åé¡ã®å£°æ
ããäŒç€ŸãããŒã«ã«ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ¡åŒµã«é¢å¿ããããè² è·ã®äžéšãWindows Azureã«ç§»è¡ããããšèããŠãããšããŸãã çŸæç¹ã§ã¯ãã¯ã©ãŠãã«æ£ç¢ºã«ç§»è¡ãããã®ïŒWebãµãŒããŒãããŒã¿ããŒã¹ãSharePointããŒã¿ã«ãªã©ïŒã¯éèŠã§ã¯ãããŸããã Windows Azureã«å±éãããããŒã«ã«Active DirectoryïŒADïŒã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžéšãšããŠãèŠãããä»®æ³ãã·ã³ããã¡ã€ã³ã«å«ãŸããŠããïŒå«ãŸããŠããå¯èœæ§ãããïŒããšãéèŠã§ãããå®éã«ã¯äŒæ¥ãããã¯ãŒã¯ã®å¥ã®ã»ã°ã¡ã³ããæ§æããããšãéèŠã§ãã
èšç»ãããæ§æã¯æ¬¡ã®ãšããã§ãã

ããæ£ç¢ºã«ã¯ãå³ã®å·ŠåŽã«ãã§ã«ããããšãå³åŽã«è¡ãããšã
ãŸããWindows Azureã«VPNnet01ãšããååã®ä»®æ³ãããã¯ãŒã¯ãäœæããŸãã ãã®ãããã¯ãŒã¯ã§ã¯ãå°ãªããšã2ã€ã®ãµãããããæäŸããå¿ èŠããããŸãã1ã€ïŒæ°åïŒãVMçšã§ããã1ã€ãããŒã«ã«ADãžã®ãã³ãã«ãæ§ç¯ããŸãã ã²ãŒããŠã§ã€å°çšã®ãµãããããæã€ããšã¯ãWindows Azureã®èŠä»¶ã§ãã
次ã«ãäœæããä»®æ³ãããã¯ãŒã¯ãšããŒã«ã«ã€ã³ãã©ã¹ãã©ã¯ãã£éã®ãã³ãã«ãæŽçããŸããæåã«ãã®ãã³ãã«ã¯Windows Azureã®åŽããæ§æããã次ã«ããŒã«ã«ãããã¯ãŒã¯ã®åŽããæ§æãããŸãã
æåŸã«ãWindows Azureã§VMãäœæãããã®ä»®æ³ãã·ã³ãããŒã«ã«ãããã¯ãŒã¯ããã¢ã¯ã»ã¹å¯èœã§ããããšã確èªããŸããéã®å ŽåããVMã¯ããŒã«ã«ã«ãããã¡ã€ã³ã³ã³ãããŒã©ãŒãšå¯Ÿè©±ã§ããŸãã
ãããã£ãŠãæé å šäœã¯ã4ã€ã®äž»èŠãªã¹ãããã«èŠçŽãããŸãã
- Windows Azureã§ä»®æ³ãããã¯ãŒã¯ãäœæãã
- Windows Azureã§ã²ãŒããŠã§ã€ãã»ããã¢ãããã
- LANäžã®S2Sã²ãŒããŠã§ã€ãšããŠã®Windows Server 2012 R2ã®æ§æ
- Windows Azureã§ã®VMã®äœæãšæ§æã®æ€èšŒ
è¡ããïŒ
Windows Azureã§ä»®æ³ãããã¯ãŒã¯ãäœæãã
çµç¹ã«ã¯æ¢ã«Windows Azureãµãã¹ã¯ãªãã·ã§ã³ããããšæããŸãã ãµãã¹ã¯ãªãã·ã§ã³ã®ãªãã·ã§ã³ã¯ããã«ãªã¹ããããŠããŸã ã ãŸããWindows Azureã®ä»®æ³ãããã¯ãŒã¯ã®æŠå¿µã«ã€ããŠãåç¥ã ãšæããŸãã ããã§ãªãå Žåã¯ãMVAããŒã¿ã«ã®ã·ã¹ãã 管çè åãWindows Azureã³ãŒã¹ã®3çªç®ã®ã¢ãžã¥ãŒã«ã§æ å ±ãèŠçŽã§ããŸãã ããããç§ã¯äž»ãªæé ã«ã€ããŠã³ã¡ã³ãããŸãã
ãã®ãããWindows Azure管çããŒã¿ã«ã«ç§»åãã[æ°èŠ]ãã¿ã³ãã¯ãªãã¯ããŠ[ ãããã¯ãŒã¯ ]ã»ã¯ã·ã§ã³ã§æ°ããä»®æ³ãããã¯ãŒã¯ã®äœæãéžæããå¿ èŠããããŸãã

