- ããã«ã管çè ãšèŠåå¡ãžã®ããŠãŒã¶ãŒãšã®äŒè©±ã®ããã®ãã³ã¬ã¯ã·ã§ã³ã®1ã€ã®æçãªç©èªã
- ãªãç¡ç·ãããã¯ãŒã¯ã§ã¯ãWLANããLANã ãã§ãªãããããã ç¡ç·ãã¡ã€ã¢ãŠã©ãŒã«
- ãã®ãããªåé¡ãåé¿ããããã®ãããªãã¯Wi-Fiãããã¯ãŒã¯ã®æ§ç¯æ¹æ³ã«é¢ããæšå¥šäºé ã
- ããã«ãä»ã®ãããªãã¯ãããã¯ãŒã¯ã§ã¯ãæå·åãããŠããªããã£ããã£ãããŒã¿ã«ã§ãããPSKã§ã®æå·åãããæãŸããå ŽåããããŸãã
ååãšããŠããã¹ãŠãäŒæ¥ãããã¯ãŒã¯ã«é¢é£ããŠããŸããããããã«ã€ããŠã¯ãã§ã«æžããŸãã ã ãããŠã é£ã®æçš¿ã§åé¡ãå°ãç°ãªãè§åºŠããèŠãŸããã
ãŸã第äžã«ãç§ã¯WIPSãšRTLSã§ã¯ãŒã«ãªWi-Fiãç·æ¥ã«å®è¡ããŠè³Œå ¥ããããšã匷èŠãããã匷èŠãããããŸããã ããããã®ç¶æ³ã«ã¯ç¬èªã®ãã¥ã¢ã³ã¹ãšåªå é äœããããŸãã誰ãããŠãŒã¶ãŒå¥çŽã®èåŸã«é ãã誰ãããŠãŒã¶ãŒãæ°ã«ããªããäžéšã®åœã§ã¯è²¬ä»»ããªããã©ããã§ååãªéšåçãªå¯Ÿçããããä»ã®èª°ããããã€ãã®ãã¥ã¢ã³ã¹ãæã£ãŠããŸãã ç§ã説æãã-誰ããèªåã§éžæããŸãã
èæ¯
ç§ãã¡ãæ³ãŸã£ãããã«ã®ååãšè©±ããããŸããã ãã®æç¹ã§ããã«ã®WLANã«ãŸã æ¥ç¶ããŠããªããšããçç±ã ãã§ãç§ã¯ãã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«è©²åœããŸããã§ããã ããã«ã§ã¯ããã¹ãŠã®ã客æ§ã«ç¡æã§Wi-FiãæäŸããŠããŸãã ãããã¯ãŒã¯ã¯ãã¹ã¯ãŒãã§ä¿è·ãããŠãããPSKã¯çŽã§çºè¡ãããæ°ãæããšã«å€æŽãããŸãã
ç©èª
ååãã©ãããããããããã¯ãŒã¯ã«æ¥ç¶ããFirefoxãéããæåãªãµã€ãã®ã¢ãã¬ã¹ãæžã蟌ã¿ãŸãã ãµã€ãã®ä»£ããã«ãããã«ã®ãµã€ãã®ã¿ã€ãã«ãšãã䜿ãã®ãã©ãŠã¶ã¯éãããšããŠãããµã€ããšäºææ§ããããŸããã ããããããããã€ã³ã¹ããŒã«ããŠãã ãã ã " ååã¯æéãåããåãããŒãžã§ããChromeãèµ·åããŸãã Androidãããã¯ãŒã¯ãšiPod Touchãžã®æ¥ç¶ã¯åãã§ãã ãã®å Žåããããããã¯åžžã«åãã§ã:)ããããããããŠã³ããŒãããŸã-ã¢ã³ããŠã€ã«ã¹ã¯éåžžã«äºæ³éãã§ãïŒ3çš®é¡ã®ãã«ãŠã§ã¢ãèŠã€ãããŸããïŒã
äžè¬çã«ããã®ããããã¯æããã§ãããã£ãã·ã³ã°ãšãããã¯ãŒã¯äžã®å°ããªãããã³ã°ã«ãã£ãŠåºããã¢ã«ããã¢ã®ãŠã€ã«ã¹ ã ãŠã€ã«ã¹èªäœã¯éèŠã§ã¯ãããŸãããããããããªãã§ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããããã«ããã®ãã¹ãŠãã©ã®ããã«æ©èœããããç解ããããšã¯éèŠã§ãã
