AWS-GCP-Site-Site-VPN

Site-Site- VPN 设置

AWS  GCP 环境之间需要设置一个VPN通道

1.                      GCP设置VPC

1.1                      创建vpc

名称随意,然后按照下图所示输入信息(区域按照自己的需要选择),其余默认。

https://pic2.zhimg.com/80/v2-723b13c00b30e88afd8f477c712ba295_720w.jpg

1.2                      创建外部IP

需要创建一个外部IP(区域选择和VPC一样的),用于aws设置网关

https://pic3.zhimg.com/80/v2-588fa72cae6adb8ad0f4824abc72cb9a_720w.jpg

IP创建成功如下图:

https://pic3.zhimg.com/80/v2-739c511672069666043d99031bead5fa_720w.jpg

2.                      AWS设置VPC

2.1                      创建vpc

按照如下图所示红圈中填入信息创建vpc并创建子网,其余默认。

https://pic4.zhimg.com/80/v2-6cdc69df71b0e65d84430960e5c9b173_720w.jpghttps://pic3.zhimg.com/80/v2-6e74c56a9557b5227428b82baddd4ce6_720w.jpg

2.2                      创建客户网关

输入名称和GCP创建的IP地址

https://pic4.zhimg.com/80/v2-9e174e2ca74a5e156585ee61e3f0a103_720w.jpg

2.3                      创建并设置虚拟私有网关

创建虚拟私有网关:

https://pic1.zhimg.com/80/v2-cb3ff02203bef69c80a8456f6c9b5b70_720w.jpg

右键单击虚拟私有网关,选择附加到VPC”

https://pic4.zhimg.com/80/v2-5dd93c5458539cf4c543a99270e1b88f_720w.jpg

选择前面创建的VPC,点击附加到VPC”

https://pic4.zhimg.com/80/v2-7b121c5d25b3b1403471216c3fd7b4f7_720w.jpg

2.4                      创建站点到站点VPN连接

https://pic3.zhimg.com/80/v2-f452c7cc8636bd747f39eb67657d0726_720w.jpg

按照下图所示创建(静态IP前缀:172.16.0.0/16GCP的子网地址空间):

https://pic4.zhimg.com/80/v2-f9fe9addc6685a4660f0095baa93165f_720w.jpg

2.5                      下载配置文件

按照如下操作下载配置文件:

https://pic2.zhimg.com/80/v2-a86e54396fe8bfa42412982b5f026c15_720w.jpg

https://pic4.zhimg.com/80/v2-0aaca633484299b61f3fad6130bf1eaf_720w.jpg

配置文件后续会用到,请记住保存路径。

2.6                      创建并配置路由表

https://pic1.zhimg.com/80/v2-1ff56a6ac7256f85597651ad036f52d0_720w.jpg

https://pic1.zhimg.com/80/v2-9422629728e331c7ad96185521254460_720w.jpg

创建完成后配置路由表:

https://pic1.zhimg.com/80/v2-44ebbc37c4e233216f65fbeaca139488_720w.jpg

勾选启用,点击保存:

https://pic2.zhimg.com/80/v2-000df5cff626f451a66e8272b3341b89_720w.jpg

编辑路由:

https://pic1.zhimg.com/80/v2-d42b802715b1f3305139d1cdd3d0de04_720w.jpghttps://pic1.zhimg.com/80/v2-d42b802715b1f3305139d1cdd3d0de04_720w.jpg

添加子网关联:

https://pic1.zhimg.com/80/v2-5fbee414a0e344987924a807834d7190_720w.jpg

勾选两个子网,点击保存关联:

https://pic4.zhimg.com/80/v2-c64491fc81fd1ba738bb608d17585db7_720w.jpg





















3.                      GCP配置VPN

创建VPN

https://pic3.zhimg.com/80/v2-769cc1f0e94aa1c3f048485d12a4d49e_720w.jpg

https://pic3.zhimg.com/80/v2-6bd2d34b4b8b480af0ea5c05f48afd92_720w.jpg

打开1.2.5步骤下载的配置文件,找到对等IPkey填入(任选其中一个通道):

https://pic4.zhimg.com/80/v2-12f403a971de02816b96db3da21e5cab_720w.jpg










再按照下图操作点击创建:

https://pic1.zhimg.com/80/v2-a6ab1957b2c6201474df79fcc4b86714_720w.jpg

4.                      检查VPN连接

AWS端:

https://pic3.zhimg.com/80/v2-f5e3f3039133594202bce963056b0886_720w.jpg



GCP端:

https://pic1.zhimg.com/80/v2-1aaf9795608829661886852520505468_720w.jpg

通过虚拟机之间相互ping来验证VPN

设置AWS安全组的入站规则:

https://pic1.zhimg.com/80/v2-47a12c2795f70aca2f371e72106daa04_720w.jpg

设置GCP的防火墙规则:

https://pic4.zhimg.com/80/v2-88a6ed80f16fe7200c76a9aa31fb15d3_720w.jpg

AWS虚拟机 pingGCP虚拟机如下所示:

https://pic4.zhimg.com/80/v2-5225009b141feea6b9b8164b4d2edf5f_720w.jpg

GCP虚拟机pingAWS虚拟机如下所示:

https://pic4.zhimg.com/80/v2-e31c8939cfdfe4001ede760703d13753_720w.jpg