網(wǎng)絡(luò)連通與白名單配置
在調(diào)用API時(shí),為了防止資源組不能正常訪問數(shù)據(jù)源,您需要在數(shù)據(jù)源中配置IP白名單,從而確保資源組的網(wǎng)絡(luò)連通性。本文為您介紹不同資源組類型對應(yīng)的IP白名單或其獲取方式,以及在數(shù)據(jù)源中配置IP白名單時(shí)的注意事項(xiàng)。
獲取白名單IP地址:公共資源組
創(chuàng)建數(shù)據(jù)服務(wù)API前,您需要提前配置好數(shù)據(jù)源。為確保數(shù)據(jù)服務(wù)成功連通數(shù)據(jù)源,請?jiān)跀?shù)據(jù)庫中添加下表中對應(yīng)地域的白名單。
隨著公共資源組的底層擴(kuò)容等操作,白名單的IP網(wǎng)段可能會動態(tài)變化。若白名單更新,DataWorks將提前進(jìn)行通知。若您的業(yè)務(wù)場景比較顧慮白名單變更,建議您使用獨(dú)享資源組。
地域 | 白名單 |
華東1(杭州) | 100.64.0.0/10,11.193.102.0/24,11.193.215.0/24,11.194.110.0/24,11.194.73.0/24,118.31.157.0/24,47.97.53.0/24,11.196.23.0/24,47.99.12.0/24,47.99.13.0/24,114.55.197.0/24,11.197.246.0/24,11.197.247.0/24,118.31.243.0/26,118.31.243.64/26,118.31.243.128/26,118.31.243.192/26,11.193.55.0/24,101.37.74.122,114.55.197.231,114.55.198.83,101.37.74.206 |
華東2(上海) | 11.193.109.0/24,11.193.252.0/24,47.101.107.0/24,47.100.129.0/24,106.15.14.0/24,10.117.28.203,10.143.32.0/24,10.152.69.0/24,10.153.136.0/24,10.27.63.15,10.27.63.38,10.27.63.41,10.27.63.60,10.46.64.81,10.46.67.156,11.192.97.0/24,11.192.98.0/24,11.193.102.0/24,11.218.89.0/24,11.218.96.0/24,11.219.217.0/24,11.219.218.0/24,11.219.219.0/24,11.219.233.0/24,11.219.234.0/24,118.178.142.154,118.178.56.228,118.178.59.233,118.178.84.74,120.27.160.26,120.27.160.81,121.43.110.160,121.43.112.137,100.64.0.0/10,10.117.39.238,11.193.96.0/24,11.193.48.0/24,11.193.108.0/24,101.132.31.146,106.15.14.240,106.15.14.75,101.132.31.221 |
華南1(深圳) | 100.106.46.0/24,100.106.49.0/24,10.152.27.0/24,10.152.28.0/24,11.192.91.0/24,11.192.96.0/24,11.193.103.0/24,100.64.0.0/10,120.76.104.0/24,120.76.91.0/24,120.78.45.0/24,47.106.63.0/26,47.106.63.128/26,47.106.63.192/26,47.106.63.64/26,11.193.94.0/24,120.78.45.154,120.78.46.137,120.78.46.107,120.78.45.140,172.26.131.130,172.26.131.129,172.26.131.128,172.26.131.127,101.133.0.0/16,101.200.0.0/16,101.226.0.0/16,110.75.0.0/16,111.13.0.0/16,111.206.0.0/16,112.126.0.0/16,114.250.0.0/16,114.66.0.0/16,116.128.0.0/16,117.185.0.0/16,118.31.0.0/16,120.77.0.0/16,121.89.0.0/16,123.6.0.0/16,182.92.0.0/16,210.51.0.0/16,221.228.0.0/16,223.4.0.0/16,223.5.0.0/16,36.150.0.0/16,39.101.0.0/16,39.104.0.0/16,39.107.0.0/16,39.156.0.0/16,39.97.0.0/16,39.98.0.0/16,39.99.0.0/16,47.92.0.0/16,47.96.0.0/11,49.7.0.0/16,8.129.0.0/16,