ç§ã¯äž»ã«ã·ã¹ã³ã®å°é家ã§ãããã·ã¹ã³ã·ã¹ãã ãºã®æ©åšã§æ§ç¯ãããããŒã¿ãããã¯ãŒã¯ã§æ©èœããIEEE 802.1xã®å€ãã®ã¢ãã«ã®1ã€ã«ã€ããŠã話ããããšæããŸãã
ãã®ã¢ãã«ãå®è£ ããã«ã¯ã次ã®ã³ã³ããŒãã³ãã®æå°ã»ãããå¿ èŠã§ãã
- ãªãŒã»ã³ãã£ã±ãŒã¿ãŒãšããŠæ©èœããã¹ã€ããã
- èªèšŒãµãŒããŒïŒRADIUSãµãŒããŒïŒ;
- DHCPãµãŒããŒã
- ãŠãŒã¶ãŒã®ã¯ãŒã¯ã¹ããŒã·ã§ã³äžã®ãµããªã«ã³ãïŒã¯ã©ã€ã¢ã³ãïŒ802.1xã
é«åºŠãªæ©èœã«ã€ããŠã¯ãäžèŠã§ã¯ãããŸããã
- ãŠãŒã¶ãŒè³æ Œæ å ±ã¹ãã¬ãŒãžãµãŒããŒïŒADãSambaãªã©ïŒ;
- 蚌ææžãµãŒããŒã
ãã€ãã£ã802.1xã¯ã©ã€ã¢ã³ãã¯ãWindows XP / Vista / 7 / CE / MobileãLinuxãSolarisãApple OS Xãªã©ãå€ãã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ååšããŸããããããå®è·µã瀺ãããã«ããŠãŒã¶ãŒã¯ãŒã«ãŒãäœæ¥ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åç©åã¹ããŒã·ã§ã³ããããã£ãŠãã®äžã«çµã¿èŸŒãŸããã«ã©ãã«ãªãµããªã«ã³ãã®è±å¯ãã¯ããããç°¡åã«ããã®ã§ã¯ãªãããããäŒç€Ÿã§ã®802.1xæšæºã®å®è£ ãšãããªã䜿çšãæ°åè€éã«ããŸãã èæ ®ããããããããã«ããŠãŒã¶ãŒã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ã€ã³ã¹ããŒã«ãããŠãããã¹ãŠã®OSã§åäœãããæé©ãªçµ±åãµãŒãããŒãã£ã¯ã©ã€ã¢ã³ãã䜿çšããããšããå§ãããŸãã
ãããã¯ãŒã¯äžã§é åžãããŠããç¡æã®ãµããªã«ã³ãã®äœ¿çšã¯ãå§ãããŸããã å®éã«ã¯ããããã¯ååã«æ©èœããŠããŸããã§ããã ã·ã¹ã³ã·ã¹ãã ãºãæäŸããCisco Secure Services Clientã«ã€ããŠã¯ãå ¬åŒWebãµã€ãããã®åŒçšã«ããããã«ãæ®å¿µãªãããµããŒããããªããªããŸãããã ã·ã¹ã³ã¯ãã·ã¹ã³ã®è²©å£²çµäºæ¥ããã³ãµããŒãçµäºæ¥ãçºè¡šããŸããã»ãã¥ã¢ãµãŒãã¹ã¯ã©ã€ã¢ã³ãã ã圱é¿ãåãã補åã泚æããæçµæ¥ã¯2012幎1æ27æ¥ã§ãã ã ç¬èªã«ã Juniper Networks Odyssey Access Clientãæ¬åœã«å¥œãã ã£ããšä»ãå ããŸããããã䜿çšããŠã奜ããªããã«äºåæ§æããMSIã€ã³ã¹ããŒã«ããã±ãŒãžãã¡ã€ã«ãäœæãããŠãŒã¶ãŒã¯ãŒã¯ã¹ããŒã·ã§ã³ã«äžå çã«å±éã§ããŸãã
IEEE 802.1xèŠæ Œã®åäœã瀺ãããã«ã以äžã¯æ¿èªããã»ã¹ã®ç°¡ç¥å³ã§ãããçªå·ã¯ã¹ãããçªå·ã瀺ããŠããŸãã
çŸåšãæ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ã管çã§ããªãäŒæ¥ãæ³åããã®ã¯å°é£ã§ãã 管çãããã€ã³ãã©ã¹ãã©ã¯ãã£ãšã¯ããã¡ã€ã³ãããã¯ãŒã¯ãæå³ããŸãã ãã¡ã€ã³ç°å¢ã§802.1xèŠæ Œã䜿çšããå Žåã1ã€ã®ãã¥ã¢ã³ã¹ãèæ ®ããå¿ èŠããããŸã- ãŠãŒã¶ãŒã¢ã«ãŠã³ãã§ã®ã¿ããŒã¿ãããã¯ãŒã¯ãèªèšŒããããšã¯ã§ããŸããïŒ åé¡ã¯ãããŒããããšãã«ããŠãŒã¶ãŒèªèšŒãŠã£ã³ããŠã衚瀺ããåã«ãã¯ãŒã¯ã¹ããŒã·ã§ã³ãããã€ãã®æ®µéãçµãå¿ èŠãããããšã§ãã
- IPã¢ãã¬ã¹ãååŸããŸãã
- ãµã€ããšãã¡ã€ã³ã³ã³ãããŒã©ãŒãå®çŸ©ããŸãã
- LDAPãSMBã䜿çšããŠADãžã®å®å šãªãã³ãã«ãèšå®ããŸãã
