GNS3ã®æè¿ã®ããŒãžã§ã³ã§ã¯ãCisco ASAãªã©ã®ããã€ã¹ããšãã¥ã¬ãŒãã§ããããã«ãªããŸããã ãã®ããã€ã¹ã¯å€æ©èœãã¡ã€ã¢ãŠã©ãŒã«ã§ãããããŸããŸãªã¢ãŒãïŒã«ãŒããã/ãã©ã³ã¹ãã¢ã¬ã³ããã·ã³ã°ã«/ãã«ãã³ã³ããã¹ãïŒã§åäœãããã©ãŒã«ããã¬ã©ã³ãæ§æïŒã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ãã¢ã¯ãã£ã/ã¢ã¯ãã£ãïŒãªã©ã§äœ¿çšã§ããŸãã ãã®èšäºã§ã¯ããã¹ãçµæãšãGNS3ã§ãã®ããã€ã¹ãä»®æ³åãããšãã«ãã®æ©èœãã©ã®çšåºŠå®å šã«ãµããŒãããããã«ã€ããŠã®çµè«ã瀺ããŸãã
ãã®èšäºããGNS3ã®ç¹å®ã®ããããžããšãã¥ã¬ãŒããããã©ããã決å®ããä»®æ³ç°å¢ã§ãœãªã¥ãŒã·ã§ã³ããããã°ããéã®æéãç¯çŽããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
ãœãŒã¹ããŒã¿
ãã¹ãã¯ã次ã®ããŒã«ã䜿çšããŠå®è¡ãããŸããã
1. Windows Server 2003 R2 Standardä»®æ³ãã·ã³ïŒIntel Xeon E5420 2.50GHzã4Gb RAMïŒ;
2. GNS3ãšãã¥ã¬ãŒã¿ãŒv.0.7.4;
3. Cisco ASA 8.0 OSã€ã¡ãŒãžïŒ2ïŒ;
4. Cisco ASDM 6.4ã®ã°ã©ãã£ã«ã«ãªç®¡çããã³ç£èŠããŒã«ïŒ5ïŒã
5. 3725ã«ãŒã¿ãŒçšã®Cisco IOS OSã€ã¡ãŒãžïŒc3725-adventerprisek9-mz.124-25dïŒ;
6. Cisco ACS 4.2ã¢ã¯ã»ã¹å¶åŸ¡ãµãŒããŒã
7. 3CDaemonã«åºã¥ãFTPãTFTPãsyslogãµãŒããŒã
ãã¹ãããããžãšæ€èšŒæè¡ã¯ãCCIEã»ãã¥ãªãã£ã®æºåã®ããã«ãInternetwork ExpertïŒINEïŒã®æåã®WBããååŸãããŸããã ã¿ã¹ã¯ãšãã¹ã察象ã®ãã¯ãããžãŒã®èª¬æã¯çç¥ããçµæã®ã¿ãæ®ããŸãã
GNS3ã§Cisco ASAãå®è¡ããæ¹æ³ã®èª¬æã¯ã è±èªã®ãªã³ã¯ãããã«ã¯ãã·ã¢èªã§èŠã€ããããšãã§ããŸãã
ãã¹ãããããžãšæ€èšŒ
1.åçã«ãŒãã£ã³ã°
æåã®ãã¹ãã§ã¯ãCisco ASAã®ãã¡ã€ã¢ãŠã©ãŒã«ïŒä»¥éMEãšåŒã³ãŸãïŒãã«ãŒãããã¢ãŒããšã·ã³ã°ã«ã¢ãŒãïŒä»®æ³ã³ã³ããã¹ããµããŒããªãïŒã§éå§ããŸããã
ããããžãŒã¯å³ã«ç€ºãããŠããŸãïŒ
ãããã®ãã§ãã¯ã®äžç°ãšããŠãåçã«ãŒãã£ã³ã°ãããã³ã«ïŒRIPãOSPFãEIGRPïŒã®åäœãåé åžãIP SLAãã©ããã³ã°ããã§ãã¯ãããŸããã