8.132.0.0/16,8.134.0.0/16,8.137.0.0/16,8.141.0.0/16,8.143.0.0/16,8.145.0.0/16,8.146.0.0/16,8.139.99.192/26,8.139.112.0/26,8.139.112.64/26,8.139.112.128/26,47.121.73.192/26,47.121.96.128/26,47.121.96.192/26,47.121.97.0/26,8.139.234.64/26,8.139.234.128/26,8.139.234.192/26,8.139.235.0/26,47.109.170.64/26,47.109.170.128/26,47.109.170.0/26,47.108.33.192/26,47.108.33.0/26,47.108.32.192/26,47.108.32.128/26,47.108.32.0/26,8.149.144.64/26,8.149.144.192/26,8.149.144.128/26,8.149.144.0/26,10.245.165.0/24 |
西南1(成都) | 11.195.52.0/24,11.195.55.0/24,47.108.22.0/24,100.64.0.0/10 |
華北2(北京) | 100.106.48.0/24,10.152.167.0/24,10.152.168.0/24,11.193.50.0/24,11.193.75.0/24,11.193.82.0/24,11.193.99.0/24,100.64.0.0/10,47.93.110.0/24,47.94.185.0/24,47.95.63.0/24,11.197.231.0/24,11.195.172.0/24,47.94.49.0/24,182.92.144.0/24,11.193.100.0/24,11.193.199.0/24,39.106.244.50,47.95.63.101,47.95.63.93,39.106.244.48,172.22.1.42,172.22.2.208,172.22.1.41,172.22.2.207 |
華北3(張家口) | 11.193.235.0/24,47.92.22.0/24,100.64.0.0/10,11.112.227.0/24 |
中國香港 | 10.152.162.0/24,11.192.196.0/24,11.193.11.0/24,100.64.0.0/10,47.89.61.0/24,47.91.171.0/24,11.193.118.0/24,47.75.228.0/24,47.56.45.0/25,47.244.92.128/25,47.101.109.0/24,11.193.200.0/24,11.193.12.0/24,47.90.71.152,47.90.71.141,47.91.171.178,47.91.172.3 |
新加坡 | 100.106.10.0/24,100.106.35.0/24,10.151.234.0/24,10.151.238.0/24,10.152.248.0/24,11.192.153.0/24,11.192.40.0/24,11.193.8.0/24,100.64.0.0/10,47.88.147.0/24,47.88.235.0/24,11.193.162.0/24,11.193.163.0/24,11.193.220.0/24,11.193.158.0/24,47.74.162.0/24,47.74.203.0/24,47.74.161.0/24,11.197.188.0/24,11.197.227.0/24,47.74.161.218,47.74.161.181,161.117.140.83,47.88.143.36 |
美國(硅谷) | 10.152.160.0/24,100.64.0.0/10,47.89.224.0/24,11.193.216.0/24,47.88.108.0/24,47.88.99.153,47.254.58.215,47.88.108.192,47.254.58.135 |
美國(弗吉尼亞) | 11.193.203.0/24,11.194.68.0/24,11.194.69.0/24,100.64.0.0/10,47.252.55.0/24,47.252.88.0/24,11.194.69.0/24,10.128.135.0/24,47.88.98.0/24 |
馬來西亞(吉隆坡) | 11.193.188.0/24,11.221.205.0/24,11.221.206.0/24,11.221.207.0/24,100.64.0.0/10,11.214.81.0/24,47.254.212.0/24,11.193.189.0/24,47.250.29.0/26,47.250.29.128/26,47.250.29.192/26,47.250.29.64/26 |
