[Amazon FSx] AWS Managed Microsoft AD๋ฅผ ์ด์šฉํ•œ FSx ํŒŒ์ผ ์‹œ์Šคํ…œ ๊ตฌ์„ฑ

2023. 3. 10. 19:13ใ†AWS

๋ณธ ํฌ์ŠคํŒ…์—์„œ๋Š” AWS Directory Service๋ฅผ ์ด์šฉํ•˜์—ฌ AWS Managed Microsoft AD๋ฅผ ๊ตฌ์„ฑํ•˜๊ณ , Windows ๊ธฐ๋ฐ˜์˜ EC2๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ํ•ด๋‹น ์„œ๋ฒ„์—์„œ Amazon FSx๋ฅผ ์ด์šฉํ•œ ํŒŒ์ผ ์‹œ์Šคํ…œ์— ์ ‘๊ทผํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ํ…Œ์ŠคํŠธํ•œ๋‹ค.

  1. Active Directory ๊ตฌ์„ฑ
  2. FSx ํŒŒ์ผ ์‹œ์Šคํ…œ์˜ Client Compute(EC2) ๊ตฌ์„ฑ
  3. FSx ํŒŒ์ผ ์‹œ์Šคํ…œ ๊ตฌ์„ฑ
  4. Client EC2์—์„œ ํŒŒ์ผ ์‹œ์Šคํ…œ ์—ฐ๊ฒฐ

 

โ˜„๏ธ To-Be Architecture

 

Amazon FSx for Windows File Server๋ฅผ ๊ตฌ์„ฑํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” Active Directory๊ฐ€ ์‚ฌ์ „์— ๊ตฌ์„ฑ๋˜์–ด ์žˆ์–ด์•ผ ํ•œ๋‹ค.

Amazon FSx๋Š” Microsoft AD(Active Directory)์™€ ํ•จ๊ป˜ ์ž‘๋™ํ•˜์—ฌ ๊ธฐ์กด Windows ํ™˜๊ฒฝ๊ณผ ํ†ตํ•ฉ๋œ๋‹ค. Amazon FSx๋ฅผ ์ด์šฉํ•˜์—ฌ ํŒŒ์ผ ์‹œ์Šคํ…œ์„ ์ƒ์„ฑํ•˜๋Š” ๊ฒฝ์šฐ, Active Directory์— ์กฐ์ธ๋˜์–ด ์‚ฌ์šฉ์ž ์ธ์ฆ๊ณผ ํŒŒ์ผ, ํด๋” ์ˆ˜์ค€์˜ ์•ก์„ธ์Šค ์ œ์–ด๋ฅผ ์ œ๊ณต๋ฐ›์•„์•ผ ํ•œ๋‹ค.

(EC2๋Š” ์ ‘๊ทผํ•˜๊ธฐ ํŽธ๋ฆฌํ•˜๋„๋ก public ์„œ๋ธŒ๋„ท์— ๊ตฌ์„ฑํ•˜์˜€์Šต๋‹ˆ๋‹ค.)

 

 

1. Active Directory ๊ตฌ์„ฑ

AWS Directory Service๋ฅผ ์ด์šฉํ•˜์—ฌ directory๋ฅผ ์ƒ์„ฑํ•œ๋‹ค.

  • Directory type: AWS Manage Microsoft AD
  • Directory DNS name: corp.example.com
  • Admin password ์„ค์ •
  • Network(VPC, Subnet) ์„ค์ •

 

2. EC2 ๊ตฌ์„ฑ

2-1. IAM Role ์ƒ์„ฑ

์•„๋ž˜ ๋‘ AWS managed Policy ์—ฐ๊ฒฐํ•œ IAM Role์„ ์ƒ์„ฑํ•œ๋‹ค.

  • AmazonSSMManagedInstanceCore : AWS Systems Manager ์„œ๋น„์Šค ํ•ต์‹ฌ ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉ
  • AmazonSSMDirectoryServiceAccess : SSM Agent๊ฐ€ ๊ด€๋ฆฌ๋˜๋Š” ์ธ์Šคํ„ด์Šค์— ๋„๋ฉ”์ธ ์กฐ์ธ์„ ์œ„ํ•ด ๋Œ€์‹  Directory Service์— ์•ก์„ธ์Šค ๊ฐ€๋Šฅ

2-2. Security Group ์ƒ์„ฑ

์šฐ์„  RDP๋ฅผ ํ†ตํ•ด ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋„๋ก 3389 ํฌํŠธ๋ฅผ ์˜คํ”ˆํ•œ๋‹ค.

