ๋Œ€ํ•œ BGP ์„ธ์…˜์„ ๊ด€๋ฆฌํ•˜์ง€ ์•Š๋Š” ํ•œ ๊ธฐ์กด Cloud Router๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

      • ROUTER_NAME์„ Cloud Router ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
      • GOOGLE_ASN์„ ๋น„๊ณต๊ฐœ ASN(64512~65534, 4200000000~4294967294)์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค. Google ASN์€ ๋™์ผํ•œ Cloud Router์— ์žˆ๋Š” ๋ชจ๋“  BGP ์„ธ์…˜์— ์‚ฌ์šฉ๋˜๋ฉฐ, ๋‚˜์ค‘์— ๋ณ€๊ฒฝํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
        gcloud compute routers create ROUTER_NAME \
        --asn GOOGLE_ASN \
        --network NETWORK \
        --region REGION \
        --project PROJECT_ID
      
    3. ๋‹ค์Œ ์„ธ๋ถ€์ •๋ณด์— ๋”ฐ๋ผ Cloud VPN ํ„ฐ๋„์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

      • TUNNEL_NAME์„ ํ„ฐ๋„ ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
      • ON_PREM_IP๋ฅผ ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์˜ ์™ธ๋ถ€ IP ์ฃผ์†Œ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
      • IKE_VERS๋ฅผ IKEv1์˜ ๊ฒฝ์šฐ 1, IKEv2์˜ ๊ฒฝ์šฐ 2๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.
      • SHARED_SECRET์„ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค. Cloud VPN ํ„ฐ๋„์˜ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์—์„œ ์ƒ๋Œ€ ํ„ฐ๋„์„ ๊ตฌ์„ฑํ•  ๋•Œ ์‚ฌ์šฉํ•œ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ์™€ ์ผ์น˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ์ง€์นจ์— ๋”ฐ๋ผ ์•”ํ˜ธ์ ์œผ๋กœ ๊ฐ•๋ ฅํ•œ ๊ณต์œ  ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
      • ROUTER_NAME์„ Cloud VPN ํ„ฐ๋„์— ๋Œ€ํ•œ ๊ฒฝ๋กœ๋ฅผ ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋ ค๋Š” Cloud Router์˜ ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค. Cloud Router๋Š” ํ„ฐ๋„์„ ๋งŒ๋“ค๊ธฐ ์ „์— ์กด์žฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

        gcloud compute vpn-tunnels create TUNNEL_NAME \
            --peer-address ON_PREM_IP \
            --ike-version IKE_VERS \
            --shared-secret SHARED_SECRET \
            --router ROUTER_NAME \
            --target-vpn-gateway GW_NAME \
            --region REGION \
            --project PROJECT_ID
        
    4. ์ธํ„ฐํŽ˜์ด์Šค ๋ฐ BGP ํ”ผ์–ด๋ฅผ ๋งŒ๋“ค์–ด์„œ Cloud Router์— ๋Œ€ํ•œ BGP ์„ธ์…˜์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ฐฉ๋ฒ• ์ค‘ ํ•˜๋‚˜๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

      • Google Cloud ์—์„œ ๋งํฌ-๋กœ์ปฌ BGP IP ์ฃผ์†Œ๋ฅผ ์ž๋™์œผ๋กœ ์„ ํƒํ•˜๋„๋ก ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.

        1. Cloud Router์— ์ƒˆ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. INTERFACE_NAME์„ ๋ฐ”๊ฟ”์„œ ์ธํ„ฐํŽ˜์ด์Šค ์ด๋ฆ„์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

          gcloud compute routers add-interface ROUTER_NAME \
              --interface-name INTERFACE_NAME \
              --vpn-tunnel TUNNEL_NAME \
              --region REGION \
              --project PROJECT_ID
          
        2. ์ธํ„ฐํŽ˜์ด์Šค์— BGP ํ”ผ์–ด๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. PEER_NAME์„ ํ”ผ์–ด ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊พธ๊ณ  PEER_ASN์„ ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ๊ตฌ์„ฑ๋œ ASN์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

          gcloud compute routers add-bgp-peer ROUTER_NAME \
              --peer-name PEER_NAME \
              --peer-asn PEER_ASN \
              --interface INTERFACE_NAME \
              --region REGION \
              --project PROJECT_ID
          

          ํ”ผ์–ด์— ๋Œ€ํ•ด ์ปค์Šคํ…€ ํ•™์Šต๋œ ๊ฒฝ๋กœ๋ฅผ ์ •์˜ํ•˜๋ ค๋ฉด --set-custom-learned-route-ranges ํ”Œ๋ž˜๊ทธ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ ๊ฒฝ๋กœ์— ๋Œ€ํ•ด --custom-learned-route-priority ํ”Œ๋ž˜๊ทธ๋ฅผ ์‚ฌ์šฉํ•ด์„œ 0์—์„œ 65535 ์‚ฌ์ด(ํฌํ•จ)์˜ ์šฐ์„ ์ˆœ์œ„ ๊ฐ’์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐ BGP ์„ธ์…˜์—๋Š” ์„ธ์…˜์— ๋Œ€ํ•ด ๊ตฌ์„ฑํ•œ ๋ชจ๋“  ์ปค์Šคํ…€ ํ•™์Šต๋œ ๊ฒฝ๋กœ์— ์ ์šฉ๋˜๋Š” ํ•˜๋‚˜์˜ ์šฐ์„ ์ˆœ์œ„ ๊ฐ’์ด ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ปค์Šคํ…€ ํ•™์Šต๋œ ๊ฒฝ๋กœ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

