Advertisement
Advertisement

More Related Content

Similar to [금융 고객을 위한 Resiliency in the Cloud] Open Discussion(20)

Recently uploaded(20)

Advertisement

[금융 고객을 위한 Resiliency in the Cloud] Open Discussion

  1. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. F I N A N C I A L S E R V I C E S Open Discussion Byeong-eok Kang, Solutions Architect
  2. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 사전 질의 유형 2
  3. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | Top 6 Questions 16 12 10 10 8 5 0 2 4 6 8 10 12 14 16 18 DR사례 AWS DR 아키텍처 DR훈련 클라우드활용 DR구성 규제 DR동향 Percentage(%)
  4. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | Next 7 Top Questions 4 3 3 2 2 2 2 0 1 1 2 2 3 3 4 4 데이터동기화 AWS지원(컨설팅,비용) AWS 구축 사례 멀티클라우드 비용효율적인DR 하이브리드DR VMware에 대한 클라우드DR Percentage(%)
  5. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | Other Questions 1 1 1 1 1 1 1 1 1 1 1 1 0 0 0 0 0 1 1 1 1 1 1 AWS DRS사례 네트워크연결 온프렘과 아키텍처 차이 장애대응 콘솔접근아키텍처 완벽한Active-Active 한국내 추가 리전 계획 AWS Active-Standby DR구성 락인대응 온프렘과 레이턴시 해소 방안 국내금융사클라우드고려사항 규제지원을 위한 신규서비스 Percentage(%)
  6. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. Database 동기화 방안 6
  7. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | AWS DMS를 이용한 동기화 7 고객 온- 프레미스 어플리케이션 사용자 AWS 인터넷 VPN 복제 인스턴스 시작 원본 및 대상 데이터베이스 접속 테이블, 스키마, 데이터베이스 선택 AWS DMS 가 테이블 생성, 데이터 로드 및 변경 사항 적용 적절한 시점에 대상 데이터베이스로 전환 AWS Database Migration Service
  8. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | 3rd Party CDC를 이용한 동기화 8 On-premises 이전 데이터 조회 경로 MainApp AWS Cloud CDC 변경된 데이터 조회 경로(빠름) RDS API
  9. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | Oracle Data Guard 9 Standby Site Primary Site Data Guard Redo 전송 (SYNC / ASYNC) Primary 데이터베이스 Standby 데이터베이스 - Physical 또는 Logical
  10. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | DB2 HADR 10 Network Connection Primary Server Standby Server HADR Keeps the two servers in sync HACMP for server monitoring Monitors the primary and initiates the takeover. -could also use heartbeat, TSA, MSCS, etc Automatic Client Reroute Client application automatically resumes on Standby
  11. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 볼륨 동기화 방안 11
  12. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | AWS CloudEndure Disaster Recovery Service 12
  13. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | 3rd Party: Veritas Volume Replicator 13
  14. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 국내 금융사 클라우드의 특징/고려사항 14
  15. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | 국내 금융사 클라우드의 특징 / 고려사항 15 아키텍처 주요 특징 v 인터넷 접속 제한 - 대고객 진입점을 제외하고는 인터넷 접속 제한 v 멀티어카운트 구성 - 멀티어카운트 구조를 활용하여 일관되게 보안과 네트워크에 대한 정책을 적용 v On-prem 보안 정책 준용 - On-prem 보안 정책과 동일한 보안 정책 적용을 위해서 방화벽, 접근제어, 암호화 등에 대해서 기존 3rd party 솔루션을 활용 v 전용선 or VPN 구성 - Direct Connect나 VPN을 이용하여 안전하게 사용 K은행 K카드
  16. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 콘솔 접근 아키텍처 16
  17. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | 프록시를 이용한 콘솔 단말 접속 구성 17 Public VPC Private NAT GateWay (or NAT Instance) Proxy 금융사 데이터센터 DX or VPN connection 내부단말 VDI Internet gateway AWS Management Console • AWS Console에 접속 가능한 IP는 NAT Gateway의 IP만 접속 가능하도록 구성함. • 단, root 계정은 IAM의 IP기반 통제를 적용할 수 없음. root 계정에 대해서도 IP기반 접속 제한 룰을 적용하려면, AWS Organizations의 멤버계정으로 생성하여 SCP로 적용하는 방안으로 적용 가능함. • 센터내 원격PC를 윈도우 기반 VDI로 구성하여 여기에서 웹브라우저로 AWS 콘솔 접속함 • AWS Console URL에 대해서는 HTTP/s Proxy서버로 접속하도록 구성함. HTTP/s Proxy서버에서 AWS Console 접속에 필요한 URL/Cookie만 인터넷을 허용(filter)하는 정책을 적용함. 방화벽
  18. © 2023, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. 금융 고객을 위한 RESILIENCY IN THE CLOUD WORKSHOP 2023 FINANCIAL SERVICES | © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Confidential and Trademark. Thank you!
Advertisement