注:
詳細は feature-releases@catonetworks.com にお問い合わせください。
Amazon Web Services (AWS)でアプリケーションコネクタを展開し、クラウド環境内で非公開アプリケーションへの安全なアクセスを提供できます。 アプリケーションコネクタは、クラウド環境とCato間の接続を確立し、一度接続すると、CMAで割り当て、関連するアプリケーションコネクタグループに関連付けます。
AWSワークフローでのアプリケーションコネクタの理解
以下はAWSでアプリケーションコネクタを展開するための高レベルのワークフローです:
CMAでアプリケーションコネクタオブジェクトを作成します
AWSマーケットプレイスからCatoアプリケーションコネクタをデプロイします
アプリケーションをコネクタに割り当てる
Create an App Connector
When you create an App Connector, you can choose the behavior for connecting to a preferred PoP in the Cato Cloud:
Disabled - the App Connector automatically connects to the best available PoP (default)
Enabled - Select the PoPs to which the connector attempts to connect to
When Preferred PoP is enabled, you can restrict an App Connector to only connect to the Preferred PoP Locations that you configure. In this case, the connector doesn't connect to a non-preferred PoP location despite any connectivity or performance issues that it is experiencing. When you use this option, you must define a primary and secondary PoP location for the App Connector.
Once the App Connector is created in the CMA, copy the serial number, as you will need to provide it when deploying the App Connector in your cloud environment.

To create an App Connector in the CMA:
From the navigation menu, click Access > App Connector, and then click New.
Enter the information in the General section, such as Connector Name and Country.
Under Type, click Virtual.
In the Connector Group section, select an existing App Connector group from the list or enter a name to create a new group.
Under Preferred PoPs, select the behavior
Disabled - the App Connector tries to connect to the best available PoP
Enabled - Select the Primary and Secondary PoP locations that the connector tries to connect to
Enabled and Only connect to the preferred PoPs - Only connect to the Primary or Secondary PoP location
Click Apply.
Amazon Web Servicesでアプリケーションコネクタを展開
Amazonマーケットプレイスで自動化されたCatoウィザードを使用してアプリケーションコネクタの仮想リソースを作成し、AWSにデプロイします。 アプリケーションコネクタの画像はマーケットプレイスで公開されています。
AWSでアプリケーションコネクタを展開する
AWSマーケットプレイスからCato Networksアプリケーションコネクタを検索し、開始をクリックします。
ネットワーク設定で、アプリケーションコネクタを新しいまたは既存のVPCに展開するかどうかを決定します。
既存のアカウントを選択した場合は、既存VPCのドロップダウンメニューで関連する仮想ネットワークをクリックします。
次のインタフェース用のサブネットを選択します(/28以上のサブネットアドレス空間):
MGMTサブネット – アプリケーションコネクタとAWS API間の管理通信
WANサブネット - アプリケーションコネクタの外部WANトラフィック(インターネットおよびCato Cloud)
LANサブネット - アプリケーションコネクタに接続された内部AWSリソースとトラフィック
セキュリティ設定について:
既存の外部セキュリティグループフィールドで、ポート443および22のインバウンドトラフィックを制御するセキュリティグループを定義します。 良好なセキュリティ対策を維持するため、これを可能な限り小さなIPアドレスのグループに限定する必要があります
既存の内部セキュリティグループフィールドで、内部ネットワークからのトラフィックを制御するセキュリティグループを定義します
インスタンス設定について:
アプリケーションコネクタを実行するインスタンスタイプを選択
MyKeyPairフィールドで、この接続を暗号化するために作成されたキー・ペアを選択します
シリアル番号フィールドで、以前CMAからコピーした値を貼り付けます。
投稿をクリックします。
アクセス > アプリケーションコネクタページで、アプリケーションコネクタを確認できます。
アプリケーションをコネクタに割り当てる
プライベートアプリケーションページまたはアプリケーションコネクタページで、アプリ割り当てリンクを使用してアプリケーションをコネクタに割り当てます。