管ç察象ã¹ã€ãããå¿ èŠãªå Žåã¯ãNM-16ESWã¢ãžã¥ãŒã«ãæèŒããCisco 3725ã«ãŒã¿ãŒã䜿çšããŸããã
NM-16ESWã¢ãžã¥ãŒã«ã®äœ¿çšæã«ãµããŒããããŠããªãL2æ©èœã®ãªã¹ãã¯ãå ¬åŒWebãµã€ãã§æäŸãããŠããŸã ã
ã³ãã³ãã©ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãCisco Catalystã¹ã€ãããšã¯å°ãç°ãªããŸãã 泚æããŠãã ããã
å®éã«ã¯ãCisco ASAããšãã¥ã¬ãŒããããšãã«WB1 INEã§èª¬æãããŠããã¿ã¹ã¯ã«åé¡ã¯ãããŸããã§ããã ãããŠäžè¬çã«ãå ãèŠæ®ããŠãçŸæç¹ã§ã¯GNS3ã§ã¯ã«ãŒãã£ã³ã°/ã·ã³ã°ã«ã¢ãŒãã®ã¿ãå€ããå°ãªããå®å šã«æ©èœãããšèšããŸãã
ãããããã§ã«ãã®æ®µéã§ããã€ãã®è£å©çãªãã°ãçºçããŸããã ããããããã°ããšããèšèã¯ããšãã¥ã¬ãŒã·ã§ã³äžã«çããå°é£ããšã©ãŒãæ£ç¢ºã«åæ ããŠããªããããããŸããããåé¡ã®çµ±äžã®ããã«äœ¿çšããŸãã
ãã°çªå·1ã ããã€ã¹ã®èµ·ååŸã«ã¹ã€ããã³ã°ãå®è¡ãããå Žåã«åããŠãåºæ¬æ§æãèšå®ããåŸã«Cisco ASAããªããŒãããå¿ èŠããããŸãã ããã§ãªãå Žåãæ¥ç¶ã¯ç¢ºç«ããããããã€ã¹ã¯çžäºã«èªèããŸããã§ããã
ãã°çªå·2ã äžè¬ã«ãããã¯ãã°ã§ã¯ãªããåºæ¬çãªGNS3èšå®ã®æ©èœã§ãã ãªããªã GNS3ãèµ·åããããã·ã³ã§ã¯ãCisco ACS4.2ãã€ã³ã¹ããŒã«ãããããŒã2000-2002ã¯ACSèªäœãçŽæ¥ãªãã¹ã³ããŸããã ãŸããGNS3ã¯ããã©ã«ãã§ã«ãŒã¿ãŒã®ã³ã³ãœãŒã«ããŒããšããŠ2000以éã®ããŒãã䜿çšãããããã«ãŒã¿ãŒãè¿œå ãããšãã«ãããã®ããŒããå€æŽããå¿ èŠãããããšã«æ³šæããŠãã ããã
ãã°çªå·3ã GNS3ããªãã«ããŠãããªã³ã«ããåŸãã«ãŒã¿ãŒæ§æã¯ä¿åãããŸããã ãã®ãã°ã¯ãäžéšã®IOSã€ã¡ãŒãžã®GNS3ã®å€ãããŒãžã§ã³ã§ãç¹ã«3700ã·ãªãŒãºã«ãŒã¿ãŒã䜿çšããŠããå Žåã«èŠ³å¯ãããŸããããšãã¥ã¬ãŒããããç»åã«äŸåããŸãã äžè¬çã«ã誰ããééããå Žåããã®æ¹æ³ã§ãã®åé¡ã解決ããããšããããšãã§ããŸãã
2.ãããã¯ãŒã¯èšå®
2çªç®ã®ãã¹ãã§ã¯ãCisco ASA MEãã«ãŒãããã·ã³ã°ã«ã¢ãŒãã§å®è¡ããŸããã