2-3. EC2 ์ƒ์„ฑ

  • OS: Windows
  • Network(VPC, Subnet) ์„ค์ •
  • 2-2์—์„œ ์ƒ์„ฑํ•œ Security Group ์—ฐ๊ฒฐ
  • IAM instance profile : 2-1์—์„œ ์ƒ์„ฑํ•œ IAM Role ์—ฐ๊ฒฐ
  • Domain join directory ์ง€์ • : 1์—์„œ ์ƒ์„ฑํ•œ directory ์„ ํƒ (์ƒ์„ฑ ์‹œ directory join์„ ๋ˆ„๋ฝํ•œ ๊ฒฝ์šฐ, 2-4 ์ฐธ๊ณ )

2-4. (์ฐธ๊ณ ) EC2 ์ƒ์„ฑ ํ›„, AWS Managed Directory์— ์กฐ์ธํ•˜๋Š” ๊ฒฝ์šฐ

(1) DNS Server Address ๋ฅผ directory DNS Server address๋กœ ๋ณ€๊ฒฝํ•œ๋‹ค.

win+R > ncpa.cpl

⇒ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅํ•œ ๋„คํŠธ์›Œํฌ ์ปค๋„ฅ์…˜ > ์šฐ์ธก ๋งˆ์šฐ์Šค > [์†์„ฑ(Properties)] ๋ฒ„ํŠผ ํด๋ฆญ

⇒ [ Internet Protocol Version 4(TCP/IPv4) ] ๋”๋ธ”ํด๋ฆญ

⇒ DNS Server adress๋ฅผ ์ž๋™์œผ๋กœ ๋ถ€์—ฌ๋ฐ›์ง€ ์•Š๊ณ , ์ง์ ‘ ์ž…๋ ฅํ•˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณ€๊ฒฝ

⇒ 1์—์„œ ์ƒ์„ฑํ•œ directory์˜ DNS Server ์ฃผ์†Œ๋กœ ๋ณ€๊ฒฝ ๋ฐ ์ ์šฉ

Directory์˜ DNS ์ฃผ์†Œ๋Š” Networking & security ํƒญ์˜ Networking details์—์„œ ํ™•์ธ ๊ฐ€๋Šฅ

(2) Computer Name/Domain ๋ณ€๊ฒฝ (์„œ๋ฒ„ ์žฌ์‹œ์ž‘ ํ•„์š”)

win+R > sysdm.cpl

⇒ [ Change ] ๋ฒ„ํŠผ ํด๋ฆญ

⇒ 1์—์„œ ์ƒ์„ฑํ•œ Directory์˜ Full Domain๋ช… ์ž…๋ ฅ (corp.example.com)

⇒ AD directory ์ƒ์„ฑ ์‹œ ์ž…๋ ฅํ–ˆ๋˜ Admin ๊ณ„์ • ์ •๋ณด ์ž…๋ ฅ

 

 

3. FSx ํŒŒ์ผ ์‹œ์Šคํ…œ ์ƒ์„ฑ (AWS FSx for Windows File Server)

3-1. Security Group ์ƒ์„ฑ

3-2. AD Domain Controller์˜ ๋ณด์•ˆ๊ทธ๋ฃน ์„ค์ •

๋ณธ ํฌ์ŠคํŒ…๊ณผ ๊ฐ™์ด AWS Directory Service๋ฅผ ์ด์šฉํ•˜์—ฌ directory๋ฅผ ๊ตฌ์„ฑํ•œ ๊ฒฝ์šฐ AD Domain Controller์˜ ๋ณด์•ˆ ๊ทธ๋ฃน์— ํ•„์š”ํ•œ Rule์ด ์ด๋ฏธ ๋ชจ๋‘ ์ ์šฉ๋˜์–ด ์žˆ๋‹ค. ( EC2 ์ฝ˜์†” > Network interfaces > DC์˜ ENI์— {directory-id}_controllers ๋ผ๋Š” ์ด๋ฆ„์˜ Security Group์ด ์ž๋™์œผ๋กœ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋‹ค. )

๊ทธ๋ ‡์ง€ ์•Š๊ณ  ์ž์ฒด ๊ด€๋ฆฌํ˜• AD๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ, 3-1์—์„œ ์ƒ์„ฑํ•œ FSx์˜ Security Group ๋ฐ Domain Controller์˜ ๋ฐฉํ™”๋ฒฝ์— ์•„๋ž˜ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ•˜์—ฌ ํ•„์š”ํ•œ ํŠธ๋ž˜ํ”ฝ์„ ์˜คํ”ˆํ•ด์•ผ ํ•œ๋‹ค.

