ãã¹ãŠã®åé¡
8.æå°ã®ãããã¯ãŒã¯ã ããŒããšã€ãã BGPããã³IP SLA
7.æå°ã®ãããã¯ãŒã¯ã ããŒã7ã VPN
6.æå°ã®ãããã¯ãŒã¯ã ããŒã6 åçã«ãŒãã£ã³ã°
5.æå°ã®ãããã¯ãŒã¯ïŒããŒã5ã NATããã³ACL
4.æå°ã®ãããã¯ãŒã¯ïŒããŒã4ã STP
3.æå°ã®ãããã¯ãŒã¯ïŒããŒã3ã éçã«ãŒãã£ã³ã°
2.æå°ã®ãããã¯ãŒã¯ã ããŒã2 æŽæµ
1.æå°ã®ãããã¯ãŒã¯ã ããŒã1 Ciscoæ©åšã«æ¥ç¶ãã
0.æå°ã®ãããã¯ãŒã¯ã ããŒããŒãã èšç»äž
7.æå°ã®ãããã¯ãŒã¯ã ããŒã7ã VPN
6.æå°ã®ãããã¯ãŒã¯ã ããŒã6 åçã«ãŒãã£ã³ã°
5.æå°ã®ãããã¯ãŒã¯ïŒããŒã5ã NATããã³ACL
4.æå°ã®ãããã¯ãŒã¯ïŒããŒã4ã STP
3.æå°ã®ãããã¯ãŒã¯ïŒããŒã3ã éçã«ãŒãã£ã³ã°
2.æå°ã®ãããã¯ãŒã¯ã ããŒã2 æŽæµ
1.æå°ã®ãããã¯ãŒã¯ã ããŒã1 Ciscoæ©åšã«æ¥ç¶ãã
0.æå°ã®ãããã¯ãŒã¯ã ããŒããŒãã èšç»äž
å°èŠæš¡ã§å± å¿å°ã®è¯ãLift mi Upãããã¯ãŒã¯ã®éçºãç¶ããŠããŸãã ã«ãŒãã£ã³ã°ãšå®å®æ§ã®åé¡ã«ã€ããŠã¯ãã§ã«èª¬æããŸããããã€ãã«ã€ã³ã¿ãŒãããã«æ¥ç¶ã§ããããã«ãªããŸããã äŒæ¥ç°å¢å ã«ååã«éã蟌ããŠãã ããïŒ
ããããéçºã«äŒŽããæ°ããåé¡ãçºçããŸãã
ãŸãããŠã€ã«ã¹ãWebãµãŒããŒã麻çºããã次ã«èª°ãããããã¯ãŒã¯ãä»ããŠæ¡æ£ããã¯ãŒã ã殺ãã垯åå¹ ã®äžéšãå æããŸããã ãŸããäžéšã®æªåœ¹ã¯ããµãŒããŒãžã®sshã§ãã¹ã¯ãŒããååŸããããšã«æ £ããŸããã
ã€ã³ã¿ãŒãããã«æ¥ç¶ãããšäœãå§ãŸãã®ãæ³åã§ããŸããïŒïŒ
ä»æ¥ã¯ïŒ
1ïŒããŸããŸãªã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒã®æ§ææ¹æ³ãåŠã¶
2ïŒçä¿¡ãã©ãã£ãã¯ãšçºä¿¡ãã©ãã£ãã¯ã®å¶éã®éããç解ããããšããŠãã
3ïŒNATã®ä»çµã¿ããã®é·æãçæãæ©èœãç解ããŠãã
4ïŒå®éã«ã¯ãNATãä»ããŠã€ã³ã¿ãŒãããæ¥ç¶ãæŽçããã¢ã¯ã»ã¹ãªã¹ãã䜿çšããŠãããã¯ãŒã¯ã»ãã¥ãªãã£ã匷åããŸãã
ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ã
ããã§ã¯ãã¢ã¯ã»ã¹ãªã¹ãã§äœãèšãå¿ èŠããããŸããïŒ å®éããã®ãããã¯ã¯æ¯èŒçåçŽã§ãCCNAã³ãŒã¹ã®æ ãè ã§ã¯ãããŸããã ããããããçš®ã®åèŠã®ããã«ç§ãã¡ã®é©ãã¹ã話ãå£ããªãã§ãã ããã
ã¢ã¯ã»ã¹ãªã¹ãã®ç®çã¯äœã§ããïŒ å®å šã«æçœãªçãã¯ãã¢ã¯ã»ã¹ãå¶éããããšã§ãããšæãããŸããããšãã°ã誰ããçŠæ¢ããããšã§ãã äžè¬çã«ãããã¯çå®ã§ãããããåºãæå³ã§ç解ããå¿ èŠããããŸããããã¯ã»ãã¥ãªãã£ã ãã§ã¯ãããŸããã ã€ãŸããæåããããããããããäºå®ã§ããããããã£ãŠãã»ããã¢ããæã«èš±å¯ãšæåŠãè¡ããŸãã ãããå®éã«ã¯ãACLã¯æ±çšæ§ãé«ã匷åãªãã£ã«ã¿ãªã³ã°ã¡ã«ããºã ã§ãã 圌ãã®å©ããåããŠãç¹å®ã®æ¿æ²»å®¶ã誰ã«çžãä»ãããã誰ãç¹å®ã®ããã»ã¹ã«åå ãããã誰ãåå ããªããã誰ãé床ã56kã«å¶éãã誰ã56Mã«ãããã決å®ããããšãã§ããŸã
å°ãããããããããããã«ãç°¡åãªäŸã瀺ããŸãã ã¢ã¯ã»ã¹ãªã¹ãã«åºã¥ããŠãããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ïŒPBRïŒãæ©èœããŸãã ããã§äœæããŠããããã¯ãŒã¯192.168.1.0/24 ããã®ãã±ããããã¯ã¹ãããã10.0.1.1ã«éä¿¡ããããããã¯ãŒã¯192.168.2.0/24ãã10.0.2.1ã«éä¿¡ãããããã«ããããšãã§ããŸãïŒéåžžã®ã«ãŒãã£ã³ã°ã¯ããã±ããã®å®å ã¢ãã¬ã¹ã«äŸåããèªåçã«ãã¹ãŠãã±ããã¯1ã€ã®ãã¯ã¹ããããã«éä¿¡ãããŸãïŒïŒ
èšäºã®æåŸã«ã PBRæ§æãšACLããŒã¹ã®é床å¶éã®äŸã瀺ããŸã ã
ACLã®çš®é¡
ããŠããã°ãããã®æè©ãå¿ããŸãããã
äžè¬çã«ãã¢ã¯ã»ã¹ãªã¹ãã¯ç°ãªããŸãã
-æšæº
-é«åºŠãª
-ãã€ãããã¯
-åå°
-æéããŒã¹
æ¬æ¥ã¯æåã®2ã€ã«çŠç¹ãçµã ã tsiskaã§èªãããšãã§ãããã¹ãŠã®è©³çŽ°ã«ã€ããŠèª¬æããŸãã
çä¿¡ããã³çºä¿¡ãã©ãã£ãã¯
ã¯ããã«ãäžã€ã®ããšã«å¯ŸåŠããŸãããã ã€ã³ããŠã³ãããã³ã¢ãŠãããŠã³ããã©ãã£ãã¯ãšã¯ã©ãããæå³ã§ããïŒ ããã¯å°æ¥å¿ èŠã«ãªããŸãã çä¿¡ãã©ãã£ãã¯ã¯ãå€éšããã€ã³ã¿ãŒãã§ã€ã¹ã«çä¿¡ãããã©ãã£ãã¯ã§ãã
çºä¿¡-ã€ã³ã¿ãŒãã§ã€ã¹ããå€éšã«éä¿¡ããããã®ã
ã¢ã¯ã»ã¹ãªã¹ããçä¿¡ãã©ãã£ãã¯ã«é©çšãããšãäžèŠãªãã±ããã¯ã«ãŒã¿ãŒã«ãéä¿¡ãããããããã£ãŠãããã«ãããã¯ãŒã¯ãŸãã¯çºä¿¡ãã±ããã«éä¿¡ãããŸãããã®åŸããã±ããã¯ã«ãŒã¿ãŒã«å°éããã«ãŒã¿ãŒã«ãã£ãŠåŠçãããåŠçãããã¿ãŒã²ããã€ã³ã¿ãŒãã§ã€ã¹ã«å°éããŠããããããã ãã§ãã
æšæºã¢ã¯ã»ã¹ãªã¹ãã¯ãéä¿¡è ã¢ãã¬ã¹ã®ã¿ããã§ãã¯ããŸãã æ¡åŒµ-éä¿¡è ã¢ãã¬ã¹ãåä¿¡è ã¢ãã¬ã¹ãããã³ããŒãã æšæºACLãåä¿¡è ã®ã§ããã ãè¿ãã«ïŒå¿ èŠä»¥äžã«ã«ããããªãããã«ïŒãæ¡åŒµACLãéä¿¡è ã®è¿ãã«èšå®ããŠïŒäžèŠãªãã©ãã£ãã¯ãã§ããã ãæ©ãããããããããã«ïŒèšå®ããããšããå§ãããŸãã
ç·Žç¿ãã
ããã«ç·Žç¿ããŸãããã å°ããªãããã¯ãŒã¯ãLift mi Upãã§ãããäœã«å¶éããå¿ èŠããããŸããïŒ
aïŒWEBãµãŒããŒã TCPããŒã80ïŒHTTPãããã³ã«ïŒãä»ããå šå¡ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã å¶åŸ¡ãå®è¡ããããã€ã¹ïŒç®¡çè ãããŸãïŒã«ã¯ãtelnetãšftpãéãå¿ èŠããããŸãããå®å šãªã¢ã¯ã»ã¹ãèš±å¯ããŸãã æ®ãã¯ãã¹ãŠé»è©±ãåããŸãã
bïŒãã¡ã€ã«ãµãŒããŒã Lift mi Upã®å± äœè ã¯ãå ±æãã©ã«ãã®ããŒãã§äœ¿çšããæ®ãã¯ãã¹ãŠFTPã§äœ¿çšããå¿ èŠããããŸãã
cïŒã¡ãŒã«ãµãŒããŒã ããã§ãSMTPãšPOP3ãã€ãŸãTCPããŒã25ãš110ãèµ·åããŸããããŸãã管çè ã®ç®¡çã¢ã¯ã»ã¹ãéããŸãã ä»ããããã¯ããŸãã
dïŒå°æ¥ã®DNSãµãŒããŒã®ããã«ãUDPããŒã53ãéãå¿ èŠããããŸã
eïŒãµãŒããŒã®ãããã¯ãŒã¯ãžã®ICMPã¡ãã»ãŒãžãèš±å¯ãã
fïŒFEOãVETãçµçã«åå ããŠããªããã¹ãŠã®éå 掟ã®äººã ã®ããã®ãã®ä»ã®ãããã¯ãŒã¯ãããã®ã§ãããããã¹ãŠãå¶éããäžéšã®ã¿ã«ã¢ã¯ã»ã¹æš©ãäžããŸãïŒç§ãã¡ã¯ãã®äžã®ç®¡çè ã§ãïŒ
gïŒç¹°ãè¿ããŸããã管çè ããããŠãã¡ããææã®äººã ããå¶åŸ¡ãããã¯ãŒã¯ã«å ¥ãããšãèš±å¯ããå¿ èŠããããŸãã
gïŒéšéã®åŸæ¥å¡éã®ã³ãã¥ãã±ãŒã·ã§ã³ã«é害ãæ§ç¯ããŸããã
aïŒWebãµãŒããŒãžã®ã¢ã¯ã»ã¹
ããã«ã¯ãçŠæ¢ãããŠããããªã·ãŒããããèš±å¯ãããŠããªããã®ã¯ãã¹ãŠçŠæ¢ãããŠããŸãã ãããã£ãŠãããã§äœããéããæ®ããéããå¿ èŠããããŸãã
ãµãŒããŒã®ãããã¯ãŒã¯ãä¿è·ããŠããã®ã§ããµãŒããŒã«åããã€ã³ã¿ãŒãã§ã€ã¹ãã€ãŸãFE0 / 0.3ã«ã·ãŒãã眮ããŸããå¯äžã®è³ªåã¯ãinãŸãã¯outã§ãããããè¡ãå¿ èŠããããŸããïŒ ãã§ã«ã«ãŒã¿ãŒäžã«ãããµãŒããŒã«ãã±ãããéä¿¡ããããªãå Žåãããã¯çºä¿¡ãã©ãã£ãã¯ã«ãªããŸãã ã€ãŸãããµãŒããŒã®ãããã¯ãŒã¯å ã«ããå®å ã¢ãã¬ã¹ïŒå®å ïŒïŒãã©ãã£ãã¯ã®éä¿¡å ãµãŒããŒãéžæããïŒãããã³çºä¿¡å ã¢ãã¬ã¹ïŒãœãŒã¹ïŒã¯ãäŒæ¥ãããã¯ãŒã¯ãŸãã¯ã€ã³ã¿ãŒãããããã®ãããã§ãããŸããŸããã
ãã1ã€ã®æ³šæïŒå®å ã¢ãã¬ã¹ïŒWEBãµãŒããŒäžã®ã«ãŒã«ãã¡ãŒã«ãµãŒããŒäžã®ã«ãŒã«ïŒã§ãã£ã«ã¿ãŒãããããæ¡åŒµã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒæ¡åŒµïŒãå¿ èŠã§ãã
ã¢ã¯ã»ã¹ãªã¹ãå ã®ã«ãŒã«ã¯ãæåã«äžèŽãããŸã§äžããäžã®é ã«ãã§ãã¯ãããŸãã ã«ãŒã«ã®1ã€ãæ©èœãããšãèš±å¯ãŸãã¯æåŠã«é¢ä¿ãªãããã§ãã¯ãåæ¢ããæ©èœããã«ãŒã«ã«åºã¥ããŠãã©ãã£ãã¯ãåŠçãããŸãã
ã€ãŸããWEBãµãŒããŒãä¿è·ããå Žåã¯ããŸãæåã«èš±å¯ãäžããå¿ èŠããããŸããæåã®è¡ã§deny ip any anyãèšå®ãããšãåžžã«æ©èœãããã©ãã£ãã¯ããŸã£ããæµããªãããã§ãã Anyã¯ããããã¯ãŒã¯ã¢ãã¬ã¹ãšããã¯ã¯ãŒããã¹ã¯0.0.0.0 0.0.0.0ãæå³ããç¹å¥ãªåèªã§ããããã¹ãŠã®ãããã¯ãŒã¯ã®ãã¹ãŠã®ããŒããå®å šã«ã«ãŒã«ã«è©²åœããããšãæå³ããŸãã å¥ã®ç¹å¥ãªåèªã¯ãã¹ãã§ã -ããã¯ãã¹ã¯255.255.255.255ãæå³ããŸã-ã€ãŸããæ£ç¢ºã«1ã€ã®æå®ãããã¢ãã¬ã¹ã§ãã