ä»®æ³ãããã¯ãŒã¯ã«ååãä»ããŠAFFINITY GROUPãéžæããŸããããã«ãããåãWindows AzureããŒã¿ã»ã³ã¿ãŒå ã«VMãé 眮ããŠããããã¯ãŒã¯ã®åŸ ã¡æéãççž®ã§ããŸãã åäžã®AFFINITY GROUPããªãå Žåããã®ãããªã°ã«ãŒããäœæããããæ±ããããŸãã

次ã®ããŒãžã§ãDNSãµãŒããŒã®ååãšIPã¢ãã¬ã¹ãæå®ããå¿ èŠããããŸãã å³å¯ã«èšãã°ããã®ãã£ãŒã«ãã¯ãªãã·ã§ã³ã§ãããåŸã§å ¥å/å€æŽã§ããŸãã ãããããã®ã·ããªãªã§ã¯ããã¹ãŠã®DNSæ å ±ããã§ã«ããã«ãããŸãã ADãšã³ã¿ãŒãã©ã€ãºã®äžéšãšããŠWindows Azureã®VMã䜿çšããäºå®ãªã®ã§ãããã§ã¯ãåŸæ¥DNSãµãŒããŒãšããŠãæ©èœãããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ååãšIPã¢ãã¬ã¹ã瀺ããŸãã ãã®ãããã¯ãŒã¯ã§äœæããããã¹ãŠã®VMã¯ããã®æ£ç¢ºãªã¢ãã¬ã¹ãDNSãµãŒããŒã¢ãã¬ã¹ãšããŠèªåçã«åãåããŸãã ãã£ãŒã«ãã空çœã®ãŸãŸã«ãããšãåŸã§äœæãããVMã¯åå解決ã«Windows Azure DNSã䜿çšãããã¡ããããã®ãããªãã·ã³ããã¡ã€ã³ã«å«ããããšã¯ã§ããŸããã æè¡çã«ã¯ãããšãã°RDPã䜿çšããŠç¹å®ã®VMã«ç§»åããDNSã¢ãã¬ã¹ãæåã§å€æŽã§ããŸããããã®ããŒãžã§æäŸããããªãã·ã§ã³ã®æ¹ãã¯ããã«äŸ¿å©ã§ãã ããã«ãä»®æ³ãã·ã³ã®TCP / IPèšå®ãæåã§å€æŽããããšã¯äžè¬çã«æšå¥šãããªãããšã«æ³šæããŠãã ããã Windows Azureã¯ãããã®èšå®ãå¶åŸ¡ãããŠãŒã¶ãŒããã·ã³ã«ä¿¡é Œã§ããã¢ã¯ã»ã¹ãè¡ããããã«ããŸãã
ãã®ããŒãžã®2çªç®ã®éèŠãªãã©ã¡ãŒã¿ãŒã¯ã ãµã€ãéVPNã®æ§æãã§ãã¯ããã¯ã¹ã§ããã泚æããå¿ èŠããããŸãã

