CodeLab: การแลกเปลี่ยนเส้นทางแบบไดนามิกกับ NCC

1. บทนำ

ภาพรวม

ใน Lab นี้ ผู้ใช้จะได้สำรวจวิธีใช้ Network Connectivity Center (NCC) เพื่อสร้างการเชื่อมต่อภายในองค์กรในวงกว้างผ่านการรองรับ VPC Spoke และการแลกเปลี่ยนเส้นทางแบบไดนามิก เมื่อผู้ใช้กำหนด VPC เป็น VPC Spoke ก็จะสามารถเชื่อมต่อ VPC กับเครือข่าย VPC หลายรายการเข้าด้วยกันผ่าน NCC Hub ได้ หากต้องการสร้างการเชื่อมต่อเครือข่ายกับเครือข่ายภายในองค์กรของผู้ใช้ ผู้ใช้สามารถแนบ NIC เสมือนของอุปกรณ์เราเตอร์ อุโมงค์ข้อมูล HA_VPN หรือไฟล์แนบ VLAN ของการเชื่อมต่อถึงกันกับ NCC Hub เดียวกันกับ NCC VPC Spoke ได้

ทรัพยากรฮับมีโมเดลการจัดการการเชื่อมต่อแบบรวมศูนย์เพื่อเชื่อมต่อ Spoke

สิ่งที่คุณจะได้สร้าง

ใน Codelab นี้ คุณจะได้สร้างโทโพโลยีฮับและ Spoke เชิงตรรกะด้วย NCC Hub ซึ่งจะใช้การเชื่อมต่อแบบผสมระหว่างเครือข่ายภายในองค์กรกับ VPC สำหรับภาระงาน

21d100d48eee31f1.png

สิ่งที่คุณจะได้เรียนรู้

  • ความแตกต่างระหว่าง VPC สำหรับภาระงานกับ VPC สำหรับการกำหนดเส้นทาง
  • การผสานรวม NCC ของ VPC Spoke และ Hybrid Spoke

สิ่งที่คุณต้องมี

  • ความรู้เกี่ยวกับเครือข่าย VPC ของ GCP
  • ความรู้เกี่ยวกับ Cloud Router และการกำหนดเส้นทาง BGP
  • โปรเจ็กต์ Google Cloud
  • ตรวจสอบโควต้า: เครือข่าย และ ขอเครือข่ายเพิ่มเติมหากจำเป็น โดยดูภาพหน้าจอด้านล่าง

6d1b99c6da87fd84.png

วัตถุประสงค์

  • ตั้งค่าสภาพแวดล้อม GCP
  • กำหนดค่า Network Connectivity Center โดยใช้ VPC เป็น Spoke
  • กำหนดค่า Network Connectivity Center โดยใช้อุโมงค์ข้อมูล HA-VPN เป็น Hybrid Spoke
  • ตรวจสอบเส้นทางของข้อมูล
  • สำรวจฟีเจอร์ความพร้อมใช้งานของ NCC
  • ล้างทรัพยากรที่ใช้แล้ว

ก่อนเริ่มต้น

คอนโซล Google Cloud และ Cloud Shell

เราจะใช้ทั้งคอนโซล Google Cloud และ Cloud Shell ตลอด Lab นี้เพื่อโต้ตอบกับ GCP

โปรเจ็กต์ NCC Hub คอนโซล Google Cloud

คุณเข้าถึง Cloud Console ได้ที่ https://console.cloud.google.com

ตั้งค่ารายการต่อไปนี้ใน Google Cloud เพื่อให้กำหนดค่า Network Connectivity Center ได้ง่ายขึ้น

ในคอนโซล Google Cloud ในหน้าตัวเลือกโปรเจ็กต์ ให้เลือกหรือสร้างโปรเจ็กต์ Google Cloud

เปิดใช้ Cloud Shell Codelab นี้ใช้ตัวแปร $เพื่อช่วยในการติดตั้งใช้งานการกำหนดค่า gcloud ใน Cloud Shell

gcloud auth list
gcloud config list project
gcloud config set project [YOUR-PROJECT-NAME]
projectname=[YOUR-PROJECT-NAME]
echo $projectname
region="us-central1"
zone="us-central1-a"

บทบาท IAM

NCC ต้องใช้บทบาท IAM เพื่อเข้าถึง API บางรายการ โปรดกำหนดค่าผู้ใช้ด้วยบทบาท IAM ของ NCC ตามที่จำเป็น

บทบาท/คำอธิบาย

สิทธิ์

networkconnectivity.editor- อนุญาตให้ผู้ดูแลระบบเครือข่ายจัดการฮับและ Spoke

networkconnectivity.hubs.networkconnectivity.spokes.networkconnectivity.gatewaynetworkconnectivity.locations.