ãããã£ãŠãæåã®ã«ãŒã«ïŒããŒã80ã§å šå¡ã«ã¢ã¯ã»ã¹ãèš±å¯ãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended Servers-out
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒåèWEB
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒtcp any host 172.16.0.2 eq 80
ãã¹ãïŒ any ïŒãããã¹ãïŒ hostã¯1ã€ã®ã¢ãã¬ã¹ã®ã¿ïŒ172.16.0.2ãããŒã80å®ãŠã®TCPãã©ãã£ãã¯ãèš±å¯ïŒ èš±å¯ ïŒããŸãã
ãã®ã¢ã¯ã»ã¹ãªã¹ããFE0 / 0.3ã€ã³ã¿ãŒãã§ã€ã¹ã§ãã³ã°ãããããšããŸãã
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.3
msk-arbat-gw1ïŒconfig-subifïŒïŒip access-group Servers-out out
æ¥ç¶ãããŠããã³ã³ãã¥ãŒã¿ãŒãã確èªããŸãã
ã芧ã®ãšãããããŒãžãéããŸãããpingã¯ã©ãã§ããïŒ
ãããŠãä»ã®ããŒãããã§ããïŒ
å®éã«ã¯ãtsiskovye ACLã®ãã¹ãŠã®ã«ãŒã«ã®åŸã«ãæé»ã®æåŠip any any ïŒæé»ã®æåŠïŒãæåŸã«è¿œå ãããŸãã ããã¯ç§ãã¡ã«ãšã£ãŠäœãæå³ããã®ã§ããããïŒ ã€ã³ã¿ãŒãã§ã€ã¹ããåºãŠãACLã®ã«ãŒã«ãæºãããªããã±ããã¯ãæé»çã«æåŠãããç Žæ£ãããŸãã ã€ãŸããå°ãªããšãpingãå°ãªããšãftpãå°ãªããšãããã§ã¯äœãæ©èœããŸããã
ããã«å ã«é²ã¿ãŸããå¶åŸ¡ãå®è¡ããã³ã³ãã¥ãŒã¿ãŒãžã®ãã«ã¢ã¯ã»ã¹ãèš±å¯ããå¿ èŠããããŸãã ããã¯ãä»ã®ãããã¯ãŒã¯ããã®ã¢ãã¬ã¹172.16.6.66ãæã€ç®¡çè ã®ã³ã³ãã¥ãŒã¿ãŒã«ãªããŸãã
æ°ããã«ãŒã«ã¯ãæ¢ã«ååšããå Žåããªã¹ãã®æåŸã«èªåçã«è¿œå ãããŸãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended Servers-out
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒTCPãã¹ã172.16.6.66ãã¹ã172.16.0.2ç¯å²20 ftpãèš±å¯
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒTCPãã¹ã172.16.6.66ãã¹ã172.16.0.2 eq telnetãèš±å¯
以äžã§ãã æ£ããããŒããã確èªããŸãïŒRTã®ãµãŒããŒã¯telnetããµããŒãããŠããªããããFTPã確èªããŸãïŒã
ã€ãŸããFTPã¡ãã»ãŒãžã¯ã«ãŒã¿ãŒã«å°éããFE0 / 0.3ã€ã³ã¿ãŒãã§ã€ã¹ããéä¿¡ãããã¯ãã§ãã ã«ãŒã¿ãŒã¯ããã±ãããè¿œå ããã«ãŒã«ãšäžèŽããããšã確èªããã³ç¢ºèªãããããæž¡ããŸãã
ãããŠãå€éšããŒããã
FTPãã±ããã¯ãæé»ã®deny ip any anyãé€ãã«ãŒã«ã®ãããã«ã該åœãããç Žæ£ãããŸãã
bïŒãã¡ã€ã«ãµãŒããŒãžã®ã¢ã¯ã»ã¹
ããã§ã¯ããŸã誰ããå± äœè ãã«ãªããã誰ã«ã¢ã¯ã»ã¹æš©ãäžããå¿ èŠããããã決å®ããå¿ èŠããããŸãã ãã¡ããããããã¯ãããã¯ãŒã¯172.16.0.0/16ããã®ã¢ãã¬ã¹ãæã£ãŠãã人ã§ã-ç§ãã¡ã¯åœŒãã«ã¢ã¯ã»ã¹æš©ãäžããã ãã§ãã
å ±æãã©ã«ããè¿œå ãããŸããã ææ°ã®ã·ã¹ãã ã®ã»ãšãã©ã¯ããã®ããã«TCPããŒã445ãå¿ èŠãšããSMBãããã³ã«ãæ¢ã«äœ¿çšããŠããŸããå€ãããŒãžã§ã³ã§ã¯ãUDP 137ããã³138ãšTCP 139ã®3ã€ã®ããŒããçµç±ããNetBiosã䜿çšãããŸããã RTã®ãã¬ãŒã ã¯ãŒã¯å ã§ã¯ããã¡ããåäœããŸããïŒã ãã ããããã«å ããŠãFTPçšã®ããŒãïŒ20ã21ãããã³å éšãã¹ãã ãã§ãªããã€ã³ã¿ãŒãããããã®æ¥ç¶çšïŒãå¿ èŠã§ãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended Servers-out
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒèš±å¯TCP 172.16.0.0 0.0.255.255ãã¹ã172.16.0.3 eq 445
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒ ä»»æã®ãã¹ã172.16.0.3ã®ç¯å²20 21ã®tcpãèš±å¯
ããã§ãåãè¡ã«è€æ°ã®ããŒããæå®ããããã«ã ç¯å²20 21ã³ã³ã¹ãã©ã¯ããåé©çšããŸããã FTPã®å Žåãäžè¬çã«èšãã°ã21çªç®ã®ããŒãã ãã§ã¯ååã§ã¯ãããŸããã å®éãããã ããéããšãèš±å¯ãããŸããããã¡ã€ã«è»¢éã¯è¡ãããŸããã
0.0.255.255-ãªããŒã¹ãã¹ã¯ïŒã¯ã€ã«ãã«ãŒããã¹ã¯ïŒã ããã«ã€ããŠã¯åŸã§èª¬æããŸã
cïŒã¡ãŒã«ãµãŒããŒãžã®ã¢ã¯ã»ã¹
ç§ãã¡ã¯ç·Žç¿ãç¶ããŸã-ä»ã¯ã¡ãŒã«ãµãŒããŒã§ã åãã¢ã¯ã»ã¹ãªã¹ãã®äžéšãšããŠãå¿ èŠãªæ°ãããšã³ããªãè¿œå ããŸãã
åºç¯ãªãããã³ã«ã®ããŒãçªå·ã®ä»£ããã«ããããã®ååãæå®ã§ããŸãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended Servers-out
msk-arbat-gw1ïŒconfig-ext-naclïŒ#permit tcp any host 172.16.0.4 eq pop3
msk-arbat-gw1ïŒconfig-ext-naclïŒ#permit tcp any host 172.16.0.4 eq smtp
dïŒDNSãµãŒããŒ
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended Servers-out
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow udp 172.16.0.0 0.0.255.255ãã¹ã172.16.0.5 eq 53
eïŒICMP
pingã§ç¶æ³ãä¿®æ£ããããšã¯æ®ã£ãŠããŸãã ãªã¹ãã®æåŸã«ã«ãŒã«ãè¿œå ããŠãæ§ããŸããããæåã«ã«ãŒã«ã衚瀺ããã®ã¯èŠãç®ãçŸããã§ãã
ããã«ã¯åçŽãªããŒãã䜿çšããŸãã ããã«ã¯ãããšãã°ããã¹ããšãã£ã¿ã䜿çšã§ããŸãã show runããACLã¹ã©ã€ã¹ãã³ããŒãã次ã®è¡ãè¿œå ããŸãã
no ip access-list extended servers-out
ip access-list extended servers-out
icmp any anyãèš±å¯ããŸã
çºèšãŠã§ã
tcp any host 172.16.0.2 eq wwwãèš±å¯ããŸã
èš±å¯tcpãã¹ã172.16.6.66ãã¹ã172.16.0.2ç¯å²20 ftp
èš±å¯tcpãã¹ã172.16.6.66ãã¹ã172.16.0.2 eq telnet
泚éãã¡ã€ã«
èš±å¯tcp 172.16.0.0 0.0.255.255ãã¹ã172.16.0.3 eq 445
tcpãèš±å¯ãã¹ã172.16.0.3ã®ç¯å²20 21
åèã¡ãŒã«
tcp any host 172.16.0.4 eq pop3ãèš±å¯ããŸã
tcp any host 172.16.0.4 eq smtpãèš±å¯ããŸã
DNSãçºèšãã
èš±å¯udp 172.16.0.0 0.0.255.255ãã¹ã172.16.0.5 eq 53
æåã®è¡ã§ã¯ãæ¢åã®ãªã¹ããåé€ããŠããå床äœæããå¿ èŠãªé åºã§ãã¹ãŠã®æ°ããã«ãŒã«ããªã¹ãããŸãã 3è¡ç®ã®ã³ãã³ãã䜿çšããŠããã¹ãŠã®ãã¹ããããã¹ãŠã®ãã¹ããžã®ãã¹ãŠã®ICMPãã±ããã®ééãèš±å¯ããŸããã
次ã«ããã¹ãŠãäžæ¬ã§ã³ããŒããŠãã³ã³ãœãŒã«ã«è²Œãä»ããŸãã ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãåè¡ãåå¥ã®ã³ãã³ããšããŠè§£éããŠå®è¡ããŸãã ãããã£ãŠãå€ããªã¹ããæ°ãããªã¹ãã«çœ®ãæããŸããã
pingã次ã®ããšã確èªããŸãã
çŽ æŽãããã
ãã®ããŒãã¯ãåææ§æã«é©ããŠããŸãããŸãã¯ãèªåãäœãããŠããããæ£ç¢ºã«ç解ããŠããå Žåã«åœ¹ç«ã¡ãŸãã åäœäžã®ãããã¯ãŒã¯ã§ãACLããªã¢ãŒãã§æ§æãããšãã«ã¹ã¿ã ããŒããŠã§ã¢ã«ã¢ã¯ã»ã¹ã§ããªããªãå±éºããããŸãã
ã«ãŒã«ãå é ãŸãã¯ä»ã®ä»»æã®å Žæã«æ¿å ¥ããã«ã¯ã次ã®ææ³ã䜿çšã§ããŸãã
ip access-list extended servers-out
1 icmp any anyãèš±å¯ããŸã
ãªã¹ãå ã®åã«ãŒã«ã«ã¯ç¹å®ã®ã¹ãããã§çªå·ãä»ããããpermit / denyãšããåèªã®åã«çªå·ãä»ãããšãã«ãŒã«ã¯æåŸã§ã¯ãªãå¿ èŠãªå Žæã«è¿œå ãããŸãã æ®å¿µãªããããã®ãããªæ©èœã¯RTã§ã¯æ©èœããŸããã
çªç¶å¿ èŠãªå ŽåïŒã«ãŒã«éã®é£ç¶ããçªå·ã¯ãã¹ãŠäœ¿çšäžïŒããã€ã§ãã«ãŒã«ã®çªå·ãå€æŽã§ããŸãïŒãã®äŸã§ã¯ãæåã®ã«ãŒã«ã®çªå·ã¯10ïŒæåã®çªå·ïŒã§ãå¢åã¯10ã§ãïŒã
ip access-list resequence Servers-out 10 10
ãã®çµæããµãŒããŒãããã¯ãŒã¯äžã®ã¢ã¯ã»ã¹ãªã¹ãã¯æ¬¡ã®ããã«ãªããŸãã
ip access-list extended servers-out