[ ãµã€ãéæ¥ç¶]ããŒãžã§ã3ã€ã®ãã©ã¡ãŒã¿ãŒãèšå®ããŸãã
- NAME-ãµã€ãã®ååãä»»æã®ååã«ããããšãã§ãããã®ããŒãžã§äœæããèšå®ã»ããã®ã¿ãèå¥ããŸãã
- VPNããã€ã¹ã®IPã¢ãã¬ã¹ -ãã®ã·ããªãªã«é©çšãããäŒæ¥ã®ããŒã«ã«ãããã¯ãŒã¯å ã®VPNã²ãŒããŠã§ã€ã®å€éšIPã¢ãã¬ã¹ãããã¯ãWindows Server 2012 R2ãã·ã³ã®å€éšãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹äžã®IPv4ã¢ãã¬ã¹ã§ãã
- ã¢ãã¬ã¹ç©ºé-Windows Azureããã¢ã¯ã»ã¹ãæäŸããããŒã«ã«ãããã¯ãŒã¯ãŸãã¯ãã®éšåã®ã¢ãã¬ã¹ç©ºéã

[ ä»®æ³ãããã¯ãŒã¯ã¢ãã¬ã¹ã¹ããŒã¹]ããŒãžã§ãäœæããä»®æ³ãããã¯ãŒã¯ã®ä»®æ³ã¢ãã¬ã¹ã¹ããŒã¹ãäœæããå¿ èŠããããŸãã ã¯ã©ãŠãå ã®VMã¯ããã®ã¹ããŒã¹ããIPã¢ãã¬ã¹ãåãåããŸãã ãããã¯ãŒã¯å šäœã®ã¢ãã¬ã¹ç¯å²ãæå®ããããããããµããããã«åå²ããå¿ èŠããããŸãã å°ãªããšã2ã€ã®ãµãããããå¿ èŠã§ããããšãæãåºãããŠãã ãããããããVMãšã²ãŒããŠã§ã€çšã§ãã åä»®æ³ãããã¯ãŒã¯ã¯ã1ã€ã®ã²ãŒããŠã§ã€ãµããããã®ã¿ãæã€ããšãã§ããŸãã

ãå®äºããã¿ã³ãã¯ãªãã¯ããŠãä»®æ³ãããã¯ãŒã¯äœæããã»ã¹ã®å®äºãåŸ ã¡ãŸãã

å®éãæåã®æ®µéã¯å®äºããŠãããWindows Azureã²ãŒããŠã§ã€ã®æ§æã«é²ãããšãã§ããŸãã
Windows Azureã§ã²ãŒããŠã§ã€ãã»ããã¢ãããã
ãããã¯ãŒã¯ãäœæããããããããã¯ãªãã¯ããŠ[ ããã·ã¥ããŒã ]ã¿ãã衚瀺ããŸãã

ç»é¢äžéšã®ã¡ãã¥ãŒã§ã[ ã²ãŒããŠã§ã€ã®äœæ ]ãã¯ãªãã¯ãã[ åçã«ãŒãã£ã³ã° ]ãéžæããŸãã çŸåšã2çš®é¡ã®ã«ãŒãã£ã³ã°ãWindows Azureã§ãµããŒããããŠããŸãã éçã«ãŒãã£ã³ã°ã¯ãŠãŒã¶ãŒå®çŸ©ã®ããªã·ãŒïŒã¢ã¯ã»ã¹ãªã¹ãïŒã«åºã¥ããŠãããåçã«ãŒãã£ã³ã°ã¯æå®ãããã«ãŒããšãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«åºã¥ããŠããŸãïŒãã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«å°çãããã±ããã¯ãVPNãã³ãã«ãä»ããŠè»¢éãããŸãïŒã åçã«ãŒãã£ã³ã°ã®å ŽåããããããWindows Azureã§ã®ä»®æ³ãããã¯ãŒã¯ã®äœæäžã«ä»®æ³ã¢ãã¬ã¹ã¹ããŒã¹ãšããŒã«ã«ã¢ãã¬ã¹ã¹ããŒã¹ã®IPç¯å²ãæ£ããèšå®ãããŠããå ŽåïŒéè€ããªããè€è£œããªããªã©ïŒãWindows AzureãšããŒã«ã«ã€ã³ãã©ã¹ãã©ã¯ãã£éã§ãã±ãããé©åã«ã«ãŒãã£ã³ã°ããå¿ èŠããããŸãã