networkconnectivity.HubAdmin- เปิดใช้สิทธิ์เข้าถึงทรัพยากรฮับและ Spoke อย่างเต็มรูปแบบ

networkconnectivity.gatewayAdvertisedRoutes.networkconnectivity.groups. networkconnectivity.hubRouteTables.networkconnectivity.hubRoutes.networkconnectivity.hubs. networkconnectivity.locations. networkconnectivity.operations.* networkconnectivity.spokes.*resourcemanager.projects.getresourcemanager.projects.list

networkconnectivity.hubViewer - เปิดใช้สิทธิ์เข้าถึงแบบอ่านอย่างเดียวสำหรับทรัพยากรฮับและ Spoke

networkconnectivity.gatewayAdvertisedRoutes.getnetworkconnectivity.gatewayAdvertisedRoutes.listnetworkconnectivity.groups.getnetworkconnectivity.groups.getIamPolicynetworkconnectivity.groups.listnetworkconnectivity.hubRouteTables.getnetworkconnectivity.hubRouteTables.getIamPolicynetworkconnectivity.hubRouteTables.listnetworkconnectivity.hubRoutes.getnetworkconnectivity.hubRoutes.getIamPolicynetworkconnectivity.hubRoutes.listnetworkconnectivity.hubs.getnetworkconnectivity.hubs.getIamPolicynetworkconnectivity.hubs.listnetworkconnectivity.hubs.listSpokesnetworkconnectivity.hubs.queryStatus networkconnectivity.locations.*networkconnectivity.spokes.getnetworkconnectivity.spokes.getIamPolicynetworkconnectivity.spokes.listresourcemanager.projects.getresourcemanager.projects.list

2. ตั้งค่าสภาพแวดล้อมเครือข่าย

ภาพรวม

ในส่วนนี้ เราจะทำให้เครือข่าย VPC 3 รายการและกฎไฟร์วอลล์ใช้งานได้ในโปรเจ็กต์เดียว แผนภาพเชิงตรรกะแสดงสภาพแวดล้อมเครือข่ายที่จะตั้งค่าในขั้นตอนนี้ เราจะใช้ VPC เพื่อจำลองเครือข่ายภายในองค์กรสำหรับ Codelab นี้

732e31532d8f6edb.png

แนวคิดหลัก 1

VPC ทั่วโลกของ Google Cloud ให้การเชื่อมต่อเส้นทางของข้อมูลระหว่างภูมิภาค GCP มากกว่า 44 ภูมิภาค Cloud Router ซึ่งเป็นบริการระดับภูมิภาคจะประกาศซับเน็ตแบบไดนามิกและเผยแพร่เส้นทางที่เรียนรู้ในภูมิภาคที่กำหนดค่าเราเตอร์หรือทั่วทั้งเครือข่าย VPC สิ่งที่กำหนดให้ Cloud Router เผยแพร่เส้นทางในระดับภูมิภาคหรือระดับโลกขึ้นอยู่กับผู้ใช้ที่กำหนดโหมดการกำหนดเส้นทางแบบไดนามิกเป็นระดับภูมิภาคหรือระดับโลก

ในส่วนนี้ เราจะเริ่มต้นด้วยการกำหนดค่า VPC แต่ละรายการด้วยโหมดการกำหนดเส้นทางระดับภูมิภาค สำหรับส่วนที่เหลือของ Codelab นี้

  • "VPC สำหรับการกำหนดเส้นทาง" หมายถึง VPC ที่ไม่ได้กำหนดค่าเป็น NCC VPC Spoke
  • "VPC สำหรับภาระงาน" หมายถึง VPC ที่กำหนดค่าเป็น NCC Spoke

สร้าง VPC สำหรับภาระงานและซับเน็ต

เครือข่าย VPC มีซับเน็ตที่คุณจะติดตั้ง GCE VM เพื่อตรวจสอบเส้นทางของข้อมูล

vpc_spoke_network_name="workload-vpc"
vpc_spoke_subnet_name="workload-subnet"
vpc_spoke_subnet_ip_range="10.0.1.0/24"
vpc_spoke_name="workload-vpc-spoke"
region="us-central1"
zone="us-central1-a"

gcloud compute networks create "${vpc_spoke_network_name}" \
--subnet-mode=custom 

gcloud compute networks subnets create "${vpc_spoke_subnet_name}" \
--network="${vpc_spoke_network_name}" \
--range="${vpc_spoke_subnet_ip_range}" \
--region="${region}"