icmp any anyãèš±å¯ããŸã
çºèšãŠã§ã
tcp any host 172.16.0.2 eq wwwãèš±å¯ããŸã
èš±å¯tcpãã¹ã172.16.6.66ãã¹ã172.16.0.2ç¯å²20 ftp
èš±å¯tcpãã¹ã172.16.6.66ãã¹ã172.16.0.2 eq telnet
泚éãã¡ã€ã«
èš±å¯tcp 172.16.0.0 0.0.255.255ãã¹ã172.16.0.3 eq 445
tcpãèš±å¯ãã¹ã172.16.0.3ã®ç¯å²20 21
åèã¡ãŒã«
tcp any host 172.16.0.4 eq pop3ãèš±å¯ããŸã
tcp any host 172.16.0.4 eq smtpãèš±å¯ããŸã
DNSãçºèšãã
èš±å¯udp 172.16.0.0 0.0.255.255ãã¹ã172.16.0.5 eq 53
ããã§ã管çè ã¯WEBãµãŒããŒã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã 圌ã«ãããã¯ãŒã¯å šäœãžã®ãã«ã¢ã¯ã»ã¹ãèš±å¯ããŸãã ãããæåã®å®¿é¡ã§ãã
eïŒãããã¯ãŒã¯ããã®ãŠãŒã¶ãŒã®æš©å©ãã®ä»
ãããŸã§ã¯ã誰ãå ¥ããªãããã«ããå¿ èŠããã£ããããå®å ã¢ãã¬ã¹ã«æ³šæãæããã¢ã¯ã»ã¹ãªã¹ãã¯ã€ã³ã¿ãŒãã§ã€ã¹ããã®ãã©ãã£ãã¯ã«ããã£ãŠããŸããã
ããã§ããããå€ã«åºããªãããã«ããå¿ èŠããããŸããä»ã®ãããã¯ãŒã¯ããã®ã³ã³ãã¥ãŒã¿ãŒããã®èŠæ±ã¯è¶ ããŠã¯ãªããŸããã ãã¡ãããç¹ã«èš±å¯ããŠãããã®ãé€ããŸãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended Other-in
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒremark IAM
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.6.61 any
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒæ³šéADMIN
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒIPãã¹ã172.16.6.66ãèš±å¯ããany
ããã§ã¯ããŸããã¹ãŠã®äººãçŠæ¢ããããšã¯ã§ãããéžæãããã®ãèš±å¯ããããšã¯ã§ããŸããã絶察ã«ãã¹ãŠã®ãã±ããããã¹ãŠã®ã«ãŒã«ã®æåŠIPã«è©²åœãã èš±å¯ããŸã£ããæ©èœããªãããã§ãã
ã€ã³ã¿ãŒãã§ã€ã¹ã«é©çšããŸãã ä»åã¯å ¥åïŒ
msk-arbat-gw1ïŒconfigïŒ#int fa0 / 0.104
msk-arbat-gw1ïŒconfig-subifïŒ#ip access-group Other-in in
ã€ãŸããã¢ãã¬ã¹ã172.16.6.61ãŸãã¯172.16.6.66ã®ãã¹ãããã®ãã¹ãŠã®IPãã±ããã¯ãæå³ããå Žæã«éä¿¡ã§ããŸãã ããã§æ¡åŒµã¢ã¯ã»ã¹ãªã¹ãã䜿çšããŠããã®ã¯ãªãã§ããïŒ çµå±ã®ãšãããéä¿¡è ã¢ãã¬ã¹ã®ã¿ããã§ãã¯ããŠããããã«èŠããŸãã 管çè ã«ãã«ã¢ã¯ã»ã¹ãäžããããããšãã°ãElevator mi UpããšããäŒç€Ÿã®ã²ã¹ãã®å Žåãåããããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ãããšãã€ã³ã¿ãŒããã以å€ã®ã©ãã«ã絶察ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
gïŒç®¡çãããã¯ãŒã¯
è€éãªããšã¯äœããããŸããã ã«ãŒã«ã¯æ¬¡ã®ããã«ãªããŸãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended management-out
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒremark IAM
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.6.61 172.16.1.0 0.0.0.255
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒæ³šéADMIN
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.6.66 172.16.1.0 0.0.0.255
ãã®ACLãFE 0 / 0.2ã€ã³ã¿ãŒãã§ã€ã¹ã®outã«é©çšããŸãã
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.2
msk-arbat-gw1ïŒconfig-subifïŒ#ip access-group Management-out out
gïŒå¶éãªã
å®äº
ãã¹ã¯ãšéãã¹ã¯
ãããŸã§ã説æãªãã§ã0.0.255.255ãšãã圢åŒã®å¥åŠãªãã©ã¡ãŒã¿ãŒãæå®ããŠããŸããããããã¯çãããããšã«ãµãããããã¹ã¯ã«äŒŒãŠããŸãã
ç解ããã®ã¯å°ãé£ããã§ãããã«ãŒã«ã«è©²åœãããã¹ãã決å®ããããã«äœ¿çšãããã®ã¯ã€ã³ããŒã¹ãã¹ã¯ã§ãã
ãªããŒã¹ãã¹ã¯ãšã¯äœããç解ããã«ã¯ãéåžžã®ãã¹ã¯ãšã¯äœããç¥ãå¿ èŠããããŸãã
æãåçŽãªäŸããå§ããŸãããã
256ã¢ãã¬ã¹ã®éåžžã®ãããã¯ãŒã¯ïŒ172.16.5.0/24ãªã©ã ãã®ãšã³ããªã¯ã©ãããæå³ã§ããïŒ
ãããŠãããã¯ãŸãã«ä»¥äžãæå³ããŸã
IPã¢ãã¬ã¹ å°æ°èšé² | 172 | 16 | 5 | 0 |
IPã¢ãã¬ã¹ ãã€ããªã¬ã³ãŒã | 10101100 | 00010000 | 00000101 | 00000000 |
ãµãããããã¹ã¯ ãã€ããªã¬ã³ãŒã | 11111111 | 11111111 | 11111111 | 00000000 |
ãµãããããã¹ã¯ å°æ°èšé² | 255 | 255 | 255 | 0 |
IPã¢ãã¬ã¹ã¯4ã€ã®éšåã«åå²ããã32ãããã®ãã©ã¡ãŒã¿ãŒã§ããã10é²æ°åœ¢åŒã§è¡šç€ºããã®ã«æ £ããŠããŸãã
ãµãããããã¹ã¯ã®é·ãã32ãããã§ããããã¯å®éã«ã¯ããµããããã¢ãã¬ã¹ã®IDã決å®ãããã³ãã¬ãŒãã§ããã¹ãã³ã·ã«ã§ãã ãã¹ã¯ã«ãŠããããããå Žåãå€ã¯å€æŽã§ããŸãããã€ãŸããéšå172.16.5ã¯å®å šã«å€æŽãããããã®ãµããããäžã®ãã¹ãŠã®ãã¹ãã§åãã§ããããŒãã®ãã¹ãã¯ç°ãªããŸãã
ã€ãŸããåãäžããäŸã§ã¯ã172.16.5.0 / 24ããããã¯ãŒã¯ã¢ãã¬ã¹ã§ããããã¹ãã¯172.16.5.1-172.16.5.254ïŒæåŸã®255ã¯ãããŒããã£ã¹ãïŒã«ãªããŸããããã¯ã00000001ã1ã§ã11111110ã254ã§ããããã§ãïŒã¢ãã¬ã¹ã®æåŸã®ãªã¯ãããã«ã€ããŠèª¬æããŠããŸãïŒ ïŒ / 24ã¯ããã¹ã¯ã®é·ãã24ãããã§ããããšãæå³ããŸããã€ãŸãã24ãŠãããïŒäžå€éšåãš8ã€ã®ãŒãïŒããããŸãã
ããšãã°ããã¹ã¯ã24ã§ã¯ãªã30ãããã§ããå Žåã
ããšãã°ã172.16.2.4 / 30ã 次ã®ããã«æžããŸãã
IPã¢ãã¬ã¹ å°æ°èšé² | 172 | 16 | 2 | 4 |
IPã¢ãã¬ã¹ ãã€ããªã¬ã³ãŒã | 10101100 | 00010000 | 00000010 | 00000100 |
ãµãããããã¹ã¯ ãã€ããªã¬ã³ãŒã | 11111111 | 11111111 | 11111111 | 11111100 |
ãµãããããã¹ã¯ å°æ°èšé² | 255 | 255 | 255 | 252 |
ã芧ã®ãšããããã®ãµããããã§ã¯æåŸã®2ãããã®ã¿å€æŽã§ããŸãã æåŸã®ãªã¯ãããã¯æ¬¡ã®4ã€ã®å€ãåãããšãã§ããŸãã
00000100-ãµããããã¢ãã¬ã¹ïŒ10é²æ°ã§4ïŒ
00000101-ããŒãã¢ãã¬ã¹ïŒ5ïŒ
00000110-ããŒãã¢ãã¬ã¹ïŒ6ïŒ
00000111-ãããŒããã£ã¹ãïŒ7ïŒ
ãããè¶ ãããã®ã¯ãã¹ãŠå¥ã®ãµããããã§ã
ã€ãŸãããµãããããã¹ã¯ã¯32ãããã®ã·ãŒã±ã³ã¹ã§ãããæåã«ãµããããã¢ãã¬ã¹ãæå³ããåäœãããã次ã«ãã¹ãã¢ãã¬ã¹ãæå³ãããŒããããããšãå°ãããããŸãã ãã®å ŽåããŒãã¯äº€äºã«ãªãããã¹ã¯å ã®åäœã¯äº€äºã«ãªããŸããã ã€ãŸãããã¹ã¯11111111.11100000.11110111.00000000ã¯äžå¯èœã§ã
ããããã¯ã€ã«ãã«ãŒããšã¯äœã§ããïŒ
倧å€æ°ã®ç®¡çè ãšäžéšã®ãšã³ãžãã¢ã«ãšã£ãŠãããã¯éåžžã®ãã¹ã¯ã®å転ã«éããŸããã ã€ãŸããæåã«ãŒããããŒãã®ã¢ãã¬ã¹ãæå®ããŸããããã¯å¿ ãäžèŽããå¿ èŠããããéã«ãŠãããã¯ç©ºãããŒãã§ãã
ã€ãŸããæåã®äŸã§ã172.16.5.0 / 24ãµãããããããã¹ãŠã®ãã¹ãããã£ã«ã¿ãªã³ã°ããå Žåãã¢ã¯ã»ã¹ãªã¹ãã«ã«ãŒã«ãèšå®ããŸãã
... 172.16.5.0 0.0.0.255
ã€ã³ããŒã¹ãã¹ã¯ã¯æ¬¡ã®ããã«ãªãããã§ãã
00000000.00000000.00000000.11111111
ãããã¯ãŒã¯172.16.2.4/30ã®2çªç®ã®äŸã§ã¯ãã€ã³ããŒã¹ãã¹ã¯ã¯æ¬¡ã®ããã«ãªããŸãã30åã®ãŒããš2ã€ã®ãŠãããïŒ
ãªããŒã¹ãã¹ã¯ ãã€ããªã¬ã³ãŒã | 00000000 | 00000000 | 00000000 | 00000011 |
ãªããŒã¹ãã¹ã¯ å°æ°èšé² | 0 | 0 | 0 | 3 |
ãããã£ãŠãã¢ã¯ã»ã¹ãªã¹ãã®ãã©ã¡ãŒã¿ã¯æ¬¡ã®ããã«ãªããŸãã
... 172.16.2.4 0.0.0.3
åŸã§ããã¹ã¯ãšåŸæ¹ãã¹ã¯ã®èª€ç®ã§ç¬ãé£ã¹ããšãæã䜿çšãããŠããæ°åããã®ãã¹ã¯ãŸãã¯ãã®ãã¹ã¯ã®ãã¹ãæ°ãèŠããŠããã§ãããã説æãããç¶æ³ã§ã¯ãã€ã³ããŒã¹ãã¹ã¯ã®æåŸã®ãªã¯ãããã¯éåžžã®ãã¹ã¯ã®æåŸã®ãªã¯ãããã255ïŒ255-252 = 3ïŒãªã© ãããŸã§ã®éãããªãã¯äžçæžåœåããŠãããåãå¿ èŠããããŸãïŒ