ã«ãŒãã£ã³ã°ã¿ã€ãã®éžæã¯ãããŒã«ã«ã€ã³ãã©ã¹ãã©ã¯ãã£åŽã§äœ¿çšãããã²ãŒããŠã§ã€ã«ãã£ãŠæ±ºãŸããŸãã ãæ¢ç¥ã®äºææ§ã®ããVPNããã€ã¹ãã»ã¯ã·ã§ã³ã®ããã¥ã¡ã³ãã§ããµããŒããããŠããã²ãŒããŠã§ã€ãšå¯Ÿå¿ããã«ãŒãã£ã³ã°ã¿ã€ãã®ãªã¹ãã確èªã§ããŸãã
Windows Azureãã²ãŒããŠã§ã€ãæ§æããã®ãåŸ ã€ããšã¯æ®ã£ãŠããŸãã ãã®ããã»ã¹ã«ã¯ãå¹³å15ã20åããããŸãã

ããŒãžã®æåŸã«ãWindows Azureã§äœæãããã²ãŒããŠã§ã€ã®å€éšIPã¢ãã¬ã¹ã衚瀺ãããŸãããã®ã¢ãã¬ã¹ã¯ãäŒæ¥ãããã¯ãŒã¯ã§ã²ãŒããŠã§ã€ãæ§æãããšãã«æ¥ç¶ãšã³ããã€ã³ããšããŠäœ¿çšããå¿ èŠããããŸãã

Windows Server 2012 / R2ã®RRASãµãŒãã¹ãå«ãç¹å®ã®ã²ãŒããŠã§ã€ã¢ãã«ïŒVPNããã€ã¹ïŒã®å ŽåãWindows Azureã¯ãVPNããã€ã¹ã§å®è¡ããå¿ èŠãããã¹ã¯ãªãããçæã§ããŸããããã«ãããWindows Azureã§ãã³ãã«ãäœæããããã«ãã®ããã€ã¹ãæ§æããŸãã ãã®ãããªã¹ã¯ãªãããèªã¿èŸŒãã«ã¯ã MANAGE KEYãæŒããŠãã³ãã«èªèšŒã«äœ¿çšãããããŒãäœæããå¿ èŠããããŸã

次ã«ãããŒãžã®å³åŽã«ãã[ VPNããã€ã¹ã¹ã¯ãªããã®ããŠã³ããŒã ]ãªã³ã¯ãã¯ãªãã¯ããŸãã
éãããŠã£ã³ããŠã§ãã²ãŒããŠã§ã€ã®è£œé å ããã©ãããã©ãŒã ãããã³ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãéžæããã¹ã¯ãªãããããŒãããŸãã

次ã«ãçµæã®ã¹ã¯ãªãããVPNããã€ã¹ã«è»¢éããŠãæ§æãå®è¡ããå¿ èŠããããŸãã
Windows Server 2012 R2ãS2Sã²ãŒããŠã§ã€ãšããŠæ§æãã
åã®æé ã§ååŸããã¹ã¯ãªããã«ãä»®æ³ãããã¯ãŒã¯ã®ã¢ãã¬ã¹ã¹ããŒã¹ãšWindows Azureã²ãŒããŠã§ã€ã®å€éšã¢ãã¬ã¹ã®æ£ããå€ãå«ãŸããŠããããšã確èªããå¿ èŠããããŸãã ãããã®å€ã¯ãäžèšã®ã¹ã¯ãªãããã©ã°ã¡ã³ãã§åŒ·èª¿è¡šç€ºãããŠããŸãã
# Install RRAS role Import-Module ServerManager Install-WindowsFeature RemoteAccess -IncludeManagementTools Add-WindowsFeature -name Routing -IncludeManagementTools # !!! NOTE: A reboot of the machine might be required here after which the script can be executed again. # Install S2S VPN Import-Module RemoteAccess Install-RemoteAccess -VpnType VpnS2S # Add and configure S2S VPN interface Add-VpnS2SInterface -Protocol IKEv2 -AuthenticationMethod PSKOnly -NumberOfTries 3 -ResponderAuthenticationMethod PSKOnly -Name 137.116.214.169 -Destination 137.116.214.169 -IPv4Subnet @("10.50.0.0/16:100") -SharedSecret 0pCpWdVuzaJuZtJpQq8TbtUAQWk7PtOk Set-VpnServerIPsecConfiguration -EncryptionType MaximumEncryption # Set S2S VPN connection to be persistent by editing the router.pbk file (required admin priveleges) Set-PrivateProfileString $env:windir\System32\ras\router.pbk "137.116.214.169" "IdleDisconnectSeconds" "0" Set-PrivateProfileString $env:windir\System32\ras\router.pbk "137.116.214.169" "RedialOnLinkFailure" "1" # Restart the RRAS service Restart-Service RemoteAccess # Dial-in to Azure gateway (optional) #Connect-VpnS2SInterface -Name 137.116.214.169
ãã¹ãŠãæ£ãããã°ãã²ãŒããŠã§ã€ãšããŠæ©èœããWindows Server 2012 R2ãæèŒãããã·ã³ã§ãã®ã¹ã¯ãªãããå®è¡ããã ãã§ãã äžèšã¯æçã«éããªãããšã匷調ããŸãã ãã¡ããã管çè æš©éãæã€ã¢ã«ãŠã³ãã§ã¹ã¯ãªããå šäœãå®è¡ããå¿ èŠããããŸãã ããšãã°ãããã¯PowerShell ISEã§å®è¡ã§ããŸãã