สร้าง VPC สำหรับการกำหนดเส้นทางและซับเน็ต

NCC รองรับช่วงซับเน็ต IPv4 ที่ถูกต้องทั้งหมด ยกเว้นที่อยู่ IP สาธารณะที่ใช้แบบส่วนตัว

routing_vpc_network_name="routing-vpc"
routing_vpc_subnet_name="routing-vpc-subnet"
routing_vpc_subnet_range="10.0.2.0/24"

gcloud compute networks create "${routing_vpc_network_name}" \
--subnet-mode=custom

gcloud compute networks subnets create "${routing_vpc_subnet_name}" \
--region="${region}" \
--network="${routing_vpc_network_name}" \
--range="${routing_vpc_subnet_range}"

สร้าง VPC ภายในองค์กรและซับเน็ต

NCC รองรับช่วงซับเน็ต IPv4 ที่ถูกต้องทั้งหมด ยกเว้นที่อยู่ IP สาธารณะที่ใช้แบบส่วนตัว

on_prem_network_name="on-prem-net-vpc"
on_prem_subnet_name="on-prem-subnet"
on_prem_subnet_range="10.0.3.0/24"

gcloud compute networks create "${on_prem_network_name}" \
--subnet-mode=custom

gcloud compute networks subnets create "${on_prem_subnet_name}" \
--region="${region}" \
--network="${on_prem_network_name}" \
--range="${on_prem_subnet_range}"

กำหนดค่ากฎไฟร์วอลล์ของ VPC สำหรับภาระงาน

workload_vpc_firewall_name="workload-protocol-fw-vpc"
workload_port_firewall_name="workload-port-firewall-vpc"

gcloud compute firewall-rules create "${workload_vpc_firewall_name}" \
--network=${vpc_spoke_network_name} \
--allow="tcp,udp,icmp"

gcloud compute firewall-rules create "${workload_port_firewall_name}" \
--network=${vpc_spoke_network_name} \
--allow="tcp:22,tcp:3389,tcp:11180,icmp"

กำหนดค่า VPC สำหรับการกำหนดเส้นทางและกฎไฟร์วอลล์ของ VPC

routing_vpc_fw_name="routing-vpc-protocol-fw"
routing_vpc_port_fw_name="routing-vpc--port-fw"

gcloud compute firewall-rules create "${routing_vpc_fw_name}" \
--network=${routing_vpc_network_name} \
--allow="tcp,udp,icmp"

gcloud compute firewall-rules create "${routing_vpc_port_fw_name}" \
--network=${routing_vpc_network_name} \
--allow="tcp:22,tcp:3389,tcp:11180,icmp"

กำหนดค่า VPC ภายในองค์กรและกฎไฟร์วอลล์ของ VPC

prem_protocol_fw_name="onprem-vpc-protocol-firewall"
prem_port_firewall_name="onprem-vpc-port-firewall-prem"

gcloud compute firewall-rules create "${prem_protocol_fw_name}" \
--network=${on_prem_network_name} \
--allow="tcp,udp,icmp"

gcloud compute firewall-rules create "${prem_port_firewall_name}" \
--network=${on_prem_network_name} \
--allow="tcp:22,tcp:3389,tcp:11180,icmp"

กำหนดค่า GCE VM ใน VPC แต่ละรายการ

คุณจะต้องมีสิทธิ์เข้าถึงอินเทอร์เน็ตชั่วคราวเพื่อติดตั้งแพ็กเกจใน "vm1-vpc1-ncc"

สร้างเครื่องเสมือน 3 เครื่อง โดยแต่ละเครื่องจะกำหนดให้กับ VPC ที่สร้างไว้ก่อนหน้านี้

gcloud compute instances create vm1-vpc-workload \
--zone us-central1-a \
--subnet="${vpc_spoke_subnet_name}" \
--metadata=startup-script='#!/bin/bash
  apt-get update
  apt-get install apache2 -y
  apt-get install tcpdump -y
  service apache2 restart
  echo "
<h3>Web Server: www-vm1</h3>" | tee /var/www/html/index.html'


gcloud compute instances create vm2-vpc-routing \
--zone us-central1-a \
--subnet="${routing_vpc_subnet_name}" \
--no-address 

gcloud compute instances create vm3-onprem \
--zone us-central1-a \
--subnet="${on_prem_subnet_name}" \
--no-address 

3. ตั้งค่าการเชื่อมต่อแบบไฮบริด

ในส่วนนี้ เราจะกำหนดค่าอุโมงค์ข้อมูล VPN ความพร้อมใช้งานสูง เพื่อเชื่อมต่อเครือข่าย VPC ภายในองค์กรและเครือข่าย VPC สำหรับการกำหนดเส้นทางเข้าด้วยกัน