ããããå®éã«ã¯ããªããŒã¹ãã¹ã¯ã¯å°ãè±å¯ãªããŒã«ã§ããããã§ã¯ãåããµããããå ã®ã¢ãã¬ã¹ãçµã¿åããããããµãããããçµã¿åããããããããšãã§ããŸãããæãéèŠãªéãã¯ã0ãš1ã亀äºã«äœ¿çšã§ããããšã§ãã ããã«ãããããšãã°ã1è¡ã§è€æ°ã®ãµããããäžã®ç¹å®ã®ãã¹ãïŒãŸãã¯ã°ã«ãŒãïŒãé€å€ã§ããŸãã
äŸ1
æå®ïŒãããã¯ãŒã¯172.16.16.0/24
å¿ èŠãªã®ã¯ ãæåã®64åã®ã¢ãã¬ã¹ïŒ172.16.16.0-172.16.16.63ïŒ ããã£ã«ã¿ãªã³ã°ããããšã§ã
解決çïŒ 172.16.16.0 0.0.0.63
äŸ2
æå®ïŒãããã¯ãŒã¯172.16.16.0/24ããã³172.16.17.0/24
å¿ èŠïŒäž¡æ¹ã®ãããã¯ãŒã¯ããã¢ãã¬ã¹ããã£ã«ã¿ãªã³ã°ãã
解決çïŒ 172.16.16.0 0.0.1.255
äŸ3
æå®ïŒãããã¯ãŒã¯172.16.0.0-172.16.255.0
å¿ èŠãªã®ã¯ ããã¹ãŠã®ãµããããããã¢ãã¬ã¹4ã®ãã¹ãããã£ã«ã¿ãªã³ã°ããããšã§ã
解決çïŒ 172.16.16.0 0.0.255.4
èªããããã«ãç§ã®äººçã®äžã§ãç§ã¯ææ°ã®ã¢ããªã±ãŒã·ã§ã³ã·ããªãªã«åºäŒãå¿ èŠã¯ãããŸããã§ããããããã¯ããã¹ãã²ã©ãç¹å®ã®ã¿ã¹ã¯ã§ãã
ãªããŒã¹ãã¹ã¯ã®è©³çŽ°ã«ã€ããŠã¯ãhttpïŒ//habrahabr.ru/post/131712/ãã芧ãã ããã
åçã®ACLããã©ãŒãã³ã¹
ä»®æ³ãããã¯ãŒã¯ïŒ
1ïŒFE0 / 1ã€ã³ã¿ãŒãã§ã€ã¹äžã®RT1ã«ãŒã¿ãŒã§ã¯ãICMP以å€ã®ãã¹ãŠãå ¥åã§ããŸãã
2ïŒFE0 / 1ã€ã³ã¿ãŒãã§ã€ã¹ã®RT2ã«ãŒã¿ãŒã§SSHãšTELNETãç¡å¹ã«ãªã£ãŠãã
ãã¹ã
ã¯ãªãã¯å¯èœ
1ïŒPC1ããServer1ãžã®Ping 2ïŒPC1ããServer1ãžã®TELNET 3ïŒPC1ããServer2ãžã®SSH 4ïŒServer2ããPC1ãžã®Ping
è¿œå
1ïŒçºä¿¡ãã©ãã£ãã¯ïŒoutïŒã«é©çšãããã«ãŒã«ã¯ãããã€ã¹èªäœã®ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããŸãããã€ãŸããtsiskaãã©ããã«ã¢ã¯ã»ã¹ããã®ãé²ãå¿ èŠãããå Žåã¯ããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§çä¿¡ãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããå¿ èŠããããŸãïŒçãã¯ãã¢ã¯ã»ã¹ããããã¯ããå¿ èŠãããå Žæããã§ãïŒã
2ïŒC ACLã¯æ³šæããå¿ èŠããããŸããã«ãŒã«ã«å°ããªãšã©ãŒããããèšå®ã®é åºãééã£ãŠããããŸãã¯äžè¬çã«ããèããããŠããªããªã¹ããããå Žåãããã€ã¹ã«ã¢ã¯ã»ã¹ããã«æ®ãããšãã§ããŸãã
ããšãã°ãã¢ãã¬ã¹172.16.6.61ãé€ãã172.16.6.0 / 24ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ããããã¯ãã次ã®ãããªã«ãŒã«ãèšå®ããŸãã
deny ip 172.16.6.0 0.0.0.255 any
permit ip host 172.16.6.61 any
ã€ã³ã¿ãŒãã§ã€ã¹ã«ACLãé©çšãããšããã«ãæåã®ã«ãŒã«ãé©çšããã2çªç®ã®ã«ãŒã«ããã§ãã¯ãããªããããã«ãŒã¿ãžã®ã¢ã¯ã»ã¹ãããã«å€±ãããŸãã
ããªãã«èµ·ãããããããªã2çªç®ã®äžå¿«ãªç¶æ³ïŒACLã®äžã«ããã¹ãã§ã¯ãªããã©ãã£ãã¯ã
ãã®ç¶æ³ãæ³åããŠãã ããããµãŒããŒã«ãŒã ã«ã¯ãããã·ãã¢ãŒãã®FTPãµãŒããŒããããŸããããã«ã¢ã¯ã»ã¹ããã«ã¯ãACL Servers-outã§21çªç®ã®ããŒããéããŠããŸãããæåã®æ¥ç¶ã確ç«ãããåŸãFTPãµãŒããŒã¯ã¯ã©ã€ã¢ã³ãã«ãããšãã°1523rdãªã©ããã¡ã€ã«ãéåä¿¡ããæºåãã§ããŠããããŒããéç¥ããŸããã¯ã©ã€ã¢ã³ãã¯ãã®ããŒããžã®TCPæ¥ç¶ã確ç«ããããšããŸãããACLãµãŒããŒããªãå Žåãã€ãŸããããã®ãããªèš±å¯ã¯ãããŸãã-ãããŠãæåãã転éã®ç©èªã¯çµãããŸããäžèšã®äŸã§ã¯ããã¡ã€ã«ãµãŒããŒãžã®ã¢ã¯ã»ã¹ãæ§æããŸããããäŸãšããŠã¯ããã§ååã§ãããããã¢ã¯ã»ã¹ã20æ¥ãš21æ¥ã«ã®ã¿éããŸãããå®éã«ã¯ããããããŸããå¿ èŠããããŸããäžè¬çãªã±ãŒã¹ã®ACLæ§æã®ããã€ãã®äŸã
3ïŒãã€ã³ã2ããéåžžã«ãã䌌ãèå³æ·±ãåé¡ãç¶ããŸãã
ããšãã°ããã®ãããªACLãã€ã³ã¿ãŒãããã€ã³ã¿ãŒãã§ã€ã¹ã«ãã³ã°ã¢ãããããšèããŸããã
èš±å¯tcpãã¹ãã®ã¢ã¯ã»ã¹ãªã¹ã1.1.1.1ãã¹ã2.2.2.2 eq 80
èš±å¯tcpãã¹ãã®ã¢ã¯ã»ã¹ãªã¹ã2.2.2.2 any eq 80
ã¢ãã¬ã¹1.1.1.1ã®ãã¹ãã¯ããµãŒããŒ2.2.2.2ãžã®80çªç®ã®ããŒãã§ã®ã¢ã¯ã»ã¹ãèš±å¯ãããŸãïŒæåã®ã«ãŒã«ïŒããããŠããµãŒããŒ2.2.2.2ããã®å éšæ¥ç¶ãèš±å¯ããŸããã
ãã ããããã§ã®ãã¥ã¢ã³ã¹ã¯ãã³ã³ãã¥ãŒã¿ãŒ1.1.1.1ãããŒã80ãžã®æ¥ç¶ã確ç«ããããšã§ããã1054ãªã©ã®å¥ã®ãµãŒããŒãããã€ãŸãããµãŒããŒããã®å¿çãã±ããããœã±ãã1.1.1.1:1054ã«å°çãã INã®ACLãããã³æé»ã®æåŠip any anyã«ããç Žæ£ãããŸããã
ãã®ç¶æ³ãåé¿ããããŒãã®æå šäœãéããªãããã«ããã«ã¯ãACLã®æ¬¡ã®ãããªããªãã¯ã«é Œãããšãã§ããŸãã
tcp host 2.2.2.2 any any establishedãèš±å¯ããŸãã
ãã®ãããªæ±ºå®ã®è©³çŽ°ã¯ã次ã®èšäºã®ããããã«ãããŸãã
4ïŒçŸä»£ã®äžçã«ã€ããŠèšãã°ããªããžã§ã¯ãã°ã«ãŒãïŒãªããžã§ã¯ãã°ã«ãŒãïŒãªã©ã®ããŒã«ãåé¿ããããšã¯ã§ããŸããã
ã¢ãã¬ã¹ãšããŒãã®æ°ãå¢ããèŠèŸŒã¿ã§ã3ã€ã®åäžã®ããŒãã§3ã€ã®ç¹å®ã®ã€ã³ã¿ãŒãããã¢ãã¬ã¹ãçºè¡ããACLãäœæããå¿ èŠããããšããŸãããããªããžã§ã¯ãã°ã«ãŒãã®ç¥èããªãå Žåã®å€èŠ³ïŒ
ip access-list extended TO-INTERNET
permit tcp host 172.16.6.66 any eq 80
permit tcp host 172.16.6.66 any eq 8080
permit tcp host 172.16.6.66 any eq 443
permit tcp host 172.16.6.67 any eq 80
permit tcp host 172.16.6.67ä»»æã®eq 8080
ã¯tcpãã¹ã172.16.6.68ãèš±å¯ããŸãä»»æã®eq
80ã¯
tcpãã¹ã172.16.6.68ãèš±å¯ããŸãä»»æã®eq 8080
ã¯tcpãã¹ã172.16.6.68ãèš±å¯ããŸãä»»æã®eq 443
ãã©ã¡ãŒã¿ã®æ°ãå¢ãããšããã®ãããªACLãç¶æããããšããŸããŸãé£ãããªããèšå®æã«ééããç¯ãããããªããŸãã
ãããããªããžã§ã¯ãã°ã«ãŒãã«ç®ãåãããšã次ã®åœ¢åŒã«ãªããŸãã
ãªããžã§ã¯ãã°ã«ãŒããµãŒãã¹INET-PORTSã®
説æäžéšã®ãã¹ãã«èš±å¯ãããããŒã
tcp eq www
tcp eq 8080
tcp eq 443
ãªããžã§ã¯ãã°ã«ãŒããããã¯ãŒã¯HOSTS-TO-INETã®
説æããã
ãã¹ãã®åç §ãèš±å¯ããããã¹ã172.16.6.66
ãã¹ã172.16.6.67
ãã¹ã172.16.6.68
ip access-listæ¡åŒµINET-OUT
èš±å¯ãªããžã§ã¯ãã°ã«ãŒãINET-PORTSãªããžã§ã¯ãã°ã«ãŒãHOSTS-TO-INET any
äžèŠè è¿«çã«èŠããŸãããèŠããšéåžžã«äŸ¿å©ã§ãã
4ïŒãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«éåžžã«åœ¹ç«ã€æ å ±ã¯ãshow ip access-listsïŒ ã³ãã³ãACLïŒ nameã®åºåããååŸã§ããŸããæå®ãããACLã®ã«ãŒã«ã®å®éã®ãªã¹ãã«å ããŠããã®ã³ãã³ãã¯åã«ãŒã«ã®äžèŽæ°ã衚瀺ããŸãã
msk-arbat-gw1ïŒsh ip access-lists nat-iâânet
æ¡åŒµIPã¢ã¯ã»ã¹ãªã¹ãnat-iâânet
permit tcp 172.16.3.0 0.0.0.255 host 192.0.2.2 eq www
permit ip 172.16.5.0 0.0.0.255 host 192.0.2.3
permit ip 172.16 .5.0 0.0.0.255ãã¹ã192.0.2.4
permit ip host 172.16.4.123 any
permit ip host 172.16.6.61 any
permit ip host 172.16.6.66 any ïŒ4 matchïŒesïŒïŒ
permit ip host 172.16.16.222 any
permit ip host 172.16.17.222ä»»æã®
èš±å¯IPãã¹ã172.16.24.222ä»»æã®
ã«ãŒã«ãã°ã®æåŸã«è¿œå ãããšãã³ã³ãœãŒã«ã§åäžèŽã«é¢ããã¡ãã»ãŒãžãåä¿¡ã§ããããã«ãªããŸããïŒåŸè ã¯PTã§ã¯æ©èœããŸããïŒ
NAT
ãããã¯ãŒã¯ã¢ãã¬ã¹å€æ-1994幎以æ¥çµ¶å¯Ÿã«å¿ èŠãªçµæžã®ã¡ã«ããºã ã圌ã«é¢ããå€ãã®ã»ãã·ã§ã³ãäžæãããããã±ãŒãžã倱ãããŸãã