次ã®ã¹ããããã¯ãã¹ã¯ãªãããã«ãŒãã£ã³ã°ãšãªã¢ãŒãã¢ã¯ã»ã¹ãµãŒãã¹ïŒRRASïŒãã€ã³ã¹ããŒã«ããã³æ§æããããšã瀺ããŠããŸãã æåããã¹ã¯ãªããã®åŸãããã€ãã®RRASãã³ããã©ã®ããã«èŠãããèŠãŠã¿ãŸãããã
ãŸãã[ ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹]ã»ã¯ã·ã§ã³ã§ãWindows Azureã®ã²ãŒããŠã§ã€ã®å€éšIPã¢ãã¬ã¹ã«å¯Ÿå¿ããååã®ã€ã³ã¿ãŒãã§ã€ã¹ã確èªã§ããŸãããã®ã€ã³ã¿ãŒãã§ã€ã¹ã®ç¶æ ã¯[ æ¥ç¶æžã¿]ã§ããå¿ èŠããããŸãã ããã§ãªãå Žåã¯ãå³ã¯ãªãã¯ããŠãã³ã³ããã¹ãã¡ãã¥ãŒãã[ æ¥ç¶ ]ãéžæããŸãã

ç解ããŠããããã«ããã³ãã«ãæ§ç¯ããããã«äœ¿çšããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã®ããããã£ã«ã¯ãWindows Azureã²ãŒããŠã§ã€ã®IPã¢ãã¬ã¹ããããŸãã

ãŸãã[ ã»ãã¥ãªã㣠]ã¿ãã§ã¯ã䜿çšãããŠãããããã³ã«ïŒIKEv2ïŒãšWindows Azureã§çæãããããŒã衚瀺ãããŸãã

ããã«ã éçã«ãŒãã»ã¯ã·ã§ã³ã«éçã«ãŒãã衚瀺ãããWindows Azureä»®æ³ãããã¯ãŒã¯ã«å±ããåä¿¡è ã¢ãã¬ã¹ãæã€ãã¹ãŠã®ãã±ããããã³ãã«ãä»ããŠè»¢éãããŸãã

RRASãµãŒããŒèªäœã¯ããã®ããããã£ãèŠããšãããããã«ãã«ãŒã¿ãŒãšããŠæ§æãããŠããŸãã

äžèšã®æ å ±ã䜿çšããŠãäœããã®çç±ã§ã¹ã¯ãªããã倱æããå ŽåãRRASãµãŒãã¹ãæåã§æ§æã§ããŸãã
ãã¹ãŠãæ£åžžãªå ŽåãWindows Azureã§äœæãããä»®æ³ãããã¯ãŒã¯ã®[ ããã·ã¥ããŒã ]ã¿ãã«æ»ããšã 次ã®ããã«è¡šç€ºãããŸãã