161d9e6b19ce53a1.png

กำหนดค่า Cloud Router ด้วย BGP ใน VPC สำหรับการกำหนดเส้นทาง

routing_vpc_router_name="routing-vpc-cr"
routing_vpc_router_asn=64525

gcloud compute routers create "${routing_vpc_router_name}" \
--region="${region}" \
--network="${routing_vpc_network_name}" \
--asn="${routing_vpc_router_asn}"

กำหนดค่า Cloud Router ด้วย BGP ใน VPC ภายในองค์กร

on_prem_router_name="on-prem-router"
on_prem_router_asn=64526

gcloud compute routers create "${on_prem_router_name}" \
--region="${region}" \
--network="${on_prem_network_name}" \
--asn="${on_prem_router_asn}"

กำหนดค่าเกตเวย์ VPN ใน VPC สำหรับการกำหนดเส้นทาง

routing_vpn_gateway_name="routing-vpc-vpn-gateway"

gcloud compute vpn-gateways create "${routing_vpn_gateway_name}" \
--region="${region}" \
--network="${routing_vpc_network_name}"

กำหนดค่าเกตเวย์ VPN ใน VPC ภายในองค์กร

on_prem_gateway_name="on-prem-vpn-gateway"

gcloud compute vpn-gateways create "${on_prem_gateway_name}" \
--region="${region}" \
--network="${on_prem_network_name}"

กำหนดค่าอุโมงค์ข้อมูล VPN ใน VPC สำหรับการกำหนดเส้นทางและ VPC ภายในองค์กร

secret_key=$(openssl rand -base64 24)
routing_vpc_tunnel_name="routing-vpc-tunnel"
on_prem_tunnel_name="on-prem-tunnel"

gcloud compute vpn-tunnels create "${routing_vpc_tunnel_name}" \
--vpn-gateway="${routing_vpn_gateway_name}" \
--peer-gcp-gateway="${on_prem_gateway_name}" \
--router="${routing_vpc_router_name}" \
--region="${region}" \
--interface=0 \
--shared-secret="${secret_key}"

gcloud compute vpn-tunnels create "${on_prem_tunnel_name}" \
--vpn-gateway="${on_prem_gateway_name}" \
--peer-gcp-gateway="${routing_vpn_gateway_name}" \
--router="${on_prem_router_name}" \
--region="${region}" \
--interface=0 \
--shared-secret="${secret_key}"

สร้างเซสชัน BGP เพื่อเพียร์ BGP VPC สำหรับการกำหนดเส้นทางและ Cloud Router ภายในองค์กร

interface_hub_name="if-hub-to-prem"
hub_router_ip="169.254.1.1"

gcloud compute routers add-interface "${routing_vpc_router_name}" \
--interface-name="${interface_hub_name}" \
--ip-address="${hub_router_ip}" \
--mask-length=30 \
--vpn-tunnel="${routing_vpc_tunnel_name}" \
--region="${region}"

bgp_hub_name="bgp-hub-to-prem"
prem_router_ip="169.254.1.2"
gcloud compute routers add-bgp-peer "${routing_vpc_router_name}" \
--peer-name="${bgp_hub_name}" \
--peer-ip-address="${prem_router_ip}" \
--interface="${interface_hub_name}" \
--peer-asn="${on_prem_router_asn}" \
--region="${region}"

interface_prem_name="if-prem-to-hub"
gcloud compute routers add-interface "${on_prem_router_name}" \
--interface-name="${interface_prem_name}" \
--ip-address="${prem_router_ip}" \
--mask-length=30 \
--vpn-tunnel="${on_prem_tunnel_name}" \
--region="${region}"

bgp_prem_name="bgp-prem-to-hub"
gcloud compute routers add-bgp-peer "${on_prem_router_name}" \
--peer-name="${bgp_prem_name}" \
--peer-ip-address="${hub_router_ip}" \
--interface="${interface_prem_name}" \
--peer-asn="${routing_vpc_router_asn}" \
--region="${region}"

โดยค่าเริ่มต้น ระบบจะไม่ประกาศซับเน็ต NCC Hub ให้กับ Hybrid Spoke ในขั้นตอนถัดไป ให้กำหนดค่า Cloud Router เพื่อประกาศเส้นทางซับเน็ต NCC ให้กับเครือข่ายภายในองค์กร

gcloud compute routers update "${routing_vpc_router_name}" \
--advertisement-mode custom \
--set-advertisement-groups=all_subnets \
--set-advertisement-ranges="${vpc_spoke_subnet_ip_range}" \
--region="${region}"
gcloud compute routers update "${on_prem_router_name}" \
--advertisement-mode custom \
--set-advertisement-groups=all_subnets \
--region="${region}"