æŽç
ããã€ãã®ç°¡åãªèª¿æ»ïŒipconfig / pingã¬ãã«ïŒãéããŠããµã€ãã¯IPã§ã¢ã¯ã»ã¹ã§ããããšãããããŸããã ãããã£ãŠãåé¡ã¯DNSã«ãããŸãã DNS 8.8.8.8ãç»é²ãããšãå®å šã«æ©èœããã€ã³ã¿ãŒããããæã«å ¥ããŸããã ããã§ãæ»æã®ä»çµã¿ãç解ã§ããŸãã
次ã®ããšãå€æããŸããã
- WLANã«ã¯å¥ã®DHCPãµãŒããŒïŒäžæ£ãªDHCPïŒããããæ£ããIP /ãã¹ã¯/ GWãçºè¡ããŸããããæ£ãããããã€ããŒã§ã¯ãªãç¬èªã®DNSãµãŒããŒãæäŸããŸããã
- åããã¹ãäžã§åãDNSãµãŒããŒãçºçãããã¹ãŠã®ååãåãIPã«è§£æ±ºãããŸããïŒãä¿¡ããããªãã»ã©ã®å¶ç¶ã®äžèŽã®ããã«ãDNSãµãŒããŒã®IPãšäžèŽããŸããïŒã
- åãIPäžã§WebãµãŒããŒãèµ·åãããå®éã«ããŒãžã衚瀺ããŠãã¡ã€ã«ãæäŸããŸããã
ã芧ã®ãšããããã¹ãŠãéåžžã«åçŽã§ãããå®è£ ã«ç¹å¥ãªã¹ãã«ã¯å¿ èŠãããŸããã 質åïŒããã«ã€ãªãããæ®éã®äººãã¯äœäººã§ããïŒ
ãŸããæ»æè ãèªåèªèº«ããããããã«éå®ããGMail / Bing / Facebookãªã©ã®ã¡ã€ã³ããŒãžãæç»ããªãã£ãããšã¯å¥åŠã§ãã -HTTPSã䜿çšããŠããŠããã¢ã«ãŠã³ããåéã§ããå¯èœæ§ããããŸããäœäººãäžæ£ãªèšŒææžã«æ³šæãæã£ãŠããã®ãããŸãã¯HTTPSããHTTPã«ãªãã€ã¬ã¯ããããã ããªã®ã§ããããã ãã ãããã·ã³äžã«3ã€ã®ããã€ã®æšéŠ¬ãååšããå Žåããã§ã«ãã¹ãŠã®ããã€ã®æšéŠ¬ãåéããŠããŸã...
çµè«ãšè§£æ±ºç
ã¢ã¯ã»ã¹ãããã¯ãŒã¯ãæ§ç¯ããå Žåããã®ãããã¯ãŒã¯ãšæç·ã€ã³ãã©ã¹ãã©ã¯ãã£ããŠãŒã¶ãŒã®ãé床ã®é¢å¿ãããä¿è·ããã ãã§ãªããäžéšã®ãŠãŒã¶ãŒãä»ã®ãŸãšããªãŠãŒã¶ãŒããä¿è·ããããšãéèŠã§ãã ããã¯ãäŒæ¥ïŒãã©ã€ããŒãïŒãããã¯ãŒã¯ãããã³ãããªãã¯ãããã¯ãŒã¯ïŒãããã¹ããããããã«ãã«ãã§ããŒã¬ã¹ãã©ã³ãªã©ïŒã«åœãŠã¯ãŸããŸãã ãã¯ã€ã€ã¬ã¹ã»ãã¥ãªãã£ãã¯æå·åã ãã§ã¯ãªããèå¥ãèªèšŒããã©ãã£ãã¯åé¢ãªã©ãååšããå¿ èŠãããããšãå¿ããŠã¯ãªããŸããã äžèšã®æ»æã¯ãæç·ã»ã°ã¡ã³ãã®ãã¡ã€ã¢ãŠã©ãŒã«ãŸãã¯IPSãæ€åºã§ããªãçŽç²ãªã¯ã€ã€ã¬ã¹æ»æã ãã§ã¯ãããŸããã ãã®ãããªåé¡ãé²ãã«ã¯ã©ãããã°ããã§ããïŒ
