Step 1: Set up your networking environment - AWS Directory Service
AWS 文档中描述的 AWS 服务或功能可能因区域而异。要查看适用于中国区域的差异,请参阅中国的 AWS 服务入门

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

Step 1: Set up your networking environment

开始本教程中的步骤之前,必须先执行以下操作:

  • 在同一区域中创建两个用于测试目的的新 AWS 账户。当您创建 AWS 账户时,它会在每个账户中自动创建专用虚拟私有云 (VPC)。记下每个账户中的 VPC ID。您稍后会需要此信息。

  • Create a VPC peering connection between the two VPCs in each account using the procedures in this step.

    注意

    While there are many ways to connect Directory owner and Directory consumer account VPCs, this tutorial will use the VPC peering method. 有关其他 VPC 连接选项,请参阅网络连接.

Configure a VPC peering connection between the directory owner and the directory consumer account

The VPC peering connection you will create is between the directory consumer and directory owner VPCs. Follow these steps to configure a VPC peering connection for connectivity with the directory consumer account. With this connection you can route traffic between both VPCs using private IP addresses.

在目录拥有者和目录使用者账户之间创建 VPC 对等连接

  1. 从 Amazon VPC 打开 https://console.amazonaws.cn/vpc/. 控制台。确保以目录拥有者账户中具有管理员凭证的用户身份登录。

  2. 在导航窗格中,选择 Peering Connections. 然后选择 Create Peering Connection (创建对等连接).

  3. 配置以下信息:

    • Peering connection name tag (对等连接名称标签):提供一个名称,用于在目录使用者账户中清楚地标识与 VPC 的此连接。

    • VPC (Requester) (VPC (申请方)):选择目录拥有者账户的 VPC ID。

    • Under Select another VPC to peer with, ensure that My account and This region are selected.

    • VPC (Accepter) (VPC (接受方)):选择目录使用者账户的 VPC ID。

  4. 选择 Create Peering Connection (创建对等连接). 在确认对话框中,选择 OK.

Since both VPCs are in the same Region, the administrator of the directory owner account who sent the VPC peering request can also accept the peering request on behalf of the directory consumer account.

代表目录使用者账户接受对等请求

  1. 从 Amazon VPC 打开 https://console.amazonaws.cn/vpc/. 控制台。

  2. 在导航窗格中,选择 Peering Connections.

  3. 选择挂起的 VPC 对等连接。(Its status is Pending Acceptance.) Choose Actions, Accept Request.

  4. 在确认对话框中,选择 Yes, Accept. In the next confirmation dialog box, choose Modify my route tables now to go directly to the route tables page.

现在您的 VPC 对等连接已处于活动状态,您必须向目录拥有者账户中的 VPC 的路由表添加条目。这样做可以将流量定向到目录使用者账户中的 VPC。

向目录拥有者账户中的 VPC 路由表添加条目

  1. While in the Route Tables section of the Amazon VPC console, select the route table for the directory owner VPC.

  2. 依次选择 Routes (路由) 选项卡、Edit (编辑)Add another route (添加其他路由).

  3. In the Destination column, enter the CIDR block for the directory consumer VPC.

  4. In the Target column, enter the VPC peering connection ID (such as pcx-123456789abcde000) for the peering connection that you created earlier in the directory owner account.

  5. 选择 Save.

向目录使用者账户中的 VPC 路由表添加条目

  1. While in the Route Tables section of the Amazon VPC console, select the route table for the directory consumer VPC.

  2. 依次选择 Routes (路由) 选项卡、Edit (编辑)Add another route (添加其他路由).

  3. In the Destination column, enter the CIDR block for the directory owner VPC.

  4. In the Target column, type in the VPC peering connection ID (such as pcx-123456789abcde001) for the peering connection that you created earlier in the directory consumer account.

  5. 选择 Save.

Make sure to configure your directory consumer VPCs’ security group to enable outbound traffic by adding the Active Directory protocols and ports to the outbound rules table. For more information, see Security groups for your VPC and AWS Managed Microsoft AD prerequisites.

下一步

Step 2: Share your directory