อัปเดตการกำหนดค่าการเพียร์ BGP ของ Cloud Router ภายในองค์กรเพื่อประกาศคำนำหน้าที่มีค่า MED เป็น "111" ในส่วนถัดไป เราจะดูพฤติกรรมของ NCC ที่มีค่า MED ของ BGP

on_prem_router_name="on-prem-router"
bgp_prem_name="bgp-prem-to-hub"

gcloud compute routers update-bgp-peer "${on_prem_router_name}" \
--peer-name="${bgp_prem_name}" \
--advertised-route-priority="111" \
--region="${region}"

ตรวจสอบสถานะของอุโมงค์ข้อมูล VPC สำหรับการกำหนดเส้นทาง

gcloud compute vpn-tunnels describe routing-vpc-tunnel \
--region=us-central1 \
--format='flattened(status,detailedStatus)'

ตรวจสอบสถานะของ Cloud Router ของ VPC สำหรับการกำหนดเส้นทาง

ใช้คำสั่ง gcloud เพื่อแสดงเส้นทางที่เรียนรู้ BGP ของ Cloud Router ของ VPC สำหรับการกำหนดเส้นทาง

gcloud compute routers get-status routing-vpc-cr \
--region=us-central1

4. ฮับ Network Connectivity Center

ภาพรวม

ในส่วนนี้ เราจะกำหนดค่า NCC Hub โดยใช้คำสั่ง gcloud NCC Hub จะทำหน้าที่เป็นระนาบควบคุมที่รับผิดชอบในการสร้างการกำหนดเส้นทางระหว่าง VPC Spoke แต่ละรายการ

6a26627c680ddac5.png

เปิดใช้บริการ API

เปิดใช้ Network Connectivity API ในกรณีที่ยังไม่ได้เปิดใช้

gcloud services enable networkconnectivity.googleapis.com

สร้าง NCC Hub

สร้าง NCC Hub โดยใช้คำสั่ง gcloud

hub_name="mesh-hub"
gcloud network-connectivity hubs create "${hub_name}"

ตัวอย่างเอาต์พุต

Create request issued for: [mesh-hub]
Waiting for operation [projects/ncc/locations/global/operations/operation-1719930559145-61c448a0426e4-2d18c8dd-7107edbe] to complete...done.               
Created hub [mesh-hub].

อธิบาย NCC Hub ที่สร้างขึ้นใหม่ จดชื่อและเส้นทางที่เชื่อมโยงไว้

gcloud network-connectivity hubs describe mesh-hub
createTime: '2024-07-02T14:29:19.260054897Z'
exportPsc: false
name: projects/ncc/locations/global/hubs/mesh-hub
policyMode: PRESET
presetTopology: MESH
routeTables:
- projects/ncc/locations/global/hubs/mesh-hub/routeTables/default
state: ACTIVE
uniqueId: 08f9ae88-f76f-432b-92b2-357a85fc83aa
updateTime: '2024-07-02T14:29:32.583206925Z'

NCC Hub ได้เปิดตัวตารางการกำหนดเส้นทางที่กำหนดระนาบควบคุมสำหรับการสร้างการเชื่อมต่อข้อมูล ค้นหาชื่อตารางการกำหนดเส้นทางของ NCC Hub

 gcloud network-connectivity hubs route-tables list --hub=mesh-hub
NAME     HUB       DESCRIPTION
default  mesh-hub

ค้นหา URI ของตารางเส้นทางเริ่มต้นของ NCC

gcloud network-connectivity hubs route-tables describe default --hub=mesh-hub
createTime: '2024-07-02T14:29:22.340190411Z'
name: projects/ncc/locations/global/hubs/mesh-hub/routeTables/default
state: ACTIVE
uid: fa2af78b-d416-41aa-b442-b8ebdf84f799

แสดงเนื้อหาของตารางการกำหนดเส้นทางเริ่มต้นของ NCC Hub หมายเหตุ* ตารางเส้นทางของ NCC Hub จะว่างเปล่าจนกว่าจะมีการกำหนด NCC Hybrid Spoke หรือ VPC Spoke

gcloud network-connectivity hubs route-tables routes list --hub=mesh-hub --route_table=default