德國(法蘭克福) | 11.192.116.0/24,11.192.168.0/24,11.192.169.0/24,11.192.170.0/24,11.193.106.0/24,100.64.0.0/10,11.192.116.14,11.192.116.142,11.192.116.160,11.192.116.75,11.192.170.27,47.91.82.22,47.91.83.74,47.91.83.93,47.91.84.11,47.91.84.110,47.91.84.82,11.193.167.0/24,47.254.138.0/24,11.194.61.0/24,47.254.185.0/24 |
日本(東京) | 100.105.55.0/24,11.192.147.0/24,11.192.148.0/24,11.192.149.0/24,100.64.0.0/10,47.91.12.0/24,47.91.13.0/24,47.91.9.0/24,11.199.250.0/24,47.91.27.0/24,11.59.59.0/24,47.245.51.128/26,47.245.51.192/26,47.91.0.128/26,47.91.0.192/26 |
英國(倫敦) | 11.199.93.0/24,100.64.0.0/10,8.208.72.0/26,8.208.72.128/26,8.208.72.192/26,8.208.72.64/26 |
印度尼西亞(雅加達(dá)) | 11.194.49.0/24,11.200.93.0/24,11.200.95.0/24,11.200.97.0/24,100.64.0.0/10,149.129.228.0/24,10.143.32.0/24,11.194.50.0/24,11.59.135.0/24,147.139.156.0/26,147.139.156.128/26,147.139.156.64/26,149.129.230.192/26,149.129.229.0/26,149.129.229.64/26,149.129.229.128/26,149.129.229.192/26 |
華北2(政務(wù)云) | 11.194.116.0/24,100.64.0.0/10,39.107.188.202,11.194.121.0/24,39.107.223.0/26,39.107.223.128/26,39.107.223.192/26,39.107.223.64/26 如果IP地址段添加不成功,請?zhí)砑酉率鯥P地址: 11.194.116.160,11.194.116.161,11.194.116.162,11.194.116.163,11.194.116.164,11.194.116.165,11.194.116.167,11.194.116.169,11.194.116.170,11.194.116.171,11.194.116.172,11.194.116.173,11.194.116.174,11.194.116.175,39.107.188.0/24,11.194.121.51,11.194.121.50,39.107.223.0/26,39.107.223.128/26,39.107.223.192/26,39.107.223.64/26 |
華東2(上海)金融云 | 140.205.46.128/25,140.205.48.0/25,140.205.48.128/25,140.205.49.0/25,140.205.49.128/25,11.192.156.0/25,11.192.157.0/25,11.192.164.0/25,11.192.165.0/25,11.192.166.0/25,11.192.167.0/25,106.11.245.0/26,106.11.245.128/26,106.11.245.192/26,106.11.245.64/26,140.205.39.0/24,106.11.225.0/24,106.11.226.0/24,106.11.227.0/24,106.11.242.0/24,100.104.8.0/24,11.192.167.0/24,47.102.181.0/24, 47.102.234.0/24 |
獲取白名單IP地址:獨(dú)享數(shù)據(jù)服務(wù)資源組
獨(dú)享數(shù)據(jù)服務(wù)資源組支持訪問公網(wǎng)環(huán)境、阿里云VPC網(wǎng)絡(luò)環(huán)境、IDC網(wǎng)絡(luò)環(huán)境下的數(shù)據(jù)源。下表將為您介紹不同網(wǎng)絡(luò)環(huán)境下如何進(jìn)行網(wǎng)絡(luò)配置,以確保獨(dú)享數(shù)據(jù)服務(wù)資源組與不同網(wǎng)絡(luò)環(huán)境數(shù)據(jù)源之間的連通性。
獨(dú)享服務(wù)資源組的使用,請參見:新增和使用獨(dú)享數(shù)據(jù)服務(wù)資源組。
數(shù)據(jù)源所在網(wǎng)絡(luò)環(huán)境 | 網(wǎng)絡(luò)連通方案 | 網(wǎng)絡(luò)連通配置操作指導(dǎo) |
數(shù)據(jù)源具備訪問公網(wǎng)的能力 | 獨(dú)享數(shù)據(jù)服務(wù)資源組可以連通。 |
|