          gcloud compute routers add-bgp-peer ROUTER_NAME \
              --peer-name=PEER_NAME_0 \
              --peer-asn=PEER_ASN \
              --interface=ROUTER_INTERFACE_NAME_0 \
              --region=REGION \
              --set-custom-learned-route-ranges=IP_ADDRESS_RANGES \
              --custom-learned-route-priority=PRIORITY
          
        3. Cloud Router๊ฐ€ ์„ ํƒํ•œ BGP IP ์ฃผ์†Œ๋ฅผ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค. ์ƒˆ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ๊ธฐ์กด Cloud Router์— ์ถ”๊ฐ€ํ•œ ๊ฒฝ์šฐ ์ƒˆ ์ธํ„ฐํŽ˜์ด์Šค์˜ BGP IP ์ฃผ์†Œ๊ฐ€ ๊ฐ€์žฅ ๋†’์€ ์ƒ‰์ธ ๋ฒˆํ˜ธ๋กœ ๋‚˜์—ด๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ”ผ์–ด IP ์ฃผ์†Œ๋Š” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•ด์•ผ ํ•˜๋Š” BGP IP์ž…๋‹ˆ๋‹ค.

          gcloud compute routers get-status ROUTER_NAME \
               --region REGION \
               --project PROJECT_ID \
               --format='flattened(result.bgpPeerStatus[].ipAddress, \
               result.bgpPeerStatus[].peerIpAddress)'
          

          ๋‹จ์ผ Cloud VPN ํ„ฐ๋„(์ƒ‰์ธ 0)์„ ๊ด€๋ฆฌํ•˜๋Š” Cloud Router์— ๋Œ€ํ•œ ์˜ˆ์ƒ ์ถœ๋ ฅ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ GOOGLE_BGP_IP๋Š” Cloud Router ์ธํ„ฐํŽ˜์ด์Šค์˜ BGP IP๋ฅผ ๋‚˜ํƒ€๋‚ด๋ฉฐ, ON_PREM_BGP_IP๋Š” ํ•ด๋‹น ํ”ผ์–ด์˜ BGP IP๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

          result.bgpPeerStatus[0].ipAddress:     GOOGLE_BGP_IP
          result.bgpPeerStatus[0].peerIpAddress: ON_PREM_BGP_IP
          
      • Google Cloud BGP ์ธํ„ฐํŽ˜์ด์Šค ๋ฐ ํ”ผ์–ด์™€ ์—ฐ๊ฒฐ๋œ BGP IP ์ฃผ์†Œ๋ฅผ ์ˆ˜๋™์œผ๋กœ ํ• ๋‹นํ•˜๋ ค๋ฉด ๋‹ค์Œ ์•ˆ๋‚ด๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.

        1. /30 ๋ธ”๋ก์˜ ๋งํฌ-๋กœ์ปฌ BGP IP ์ฃผ์†Œ ์Œ์„ 169.254.0.0/16 ๋ฒ”์œ„ ์ค‘์—์„œ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ช…๋ น์–ด์—์„œ GOOGLE_BGP_IP๋ฅผ ๋ฐ”๊ฟ”์„œ ์ด๋Ÿฌํ•œ BGP IP ์ฃผ์†Œ ์ค‘ ํ•˜๋‚˜๋ฅผ Cloud Router์— ํ• ๋‹นํ•ฉ๋‹ˆ๋‹ค. ๋‹ค๋ฅธ BGP IP ์ฃผ์†Œ๋Š” ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ด ์ฃผ์†Œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ธฐ๊ธฐ๋ฅผ ๊ตฌ์„ฑํ•˜๊ณ  ์•„๋ž˜์˜ ๋งˆ์ง€๋ง‰ ๋ช…๋ น์–ด์—์„œ ON_PREM_BGP_IP๋ฅผ ๋ฐ”๊ฟ”์•ผ ํ•ฉ๋‹ˆ๋‹ค.