ตารางเส้นทางของ NCC Hub ควรว่างเปล่า

5. NCC ที่มี Hybrid Spoke และ VPC Spoke

ภาพรวม

ในส่วนนี้ คุณจะได้กำหนดค่า NCC Spoke 2 รายการโดยใช้คำสั่ง gcloud Spoke รายการหนึ่งจะเป็น VPC Spoke และอีกรายการหนึ่งจะเป็น Hybrid Spoke (VPN)

f234ce75342022d8.png

กำหนดค่า VPC สำหรับภาระงานเป็น NCC Spoke

กำหนดค่า VPC สำหรับภาระงานเป็น NCC Spoke และกำหนดให้กับ NCC Hub ที่สร้างไว้ก่อนหน้านี้ การเรียก API ของ NCC Spoke ต้องระบุสถานที่ แฟล็ก "--global" ช่วยให้ผู้ใช้ไม่ต้องระบุเส้นทาง URI แบบเต็มเมื่อกำหนดค่า NCC Spoke ใหม่

vpc_spoke_name="workload-vpc-spoke"
vpc_spoke_network_name="workload-vpc"

gcloud network-connectivity spokes linked-vpc-network create "${vpc_spoke_name}" \
--hub="${hub_name}" \
--vpc-network="${vpc_spoke_network_name}" \
--global
Create request issued for: [workload-vpc-spoke]
Waiting for operation [projects/ncc/locations/global/operations/operation-1719931097138-61c44aa15463f-90de22c7-40c10e6b] to complete...done.               
Created spoke [workload-vpc-spoke].
createTime: '2024-07-02T14:38:17.315200822Z'
group: projects/ncc/locations/global/hubs/mesh-hub/groups/default
hub: projects/ncc/locations/global/hubs/mesh-hub
linkedVpcNetwork:
  uri: https://www.googleapis.com/compute/v1/projects/ncc/global/networks/workload-vpc
name: projects/ncc/locations/global/spokes/workload-vpc-spoke
spokeType: VPC_NETWORK
state: ACTIVE
uniqueId: 33e50612-9b62-4ec7-be6c-962077fd47dc
updateTime: '2024-07-02T14:38:44.196850231Z'

กำหนดค่าอุโมงค์ข้อมูล VPN ใน VPC สำหรับการกำหนดเส้นทางเป็น Hybrid Spoke

ใช้คำสั่ง gcloud นี้เพื่อกำหนดค่าอุโมงค์ข้อมูล VPN เป็น Hybrid Spoke เพื่อเข้าร่วม Mesh-Hub

vpn_spoke_name="hybrid-spoke"
routing_vpc_tunnel_name="routing-vpc-tunnel"
region="us-central1"
hub_name="mesh-hub"

gcloud network-connectivity spokes linked-vpn-tunnels create "${vpn_spoke_name}" \
--region="${region}" \
--hub="${hub_name}" \
--vpn-tunnels="${routing_vpc_tunnel_name}"

ตัวอย่างเอาต์พุต

Create request issued for: [hybrid-spoke]
Waiting for operation [projects/ncc/locations/us-central1/operations/operation-1719932916561-61c45168774be-0a06ae03-88192175] to complete...done.          
Created spoke [hybrid-spoke].

แม้ว่า NCC Hub จะเรียนรู้เส้นทางซับเน็ต VPC ทั้งหมด แต่โดยค่าเริ่มต้น NCC จะไม่ประกาศคำนำหน้าเหล่านี้ให้กับ Hybrid Spoke หากต้องการบังคับให้ NCC Hub ประกาศซับเน็ต VPC สำหรับภาระงานภายในองค์กร ผู้ดูแลระบบเครือข่ายควรใช้แฟล็ก "include-import-ranges" เพื่อนำเข้าช่วง IPv4 จากฮับไปยัง Hybrid Spoke

ใช้คำสั่งเพื่ออัปเดต NCC Hybrid Spoke เพื่อประกาศคำนำหน้าตารางเส้นทาง NCC Hub ทั้งหมดไปยังเครือข่ายภายในองค์กร

vpn_spoke_name="hybrid-spoke"
routing_vpc_tunnel_name="routing-vpc-tunnel"
region="us-central1"
hub_name="mesh-hub"

gcloud network-connectivity spokes linked-vpn-tunnels update "${vpn_spoke_name}" \
--region="${region}" \
--include-import-ranges=ALL_IPV4_RANGES

ตรวจสอบการกำหนดค่า Spoke ของ Mesh-Hub

ใช้คำสั่ง gcloud เพื่อแสดงเนื้อหาของตารางการกำหนดเส้นทางเริ่มต้นของ NCC Hub

gcloud network-connectivity hubs list-spokes mesh-hub 

วิเคราะห์ตารางการกำหนดเส้นทางเริ่มต้นของ Mesh-Hub

ใช้คำสั่ง gcloud เพื่อแสดงเนื้อหาของตารางการกำหนดเส้นทางเริ่มต้นของ NCC Hub

gcloud network-connectivity hubs route-tables routes list --hub=mesh-hub \
--route_table=default

ระบบจะเผยแพร่คำนำหน้าที่ Cloud Router เรียนรู้ที่มีค่า MED ของ BGP ไปยัง NCC Spoke เมื่อใช้การแลกเปลี่ยนเส้นทางแบบไดนามิกกับ NCC Hybrid Spoke