ãŸãã¯ãããŒãžã®äžéšã«ãã[æ¥ç¶]ãã¿ã³ãã¯ãªãã¯ãããšããã®ããã«ãªããŸãã
Windows Azureã§ã®VMã®äœæãšæ§æã®æ€èšŒ
ãã³ãã«ãäœæãããã®ã§ãæ§æã確èªããããã«æ®ããŸãã
ãããè¡ãã«ã¯ãWindows Azureã§VMãäœæããADããŒã«ã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ãã®VMãæå¹ã«ããŠã¿ãŸãã æé ã¯ããªãæšæºçã§ãã[ ä»®æ³ãã·ã³ ]ã»ã¯ã·ã§ã³ã§[ æ°èŠ ]ãã¯ãªãã¯ãã[ ã®ã£ã©ãªãŒãã]ãéžæããŸãã

ã²ã¹ãOSãšããŠãããšãã°ãWindows Server 2012ãéžæããŸãã

VMåã管çè ãã°ã€ã³ããã³ãã¹ã¯ãŒããèšå®ãã

ãã·ã³ã以åã«äœæãããä»®æ³ãããã¯ãŒã¯ã«æ¥ç¶ãããããšã確èªããŸãã

æåŸã®ããŒãžã§ã¯ããã¹ãŠãå€æŽããŸããã

VMã®èµ·ååŸãRDPãä»ããŠVMã«æ¥ç¶ããIPèšå®ã確èªã§ããŸãã ãã®å Žåããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ã¢ãã¬ã¹ïŒ192.168.3.200ïŒãDNSãµãŒããŒã®ã¢ãã¬ã¹ãšããŠæå®ãããŠããéãVMãä»®æ³ãããã¯ãŒã¯ã®ã¢ãã¬ã¹ã¹ããŒã¹ããã¢ãã¬ã¹10.50.1.4ãåä¿¡ããããšã¯æããã§ãã

ãã¡ãããã¡ã€ã¢ãŠã©ãŒã«ãICMPãèš±å¯ããŠããªãéãããã¡ã€ã³ã³ã³ãããŒã©ãŒã§åå解決ãšpingã確èªããŸãã

éä¿¡ã¯æ§æãããŸããããã¡ã€ã³ã«VMãå«ããã ãã§ããããã¯æãäžè¬çãªæé ã§ãããããã§ã¯è©³ãã説æããŸããã
ãã®ããããã¹ãŠã®æ®µéãçµãŠãããŒã«ã«ã€ã³ãã©ã¹ãã©ã¯ãã£ãWindows Azureã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«ãã£ãŠæ¡åŒµãããŸããã ãã®ã»ã°ã¡ã³ãã§ã¯ãè¿œå ã®ãµãããããäœæããå¿ èŠãªæ§æã®VMãèµ·åããå¿ èŠãªãµãŒãã¹ããããã«è»¢éããç£èŠãæ§æãããã®æ¹æ³ã§ã¯ã©ãŠããªãœãŒã¹ã䜿çšããŠITéšéãçŽé¢ããã¿ã¹ã¯ã解決ã§ããŸãã
å¿ èŠã«å¿ããŠäžèšã®æé ãåçŸã§ããããã«ãèšå®ã®ååã«è©³çŽ°ãªèª¬æãæäŸããŸããã åè¿°ã®ããã«ãWindows Azure Webãµã€ãã§ã¯ãããŸããŸãªã¿ã€ãã®VPNã²ãŒããŠã§ã€çšã®ã¹ã¯ãªãããèŠã€ããããšãã§ããŸãã ãã ããããã€ã¹ããã®ãªã¹ãã«ãªãå Žåã§ããã²ãŒããŠã§ã€ãæ§æã§ããŸããäœæ¥ã®ããžãã¯ãšãWindows Azureã§äœ¿çšãããŠãããããã³ã«ãšèªèšŒã¡ã«ããºã ãç解ããŠããŸãã äžè¬çã«ããã¯ãããžãŒãåŠã¶æè¯ã®æ¹æ³ã¯èªåã§è©ŠããŠã¿ãããšã§ãã :)
ï
çŽ æãã圹ã«ç«ãŠã°å¹žãã§ãïŒ