创建VPC边界防火墙(防护云企业网基础版的网络实例和指定VPC之间的互访流量)

本文介绍如何使用Terraform创建VPC边界防火墙(防护云企业网基础版的网络实例和指定VPC之间的互访流量)。

注意事项

前提条件

  • 已创建阿里云账号和访问密钥(AccessKey)。具体操作,请参见创建AccessKey

  • 已经安装并配置了Terraform。

创建VPC边界防火墙

  1. Terraform执行目录下的terraform.tf文件中,配置如下内容。

    代码示例如下:

    provider "alicloud" {
      version = "~> 1.203.0"
    }
    
    resource "alicloud_cloud_firewall_vpc_firewall_cen" "default" {
      cen_id = "cen-cjok7uyb5w2b27****"
      local_vpc {
        network_instance_id = "vpc-wz9vxghjlwdgi3jfq****"
      }
      status            = "open"
      member_uid        = "141518928482****"
      vpc_region        = "cn-shenzhen"
      vpc_firewall_name = "tf-test"
    }

  1. 运行terraform init,对环境进行初始化。

    代码示例如下:

    Initializing the backend...
    
    Initializing provider plugins...
    - Checking for available provider plugins...
    - Downloading plugin for provider "alicloud" (hashicorp/alicloud) 1.203.0...
    
    
    Warning: registry.terraform.io: For users on Terraform 0.13 or greater, this provider has moved to aliyun/alicloud. Please update your source in required_providers.
    
    
    Terraform has been successfully initialized!
    
    You may now begin working with Terraform. Try running "terraform plan" to see
    any changes that are required for your infrastructure. All Terraform commands
    should now work.
    
    If you ever set or change modules or backend configuration for Terraform,
    rerun this command to reinitialize your working directory. If you forget, other
    commands will detect it and remind you to do so if necessary.

  1. 运行terraform apply出现如下配置信息后,确认配置信息并输入yes,开始创建。

    代码示例如下:

    An execution plan has been generated and is shown below.
    Resource actions are indicated with the following symbols:
      + create
    
    Terraform will perform the following actions:
    
      # alicloud_cloud_firewall_vpc_firewall_cen.default will be created
      + resource "alicloud_cloud_firewall_vpc_firewall_cen" "default" {
          + cen_id            = "cen-cjok7uyb5w2b27573v"
          + connect_type      = (known after apply)
          + id                = (known after apply)
          + lang              = (known after apply)
          + member_uid        = "141518928482****"
          + status            = "open"
          + vpc_firewall_id   = (known after apply)
          + vpc_firewall_name = "tf-test"
          + vpc_region        = "cn-shenzhen"
    
          + local_vpc {
              + attachment_id         = (known after apply)
              + attachment_name       = (known after apply)
              + defend_cidr_list      = (known after apply)
              + eni_list              = (known after apply)
              + manual_vswitch_id     = (known after apply)
              + network_instance_id   = "vpc-wz9vxghjlwdgi3jfqxa2d"
              + network_instance_name = (known after apply)
              + network_instance_type = (known after apply)
              + owner_id              = (known after apply)
              + region_no             = (known after apply)
              + route_mode            = (known after apply)
              + support_manual_mode   = (known after apply)
              + transit_router_id     = (known after apply)
              + transit_router_type   = (known after apply)
              + vpc_cidr_table_list   = (known after apply)
              + vpc_id                = (known after apply)
              + vpc_name              = (known after apply)
            }
        }
    
    Plan: 1 to add, 0 to change, 0 to destroy.
    
    Do you want to perform these actions?
      Terraform will perform the actions described above.
      Only 'yes' will be accepted to approve.
    
      Enter a value: yes
    
    alicloud_cloud_firewall_vpc_firewall_cen.default: Creating...
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [10s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [20s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [30s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [40s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [50s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [1m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [1m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [1m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [1m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [1m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [1m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [2m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [2m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [2m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [2m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [2m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [2m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [3m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [3m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [3m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [3m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [3m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [3m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [4m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [4m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [4m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [4m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [4m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [4m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [5m0s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [5m10s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [5m20s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [5m30s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [5m40s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Still creating... [5m50s elapsed]
    alicloud_cloud_firewall_vpc_firewall_cen.default: Creation complete after 5m56s [id=vfw-5d6505900bc043d9****]
    
    Apply complete! Resources: 1 added, 0 changed, 0 destroyed.

    创建成功后,可以返回VPC边界防火墙IDvfw-5d6505900bc043d9****。

  2. 查看结果。

    • 运行terraform show查看VPC边界防火墙详细信息。

      # alicloud_cloud_firewall_vpc_firewall_cen.default:
      resource "alicloud_cloud_firewall_vpc_firewall_cen" "default" {
          cen_id            = "cen-cjok7uyb5w2b27****"
          connect_type      = "cen"
          id                = "vfw-5d6505900bc043d9****"
          member_uid        = "141518928482****"
          status            = "open"
          vpc_firewall_name = "tf-test"
          vpc_region        = "cn-shenzhen"
      
          local_vpc {
              attachment_id         = "tr-attach-t8dpknea00bu7t****"
              defend_cidr_list      = [
                  "172.XX.XX.0/24",
              ]
              eni_list              = [
                  {
                      eni_id                 = "eni-wz9h9yutle1k3eq7****"
                      eni_private_ip_address = "172.XX.XX.130"
                  },
              ]
              network_instance_id   = "vpc-wz9vxghjlwdgi3jfq****"
              network_instance_name = "深圳172"
              network_instance_type = "VPC"
              owner_id              = "141518928482****"
              region_no             = "cn-shenzhen"
              route_mode            = "auto"
              support_manual_mode   = "0"
              transit_router_id     = "tr-wz9pt44zpj0bgh3cf****"
              transit_router_type   = "Basic"
              vpc_cidr_table_list   = [
                  {
                      route_entry_list = [
                          {
                              destination_cidr     = "172.XX.XX.0/24"
                              next_hop_instance_id = "vpc-wz9vxghjlwdgi3jfq****"
                          },
                      ]
                      route_table_id   = ""
                  },
              ]
              vpc_id                = "vpc-wz9vxghjlwdgi3jfq****"
              vpc_name              = "深圳172"
          }
      }
    • 登录云防火墙控制台,在防火墙开关>VPC边界防火墙页面,搜索VPC边界防火墙实例ID查看详细信息。

      image..png