关于 Cloudflare 如何编排连向你云网络的 VPN 连通性的详细信息,请参阅此页面。
注意:此图片中的标签可能反映了以前的产品名称。
当使用 Cloudflare One Multi-Cloud Networking(原 Magic Cloud Networking)(beta) 自动创建连向你 AWS 账户的 On-ramp 时,你需要注意 Cloudflare 将代表你进行的以下配置更改:
- Cloudflare 将创建一个名为 Cloudflare WAN and Cloudflare Edge 的新客户托管前缀列表,其中填充了你的 Cloudflare WAN Address Space 前缀以及 Cloudflare 全球网络服务器的 IPv4 地址范围(如果你使用任何 Cloudflare L7 处理功能,后者的前缀是必需的)。你必须在网络安全组 (NSG) 中创建允许发往/来自此前缀列表的流量的规则,以便与 Cloudflare WAN(原 Magic WAN)保持连通。(前缀列表将包含大约 15 到 25 个条目,每个条目都会计入你 AWS 账户中 NSG 的每个安全组规则配额。)
- Cloudflare 将创建一个 Virtual Private Gateway 并将其附加到你的虚拟私有云 (VPC)。如果现有 Virtual Private Gateway 已附加到该 VPC,则 On-ramp 创建将失败。
- Cloudflare 将启用从 Virtual Private Gateway 到 VPC 中所有路由表的路由传播。这将导致 Cloudflare WAN Address Space 中的每个前缀都有一条指向该网关的路由。
- Cloudflare 将在 Cloudflare WAN 中为你 VPC 中的每个 IPv4 CIDR(无类别域间路由)块添加一条路由。
注意:此图片中的标签可能反映了以前的产品名称。
当使用 Multi-Cloud Networking (beta) 自动创建连向你 Azure 账户的 On-ramp 时,你需要注意 Cloudflare 将代表你进行的以下配置更改:
- Cloudflare 将在你的虚拟网络 (VNet) 中创建一个 Virtual Network Gateway。Azure 中的 Virtual Network Gateway 要求名为
GatewaySubnet的子网。如果你的 VNet 中尚不存在GatewaySubnet,Cloudflare 将创建一个。如果你的 VNet 中没有足够的未使用地址空间来为GatewaySubnet创建/27子网,或者存在GatewaySubnet但没有足够的剩余地址空间供 Virtual Network Gateway 使用,则 On-ramp 创建将失败。 - Cloudflare 将在你的 VNet 中的所有路由表上启用网关路由传播。这将导致你的 Cloudflare WAN Address Space 中的每个前缀都有一条指向网关的路由。如果你的 VNet 拥有其他 Virtual Network Gateway,它们的路由也会传播到你的路由表。如果你删除 On-ramp,路由传播不会被禁用。
- 默认情况下,Azure 中的网络安全组包含针对与
VirtualNetwork服务标记发往/来自的出站/入站流量的 Allow 规则,该服务标记包含 Virtual Network Gateway 地址空间(因此也包含你的 Cloudflare WAN Address Space)。如果你不希望 VNet 中的所有资源都可从 Cloudflare WAN 访问,请在你的网络安全组 (NSG) 中添加适当的 Deny 规则。 - Cloudflare 将在 Cloudflare WAN 中为你 VNet 中的每个 IPv4 地址范围添加一条路由。
注意:此图片中的标签可能反映了以前的产品名称。
当使用 Multi-Cloud Networking (beta) 自动创建连向你 Google Cloud Platform (GCP) 账户的 On-ramp 时,你需要注意 Cloudflare 将代表你进行的以下配置更改:
- Cloudflare 将从 GCP 保留一个公共互联网可路由 IP 地址。
- Cloudflare 将在你指定的区域中创建一个 VPN 网关和两个 VPN 隧道。
- Cloudflare 将为你 VPC 内 Cloudflare WAN Address Space 中的每个前缀创建指向 VPN 隧道的路由。
- Cloudflare 将在 Cloudflare WAN 中为你 VPC 中的所有子网 CIDR 前缀添加路由。这包括 VPC 内的所有区域。发往 VPN 网关区域以外区域的流量将受 GCP 跨区域计费 ↗的约束。
- 通过 VPN 隧道发往和发自你的 VM 实例的流量仍受 VPC 防火墙规则约束,并且可能需要进一步配置 ↗。
Multi-Cloud Networking (beta) 在你的云环境中发现以下资源类型。这些资源用于构建你云网络拓扑与连通性的全面视图。
- AWS Customer Gateway
- AWS EC2 Managed Prefix List
- AWS EC2 Transit Gateway
- AWS EC2 Transit Gateway Prefix List
- AWS EC2 Transit Gateway VPC Attachment
- AWS Egress Only Internet Gateway
- AWS Internet Gateway
- AWS Instance
- AWS Network Interface
- AWS Route Table
- AWS Route Table Association
- AWS Security Group
- AWS Subnet
- AWS VPC
- AWS VPC IPv4 CIDR Block Association
- AWS VPC Security Group Egress Rule
- AWS VPC Security Group Ingress Rule
- AWS VPN Connection
- AWS VPN Connection Route
- AWS VPN Gateway
- Azure Application Security Group
- Azure Load Balancer
- Azure Load Balancer Backend Address Pool
- Azure Load Balancer NAT Pool
- Azure Load Balancer NAT Rule
- Azure Load Balancer Rule
- Azure Local Network Gateway
- Azure Network Interface
- Azure Network Interface Application Security Group Association
- Azure Network Interface Backend Address Pool Association
- Azure Network Interface Security Group Association
- Azure Network Security Group
- Azure Public IP
- Azure Route
- Azure Route Table
- Azure Subnet
- Azure Subnet Route Table Association
- Azure Virtual Machine
- Azure Virtual Machine Gateway Connection
- Azure Virtual Network
- Azure Virtual Network Gateway
- Azure Virtual Network Gateway Connection
- Google Compute Address
- Google Compute Forwarding Rule
- Google Compute Global Address
- Google Compute HA VPN Gateway
- Google Compute Interconnect Attachment
- Google Compute Network
- Google Compute Network Firewall Policy
- Google Compute Network Firewall Policy Rule
- Google Compute Route
- Google Compute Router
- Google Compute Subnetwork
- Google Compute VPN Gateway
- Google Compute VPN Tunnel