(์ฐธ๊ณ ) AWS Docs: File System Access Control with Amazon VPC

3-3. ํŒŒ์ผ ์‹œ์Šคํ…œ ์ƒ์„ฑ

  • ํŒŒ์ผ ์‹œ์Šคํ…œ: Amazon FSx for Windows File Server
  • Windows Authentication : AWS Managed Microsoft Active Directory > 1์—์„œ ์ƒ์„ฑํ•œ directory ์„ ํƒ

AD์™€ ์ •์ƒ์ ์œผ๋กœ ํ†ต์‹ ๋˜์–ด ํŒŒ์ผ ์‹œ์Šคํ…œ์ด ๋ฌธ์ œ ์—†์ด ์ƒ์„ฑ๋œ ๊ฒฝ์šฐ, ์œ„์™€ ๊ฐ™์ด ์ƒํƒœ๊ฐ€ Available๋กœ ์ž˜ ํ‘œ์‹œ๋œ๋‹ค.

 

 

 

4. Client์—์„œ ํŒŒ์ผ ์‹œ์Šคํ…œ ์—ฐ๊ฒฐ

3์—์„œ ์ƒ์„ฑํ•œ FSx ํŒŒ์ผ ์‹œ์Šคํ…œ์˜ ์ฝ˜์†”์—์„œ ์šฐ์ธก ์ƒ๋‹จ์˜ Attach ๋ฒ„ํŠผ์„ ๋ˆ„๋ฅด๋ฉด ์—ฐ๊ฒฐ ๋ฐฉ๋ฒ•์ด ๊ฐ€์ด๋“œ๋œ๋‹ค.

2์—์„œ ์ƒ์„ฑํ•œ Client ์ธ์Šคํ„ด์Šค์— ์ ‘์†ํ•˜์—ฌ ์•„๋ž˜์™€ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•œ๋‹ค. Z๋Š” ๋‹ค๋ฅธ ๊ฐ€๋Šฅํ•œ drive ๋ฌธ์ž๋กœ ๋ณ€๊ฒฝํ•˜์—ฌ๋„ ๋ฌด๋ฐฉํ•˜๋‹ค.

net use Z: \\{FSx-DNS-Name}\share

FSx ํŒŒ์ผ ์‹œ์Šคํ…œ ๊ตฌ์„ฑ ์„ฑ๊ณต~!

(Command ์‹คํ–‰ ์‹œ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ FSx, EC2, AD์˜ ๋ณด์•ˆ๊ทธ๋ฃน์„ ์ž˜ ์‚ดํŽด๋ณด์ž)

 

 

5. (์ฐธ๊ณ ) Windows EC2์— AD ๊ด€๋ฆฌ ํˆด ์„ค์น˜ ๋ฐ ๊ด€๋ฆฌ

5-1. 1์—์„œ ์ƒ์„ฑํ•œ Directory Admin ๊ณ„์ •์œผ๋กœ ์ ‘์†

5-2. Powershell์—์„œ ์•„๋ž˜์˜ ๋ช…๋ น์–ด ์‹คํ–‰

Install-WindowsFeature RSAT-ADDS

5-3. Server Manger๋ฅผ ํ†ตํ•ด Feature๋ฅผ ์„ค์น˜

[ Windows Server > Server manager > Add Roles and Features ]์—์„œ ์•„๋ž˜ 3๊ฐœ์˜ Feature๋ฅผ ์„ค์น˜ํ•œ๋‹ค.

โ‘  Active Directory Domain Services

โ‘ก Active Directory Lightweight Domain Services

โ‘ข DNS Server

5-4. Windows Administrative Tools์—์„œ ์„ค์น˜ ํ™•์ธ ๊ฐ€๋Šฅ

5-5. Active Directory users and Computers > FSx ์กฐ์ธ ํ™•์ธ ๊ฐ€๋Šฅ

 

 

 

 

๐Ÿ”— ์ฐธ๊ณ  ๋งํฌ

  1. AWS Docs: Seamlessly join a Windows EC2 instance
  2. AWS Docs: Manually join a Windows instance
  3. AWS Docs: File System Access Control with Amazon VPC
  4. AWS Docs: Installing the Active Directory administration tools