數(shù)據(jù)源在經(jīng)典網(wǎng)絡(luò)內(nèi) | 獨(dú)享數(shù)據(jù)服務(wù)資源組不支持網(wǎng)絡(luò)連通,如需連通請使用公共數(shù)據(jù)服務(wù)資源組。 | 無。 |
數(shù)據(jù)源在VPC內(nèi) - 數(shù)據(jù)源和DataWorks在同一個(gè)地域、同一個(gè)VPC、同一個(gè)V-Switch中 | 獨(dú)享服務(wù)資源組可以連通。 |
|
數(shù)據(jù)源在VPC內(nèi) - 數(shù)據(jù)源和DataWorks在同一個(gè)地域、同一個(gè)VPC,不同V-Switch中 | 獨(dú)享數(shù)據(jù)服務(wù)資源組可以連通。 | |
數(shù)據(jù)源在VPC內(nèi) - 數(shù)據(jù)源和DataWorks在同一個(gè)地域、不同VPC中 | 獨(dú)享數(shù)據(jù)服務(wù)資源組可以連通。 |
|
數(shù)據(jù)源在VPC內(nèi) - 數(shù)據(jù)源和DataWorks在不同地域中 | 獨(dú)享數(shù)據(jù)服務(wù)資源組可連通。 |
|
數(shù)據(jù)源在IDC內(nèi) | 獨(dú)享數(shù)據(jù)服務(wù)資源組可以連通。 |
|
配置數(shù)據(jù)源白名單
為避免因?yàn)閿?shù)據(jù)源設(shè)置了白名單控制,導(dǎo)致DataWorks數(shù)據(jù)服務(wù)與數(shù)據(jù)源之間,您需要根據(jù)使用的資源組情況,將上述資源組對應(yīng)的IP地址添加到數(shù)據(jù)源的白名單中。而配置數(shù)據(jù)源白名單時(shí),不同數(shù)據(jù)源的白名單配置的注意事項(xiàng)不同。
以阿里云云數(shù)據(jù)庫RDS為例,產(chǎn)品支持通用模式IP白名單和高安全模式IP白名單兩種白名單配置方式,添加白名單時(shí)配置的白名單分組可能會影響數(shù)據(jù)服務(wù)與數(shù)據(jù)庫的網(wǎng)絡(luò)連通。
如果RDS為通用模式IP白名單模式:
通用模式IP白名單不區(qū)分經(jīng)典網(wǎng)絡(luò)和專有網(wǎng)絡(luò)白名單分組。
公共數(shù)據(jù)服務(wù)資源組、獨(dú)享數(shù)據(jù)服務(wù)資源組可以使用同樣的白名單分組配置。
說明在通用白名單模式下,設(shè)置的IP地址,既可通過經(jīng)典網(wǎng)絡(luò),也可通過專有網(wǎng)絡(luò)訪問RDS實(shí)例。
如果RDS為高安全模式IP白名單模式:
高安全模式區(qū)分經(jīng)典網(wǎng)絡(luò)和專有網(wǎng)絡(luò)白名單分組。
說明在高安全模式下,白名單分組需指定網(wǎng)絡(luò)隔離模式,例如設(shè)置在經(jīng)典網(wǎng)絡(luò)的白名單IP地址,不可從專有網(wǎng)絡(luò)訪問RDS實(shí)例,反之亦然。
獨(dú)享數(shù)據(jù)服務(wù)資源組使用VPC內(nèi)網(wǎng)直接連接數(shù)據(jù)庫時(shí),白名單分組需選擇使用專有網(wǎng)絡(luò)白名單分組。
公共數(shù)據(jù)服務(wù)資源組訪問VPC網(wǎng)絡(luò)數(shù)據(jù)源(例如,實(shí)例模式配置的專有網(wǎng)絡(luò) RDS MySQL)時(shí),白名單分組需選擇使用專有網(wǎng)絡(luò)白名單分組。
數(shù)據(jù)服務(wù)資源組使用公網(wǎng)連接地址、經(jīng)典網(wǎng)絡(luò)連接地址直接訪問數(shù)據(jù)庫時(shí),白名單分組需選擇使用經(jīng)典網(wǎng)絡(luò)白名單分組。
如果您在數(shù)據(jù)庫將白名單模式從通用模式IP白名單模式切換為高安全模式IP白名單模式:
RDS會將通用模式IP白名單復(fù)制分為2份,分別放到經(jīng)典網(wǎng)絡(luò)和專有網(wǎng)絡(luò)白名單分組類型里面。
其他白名單配置注意事項(xiàng):
設(shè)置白名單不會影響RDS實(shí)例的正常運(yùn)行。
默認(rèn)的IP白名單分組(default )不能刪除,只能清空。
請勿修改或刪除系統(tǒng)自動生成的分組,避免影響相關(guān)產(chǎn)品的使用。例如ali_dms_group(DMS產(chǎn)品IP地址白名單分組)、hdm_security_ips(DAS產(chǎn)品IP地址白名單分組)。
說明建議您在數(shù)據(jù)庫配置白名單時(shí),單獨(dú)為DataWorks白名單新建一個(gè)白名單分組。
默認(rèn)的IP白名單只包含127.0.0.1,表示任何IP均無法訪問該RDS實(shí)例。
RDS白名單配置詳情可參見通過客戶端、命令行連接RDS MySQL實(shí)例。其他類型的數(shù)據(jù)源類似,可參考各數(shù)據(jù)源數(shù)據(jù)庫的白名單配置步驟,分別添加對應(yīng)的白名單。