- Kerberosã¯ãŒã¯ã¹ããŒã·ã§ã³ã¢ã«ãŠã³ãã䜿çšããŠãã¡ã€ã³ã«ãã°ã€ã³ããŸãã
- GPOãããŠã³ããŒãããŸãã
- ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§GPOã«ãã£ãŠèŠå®ãããã¹ã¯ãªãããå®è¡ããŸãã
åèšã§ããŠãŒã¶ãŒã¢ã«ãŠã³ãã§ã®ã¿æ¿èªãå®è¡ãããå Žåãããã¯çºçããŸããã çç±ã¯ç°¡åã§ããç¡èš±å¯ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ããŒãäžã«ããŒã¿ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããŸãããéåžžã®æäœã«é垞䜿çšãããEAPoLãé€ããã¹ãŠã®ãããã³ã«ã¯ãèš±å¯ããããŸã§ãããã¯ãããŸãã ãããã£ãŠããŠãŒã¶ãŒããã°ã€ã³ããåã«ãã¹ããŒã·ã§ã³ããããã¯ãŒã¯ã§èš±å¯ãããŠããªãã£ãå Žåãã°ã«ãŒãããªã·ãŒã¯é©çšãããŸããã ãã¡ã€ã³ç°å¢ã§äœæ¥ããŠããå Žåã¯ãæåã«ãããã¯ãŒã¯äžã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãæ¿èªããŠãäžèšã®ãã¹ãŠã®æé ãå®è¡ããå¿ èŠããããŸãã ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®èš±å¯åŸã«äœããããã¯ããªãã決ããã®ã¯ããªã次第ã§ããã2ã€ã®ãªãã·ã§ã³ããããŸãïŒ
- ãã®ãŸãŸã«ããŠãããŸãã
- ãŠãŒã¶ãŒè³æ Œæ å ±ã䜿çšããŠè¿œå ã®æ¿èªãå®è¡ããŸãã
æåã«ã¯ãŒã¯ã¹ããŒã·ã§ã³ãæ¿èªãã次ã«ADã®è³æ Œæ å ±ã«åŸã£ãŠãŠãŒã¶ãŒãæ¿èªãããšããŸãã äžæ¹ã§ã¯ãã¢ãããŒãã¯æ£ããã§ãããä»æ¹ã§ã¯ã次ã®åé¡ãçºçããŸãã
- ç»é²æé ã®é«éæé©åïŒé«éãã°ãªã³æé©åïŒã䜿çšããå Žåãã°ã«ãŒãããªã·ãŒãšã¹ã¯ãªããã¯ããŠãŒã¶ãŒãèš±å¯ãããIPã¢ãã¬ã¹ã®ãã®åŸã®å€æŽã§å¥ã®VLANã«ç§»åããããŸã§ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«é©çšããæéããããŸããã
- Fast Logon Optimizationããªãã«ããå Žåãã°ã«ãŒãããªã·ãŒãšã¹ã¯ãªãããå€æ°ããããŠãŒã¶ãŒãéåžžã«é«éã§ããããã«è³æ Œæ å ±ãå ¥åããIPã¢ãã¬ã¹ãå€æŽããŠVLANã«ã¢ã¯ã»ã¹ããã¯ãŒã¯ã¹ããŒã·ã§ã³ãæ£ããåãæ¿ããããã»ã¹ãè¡ããšããã®ãããªäžå¿«ãªç¶æ³ãçºçããå¯èœæ§ããããŸãäžæãããŸãã
- ãŠãŒã¶ãŒè³æ Œæ å ±ã«åŸã£ãŠèªèšŒã䜿çšããå Žåã管çè ã«ããã¯ãŒã¯ã¹ããŒã·ã§ã³ãžã®ãªã¢ãŒãæ¥ç¶ã®åé¡ã¯é€å€ãããŸããã VLANãå€æŽããå¥ã®ãŠãŒã¶ãŒã«æ¥ç¶ãããšãã«IPã¢ãã¬ã¹ãå€æŽã§ããŸãã
æãæçã§å®å šãªãªãã·ã§ã³ã¯ããŠãŒã¶ãŒã®æ¿èªãªãã«èšŒææžã䜿çšããŠãããã¯ãŒã¯äžã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãæ¿èªããããšã§ãã ãã¡ãããããã¯ãŠãŒã¶ãŒèªèšŒãæ°žä¹ ã«æåŠããå¿ èŠããããšããæå³ã§ã¯ãããŸããã ãã®ããã«ããããã«ç°ãªã芳ç¹ããæ¿èªããã»ã¹ã«ã¢ãããŒãããå¿ èŠããããŸã-VLANïŒåçVLANïŒããŠãŒã¶ãŒæš©å©ã®äž»èŠãªåºåããšããŠå€æŽããæé ã«ã€ããŠèª¬æããåã«ããã®å Žåãåçã¢ã¯ã»ã¹ãªã¹ãã圹ç«ã¡ãŸãã ãã®çµæãVLANãšIPã¢ãã¬ã¹ãå€æŽãã代ããã«ãç¹å®ã®VLANã®ACLã«ãŒã«ãç¹å®ã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹æš©ã«åŸã£ãŠå€æŽãããŸãã æ®å¿µãªããããã®æ©èœã¯ã©ãã§ãå©çšã§ããããã§ã¯ãããŸããããå°ãªããšãACSããŒãžã§ã³5.2ã¢ã¯ã»ã¹ã³ã³ãããŒã«ãµãŒããŒã§ã¯å©çšã§ããŸãã