ãã®ãã¹ãã§ã¯ãã¢ã¯ã»ã¹ãªã¹ãïŒACLïŒã®åäœãããŸããŸãªNATãªãã·ã§ã³ïŒåçNATãPATãéçNATãPATãåçããªã·ãŒNATãéçããªã·ãŒNATãPATãã¢ã€ãã³ãã£ãã£NATãNATå é€ãå€éšåçNATïŒã ASDMãDNS Doctoringæ©èœãæçåããããã©ãã£ãã¯ã®åŠçãMEãä»ããBGPæ¥ç¶ã®åãæž¡ãããã«ããã£ã¹ããNTPãããã³ã«æäœãã€ãã³ããã®ã³ã°ïŒsyslogãSNMPïŒãDHCPãµãŒããŒãšããŠã®MEæäœããã©ãã£ãã¯ããªã·ã³ã°ããã³ã·ã§ãŒãã³ã°ã
ASDMå¶åŸ¡ã«ã¯ããã€ãã®åé¡ããããŸããïŒGNS3ã§ASDMãæ§æããæ¹æ³ã«é¢ãããããªã®æ瀺ãèŠãããšãã§ããŸãïŒã ASDMããªã³ã«ãããšãããã€ã¹ãã°ã¯æ¬¡ã®ã¡ãã»ãŒãžã§ãããã¯ãããŸãã
%ASA-5-402128: CRYPTO: An attempt to allocate a large memory block
failed, size: size, limit: limit
ãããã°ãå°ãè€éã«ãªããŸãã ãã£ã«ã¿ã䜿çšãããããã®ã¡ãã»ãŒãžã®ãã°ãç¡å¹ã«ããããšãã§ããŸãïŒ
no logging message 402128
ïŒã
é倧ãªæ¬ é¥ã®ãã¡ïŒ
ãã°çªå·4ã DHCPãµãŒããŒãšããŠã®Cisco ASA MEã¯ãGNS3ç°å¢ã§ã¯æ©èœããŸããã
3.ãã©ã³ã¹ãã¢ã¬ã³ãã¢ãŒãã®Cisco ASA
3çªç®ã®ãã¹ãã§ã¯ãééã¢ãŒãã§ã®MEã®åäœã確èªãããŸããã ãã©ã³ã¹ãã¢ã¬ã³ãã¢ãŒãã®ASAã¯ãããå€ãã®ã€ã³ã¿ãŒãã§ã€ã¹ãæã€ããšãã§ããã«ãããããããããŒã¿è»¢éã«2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒã·ã³ã°ã«ã¢ãŒãïŒã®ã¿ïŒããã³å¶åŸ¡ãã©ãã£ãã¯çšã®1ã€ã®å°çšã€ã³ã¿ãŒãã§ã€ã¹ïŒãã䜿çšã§ããŸããã
ãã®ã¢ãŒãã§ã¯ãGNS3ç°å¢ã§ã®Cisco ASAã®æ¬æ Œçãªåäœã¯ãµããŒããããŠããŸããã ã«ãŒã¿ãŒãããã§ãã¯ããå ŽåãMgmtã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšã§ããŸããããã¡ã€ã¢ãŠã©ãŒã«ã§æ¥ç¶ã確ç«ããããšããè©Šã¿ã衚瀺ãããã«ããããããããã©ãã£ãã¯ã¯ãã¡ã€ã¢ãŠã©ãŒã«ãééããŸããã
å®éããã®ãããARPã€ã³ã¹ãã¯ã·ã§ã³ãEthertype ACLããã©ã³ã¹ãã¢ã¬ã³ããã¡ã€ã¢ãŠã©ãŒã«NATãªã©ã®ã¡ã«ããºã ã®åäœã確èªããããšã¯ã§ããŸããã§ããã
ãã°çªå·5ã Cisco ASAã®ééã¢ãŒãã¯ãGNS3ç°å¢ã§ã¯ãµããŒããããŠããŸããã
4.ä»®æ³ã³ã³ããã¹ãã¢ãŒãã®Cisco ASA
ãã®ã¢ãŒãã§ã¯ãCustomerAãCustomerBã®2ã€ã®ä»®æ³ã³ã³ããã¹ããäœæãããŸããã