ã»ãšãã©ã®å ŽåãããŒã«ã«ãããã¯ãŒã¯ãã€ã³ã¿ãŒãããã«æ¥ç¶ããå¿ èŠããããŸããå®éã«ã¯ãçè«çã«ã¯255 * 255 * 255 * 255 = 4,228,250,625ã®40åã®ã¢ãã¬ã¹ããããŸããããšãå°çäžã®ãã¹ãŠã®äœæ°ãã³ã³ãã¥ãŒã¿ãŒã1å°ããæã£ãŠããªããŠããã¢ãã¬ã¹ã¯ååã§ã¯ãããŸããããããŠãããã§ã¯ãã¢ã€ãã³ã¯ã€ã³ã¿ãŒãããã«æ¥ç¶ãããŠããŸãããè³¢ã人ã ã¯ã90幎代ååã«ãããå®çŸããäžæçãªè§£æ±ºçãšããŠãã¢ãã¬ã¹ã¹ããŒã¹ããããªãã¯ïŒçœïŒãšãã©ã€ããŒãïŒãã©ã€ããŒããã°ã¬ãŒïŒã«åããããšãææ¡ããŸããã
åŸè ã«ã¯3ã€ã®ç¯å²ãå«ãŸããŸãïŒ
10.0.0.0/8
172.16.0.0/12
192.168.0.0/16
ãããã¯ãã©ã€ããŒããããã¯ãŒã¯ã§èªç±ã«äœ¿çšã§ããŸãããããã£ãŠããã¡ããç¹°ãè¿ã䜿çšãããŸããäžææ§ãã©ããããïŒèª°ããªã¯ãšã¹ããåä¿¡ããWEBãµãŒããŒã«è¿ä¿¡ã¢ãã¬ã¹192.168.1.1ã§å¿çããŸããïŒãã¹ãã¬ã³ã ïŒTatneftäŒæ¥ã§ããïŒãããšãéšå±ã®DlinkïŒå€§ããªã€ã³ã¿ãŒãããã§ã¯ããã©ã€ããŒããããã¯ãŒã¯ã«ã€ããŠèª°ãç¥ããªã-ã«ãŒãã£ã³ã°ãããªãã
ãã®åŸãNATãç»å ŽããŸããæŠããŠãããã¯ãããã»ããã¢ããã§ãããããŸãã«èšã£ãŠãããã€ã¹äžã®ãã©ã€ããŒãã¢ãã¬ã¹ã¯åçŽã«ãã¯ã€ãã¢ãã¬ã¹ã«çœ®ãæããããŸããããã¯ããã±ãããWEBãµãŒããŒã«ç§»åãããšãã«ãã±ããã®åŸåã«è¡šç€ºãããŸããããããçœãã¢ãã¬ã¹ã¯éåžžã«ããã«ãŒãã£ã³ã°ãããŠããããã±ããã¯ç¢ºå®ã«æ©æŠããŠããããã€ã¹ã«æ»ããŸãã
ãããã次ã«äœããã¹ãããã©ããã£ãŠç解ããã®ã§ããããïŒããã«å¯ŸåŠããŸãã
NATã¿ã€ã
éç
ãã®å Žåã1ã€ã®å éšã¢ãã¬ã¹ã1ã€ã®å€éšã¢ãã¬ã¹ã«å€æãããŸããåæã«ãå€éšã¢ãã¬ã¹ã«å±ããã¹ãŠã®ãªã¯ãšã¹ãã¯å éšã«ãããŒããã£ã¹ããããŸãããã®ãã¹ãããã®çœãIPã¢ãã¬ã¹ã®ææè ã§ãããã®ããã§ãã
次ã®ã³ãã³ãã§æ§æãããŸãã
RouterïŒconfigïŒïŒip nat inside source static 172.16.6.5 198.51.100.2
äœãèµ·ãã£ãŠããïŒ
1ïŒããŒã172.16.6.5ã¯WEBãµãŒããŒãã¢ãã¬ã¹æå®ããŸããåä¿¡è ã®ã¢ãã¬ã¹ã192.0.2.2ãéä¿¡è ã172.16.6.5ã®IPãã±ãããéä¿¡ããŸãã
2ïŒäŒæ¥ãããã¯ãŒã¯ã§ã¯ããã±ããã¯ã²ãŒããŠã§ã€172.16.6.1ã«é ä¿¡ãããNATãæ§æãããŸã
3ïŒæ§æãããã³ãã³ãã«åŸã£ãŠãã«ãŒã¿ãŒã¯çŸåšã®IPããããŒãåé€ããæ°ããã¢ãã¬ã¹ã«å€æŽããŸããããã§ããã¯ã€ãã¢ãã¬ã¹198.51.100.2ã¯æ¢ã«éä¿¡è ã¢ãã¬ã¹ãšããŠè¡šç€ºãããŸãã
4ïŒã€ã³ã¿ãŒãããã§ã¯ãæŽæ°ãããããã±ãŒãžã¯ãµãŒããŒ192.0.2.2ã«å°éããŸãã
5ïŒåœŒã¯ãåçã198.51.100.2ã«éä¿¡ããå¿ èŠãããããšã確èªããå¿çIPãã±ãããæºåããŸããéä¿¡è ã®ã¢ãã¬ã¹ãšããŠãå®éã®ãµãŒããŒã¢ãã¬ã¹ã¯192.0.2.2ãå®å ã¢ãã¬ã¹ã¯198.51.100.2ã§ã
6ïŒãã±ããã¯ã€ã³ã¿ãŒããããçµç±ããŠæ»ã£ãŠããŸãããåãæ¹æ³ã§ãããšããäºå®ã§ã¯ãããŸããã
7ïŒããã³ã°ããã€ã¹ã§ã¯ãã¢ãã¬ã¹198.51.100.2ãžã®ãã¹ãŠã®èŠæ±ã172.16.6.5ã«ãªãã€ã¬ã¯ãããå¿ èŠãããããšã瀺ãããŠããŸããã«ãŒã¿ãŒã¯å éšã«é ãããTCPã»ã°ã¡ã³ããåã³é€å»ããæ°ããIPããããŒãèšå®ããŸãïŒéä¿¡è ã¢ãã¬ã¹ã¯å€æŽãããŸãããå®å ã¢ãã¬ã¹ã¯172.16.6.5ã§ãïŒã
8ïŒå éšãããã¯ãŒã¯ã§ã¯ããã±ããã¯ã€ãã·ãšãŒã¿ãŒã«è¿ãããŸããã€ãã·ãšãŒã¿ãŒã¯ãåœââå¢ã§ââ圌ã«èµ·ãã£ãå¥è·¡ãããç¥ããŸããã
ãããŠãããã¯ã¿ããªãšäžç·ã«ãªããŸãã
ããã«ãã€ã³ã¿ãŒãããããæ¥ç¶ãéå§ãããå Žåããã±ããã¯èªåçã«ããã³ã°ããã€ã¹ãééããŠå éšãã¹ãã«å°éããŸãã
ãã®ã¢ãããŒãã¯ããããã¯ãŒã¯å ã«å€éšããã®ãã«ã¢ã¯ã»ã¹ãå¿ èŠãªãµãŒããŒãããå Žåã«åœ¹ç«ã¡ãŸãããã¡ããã1ã€ã®ã¢ãã¬ã¹ãä»ããŠã€ã³ã¿ãŒãããäžã®300åã®ãã¹ãã解æŸããå Žåã¯ããã®ãªãã·ã§ã³ã䜿çšã§ããŸããããã®NATãªãã·ã§ã³ã¯ãçœãIPã¢ãã¬ã¹ã®ä¿åã«ã¯åœ¹ç«ã¡ãŸããããããã§ã䟿å©ã§ãã
ãã€ãããã¯
ãã¯ã€ãã¢ãã¬ã¹ã®ããŒã«ããããŸããããšãã°ããããã€ããŒã16åã®ã¢ãã¬ã¹ãæã€ãããã¯ãŒã¯198.51.100.0/28ãå²ãåœãŠãŸããããããã®2ã€ïŒæåãšæåŸïŒã¯ãããã¯ãŒã¯ã¢ãã¬ã¹ãšãããŒããã£ã¹ãã¢ãã¬ã¹ã§ãããã«ãŒãã£ã³ã°ã確å®ã«ããããã«ãããã«2ã€ã®ã¢ãã¬ã¹ãæ©åšã«å²ãåœãŠãããŸããNATã«æ®ãã®12åã®ã¢ãã¬ã¹ã䜿çšããããããéããŠãŠãŒã¶ãŒã解æŸã§ããŸãã
ç¶æ³ã¯éçNATãšäŒŒãŠããŸã-1ã€ã®ãã©ã€ããŒãã¢ãã¬ã¹ã1ã€ã®å€éšã«å€æãããŸã-ããããå€éšã¯æ確ã«ä¿®æ£ãããŠããŸããããæå®ãããç¯å²ããåçã«éžæãããŸãã
次ã®ããã«æ§æãããŸãã
ã«ãŒã¿ãŒïŒconfigïŒ#ip nat pool lol_pool 198.51.100.3 198.51.103.14
ãã€ãã£ã³ã°ã®ã¢ãã¬ã¹ãéžæããããããªãã¯ã¢ãã¬ã¹ã®ããŒã«ïŒç¯å²ïŒãèšå®ããŸã
RouterïŒconfigïŒïŒaccess-list 100 permit ip 172.16.6.0 0.0.0.255 any
éä¿¡å ã¢ãã¬ã¹ã172.16.6.xã§ãããã¹ãŠã®ãã±ãããæž¡ãã¢ã¯ã»ã¹ãªã¹ããèšå®ããŸããxã¯0ã255ã§ãã
ã«ãŒã¿ãŒïŒconfigïŒ#ip nat inside source list 100 pool lol_pool
ãã®ã³ãã³ãã䜿çšããŠãäœæãããACLãšããŒã«ããããã³ã°ããŸãã
ãã®ãªãã·ã§ã³ãæ®éçã§ã¯ãããŸããã300ã®å€éšã¢ãã¬ã¹ããªãå Žåã300人ã®ãŠãŒã¶ãŒãã€ã³ã¿ãŒãããã«è§£æŸããããšãã§ããŸãããçœãã¢ãã¬ã¹ã䜿ãæãããããšã誰ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããªããªããŸããåæã«ããã§ã«èªåèªèº«ã§å€éšã¢ãã¬ã¹ãååŸã§ãããŠãŒã¶ãŒãåäœããŸããclear ip nat translation ã³ãã³ãã¯ãçŸåšã®ãã¹ãŠã®ãããŒããã£ã¹ããããããããå€éšã¢ãã¬ã¹ã解æŸããã®ã«åœ¹ç«ã¡ãŸã*å€éšã¢ãã¬ã¹
ãåçã«å²ãåœãŠãããšã«å ããŠããã®åçNATã¯ãåå¥ã®ããŒããã©ã¯ãŒãã£ã³ã°èšå®ããªããšãããŒã«ã¢ãã¬ã¹ã®1ã€ã«å€éšæ¥ç¶ã§ããªããªããšããç¹ã§éçãšç°ãªããŸãã
å€å¯Ÿäž
次ã®ã¿ã€ãã«ã¯ããã€ãã®ååããããŸããNATãªãŒããŒããŒããããŒãã¢ãã¬ã¹å€æïŒPATïŒãIPãã¹ã«ã¬ãŒããå€å¯Ÿ1 NATã
å§ã¯ããèªäœãç©èªã£ãŠããŸã-1ã€ã®å€éšã¢ãã¬ã¹ãä»ããŠãå€ãã®å人ãäžçã«å ¥ããŸããããã«ãããå€éšã¢ãã¬ã¹ã®äžè¶³ã®åé¡ã解決ãã誰ããäžçã«åºãããããã«ããããšãã§ããŸãã
ããã§ã¯ããããã©ã®ããã«æ©èœãããã«ã€ããŠèª¬æããå¿ èŠããããŸãã2ã€ã®ãã©ã€ããŒãã¢ãã¬ã¹ã1ã€ã«å€æããæ¹æ³ã¯æ³åã§ããŸãããã€ã³ã¿ãŒãããããè¿ããããã±ããããã®ã¢ãã¬ã¹ã«è»¢éããå¿ èŠããããŠãŒã¶ãŒãã«ãŒã¿ãŒã¯ã©ã®ããã«ç解ããŸããïŒ
ãã¹ãŠãéåžžã«åçŽã§ãã
å éšãããã¯ãŒã¯ããã®2ã€ã®ãã¹ãããããã±ãããããã³ã°ããã€ã¹ã«å°éãããšããŸããäž¡æ¹ãšããWebãµãŒããŒ192.0.2.2ãžã®ãªã¯ãšã¹ãã䜿çšããŸãã
ãã¹ãããã®ããŒã¿ã¯æ¬¡ã®ããã«ãªããŸãã
éä¿¡è ã¢ãã¬ã¹ | éä¿¡è ããŒã | åå人ã®äœæ | åä¿¡è ããŒã |
172.16.6.5 | 23761 | 192.0.2.2 | 80 |
172.16.4.5 | 39800 | 192.0.2.2 | 80 |
ã«ãŒã¿ãŒã¯ãæåã®ãã¹ãããIPãã±ãããæ€åºããããããTCPã»ã°ã¡ã³ããæœåºããŠå°å·ããæ¥ç¶ã確ç«ãããŠããããŒããèŠã€ããŸããããã«ã¯ãå éšãããã¯ãŒã¯ããã®ã¢ãã¬ã¹ãå€æŽãããå€éšã¢ãã¬ã¹198.51.100.2ããããŸãã
ããããã圌ã¯ç¡æã®ããŒããäŸãã°11874ãéžæããŸãããããŠã圌ã¯æ¬¡ã«äœãããŸããïŒåœŒã¯ãã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ããŒã¿ãæ°ããTCPã»ã°ã¡ã³ãã«ããã¯ããŸããå®å ããŒããšããŠãŸã 80ãæ®ã£ãŠããïŒWEBãµãŒããŒã¯æ¥ç¶ãåŸ æ©ããŠããŸãïŒãéä¿¡è ããŒãã¯23761ãã11874ã«å€ãããŸãããã®TCPã»ã°ã¡ã³ãã¯æ°ããIPã«ã«ãã»ã«åãããŸãéä¿¡è ã®IPã¢ãã¬ã¹ã172.16.6.5ãã198.51.100.2ã«å€æŽããããã±ããã
