注意:
请联系 feature-releases@catonetworks.com 以获取有关启用和使用此功能的更多信息。
您可以在 Amazon Web Services (AWS) 中部署应用连接器,来为您的云环境中的私有应用程序提供安全访问。应用连接器在您的云环境和 Cato 之间建立连接,连接后,您可以在 CMA 中分配它并将其与相关的应用连接器组相关联。
应用连接器基于 Cato vSocket 基础设施和镜像,从 vSocket v26.0.23570 开始。如果您无法访问此 Socket 版本,请 contact Support 并请求他们将其提供给您的账户。
您还可以使用 Cato Terraform 模块 来创建和管理 AWS 应用连接器。
了解 AWS 中应用连接器工作流程
以下是一个在 AWS 中部署应用连接器的高级工作流程:
您在 CMA 中创建应用连接器对象
从 AWS Marketplace 部署 Cato 应用连接器
为连接器分配应用程序
Create an App Connector
When you create an App Connector, you can choose the behavior for connecting to a preferred PoP in the Cato Cloud:
Disabled - the App Connector automatically connects to the best available PoP (default)
Enabled - Select the PoPs to which the connector attempts to connect to
When Preferred PoP is enabled, you can restrict an App Connector to only connect to the Preferred PoP Locations that you configure. In this case, the connector doesn't connect to a non-preferred PoP location despite any connectivity or performance issues that it is experiencing. When you use this option, you must define a primary and secondary PoP location for the App Connector.
Once the App Connector is created in the CMA, copy the serial number, as you will need to provide it when deploying the App Connector in your cloud environment.

To create an App Connector in the CMA:
From the navigation menu, click Access > App Connector, and then click New.
Enter the information in the General section, such as Connector Name and Country.
Under Type, click Virtual.
In the Connector Group section, select an existing App Connector group from the list or enter a name to create a new group.
Under Preferred PoPs, select the behavior
Disabled - the App Connector tries to connect to the best available PoP
Enabled - Select the Primary and Secondary PoP locations that the connector tries to connect to
Enabled and Only connect to the preferred PoPs - Only connect to the Primary or Secondary PoP location
Click Apply.
在 Amazon Web Services 部署应用连接器
使用 AWS Marketplace 中的 Cato 向导自动创建应用连接器的虚拟资源,并将其部署到 AWS。应用连接器映像在 Marketplace 中公开可用。
在 AWS 中部署应用连接器
从 AWS Marketplace 中搜索 Cato Networks 应用连接器,然后点击 启动。
在 网络配置下,决定是否在新的或现有的 VPC 中部署应用连接器。
如果选择现有账户,在 现有 VPC 下拉菜单中,点击相关虚拟网络。
为以下接口选择子网(最小子网地址空间为 /28):
MGMT 子网 – 应用连接器与 AWS API 之间的管理通信
WAN子网 - 应用连接器的外部WAN流量(互联网和Cato云)
LAN 子网 - 连接到应用连接器的内部 AWS 资源和流量
在 安全配置下:
在 现有内部安全组 字段中,定义控制来自您内部网络的流量的安全组。
在 实例配置下:
选择运行应用连接器的实例类型
在 MyKeyPair 字段中,选择创建的用于加密此连接的密钥对
在 序列号 字段中,粘贴早前从 CMA 复制的值。
点击 提交。
您可以在访问 > 应用连接器页面中查看您的应用连接器。
为连接器分配应用程序
您可以从私有应用页面或应用连接器页面为连接器分配应用程序,使用 分配应用 链接。