ãšããã§ãããã§ã¯ãACSã¢ã¯ã»ã¹å¶åŸ¡ãµãŒããŒãå¥åCiscoã¢ã¯ã»ã¹å¶åŸ¡ãµãŒããŒãå¥åRADIUSãµãŒããŒãããã³è³æ Œæ å ±ã¹ãã¬ãŒãžïŒActive Directoryãªã©ïŒã®é¢ä¿ã®ããã€ãã®è«çèŠçŽ ãæ€èšããŸãã ADãšã®é¢ä¿ã¯ãACSãµãŒããŒäžã§ã¿ã€ãããšã«ç¢ºç«ãããŸãã
ACSãªããžã§ã¯ãã°ã«ãŒã= ADãªããžã§ã¯ãã°ã«ãŒã
ç¹å®ã®ã°ã«ãŒãã®ãªããžã§ã¯ãã®ã¢ã¯ã»ã¹æš©ã¯ãACSã§èšå®ãããŸãã äœæ¥ã®è«çã¯æ¬¡ã®ãšããã§ãã
- èªèšŒããŒã¿ã®æ€èšŒã®èŠæ±ãå°çããŸããã
- ACSã¯ãADãµãŒããŒã«å¯ŸããŠãããã誰ã§ãã©ã®ADã°ã«ãŒãã«å±ããŠããããå°ããŸãã
- ADã¯ãããããã®ãããªãªããžã§ã¯ãã§ãããç§ã®ã°ã«ãŒãã«ãããšå ±åããŠããŸãã
- ACSã¯ãADã°ã«ãŒãåãšããŒã«ã«ã«äœæãããã°ã«ãŒããã察å¿ããACSã¢ã¯ã»ã¹ããªã·ãŒã«ãããããŸãã
- äžèŽãèŠã€ãã£ãå ŽåãACSã¯ããã®ã°ã«ãŒãã®ACSã«èšå®ãããã»ãã¥ãªãã£åºæºã«åŸã£ãŠãããŒãã«é©çšããã¢ã¯ã»ã¹ã«ãŒã«ãã¹ã€ããã«éç¥ããŸãã
äžèŽãèŠã€ãããªãããADãµãŒããŒãè³æ Œæ å ±ãç¡å¹ã§ãããšå ±åããå Žåãã¹ã€ããã¯ããŒããã²ã¹ãVLANã«é 眮ããŸãã
æ¿èªé åºãå€ããå°ãªããæ確ã«ãªã£ãã®ã§ãç·æ¥äºæ ã«åããå¿ èŠããããŸãã
1. 802.1xã¯ã©ã€ã¢ã³ããæå¹ã«ãªã£ãŠããŸãã ã ã¯ã©ã€ã¢ã³ããã¢ã¯ãã£ãã§ãªãå Žåãã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯èªèº«ãèå¥ã§ãããããŒã¿ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãå¶éãããã²ã¹ãVLANã«èªåçã«é 眮ãããŸãã ãã®æ©èœãå®è¡ããããã»ã¹ãå³ã«ç€ºããŸãã
2. 802.1xã¯ã©ã€ã¢ã³ãã¯æå¹ã«ãªã£ãŠããŸãããæ£ããæ§æãããŠããŸãã ã ã¯ã©ã€ã¢ã³ããèªèº«ãæ£ããèå¥ã§ããªãå Žåãã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ã¢ã¯ã»ã¹ãå¶éãããã²ã¹ãVLANã«èªåçã«é 眮ãããŸãã ãã®æ©èœãå®è¡ããããã»ã¹ãå³ã«ç€ºããŸãã
3. RADIUSãµãŒããŒã¯äœ¿çšã§ããŸãã ã èªèšŒãµãŒããŒã«é害ãçºçããå Žåã®ãã©ãŒã«ããã¬ã©ã³ã¹ãåäžãããããã«ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ãã§ãŒã«ãªãŒããŒVLANã«é 眮ããããžã§ãã«æäœéå¿ èŠãªããŒã¿ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹æš©ãä»äžãããŸãã
ããã§ã¯ãRADIUSãµãŒããŒã®ã¢ã¯ã»ã¹äžèœã®å€å®ã«ãããã·ã¹ã³ã·ã¹ãã ãºãããããããŸããã€ãŸãããããã¿ã€ã ã¿ã€ããŒãåãããšãã¹ã€ããã¯ãããRADIUSãµãŒããŒãçããŠãããšèŠãªããæ§æãããŠããå Žåã¯ãæ¥ç¶ãããŠãããã¹ãŠã®ãŠãŒã¶ãŒã®åèªèšŒããã»ã¹ãéå§ããŸãã RADIUSãµãŒããŒããŸã æ»ãã§ããéã«ããŠãŒã¶ãŒãåã³ãã°ã€ã³ããããšã匷å¶ããããšãã«ãŠãŒã¶ãŒãããœãŒã»ãŒãžããéå§ããæ¹æ³ãæ³åããããšã¯é£ãããããŸããããã¹ã€ããã¯ãããçããŠãããšèŠãªããŸãã ãã®çµæãã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯VLANã«ãŸã£ãããã°ã€ã³ã§ããã空äžã«ãµã¹ãã³ãããããŸãŸã«ãªãããããã¯ãŒã¯ããåæãããã²ã¹ãVLANãŸãã¯ãã§ãŒã«ãªãŒããŒVLANã®ãããã«ãã¢ã¯ã»ã¹ã§ããªããªããŸãã