        2. Cloud Router์— ์ƒˆ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. INTERFACE_NAME์„ ๋ฐ”๊ฟ”์„œ ์ธํ„ฐํŽ˜์ด์Šค ์ด๋ฆ„์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

          gcloud compute routers add-interface ROUTER_NAME \
              --interface-name INTERFACE_NAME \
              --vpn-tunnel TUNNEL_NAME \
              --ip-address GOOGLE_BGP_IP \
              --mask-length 30 \
              --region REGION \
              --project PROJECT_ID
          
        3. ์ธํ„ฐํŽ˜์ด์Šค์— BGP ํ”ผ์–ด๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. PEER_NAME์„ ํ”ผ์–ด ์ด๋ฆ„์œผ๋กœ ๋ฐ”๊พธ๊ณ  PEER_ASN์„ ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ๊ตฌ์„ฑ๋œ ASN์œผ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

          gcloud compute routers add-bgp-peer ROUTER_NAME \
              --peer-name PEER_NAME \
              --peer-asn PEER_ASN \
              --interface INTERFACE_NAME \
              --peer-ip-address ON_PREM_BGP_IP \
              --region REGION \
              --project PROJECT_ID
          

          ํ”ผ์–ด์— ๋Œ€ํ•ด ์ปค์Šคํ…€ ํ•™์Šต๋œ ๊ฒฝ๋กœ๋ฅผ ์ •์˜ํ•˜๋ ค๋ฉด --set-custom-learned-route-ranges ํ”Œ๋ž˜๊ทธ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ ๊ฒฝ๋กœ์— ๋Œ€ํ•ด --custom-learned-route-priority ํ”Œ๋ž˜๊ทธ๋ฅผ ์‚ฌ์šฉํ•ด์„œ 0์—์„œ 65535 ์‚ฌ์ด(ํฌํ•จ)์˜ ์šฐ์„ ์ˆœ์œ„ ๊ฐ’์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ฐ BGP ์„ธ์…˜์—๋Š” ์„ธ์…˜์— ๋Œ€ํ•ด ๊ตฌ์„ฑํ•œ ๋ชจ๋“  ์ปค์Šคํ…€ ํ•™์Šต๋œ ๊ฒฝ๋กœ์— ์ ์šฉ๋˜๋Š” ํ•˜๋‚˜์˜ ์šฐ์„ ์ˆœ์œ„ ๊ฐ’์ด ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ปค์Šคํ…€ ํ•™์Šต๋œ ๊ฒฝ๋กœ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

          gcloud compute routers add-bgp-peer ROUTER_NAME \
              --peer-name=PEER_NAME_0 \
              --peer-asn=PEER_ASN \
              --interface=ROUTER_INTERFACE_NAME_0 \
              --region=REGION \
              --set-custom-learned-route-ranges=IP_ADDRESS_RANGES \
              --custom-learned-route-priority=PRIORITY
          

    ๊ตฌ์„ฑ ์™„๋ฃŒํ•˜๊ธฐ

    ์ƒˆ Cloud VPN ๊ฒŒ์ดํŠธ์›จ์ด ๋ฐ ๊ด€๋ จ VPN ํ„ฐ๋„์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๋จผ์ € ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•˜์„ธ์š”.

    1. Google Cloud VM ์ธ์Šคํ„ด์Šค์—์„œ ์„œ๋“œ ํŒŒํ‹ฐ VPN ์†Œํ”„ํŠธ์›จ์–ด๋กœ ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด ๊ตฌ์„ฑ์„ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์—์„œ ํ•ด๋‹น ํ„ฐ๋„์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ณธ VPN์— ๋™์  ๋ผ์šฐํŒ…๋งŒ ์‚ฌ์šฉํ•˜์—ฌ Google Cloud๋‚ด์—์„œ ์‹คํ–‰๋˜๋Š” ์„œ๋“œ ํŒŒํ‹ฐ VPN ์†Œํ”„ํŠธ์›จ์–ด์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
    2. Google Cloud ๋ฐ ํ”ผ์–ด ๋„คํŠธ์›Œํฌ์—์„œ ํ•„์š”์— ๋”ฐ๋ผ ๋ฐฉํ™”๋ฒฝ ๊ทœ์น™์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.
    3. VPN ํ„ฐ๋„ ๋ฐ ์ „๋‹ฌ ๊ทœ์น™์˜ ์ƒํƒœ๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

    ๋‹ค์Œ ๋‹จ๊ณ„

    • ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์— ํ—ˆ์šฉ๋˜๋Š” IP ์ฃผ์†Œ๋ฅผ ์ œ์–ดํ•˜๋ ค๋ฉด ํ”ผ์–ด VPN ๊ฒŒ์ดํŠธ์›จ์ด์˜ IP ์ฃผ์†Œ ์ œํ•œ ์ฐธ์กฐํ•˜๊ธฐ
    • ๊ณ ๊ฐ€์šฉ์„ฑ ๋ฐ ๋†’์€ ์ฒ˜๋ฆฌ๋Ÿ‰ ์‹œ๋‚˜๋ฆฌ์˜ค ๋˜๋Š” ๋‹ค์ค‘ ์„œ๋ธŒ๋„ท ์‹œ๋‚˜๋ฆฌ์˜ค๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๊ณ ๊ธ‰ ๊ตฌ์„ฑ ์ฐธ์กฐํ•˜๊ธฐ
    • Cloud VPN์„ ์‚ฌ์šฉํ•  ๋•Œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์ผ๋ฐ˜์ ์ธ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋ ค๋ฉด ๋ฌธ์ œ ํ•ด๊ฒฐ ์ฐธ์กฐํ•˜๊ธฐ