ใช้คำสั่ง gcloud เพื่อดูค่าลำดับความสำคัญของ "111"

gcloud network-connectivity hubs route-tables routes list \
--hub=mesh-hub \
--route_table=default \
--effective-location=us-central1 \
--filter=10.0.3.0/24

เปลี่ยนไปใช้ Cloud Router ภายในองค์กร

ใช้คำสั่ง gcloud เพื่อดูเส้นทางที่ Cloud Router เรียนรู้จากเครือข่ายภายในองค์กร

gcloud compute routers get-status on-prem-router \
--region=us-central1\
--format="yaml(result.bgpPeerStatus)" 

6. ตัวกรอง NCC Hybrid Spoke

ในส่วนนี้ เราจะสร้างซับเน็ตใหม่ 2 รายการ รายการหนึ่งใน VPC ภายในองค์กรและอีกรายการหนึ่งใน VPC สำหรับภาระงาน และดูพฤติกรรมของตัวกรอง NCC Hybrid Spoke

ใช้คำสั่งเพื่อสร้างซับเน็ตใหม่ใน VPC ภายในองค์กร

on_prem_network_name="on-prem-net-vpc"
on_prem_subnet_name="on-prem-subnet30"
on_prem_subnet_range="10.30.30.0/24"
region="us-central1"

gcloud compute networks subnets create "${on_prem_subnet_name}" \
--region="${region}" \
--network="${on_prem_network_name}" \
--range="${on_prem_subnet_range}"

ใช้คำสั่งเพื่อสร้างซับเน็ตใหม่ใน VPC สำหรับภาระงาน

vpc_spoke_network_name="workload-vpc"
vpc_spoke_subnet_name="workload-subnet10"
vpc_spoke_subnet_ip_range="10.10.10.0/24"
vpc_spoke_name="workload-vpc-spoke"
region="us-central1"

gcloud compute networks subnets create "${vpc_spoke_subnet_name}" \
--network="${vpc_spoke_network_name}" \
--range="${vpc_spoke_subnet_ip_range}" \
--region="${region}"

ผู้ดูแลระบบสามารถใช้แฟล็ก "--exclude-export-ranges" เพื่อกรองคำนำหน้า IP ที่ส่งออกไปยังตารางเส้นทาง NCC Hub ซึ่งจะช่วยให้ผู้ดูแลระบบควบคุมขนาดของตารางเส้นทาง NCC Hub ได้ โดยค่าเริ่มต้น ระบบจะเรียนรู้คำนำหน้า IPv4 ทั้งหมดจากภายในองค์กรและอนุญาตให้เข้าสู่ตารางเส้นทาง NCC Hub

ใช้คำสั่งเพื่ออัปเดต NCC Hybrid Spoke เพื่อกรองคำนำหน้า 10.30.30.0/24 ไม่ให้แทรกลงในตารางเส้นทาง NCC Hub

vpn_spoke_name="hybrid-spoke"
routing_vpc_tunnel_name="routing-vpc-tunnel"
region="us-central1"
hub_name="mesh-hub"

gcloud network-connectivity spokes linked-vpn-tunnels update "${vpn_spoke_name}" \
--region="${region}" \
--exclude-export-ranges=10.30.30.0/24

ใช้คำสั่ง gcloud เพื่อยืนยันว่าคำนำหน้า 10.30.30.0/24 **ไม่ได้** อยู่ในตารางเส้นทาง NCC Hub

gcloud network-connectivity hubs route-tables routes list \
--hub=mesh-hub \
--route_table=default \
--effective-location=us-central1 \
--filter=10.30.30.0/24

เปลี่ยนไปใช้เราเตอร์ภายในองค์กรและใช้คำสั่ง gcloud เพื่อดูว่าเราเตอร์ได้เรียนรู้ซับเน็ต 10.10.10.0/24 ของ VPC สำหรับภาระงานแล้ว

gcloud compute routers get-status on-prem-router \
--region=us-central1\
--format="yaml(result.bgpPeerStatus)" 

คำสั่งด้านล่างที่มีแฟล็ก "–exclude-import-ranges" เพื่อกรองคำนำหน้า 10.10.10.0/24 ที่เฉพาะเจาะจงไม่ให้ประกาศไปยังเราเตอร์ภายในองค์กร

vpn_spoke_name="hybrid-spoke"
routing_vpc_tunnel_name="routing-vpc-tunnel"
region="us-central1"
hub_name="mesh-hub"

gcloud network-connectivity spokes linked-vpn-tunnels update "${vpn_spoke_name}" \
--region="${region}" \
--exclude-import-ranges=10.10.10.0/24