ãã®ãšã©ãŒã¯ã·ã¹ã³ã«ãã£ãŠå ¬åŒã«èªèããããã®ã§ããããã®èª¬æã¯Webãµã€ãã§ç¢ºèªã§ããŸãã
" CSCir00551-誀解ãæãååŸãããã°ã¡ãã»ãŒãž
説æ
çç¶ïŒ
ãïŒ RADIUS-4-RADIUS_ALIVEïŒRADIUSãµãŒããŒ172.27.66.89:2295,2296ãè¿ãããŸãããã
å°ã誀解ãæãã§ãã ãµãŒããŒãæ»ã£ããšèšã£ãŠããã®ã§ã¯ãªãã
èããŠããæèŠã RADIUSããµãŒããŒãããŒã¯ãããšèšã£ãŠããã ãã§ã
ãããã¿ã€ã ã¿ã€ããŒã®æéãåããŠãããRADIUSã¯
ãã®ãµãŒããŒã«ã¡ãã»ãŒãžãåéä¿¡ããŠãã ããã
æ¡ä»¶ïŒ
ãªã
åé¿çïŒ
ãªã ã
ã¹ã€ããã®ãã¹ãŠã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ããã®ãšã©ãŒã®åœ±é¿ãåããŸãããæ€èšŒããææ°ããŒãžã§ã³ãŸã§ã§ãã ããã«ããããã¯ãã¹ãŠãå ¬åŒã®ã·ã¹ã³Webãµã€ãã®åœ±é¿ãåããOSãªã¹ãã«ãªã¹ããããŠããŸãã ãªããã®ãšã©ãŒããŸã ä¿®æ£ããŠããªãã®ãã¯è¬ã®ãŸãŸã§ãã
äžèšã®ãã¹ãŠãå®è£ ããã«ã¯ãå€ãã®äœæ¥ãå¿ èŠã§ããACSãµãŒããŒã蚌ææžãµãŒããŒãADãDHCPãã¢ã¯ã»ã¹ã¹ã€ããã®ã»ããã¢ããããå§ãŸããã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ã®ãµããªã«ã³ãã®ã»ããã¢ãããšèšŒææžã®çºè¡ã§çµãããŸãã
ããã§ã¯ãã¹ã€ããã®ã¿ã®æ§æã«çŠç¹ãåœãŠãŸãã èšå®ã¯ãiOSã®æ°èŠæ§ã«ãã£ãŠç°ãªããŸãã
å€ãiOS
RADIUSãµãŒããŒãšã®éä¿¡ãæ§æããã«ã¯ãã°ããŒãã«æ§æã¢ãŒãã§æ¬¡ã®ã³ãã³ããå¿ èŠã§ãã
aaa new-model
aaa authentication dot1x default group radius
aaa authorization network default group radius
radius-server host 192.168.20.20 auth-port 1645 acct-port 1646 key SecretSharedKey123
radius-server source-ports 1645-1646
radius-server dead-criteria time 5 tries 4
radius-server deadtime 30
dot1x system-auth-control
åäžã®ããŒããæ§æããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
1.äžè¬çãªã³ãã³ãïŒ
interface GigabitEthernet1/0/1
switchport mode access
dot1x pae authenticator
dot1x port-control auto
dot1x timeout quiet-period 5
dot1x timeout server-timeout 10
dot1x timeout tx-period 5
spanning-tree portfast
end
2.ã²ã¹ãVLANïŒ
interface GigabitEthernet1/0/1
dot1x guest-vlan 1 // VLAN
dot1x auth-fail vlan 1 //auth-fail VLAN
dot1x auth-fail max-attempts 2
end
3.ãã§ã€ã«ãªãŒããŒVLANïŒ
interface GigabitEthernet1/0/1
dot1x critical