2çªç®ã®ãã¹ãããã®ãã±ããã§ãåãããšãèµ·ãããŸããããšãã°ã11875ãªã©ã次ã®ç©ºãããŒãã®ã¿ãéžæãããŸããã空ããã¯ãä»ã®ãã®ãããªæ¥ç¶ã§ãŸã å æãããŠããªãããšãæå³ããŸãã
ã€ã³ã¿ãŒãããã«éä¿¡ãããããŒã¿ã¯ããã®ããã«ãªããŸãã
éä¿¡è ã¢ãã¬ã¹ | éä¿¡è ããŒã | åå人ã®äœæ | åä¿¡è ããŒã |
198.51.100.2 | 11874 | 192.0.2.2 | 80 |
198.51.100.2 | 11875 | 192.0.2.2 | 80 |
NATããŒãã«ã«ã圌ã¯éä¿¡è ãšåä¿¡è ã®ããŒã¿ãæžã蟌ã¿ãŸã
ããŒã«ã«éä¿¡è ã¢ãã¬ã¹ | éä¿¡è ã®ããŒã«ã«ããŒã | ã°ããŒãã«éä¿¡è ã¢ãã¬ã¹ | éä¿¡è ã°ããŒãã«ããŒã | åå人ã®äœæ | åä¿¡è ããŒã |
172.16.6.5 | 23761 | 198.51.100.2 | 11874 | 192.0.2.2 | 80 |
172.16.4.5 | 39800 | 198.51.100.2 | 11875 | 192.0.2.2 | 80 |
WEBãµãŒããŒã®å Žåããããã¯2ã€ã®å®å šã«ç°ãªãèŠæ±ã§ãããããããåå¥ã«åŠçããå¿ èŠããããŸãããã®åŸã圌ã¯æ¬¡ã®ãããªåçãéä¿¡ããŸãã
éä¿¡è ã¢ãã¬ã¹ | éä¿¡è ããŒã | åå人ã®äœæ | åä¿¡è ããŒã |
192.0.2.2 | 80 | 198.51.100.2 | 11874 |
192.0.2.2 | 80 | 198.51.100.2 | 11875 |
ãããã®ãã±ããã®1ã€ãã«ãŒã¿ãŒã«å°éãããšããã®ãã±ããã®ããŒã¿ãšNATããŒãã«ã®ãšã³ããªãäžèŽããŸããäžèŽãèŠã€ãããšãéã®æé ãçºçããŸãããã±ãããšTCPã»ã°ã¡ã³ãã¯ãå®å ãšããŠã®ã¿å ã®ãã©ã¡ãŒã¿ãŒãšãšãã«è¿ãããŸãã
éä¿¡è ã¢ãã¬ã¹ | éä¿¡è ããŒã | åå人ã®äœæ | åä¿¡è ããŒã |
192.0.2.2 | 80 | 172.16.6.5 | 23761 |
192.0.2.2 | 80 | 172.16.4.5 | 39800 |
ãããŠä»ããã±ããã¯å éšãããã¯ãŒã¯ãä»ããŠéå§ã³ã³ãã¥ãŒã¿ãŒã«é ä¿¡ãããŸããéå§ã³ã³ãã¥ãŒã¿ãŒã¯ãããŒã¿ãå¢çã§å³ããåŠçãããŠããããšãèªèããŠããŸããã
ç°è°ç³ãç«ãŠã¯ããããå¥ã®ã€ãªããã§ããã€ãŸããWEBããŒãžãéãããšããŸãã-ããã¯ããŒã80ã䜿çšããHTTPãããã³ã«ã§ãããããè¡ãã«ã¯ãã³ã³ãã¥ãŒã¿ãŒããªã¢ãŒããµãŒããŒãšã®TCPã»ãã·ã§ã³ã確ç«ããå¿ èŠããããŸãããã®ãããªã»ãã·ã§ã³ïŒTCPãŸãã¯UDPïŒã¯ã2ã€ã®ãœã±ããã§å®çŸ©ãããŸãïŒããŒã«ã«IPã¢ãã¬ã¹ïŒããŒã«ã«ããŒããšãªã¢ãŒãIPã¢ãã¬ã¹ïŒãªã¢ãŒãããŒããéåžžã®ç¶æ³ã§ã¯ãã³ã³ãã¥ãŒã¿ãŒãµãŒããŒæ¥ç¶ã1ã€ç¢ºç«ããŸãããNATæ¥ç¶ã®å Žåã¯ãã«ãŒã¿ãŒãµãŒããŒãšã³ã³ãã¥ãŒã¿ãŒãã³ã³ãã¥ãŒã¿ãŒãµãŒããŒã»ãã·ã§ã³ãæã£ãŠãããšèãã2ã€ã®æ¥ç¶ããããŸãã
æ§æã¯ãããã«ç°ãªããŸãïŒãªãŒããŒããŒããšããèšèãè¿œå ãããŠããŸãïŒ
RouterïŒconfigïŒïŒaccess-list 101 permit 172.16.4.0 0.0.0.255
RouterïŒconfigïŒ#ip nat inside source list 101 interface fa0 / 1 overload
åæã«ããã¡ãããã¢ãã¬ã¹ããŒã«ãæ§æããããšãã§ããŸãã
RouterïŒconfigïŒ#ip nat pool lol_pool 198.51.100.2 198.51.103.14
RouterïŒconfigïŒïŒaccess-list 100 permit 172.16.6.0 0.0.0.255
RouterïŒconfigïŒ#ip nat inside source list 100 pool lol_pool overload
ããŒã転é
ãã以å€ã®å Žåã圌ãã¯ããå€ãã®ããŒã転éãŸãã¯ãããã³ã°ãèšããŸãã
NATã«ã€ããŠè©±ãå§ãããšãã1察1ã®å€æãè¡ãããå€éšããã®èŠæ±ã¯ãã¹ãŠå éšãã¹ãã«èªåçã«ãªãã€ã¬ã¯ããããŸããããããã£ãŠããµãŒããŒãã€ã³ã¿ãŒãããäžã«é 眮ããããšãå¯èœã§ãã
ããããããªãããã®ãããªæ©äŒãæã£ãŠããªãå Žå-ããªãã¯çœãã¢ãã¬ã¹ã«å¶éãããŠããããŸãã¯ããŒãã®æå šäœã§ãããå ¬éããããªãå Žåãç§ã¯äœããã¹ãã§ããïŒ
ç¹å®ã®ãã¯ã€ãã¢ãã¬ã¹ããã³ã«ãŒã¿ãŒäžã®ç¹å®ã®ããŒãã«å°çãããã¹ãŠã®èŠæ±ããç®çã®å éšã¢ãã¬ã¹ã®ç®çã®ããŒãã«ãªãã€ã¬ã¯ãããããã«æå®ã§ããŸãã
RouterïŒconfigïŒ#ip nat inside source static tcp 172.16.0.2 80 198.51.100.2 80æ¡åŒµå¯èœ
ãã®ã³ãã³ãã䜿çšãããšãã€ã³ã¿ãŒãããããããŒã80ã®ã¢ãã¬ã¹198.51.100.2ã«éä¿¡ãããTCPèŠæ±ã¯ãåã80çªç®ã®ããŒãã®å éšã¢ãã¬ã¹172.16.0.2ã«ãªãã€ã¬ã¯ããããŸãããã¡ãããUDPã転éããŠãããããŒãããå¥ã®ããŒãã«ãªãã€ã¬ã¯ãããããšãã§ããŸããããã¯ãããšãã°ãå€éšRDPã¢ã¯ã»ã¹ãå¿ èŠãšããã³ã³ãã¥ãŒã¿ãŒã2å°ããå Žåã«äŸ¿å©ã§ããRDPã¯ããŒã3389ã䜿çšããŸããåãããŒããç°ãªããã¹ãã«è»¢éããããšã¯ã§ããŸããïŒåãå€éšã¢ãã¬ã¹ã䜿çšããŠããå ŽåïŒããããã£ãŠããããè¡ãããšãã§ããŸãã
RouterïŒconfigïŒïŒip nat inside source static tcp 172.16.6.61 3389 198.51.100.2 3389
RouterïŒconfigïŒïŒip nat inside source static tcp 172.16.6.66 3389 198.51.100.2 3398
次ã«ãã³ã³ãã¥ãŒã¿ãŒ172.16.6.61ã«ã¢ã¯ã»ã¹ããã«ã¯ãããŒã198.51.100.2lla389ãããã³172.16.6.66-198.51.100.2lla398ã§RDPã»ãã·ã§ã³ãéå§ããŸããã«ãŒã¿ãŒèªäœã¯ãå¿ èŠã«å¿ããŠãã¹ãŠãåæ£ããŸãã
ã¡ãªã¿ã«ããã®ã³ãã³ãã¯æåã®ç¹å¥ãªã±ãŒã¹ã§ãïŒip nat inside source static 172.16.6.66 198.51.100.2ããã®å Žåã«ã®ã¿ããã¹ãŠã®ãã©ãã£ãã¯ãããã³ãã®äŸã§ã¯ç¹å®ã®TCPãããã³ã«ããŒãã®è»¢éã«ã€ããŠèª¬æããŠããŸãã
ãããäžè¬çãªNATã®æ©èœã§ãããã®æ©èœãé·æ/çæã«ã€ããŠå€ãã®èšäºãæžãããŠããŸããããããã¯æ³šç®ã«å€ããŸããã
NATã®åŒ±ç¹ãšåŒ·ã¿
+
-ãŸãã NATã䜿çšãããšããããªãã¯IPã¢ãã¬ã¹ãä¿åã§ããŸããå®éã«ããã®ããã«åœŒã¯äœæãããŸããã 1ã€ã®ã¢ãã¬ã¹ãéããŠãçè«çã«ã¯65,000ãè¶ ããã°ã¬ãŒã¢ãã¬ã¹ïŒããŒãã®æ°ïŒãçºè¡ã§ããŸãã
-第äºã«ãPATãšãã€ãããã¯NATã¯ããçšåºŠããã¡ã€ã¢ãŠã©ãŒã«ã§ãããå€éšæ¥ç¶ãç¬èªã®ãã¡ã€ã¢ãŠã©ãŒã«ãšãŠã€ã«ã¹å¯Ÿçãæããªããšã³ãã³ã³ãã¥ãŒã¿ãŒã«å°éããããšãé²ããŸããå®éã«ã¯ãäºæããªãããŸãã¯èš±å¯ãããŠããªãããã€ã¹ã®å€éšãããã±ãããå°çããå Žåãåã«ç Žæ£ãããŸãã
ãã±ãããã¹ãããããŠåŠçããã«ã¯ã次ã®æ¡ä»¶ãæºãããŠããå¿ èŠããããŸã
ã1ïŒNATããŒãã«ã«ã¯ããã±ããå ã®éä¿¡è ã¢ãã¬ã¹ãšããŠç€ºããããã®å€éšã¢ãã¬ã¹ã®ãšã³ããªãå¿ èŠã§ãã
ãããŠ
2ïŒãã±ããå ã®éä¿¡è ããŒãã¯ããšã³ããªå ã®ãã®çœãã¢ãã¬ã¹ã®ããŒããšäžèŽããå¿ èŠããããŸã
ãããŠ
3ïŒãã±ããã®å®å ããŒãã¯ããšã³ããªã®ããŒããšäžèŽããŸãã
ãŸãã¯
ããŒã転éãæ§æãããŸãã
ãã ããNATããã¡ã€ã¢ãŠã©ãŒã«ãšèŠãªãå¿ èŠã¯ãããŸãããè¿œå ã®ãã³ã«ãããŸããã
-第äžã«ãNATã¯ãããã¯ãŒã¯ã®å éšæ§é ãpr玢奜ããªç®ããé ããŸã-å€éšããã«ãŒãããã¬ãŒã¹ãããšããã©ãã³ã°ããã€ã¹ä»¥å€ã«äœã衚瀺ãããŸããã
-
NATã«ã¯çæããããŸãã æãå ·äœçãªãã®ã¯ããããã次ã®ãšããã§ãã
-äžéšã®ãããã³ã«ã¯ãæŸèæãªãã§ã¯NATãä»ããŠåäœã§ããŸããã ããšãã°ãFTPãŸãã¯ãã³ããªã³ã°ãããã³ã«ïŒã©ãã§FTPãã»ããã¢ããããã ãã§ããã«ãããããããå®éã«ã¯ãããã«ããå€ãã®åé¡ãçºçããå¯èœæ§ããããŸãïŒ
-å¥ã®åé¡ã¯ã1ã€ã®ã¢ãã¬ã¹ãã1ã€ã®ãµãŒããŒãžã®èŠæ±ãå€æ°ããããšã§ãã Rapidshareã«è¡ã£ããšãã«å€ãã®äººããããç®æããŸãããã圌ã¯ããªãã®IPãããã§ã«æ¥ç¶ãããã圌ã¯åãã€ããŠãããç¬ããããŠããªãã®é£äººã¯ãã§ã«åžã蟌ãã§ãããšæããŸãã åãçç±ã§ããµãŒããŒãç»é²ãæåŠããããšãã«ICQã«åé¡ããããŸããã
-çŸåšãåé¡ã¯ããŸãé¢ä¿ãããŸããïŒããã»ããµãšRAMã®è² è·ã å°èŠæš¡ãªãã£ã¹ã§ã¯ãåçŽãªã«ãŒãã£ã³ã°ïŒIPããããŒãèŠãã ãã§ãªããåé€ãTCPããããŒã®åé€ãããŒãã«ãžã®æ°ããããããŒã®è¿œå ãå¿ èŠïŒã«æ¯ã¹ãŠäœæ¥éãéåžžã«å€§ãããããããã«åé¡ããããŸãã
ç§ã¯ãã®ãããªç¶æ³ã«åºããããŸããã
èãããã解決çã®1ã€ã¯ãNATæ©èœãå¥ã®PCãŸãã¯Cisco ASAãªã©ã®å°çšããã€ã¹ã«è»¢éããããšã§ãã
