Azure 네트워크 인터페이스 IP 전달 설정 점검

트래픽 중계가 필요한 인터페이스에서만 IP 전달을 사용하세요.

설명

IP 전달은 NIC에 할당된 주소와 다른 목적지·출발지의 트래픽을 처리할 수 있게 합니다. 실제 중계에는 VM의 소프트웨어와 라우팅 설정도 필요합니다.

잠재적 영향

불필요한 전달 기능이 라우팅과 결합하면 의도하지 않은 중계 경로가 생길 수 있습니다.

해결 방법

일반 워크로드에는 ip_forwarding_enabled = false를 사용하세요. 방화벽 같은 네트워크 장비에 필요한 경우에는 라우팅과 접근 정책을 함께 검토하세요.

예시

현재 AzureRM의 IP 전달 옵션을 바꾸는 예시입니다.

변경 전

hcl
resource "azurerm_network_interface" "example" {
  name                = "example-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
  }

  ip_forwarding_enabled = true
}

변경 후

hcl
resource "azurerm_network_interface" "example" {
  name                = "example-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
  }

  ip_forwarding_enabled = false
}

참조