CustomerAã³ã³ããã¹ãã§äœ¿çšãããã€ã³ã¿ãŒãã§ã€ã¹ïŒE0 / 1.121ïŒInsideAïŒãE0 / 2ïŒDMZïŒãE0 / 0ïŒOutsideïŒ
CustomerBã³ã³ããã¹ãã§äœ¿çšãããã€ã³ã¿ãŒãã§ã€ã¹ïŒE0 / 1.122ïŒInsideBïŒãE0 / 2ïŒDMZïŒãE0 / 0ïŒOutsideïŒ
DMZããã³å€éšã€ã³ã¿ãŒãã§ã€ã¹ã¯ãã³ã³ããã¹ãéã§å ±æãããŸãã
GNS3ã§ã¯ããã®ã¢ãŒãã¯
mac-address auto
ïŒ
no mac-address auto
ïŒã³ãã³ããç¡å¹ã«ãªã£ãŠããå Žåã«ã®ã¿ãµããŒããããŸãã ãã®ã³ãã³ãã¯ãåã³ã³ããã¹ãã®å ±æã€ã³ã¿ãŒãã§ã€ã¹ã«ä»®æ³MACã¢ãã¬ã¹ãçæããŸãã ä»®æ³MACã¯ãé©åãªã³ã³ããã¹ãã§é ä¿¡ããããã±ãŒãžãåé¡ããããã®åºæºã®1ã€ã§ãã ãããã£ãŠãåæãããšãã¯ãä»ã®åé¡åºæºã䜿çšãããŸãïŒã¢ã¯ãã£ããªNATå€æã®ãšã³ããªïŒã
ã·ããªãªã«ãããã¯ãŒã¯ã¢ãã¬ã¹å€æã®äœ¿çšãå«ãŸããŠããªãå Žåãããã€ãã®ã³ã³ããã¹ãã§å ±æã€ã³ã¿ãŒãã§ã€ã¹ã§åãIPãšMACââã䜿çšããããšã¯ã§ããŸããã
ãã°çªå·6ã ä»®æ³ã³ã³ããã¹ãã®äœ¿çšã¯ã
mac-address auto
ã³ãã³ããç¡å¹ã«ãªã£ãŠããå Žåã«ã®ã¿å¯èœã§ããããã«ãããCisco ASA MEã®å¯èœãªå±éã·ããªãªã«å¶éã課ããããŸãã
5.ã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ã¢ãŒãã§ã®ãã§ã€ã«ã»ãŒãæ§æ
ãã®ã¢ãŒãã§ã¯ã1ã€ã®ããã€ã¹ã®ã¿ãã¢ã¯ãã£ãã«ãªãã2çªç®ã®ããã€ã¹ã¯ããã·ãç¶æ ã«ãªããŸãã ããã€ã¹ã¯ãæ§æãšæ¥ç¶ç¶æ ã®ããŒãã«ãçžäºã«åæããŸããããã«ãããã¢ã¯ãã£ããªéšåã«é害ãçºçããå Žåã«ããã§ã«ç¢ºç«ãããŠããæ¥ç¶ãåæãããŸããã
ãã¹ãäžãã«ãŒã¿ãŒR1ã¯ã«ãŒã¿ãŒR2ãžã®telnetæ¥ç¶ã確ç«ãããã®åŸãé害ãã·ãã¥ã¬ãŒãããŸããïŒã¢ã¯ãã£ããªMEã«æ¥ç¶ãããã¹ã€ããSW1ã®ããŒãããªãã«ããããšã«ããïŒã è«ççã«ã¯ããã§ãŒã«ãªãŒããŒãã¢ãåãæ¿ããããtelnetæ¥ç¶ãåŒãç¶ãæ©èœããã¯ãã§ãã MEéã§ã¹ããŒããã«ãªã³ã¯ãèšå®ããŸããã