3ã4ã®BGPãã«ãã¥ãŒãããŒãªã³ã°ããã«ãŒã¿ãŒãæã€å€§èŠæš¡ãªãã¬ãŒã€ãŒã®å Žåãããã¯åé¡ã§ã¯ãããŸããã
ä»ã«äœãç¥ãå¿ èŠããããŸããïŒ
-NATã¯ãäž»ã«ãã©ã€ããŒãã¢ãã¬ã¹ãæã€ãã¹ããžã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæäŸããããã«äœ¿çšãããŸãã ããããå¥ã®ã¢ããªã±ãŒã·ã§ã³ããããŸã-亀差ããã¢ãã¬ã¹ã¹ããŒã¹ãæã€2ã€ã®ãã©ã€ããŒããããã¯ãŒã¯éã®æ¥ç¶ã
ããšãã°ãããªãã®äŒç€Ÿã¯ã¢ã¯ãã¥ãã³ã¹ã¯ã§æ¯åºãè³Œå ¥ããŸãã ã¢ãã¬ã¹æå®ã¯10.0.0.0-10.1.255.255ã§ã10.1.1.0-10.1.10.255ã§ãã ç¯å²ã¯æããã«äº€å·®ããŸããåãã¢ãã¬ã¹ãã¢ã¯ãã¥ãã³ã¹ã¯ãšæ¬éšã«ããå¯èœæ§ããããããã«ãŒãã£ã³ã°ãèšå®ããããšã¯ã§ããŸããã
ãã®å ŽåãNATã¯ãžã£ã³ã¯ã·ã§ã³ã§æ§æãããŸãã ã°ã¬ãŒã®ã¢ãã¬ã¹ã¯æž¬å®ããªããããããšãã°10.2.1.0-10.2.10.255ã®ç¯å²ãéžæããŠã1察1ã®å€æãå®è¡ã§ããŸãã
10.1.1.1-10.2.1.1
10.1.1.2-10.2.1.2
...
10.1.10.255-10.2.10.255
-倧èŠæš¡ãªå€§äººã®ããã¡ãã§ã¯ãNATã¯å¥ã®ããŒãã«å®è£ ã§ããŸãïŒå€ãã®å Žåãå®è£ ãããŠããŸãïŒã å察ã«ããªãã£ã¹è ºã«ã¯ãã»ãšãã©åžžã«ãããŸãã
-IPv6ã®æ®åã«ãããNATã®å¿ èŠæ§ã¯ãªããªããŸãã ãã§ã«ã倧èŠæš¡ãªé¡§å®¢ã¯NAT64æ©èœã«èå³ãæã¡å§ããŠããŸããããã¯ãIPv4çµç±ã§äžçã«ã¢ã¯ã»ã¹ã§ããå éšãããã¯ãŒã¯ããã§ã«IPv6äžã«ãããšãã§ãã
-ãã¡ãããããã¯NATã®è¡šé¢çãªå€èŠ³ã«ããããç¬åŠã¯ããªããdrããããªãããã«åœ¹ç«ã€ãã¥ã¢ã³ã¹ã®æµ·ããŸã ãããŸãã
NATãã©ã¯ãã£ã¹
çŸå®ã¯ç§ãã¡ã«äœãå¿ èŠãšããŸããïŒ
1ïŒå¶åŸ¡ãããã¯ãŒã¯ã«ã¯ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ããŸã£ãããããŸãã
2ïŒVETãããã¯ãŒã¯ã®ãã¹ãã¯ãLinkmeup.ruãªã©ã®å°çšãµã€ãã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã
3ïŒäŒèšã®çŽ æµãªå¥³æ§ã¯ãã¯ã©ã€ã¢ã³ãéè¡ã®äžçã«çªãéããå¿ èŠãããã
4ïŒFEOã¯ããã¡ã€ãã³ã·ã£ã«ãã£ã¬ã¯ã¿ãŒãé€ããã©ãã«ããªãªãŒã¹ããŸãã
5ïŒãã®ä»ã®ãããã¯ãŒã¯ãã³ã³ãã¥ãŒã¿ãŒãããã³ç®¡çè ã®ã³ã³ãã¥ãŒã¿ãŒ-ã€ã³ã¿ãŒããããžã®ãã«ã¢ã¯ã»ã¹ãèš±å¯ããŸãã ä»ã®ãã¹ãŠã¯æžé¢ã«ããèŠæ±ã«å¿ããŠéãããšãã§ããŸãã
6ïŒãµã³ã¯ãããã«ãã«ã¯ãšã±ã¡ããŽã©ã®æãå¿ããªãã§ãã ããã ç°¡åã«ããããã«ããããã®ãµããããããã®enikiesã«å¯Ÿãããã«ã¢ã¯ã»ã¹ãæ§æããŸãã
7ïŒãµãŒããŒã§å¥ã®æã ãããã«ã€ããŠã¯ãããŒã転éãæ§æããŸãã å¿ èŠãªãã®ïŒ
aïŒWEBãµãŒããŒã¯ããŒã80ã§ã¢ã¯ã»ã¹å¯èœã§ãªããã°ãªããŸãã
bïŒ25æ¥ãš110æ¥ã®ã¡ãŒã«ãµãŒããŒ
cïŒãã¡ã€ã«ãµãŒããŒã¯FTPçµç±ã§äžçäžããã¢ã¯ã»ã¹ã§ããŸãã
8ïŒç®¡çè ããã³åœç€Ÿã®ã³ã³ãã¥ãŒã¿ãŒã¯ãRââDPãä»ããŠã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ããå¿ èŠããããŸãã å®éãããã¯ééã£ãæ¹æ³ã§ãããã§ã«ããŒã«ã«ãããã¯ãŒã¯äžã«ããå Žåããªã¢ãŒãæ¥ç¶ã«VPNæ¥ç¶ã䜿çšããRDPã䜿çšããå¿ èŠããããŸãããããã¯å¥ã®ãŸã£ããç°ãªãèšäºã®ãããã¯ã§ãã
æåã«ããã¹ããµã€ããæºåããŸãã
ã€ã³ã¿ãŒãããæ¥ç¶ã¯ããããã€ããŒãæäŸããæ¢åã®ãªã³ã¯ãä»ããŠæŽçãããŸãã
圌ã¯ãããã€ããŒã®ãããã¯ãŒã¯ã«è¡ããŸãã ãã®ã¯ã©ãŠãå ã®ãã¹ãŠã¯æœè±¡çãªãããã¯ãŒã¯ã§ãããå®éã«ã¯æ°åã®ã«ãŒã¿ãŒãšæ°çŸã®ã¹ã€ããã§æ§æãããããšãæãåºããŠãã ããã ãã ãã管çãšäºæž¬ãå¯èœãªãã®ãå¿ èŠãªã®ã§ãããã«å¥ã®ã«ãŒã¿ãŒãé 眮ããŸãã äžæ¹ã§ã¯ãã€ã³ã¿ãŒãããäžã®ããäžæ¹ã®ãµãŒããŒäžã®ã¹ã€ããããã®ãªã³ã¯ããããŸãã
次ã®ãµãŒããŒãå¿ èŠã§ãã
1.äŒèšå£«åãã®2ã€ã®ã¯ã©ã€ã¢ã³ããã³ã¯ïŒsperbank.ruãmmm-bank.ruïŒ
2. PTOshnikovã®Linkmeup.ru
3. YandexïŒyandex.ruïŒ
ãã®ãããªæ¥ç¶ã®å Žåãå¥ã®VLANãmsk-arbat-gw1ã«äžããŸãã ãã¡ããã圌ã®æ°ã¯ãããã€ããŒãšäžèŽããŠããŸãã VLAN 6ã«ããŸããã
ãããã€ããŒã198.51.100.0/28ã®ãµãããããæäŸãããšããŸã ã æåã®2ã€ã®ã¢ãã¬ã¹ã¯ãªã³ã¯ã®æ§æã«äœ¿çšããïŒ198.51.100.1ããã³198.51.100.2ïŒãæ®ãã®ã¢ãã¬ã¹ã¯NATã®ããŒã«ãšããŠäœ¿çšããŸãã ãã ããããŒã«ã«ã¢ãã¬ã¹198.51.100.2ã䜿çšããããšãå®å šã«æ°ã«ãã人ã¯ããŸããã ããã§ã¯ããã£ãŠã¿ãŸããã ïŒ poolïŒ198.51.100.2-198.51.100.14
ç°¡åã«ããããã«ãå ¬éãµãŒããŒãåããµããããäžã«ãããšä»®å®ããŸãã
192.0.2.0/24
æ¢ã«å®å šã«èªèããŠãããªã³ã¯ãšã¢ãã¬ã¹ã®æ§ææ¹æ³ã
ãããã€ããŒã®ãããã¯ãŒã¯ã«ã¯ã«ãŒã¿ãŒã1ã€ãããªãããã¹ãŠã®ãããã¯ãŒã¯ãããã«çŽæ¥æ¥ç¶ãããŠãããããã«ãŒãã£ã³ã°ãæ§æããå¿ èŠã¯ãããŸããã
ãã ããmsk-arbat-gw1ã¯ã€ã³ã¿ãŒããããžã®ãã±ããã®éä¿¡å ãèªèããŠããå¿ èŠããããããããã©ã«ãã«ãŒããå¿ èŠã§ãã
msk-arbat-gw1ïŒconfigïŒïŒip route 0.0.0.0 0.0.0.0 198.51.100.1
é çªã«
ãŸããã¢ãã¬ã¹ããŒã«ãæ§æããŸã
msk-arbat-gw1ïŒconfigïŒïŒip nat pool main_pool 198.51.100.2 198.51.100.14 netmask 255.255.255.240
次ã«ãACLãåéããŸãã
msk-arbat-gw1ïŒconfigïŒïŒip access-list extended nat-iâânet
1ïŒç®¡çãããã¯ãŒã¯
ã€ã³ã¿ãŒãããã«ãŸã£ããã¢ã¯ã»ã¹ã§ããªã
å®äº
2ïŒVETãããã¯ãŒã¯ããã®ãã¹ã
Linkmeup.ruãªã©ã®å°éãµã€ãã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒèš±å¯TCP 172.16.3.0 0.0.0.255ãã¹ã192.0.2.2 eq 80
3ïŒäŒèš
äž¡æ¹ã®ãµãŒããŒäžã®ãã¹ãŠã®ãã¹ããžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸã
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒpermit ip 172.16.5.0 0.0.0.255 host 192.0.2.3
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒpermit ip 172.16.5.0 0.0.0.255 host 192.0.2.4
4ïŒFEO
CFOã®ã¿ã«èš±å¯ãäžããŸã-ããã¯1ã€ã®ãã¹ãã«ãããŸããã
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.4.123 any
5ïŒãã®ä»
ãã«ã¢ã¯ã»ã¹å¯èœãªã³ã³ãã¥ãŒã¿ãŒ
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.6.61 any
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒIPãã¹ã172.16.6.66ãèš±å¯ããany
6ïŒãµã³ã¯ãããã«ãã«ã¯ãšã±ã¡ããŽã©ã®æ¯åº
ãšããã¹ã®ã¢ãã¬ã¹ãåãã«ããŸãïŒ172.16.x.222
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒIPãã¹ã172.16.16.222ãèš±å¯ããany
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.17.222 any
msk-arbat-gw1ïŒconfig-ext-naclïŒïŒallow ip host 172.16.24.222 any
ããã¯ãACLãçŸåšã©ã®ããã«èŠãããã§ãïŒ
ip access-list extended nat-iâânet
PTOã®çºèš
èš±å¯tcp 172.16.3.0 0.0.0.255ãã¹ã192.0.2.2 eq www
説æäŒèš
èš±å¯IP 172.16.5.0 0.0.0.255ãã¹ã192.0.2.3
IP 172.16.5.0 0.0.0.255ãã¹ã192.0.2.4ãèš±å¯
çºèšFEO
IPãã¹ã172.16.4.123ãèš±å¯
çºèšIAM
IPãã¹ã172.16.6.61ãèš±å¯
åèADMIN
IPãã¹ã172.16.6.66ãèš±å¯
泚éSPB_VSL_ISLAND
IPãã¹ã172.16.16.222ãèš±å¯
åèSPB_OZERKI
IPãã¹ã172.16.17.222ãèš±å¯
åèKMR
IPãã¹ã172.16.24.222ãèš±å¯
以äžãéå§ããŸãã
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source list nat-iâânet pool main_pool overload