dot1x critical vlan 150 //failover VLAN
end
ãã¹ãŠäžç·ã«ïŒ
interface GigabitEthernet1/0/1
switchport mode access
dot1x critical
dot1x pae authenticator
dot1x port-control auto
dot1x timeout quiet-period 5
dot1x timeout server-timeout 10
dot1x timeout reauth-period server
dot1x timeout tx-period 5
dot1x reauthentication
dot1x guest-vlan 1 // VLAN
dot1x auth-fail vlan 1 //auth-fail VLAN
dot1x auth-fail max-attempts 2
dot1x critical vlan 150 //failover VLAN
spanning-tree portfast
end
æ°ããiOS
RADIUSãµãŒããŒãšã®éä¿¡ãæ§æããã«ã¯ãã°ããŒãã«æ§æã¢ãŒãã§æ¬¡ã®ã³ãã³ããå¿ èŠã§ãã
aaa new-model
aaa authentication dot1x default group radius
aaa authorization network default group radius
radius-server dead-criteria time 5 tries 4
radius-server deadtime 30
radius-server host 192.168.20.20 key SecretSharedKey123
dot1x system-auth-control
åäžã®ããŒããæ§æããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸãã
1.äžè¬çãªã³ãã³ãïŒ
interface GigabitEthernet1/0/1
switchport mode access
authentication port-control auto
authentication violation protect
dot1x pae authenticator
dot1x timeout quiet-period 5
dot1x timeout server-timeout 10
dot1x timeout tx-period 5
spanning-tree portfast
end
2.ã²ã¹ãVLANïŒ
authentication event fail action authorize vlan 1
authentication event no-response action authorize vlan 1
3.ãã§ã€ã«ãªãŒããŒVLANïŒ
authentication event server dead action authorize vlan 150
ãã¹ãŠäžç·ã«ïŒ
interface GigabitEthernet0/2
switchport mode access
authentication event fail action authorize vlan 1
authentication event server dead action authorize vlan 150
authentication event no-response action authorize vlan 1
authentication port-control auto
authentication periodic
authentication timer reauthenticate server
authentication violation protect
dot1x pae authenticator
dot1x timeout quiet-period 5
dot1x timeout server-timeout 10
dot1x timeout tx-period 5
spanning-tree portfast
end
çµè«ãšããŠã802.1xæšæºã®åäœåçã«ã€ããŠãããé·ããããæ·±ããããæ·±ãèªãããšãã§ããããšã«æ³šæããããšæããŸãã ãã®è³æã§ã¯ããã®æšæºã䜿çšããäžã§æãåºæ¬çãªåºæ¬ååãè¿°ã¹ãããšããŸããã ãã€ãŠããã®ãããªè³æã¯ãä»åŸã®ç 究ã®åºçºç¹ãšããŠéåžžã«æçšã§ããã