ãã ããGNS3ä»®æ³ç°å¢ã§ã¯ãçµæã¯ç°ãªããŸãã ãã§ãŒã«ãªãŒããŒãã¢ã®åãæ¿ããçºçããŸããããTelnetã»ãã·ã§ã³ãäžæãããŸããã ããã«ããã¡ã€ã¢ãŠã©ãŒã«ãééãããã©ãã£ãã¯ã¯ãŸã£ããæ©èœããªããªããŸããã ããã¯ãã¢ã¯ãã£ããªéšåãå€æŽããããšããäºå®ã«ãããããããã¯ã©ã¹ã¿ãŒã¯æåã®ãã¡ã€ã¢ãŠã©ãŒã«ã®MACã¢ãã¬ã¹ã§ARPèŠæ±ã«å¿çãç¶ãããšããäºå®ã«ãããã®ã§ãïŒãã ããããã·ãã¢ãŒãã«æ¢ã«åãæ¿ããããŠããŸãïŒã ã¯ã©ã¹ã¿ãã¢ã®å®å šãªåèµ·ååŸãç¶æ³ã¯å€ãããŸããã
ãã°çªå·7ã ã¢ã¯ãã£ãããã€ã¹ãããã·ãããã€ã¹ã«åãæ¿ããåŸããã§ãŒã«ãªãŒããŒã¢ãŒãã®ã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ã®Cisco ASAã¯ãARPèŠæ±ãžã®èª€ã£ãå¿çã«ããããã©ãã£ãã¯ã®ééãåæ¢ããŸãã
ç§ã®ç¥ãéããCisco PIX 7ããŒãžã§ã³ããšãã¥ã¬ãŒããããšãããã®åé¡ã¯çºçããŸããã ãããã£ãŠãå¿ èŠã«å¿ããŠãã®ãœãªã¥ãŒã·ã§ã³ã䜿çšããŠãã ããã
6.ã¢ã¯ãã£ã/ã¢ã¯ãã£ãã¢ãŒãã§ã®ãã§ã€ã«ã»ãŒãæ§æ
ãã®ã¢ãŒãã§ã¯ãäž¡æ¹ã®ããã€ã¹ãã¢ã¯ãã£ãã§ãã ããã¯ããã€ãã®ä»®æ³ã³ã³ããã¹ãã䜿çšããããšã§å®çŸããããã®äžéšã¯ã¯ã©ã¹ã¿ãŒã®äžéšã§ã¢ã¯ãã£ãã«ãªããäžéšã¯ä»ã§ã¢ã¯ãã£ãã«ãªããŸãã
åã®æ®µèœã§èª¬æãããã®ãšåæ§ã®æ€èšŒãèšç»ãããŸããã ããããããã¯å°ãæ©ãçµãããŸããã çç±ã¯æ¬¡ã®ãšããã§ããããã€ã¹ã¯ã¯ã©ã¹ã¿ã«çµåãããŸããããã©ãã£ãã¯ã¯ééããŸããã ã¢ã¯ãã£ã/ã¢ã¯ãã£ãã®ãã§ãŒã«ãªãŒããŒæ§æã§ã¯ãä»®æ³MACã¢ãã¬ã¹ã䜿çšãããŸãã
ãã°çªå·8ã ãã©ãã£ãã¯ã¯ãã¢ã¯ãã£ã/ã¢ã¯ãã£ããã§ãŒã«ãªãŒããŒã¢ãŒãã®Cisco ASAã¯ã©ã¹ã¿ãééããŸããã
7.åé·ã€ã³ã¿ãŒãã§ãŒã¹
æåŸã®ãã¹ãã§ã¯ãCisco ASAã®åé·ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠã¹ããŒã ãæ§ç¯ããŸãããããã«ãããè€æ°ã®ç©çã€ã³ã¿ãŒãã§ã€ã¹ãè«çã€ã³ã¿ãŒãã§ã€ã¹ã«çµåã§ããŸãã ãã®å Žåã1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®ã¿ãã¢ã¯ãã£ãã«ãªãã2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯æåã®ã€ã³ã¿ãŒãã§ã€ã¹ã倱æããåŸã«ã®ã¿ã¢ã¯ãã£ãã«ãªããŸãã