ããããã€ã³ã¿ãŒãã§ãŒã¹ãæ§æããªããã°å¹žçŠãå®å šã«ããããšã¯ã§ããŸããã
å€éšã€ã³ã¿ãŒãã§ã€ã¹ã§ã ip nat outsideã³ãã³ããäžããå¿ èŠããããŸã
å éšïŒ ip nat inside
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.101
msk-arbat-gw1ïŒconfig-subifïŒïŒip nat inside
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.102
msk-arbat-gw1ïŒconfig-subifïŒïŒip nat inside
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.103
msk-arbat-gw1ïŒconfig-subifïŒïŒip nat inside
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.104
msk-arbat-gw1ïŒconfig-subifïŒïŒip nat inside
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 1.6
msk-arbat-gw1ïŒconfig-subifïŒïŒip nat outside
ããã«ãããã«ãŒã¿ãŒã¯ãã±ããã®åŠçãåŸ æ©ããå ŽæãšãåŸã§éä¿¡ããå Žæãææ¡ã§ããŸãã
ã€ã³ã¿ãŒãããäžã®ãµãŒããŒããã¡ã€ã³åã§ã¢ã¯ã»ã¹ã§ããããã«ããã«ã¯ããããã¯ãŒã¯äžã«DNSãµãŒããŒãååŸããããšããå§ãããŸãã
åœç¶ãã¢ã¯ã»ã¹ããã§ãã¯ããããã€ã¹ã«ç»é²ããå¿ èŠããããŸãã
ã·ã§ãŒã¯ç¶ããªããã°ãªããŸããïŒ
管çã³ã³ãã¥ãŒã¿ãŒããããã¹ãŠãå©çšå¯èœã§ãïŒ
VETãããã¯ãŒã¯ããã¯ãããŒã80ïŒHTTPïŒãä»ããŠlinkmeup.ru Webãµã€ãã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã
FEOãããã¯ãŒã¯ã§ã¯ã4.123ã®ã¿ãäžçã«å ¥ããŸãïŒè²¡åãã£ã¬ã¯ã¿ãŒïŒ
äŒèšã§ã¯ãã¯ã©ã€ã¢ã³ããã³ã¯ãµã€ãã®ã¿ãæ©èœããŸãã ãã ããIPãããã³ã«ã«ã¯å®å šã«èš±å¯ãäžããããŠãããããpingãå¯èœã§ãã
7ïŒãµãŒããŒ
ããã§ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ããããã«ããŒã転éãæ§æããå¿ èŠããããŸãã
aïŒWebãµãŒããŒ
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.0.2 80 198.51.100.2 80
ããšãã°ãã¢ãã¬ã¹192.0.2.7ã®ãã¹ãPCãããããå®è¡ã§ããŸãã
ãµãŒããŒã®ãããã¯ãŒã¯ã§ã¯ãmsk-arbat-gw1ã«èšå®ãããã€ã³ã¿ãŒãã§ã€ã¹ããªããããäœãæ©èœããŸããã
msk-arbat-gw1ïŒconfigïŒïŒint fa0 / 0.3
msk-arbat-gw1ïŒconfig-subifïŒïŒip nat inside
ãããŠä»ïŒ
bïŒãã¡ã€ã«ãµãŒããŒ
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.0.3 20 198.51.100.3 20
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.0.3 21 198.51.100.3 21
ãã®ç®çã®ããã«ãACL Servers-outã§ããã¹ãŠã®ãŠãŒã¶ãŒã®ããã«20-21çªç®ã®ããŒããéããŸãã
cïŒã¡ãŒã«ãµãŒããŒ
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.0.4 25 198.51.100.4 25
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.0.4 110 198.51.100.4 110
ãã§ãã¯ãé£ãããããŸããã æ瀺ã«åŸã£ãŠãã ããïŒ
ãŸããã¡ãŒã«ãµãŒããŒãæ§æããŸãã ãã¡ã€ã³ãæå®ãã2人ã®ãŠãŒã¶ãŒãäœæããŸãã
次ã«ããã¡ã€ã³ãDNSã«è¿œå ããŸãã ãã®æé ã¯ãªãã·ã§ã³ã§ã-IPçµç±ã§ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããŸããããªãã§ããïŒ
ãããã¯ãŒã¯ããã³ã³ãã¥ãŒã¿ãŒãæ§æããŸãã
å€ããïŒ
ç§ãã¡ã¯æçŽãæºåããŠããŸãïŒ
ããŒã«ã«ãã¹ãã§ã[åä¿¡]ãã¯ãªãã¯ããŸãã
8ïŒç®¡çã³ã³ãã¥ãŒã¿ãŒããã³åœç€Ÿã®ã³ã³ãã¥ãŒã¿ãŒãžã®RDPã¢ã¯ã»ã¹
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.6.61 3389 198.51.100.10 3389
msk-arbat-gw1ïŒconfigïŒïŒip nat inside source static tcp 172.16.6.66 3389 198.51.100.10 3398
å®å šæ§
æåŸã«ã1ã€ã®çºèšã ããã¯ããããããã€ããããã€ã¹ã§ããIPnatã®å€éšã€ã³ã¿ãŒãã§ã€ã¹ã§ãã€ã³ã¿ãŒãããã«å¯ŸããŠå€åãã«èŠããŸãã ãããã£ãŠãå¿ èŠãªãã®ãæåŠãèš±å¯ããå Žæã§ããã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ACLããã³ã°ã¢ããããŠã害ã¯ãããŸããã ãã®èšäºã§ã¯æ¢ã«ãã®åé¡ã«ã€ããŠã¯è§ŠããŸããã
ããã«é¢ããŠãNATãã¯ãããžãŒã®æåã®ç¥äººã¯å®å šã§ãããšèããããšãã§ããŸãã
å¥ã®DZãããµã³ã¯ãããã«ãã«ã¯ãšã±ã¡ããŽã©ã«ããEnikievã³ã³ãã¥ãŒã¿ãŒããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããªãçç±ã«ã€ããŠã®è³ªåã«çããŸãã çµå±ã®ãšããããã§ã«ã¢ã¯ã»ã¹ãªã¹ãã«è¿œå ããŠããŸãã
ãªãªãŒã¹è³æ
æ°ããIPèšç»ãåãã€ã³ãããã³èŠå¶ã®åãæ¿ãèšç»
å®éšå®€ã§ã®RTãã¡ã€ã«
ããã€ã¹æ§æ
è¿œå ãªã³ã¯ïŒ
äžè¬æ å ±ãšTCPããŒããã©ã³ã·ã³ã°
2ã€ã®ãããã€ããŒ+ NAT
ã·ã¹ã³ããã®æçšãªæ å ±
ç§ãã¡ã®ååhabruiserã¯NATã®æ©èœã«é¢ããããã€ãã®èšäºãæžããŸãã ã ãã®èšäºã¯ç¹ã«èå³æ·±ããããããŸããã
ãããããããããã§ããããã«ã誰ãciscoã«ã€ããŠciscoã«ã€ããŠæžãããšã¯ãããŸããã
ãªããŒã¹ãã¹ã¯
ããŒãã¹
èšäºã®äŸã®PBRã»ããã¢ãã
ã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã
ããã©ã«ãã«ãŒããè¿œå ããŸãã
ã¢ã¯ã»ã¹ãªã¹ãã§ã192.168.2.0 / 24ãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ãé€å€ããŸã
ã«ãŒãããããäœæããŸãããããã¯ãŒã¯ããã®ãã±ããã192.168.2.0/24ã®å Žåããã¯ã¹ãããã10.0.2.1ãïŒ10.0.1.1ã§ã¯ãªãïŒå²ãåœãŠãŸãã
ã€ã³ã¿ãŒãã§ã€ã¹ã§ã«ãŒãã䜿çšããŸãã
ããã¯åŒ·åãªããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ããŒã«ã®äœ¿çšã®1ã€ã«éãããæ®å¿µãªããRTã®ã©ã®åœ¢åŒã«ãå®è£ ãããŠããŸããã
ããã©ã«ãã«ãŒããè¿œå ããŸãã
ip route 0.0.0.0 0.0.0.0 10.0.1.1
ã¢ã¯ã»ã¹ãªã¹ãã§ã192.168.2.0 / 24ãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ãé€å€ããŸã
ã¢ã¯ã»ã¹ãªã¹ã101 permit ip 192.168.2.0 0.0.0.255 any
ã«ãŒãããããäœæããŸãããããã¯ãŒã¯ããã®ãã±ããã192.168.2.0/24ã®å Žåããã¯ã¹ãããã10.0.2.1ãïŒ10.0.1.1ã§ã¯ãªãïŒå²ãåœãŠãŸãã
ã«ãŒããããã¯ã©ã€ã¢ã³ãèš±å¯5
IPã¢ãã¬ã¹101ãšäžèŽ
ip next-hop 10.0.2.1ãèšå®ããŸã
ã€ã³ã¿ãŒãã§ã€ã¹ã§ã«ãŒãã䜿çšããŸãã
ip policy route-map CLIENT
ããã¯åŒ·åãªããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ããŒã«ã®äœ¿çšã®1ã€ã«éãããæ®å¿µãªããRTã®ã©ã®åœ¢åŒã«ãå®è£ ãããŠããŸããã
ACLã€ã³ã¿ãŒãã§ã€ã¹ã®é床å¶é
åãäŸã§ã¯ã192.168.1.0 / 24ãããã¯ãŒã¯ã®é床ã1.5 Mb / sã«ã192.168.2.0 / 24ã®é床ã64 kb / sã«å¶éããŸãã
10.0.1.1ã§ã¯ã次ã®ã³ãã³ããå®è¡ã§ããŸãã
10.0.1.1ã§ã¯ã次ã®ã³ãã³ããå®è¡ã§ããŸãã
RouterïŒconfigïŒïŒaccess-list 100 permit ip 192.168.1.0 0.0.0.255 any
RouterïŒconfigïŒïŒaccess-list 101 permit ip 192.168.2.0 0.0.0.255 any
ã«ãŒã¿ãŒïŒconfigïŒïŒinterface fa0 / 0
RouterïŒconfig-ifïŒïŒrate-limit output access-group 100 1544000 64000 64000 conform-action transmit exceed-action drop
ã«ãŒã¿ïŒconfig-ifïŒïŒã¬ãŒãå¶éåºåaccess-group 101 64000 16000 16000 conform-action transmit exceed-action drop
äžæ³šæãªäººã ã®æçåé¡ã¯ã LJã§å®è£ ã§ããŸãã
å ±èè ã®thegluckã«æè¬
JDimaèšäºã®æºåã«ãååããã ãããããšãããããŸã