เปลี่ยนไปใช้เราเตอร์ภายในองค์กรและใช้คำสั่ง gcloud เพื่อตรวจสอบตารางการกำหนดเส้นทาง โปรดทราบว่าคำนำหน้า 10.10.10.0/24 ไม่ควร ปรากฏ

gcloud compute routers get-status on-prem-router \
--region=us-central1\
--format="yaml(result.bgpPeerStatus)" 

7. ตรวจสอบเส้นทางของข้อมูล

ในขั้นตอนนี้ เราจะตรวจสอบเส้นทางของข้อมูลระหว่าง NCC Hybrid Spoke กับ VPC Spoke 9eb9c4936851deb0.png

ใช้เอาต์พุตจากคำสั่ง gcloud เหล่านี้เพื่อเข้าสู่ระบบ VM ภายในองค์กร

gcloud compute instances list --filter="name=vm3-onprem"

เข้าสู่ระบบอินสแตนซ์ VM ที่อยู่ในเครือข่ายภายในองค์กร

gcloud compute ssh vm3-onprem --zone=us-central1-a

ในเทอร์มินัลของ vm3-onprem ให้ใช้คำสั่ง curl เพื่อสร้างเซสชันเว็บกับ VM ที่โฮสต์ใน workload-vpc

curl 10.0.1.2 -v
*   Trying 10.0.1.2:80...
* Connected to 10.0.1.2 (10.0.1.2) port 80 (#0)
> GET / HTTP/1.1
> Host: 10.0.1.2
> User-Agent: curl/7.74.0
> Accept: */*
> 
* Mark bundle as not supporting multiuse
< HTTP/1.1 200 OK
< Date: Wed, 03 Jul 2024 15:41:34 GMT
< Server: Apache/2.4.59 (Debian)
< Last-Modified: Mon, 01 Jul 2024 20:36:16 GMT
< ETag: "1e-61c358c8272ba"
< Accept-Ranges: bytes
< Content-Length: 30
< Content-Type: text/html
< 

<h3>Web Server: www-vm1</h3>
* Connection #0 to host 10.0.1.2 left intact

8. ล้าง

เข้าสู่ระบบ Cloud Shell และลบทรัพยากร GCP

ลบ NCC Spoke

gcloud network-connectivity spokes delete workload-vpc-spoke --global \
--quiet

gcloud network-connectivity spokes delete hybrid-spoke \
--quiet \
--region us-central1

ลบ NCC Hub

gcloud network-connectivity hubs delete mesh-hub --quiet

ลบกฎไฟร์วอลล์

gcloud compute firewall-rules delete onprem-vpc-port-firewall-prem onprem-vpc-protocol-firewall routing-vpc--port-fw routing-vpc-protocol-fw workload-port-firewall-vpc workload-protocol-fw-vpc --quiet

ลบอุโมงค์ข้อมูล HA-VPN

gcloud compute vpn-tunnels delete on-prem-tunnel \
--region=us-central1 \
--quiet 

gcloud compute vpn-tunnels delete routing-vpc-tunnel \
--region=us-central1 \
--quiet 

ลบเกตเวย์ VPN

gcloud compute vpn-gateways delete on-prem-vpn-gateway \
--region=us-central1 --quiet

gcloud compute vpn-gateways delete routing-vpc-vpn-gateway \
--region us-central1 --quiet

ลบ Cloud Router

gcloud compute routers delete routing-vpc-cr --region us-central1 --quiet

gcloud compute routers delete on-prem-router --region us-central1 --quiet

ลบอินสแตนซ์ GCE

gcloud compute instances delete vm1-vpc-workload \
--zone=us-central1-a \
--quiet


gcloud compute instances delete vm2-vpc-routing \
--zone=us-central1-a \
--quiet

gcloud compute instances delete vm3-onprem \
--zone=us-central1-a \
--quiet

ลบซับเน็ต VPC

gcloud compute networks subnets delete workload-subnet --region us-central1 --quiet

gcloud compute networks subnets delete on-prem-subnet --region us-central1 --quiet

gcloud compute networks subnets delete routing-vpc-subnet --region us-central1 --quiet

ลบ VPC

gcloud compute networks delete on-prem-net-vpcworkload-vpc routing-vpc 
--quiet 

9. ยินดีด้วย

คุณทำ Lab Network Connectivity Center สำหรับการแลกเปลี่ยนเส้นทางแบบไดนามิกเสร็จสมบูรณ์แล้ว

สิ่งที่คุณได้เรียนรู้

  • การแลกเปลี่ยนเส้นทางแบบไดนามิกด้วย Network Connectivity Center

ขั้นตอนถัดไป

©Google, LLC หรือบริษัทในเครือ สงวนลิขสิทธิ์ ห้ามเผยแพร่