ãã¹ãã§ã¯ãã¢ã¯ãã£ããªASAã€ã³ã¿ãŒãã§ã€ã¹ã«æ¥ç¶ãããŠããã¹ã€ããããŒããåæãããŸããã é害ãæ€åºãããåŸã2çªç®ã®MEã€ã³ã¿ãŒãã§ã€ã¹ãã¢ã¯ãã£ãã«ãªããŸãã ãã ããGNS3ç°å¢ã§ã¯ãMEã¯ãã®éšåã§ã¹ã€ããã®ããŒãåæãæ€åºããªãã£ããããã¢ã€ãã«ã€ã³ã¿ãŒãã§ã€ã¹ã¯ã¢ã¯ãã£ãç¶æ ã®ãŸãŸã§ããã
ãã°çªå·9ã MEã«é£æ¥ããããã€ã¹ã§ç©çæ¥ç¶ã倱æããå Žåãåé·ã€ã³ã¿ãŒãã§ã€ã¹ã®åãæ¿ãã¯çºçããŸããã
çµè«
ãã¹ãã§ã¯ãGNS3ç°å¢ã§ã®ãã¹ãŠã®Cisco ASAåäœã¢ãŒããå®å šã«ãµããŒããããŠããããã§ã¯ãªãããšã瀺ãããŠããŸãã ã«ãŒãã£ã³ã°ãããã·ã³ã°ã«ã¢ãŒãã¢ãŒãã䜿çšããå Žåãåé¡ã¯æãå°ãªããªããŸããã äžè¬çã«ããã®ã¢ãŒãã¯æãäžè¬çã§ãããæ©èœé¢ã§æãå®å šã§ãã ééã¢ãŒãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã¯æ£ããæ©èœããŸããã§ããã
ä»®æ³ã³ã³ããã¹ãã䜿çšããã¢ãŒãã¯GNS3ã§å¯èœã§ãããä»®æ³MACã¢ãã¬ã¹ãçæããæ©èœãç¡å¹ã«ããå¿ èŠããããŸããããã«ãããCisco ASAã§äœæ¥ããéã«å€ãã®ã·ããªãªãå®è£ ã§ããªããªããŸãã
2ã€ã®ASAããã€ã¹ããã§ãŒã«ãªãŒããŒã¯ã©ã¹ã¿ãŒã«ããŒãžãããŠããããšã確èªããããšãç®æšã®å ŽåãGNS3ã䜿çšã§ããŸãã ãã ããã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ã¢ãŒãã®å Žåãåãæ¿ãäžïŒé害ã®å ŽåïŒããã¹ãŠã®å Žåã§ã¢ã¯ãã£ã/ã¢ã¯ãã£ãã®å Žåããã©ãã£ãã¯ã¯ã¯ã©ã¹ã¿ãŒãã¢ãééããŸããã
åé·ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšãããšãã¢ã¯ãã£ã/ã¹ã¿ã³ãã€ã¢ãŒãã«äŒŒãç¶æ³ãçºçããŸãã ã¢ã¯ãã£ãã€ã³ã¿ãŒãã§ã€ã¹ã«é害ãçºçããå Žåããã©ãã£ãã¯ã¯ASAãééããŸããã
ãã¹ãã§äœ¿çšããããã¹ãŠã®æ§æã¯ãå®éã®æ©åšã§ãã¹ããããèŠæ ãªãã«æ©èœããããšã«æ³šæããŠãã ããã
ããããããããŸãã¯GNS3ã§ãã®Cisco ASAåäœã¢ãŒããå®å šã«èµ·åããæ¹æ³ããããŸãããã®å Žåãé²åºã»ãã·ã§ã³ã調æŽããã³ã¡ã³ãã§ãã®ç¥èãå ±æã§ããŸãã
ãã®ãœãªã¥ãŒã·ã§ã³ã誰ãã«ãšã£ãŠæ°ãããã®ã§ããå Žåãå ¬åŒWebãµã€ãã§ãããç¥ãããšãã§ããŸãããŸããã·ã¹ã³è©Šéšã®æºåãããCBT Nuggetsã¹ã¿ãã£ã¬ã€ãã®æåãªèè ããã®ãå°ããªã40åã®ãããªãèŠãããšãã§ããŸãã