æãç°¡åãªè§£æ±ºçã¯ããŠãŒã¶ãŒéã®éä¿¡ãçŠæ¢ããããšã§ãã éåžžãããã¯ãWLANèšå®ã§åäžã®ãã§ãã¯ããŒã¯ããªã³/ãªãããããšã§è¡ãããŸãïŒãMUééä¿¡ãç¡å¹ã«ããããCisco PSPFãããã³ã¢ããã°ïŒã ãã ãããããã¹ãããã®ãŠãŒã¶ãŒã¯åžžã«ããã奜ããšã¯éããããããã¯ãŒã¯ïŒã²ãŒãã³ã°ããŒãã£ãŒãäŒæ¥ãããã¯ãŒã¯ã®VoWLANãªã©ïŒã䜿çšãããšããç®æšã«åããå¯èœæ§ããããŸãã ãã ããæ¢ã«è¿°ã¹ãããã«ãççŸããªãå Žåã¯ããããè¡ãã®ãæãç°¡åã§ããã®é ç®ãã䜿çšæ¡ä»¶ãã«èšè¿°ããã®ãæãç°¡åã§ãã
æåã®æ¹æ³ã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§DHCPãDNSãããã³ïŒäŒç€Ÿããšã®ïŒããã³ARPå¿çãçŠæ¢ããããšã§ãã ãããè¡ãã«ã¯ãWLANéãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ã§ãããã¡ã€ã¢ãŠã©ãŒã«ãã¢ã¯ã»ã¹ãã€ã³ãã«çŽæ¥é 眮ããå¿ èŠããããŸãïŒåŸæ¥ã®FWãšã®éãã匷調ããããã«ãã¯ã€ã€ã¬ã¹ãã¡ã€ã¢ãŠã©ãŒã«ãšåŒã°ããŸãïŒã ãã€ãŠç§ã«ãšã£ãŠã¯ãäžéšã®èåãªãã³ããŒããã®æ¹æ³ãïŒä»æ¥ãŸã§ïŒç¥ããªãã®ã¯å€§ããªé©ãã§ããã
DNSããã³DHCPå¿çã¯ãæç·ãã¹ãããã®ã¿èš±å¯ãããŸãã ã¯ã©ã€ã¢ã³ãããã®ARPå¿çã¯ãŸã£ããå¿ èŠãããŸãã-ãã€ã³ãã¯ãŸã ã¯ã©ã€ã¢ã³ãã®ãã¹ãŠã®MACã¢ãã¬ã¹ãç¥ã£ãŠããïŒã¢ãœã·ãšãŒã·ã§ã³äžïŒããããã·ARPãä»ããŠãªã¯ãšã¹ãã«å¿çã§ããããããããã¯ãŒã¯äžã®åœãã©ãã£ãã¯ã®éãæžå°ããŸãã
ãã®ããã«ããŠãDHCP / DNS / ARPã¹ããŒãã£ã³ã°ãäžæ£ãªDHCP / DNSãAPRãã€ãºãã³ã°ããããã«é¢é£ä»ããããMiTMæ»æãæé€ããŸãïŒããã«å€ãã®å Žåãã³ã¡ã³ãã®è£è¶³ïŒã
ããã§ã¯ãå¥ã®åŽé¢ã«æ³šç®ããŸãããã ããã§ããããã¯ãŒã¯äžã«åœã®ãµãŒããŒãçºèŠããŸããã MACã§ãããã¯ã§ããŸãã ããããæ»æè ãæãè ã§ãªããå®æçã«èªåã®ããºãæãã®ã¢ã¯ãã£ããã£ããã§ãã¯ããå Žåã圌ã¯ããã«æ°ã¥ããMACãå€æŽãããã¹ãŠãç¶è¡ããŸãã ããã«ãæ»æè ã¯PSKãç¥ã£ãŠãããããã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããŠããªããŠããWPA2ã䜿çšããŠããŠãããŠãŒã¶ãŒã«ãããã¯ãŒã¯ã«ãã±ãããéä¿¡ã§ããŸãã ãããè¡ãã«ã¯ãããªãåªåããŠãã ããã WPA / WPA2ã§ã¯ãããŒã®é åžã¯WEPãããè€éã§ããã å¯èœã§ãã æµãåãé€ãå¯äžã®æ¹æ³ã¯ãPSKãå€æŽããããšã§ãã ãããŠããã¹ãŠã®é¡§å®¢ã®ããã«ãããå€æŽããŠãã ããïŒ ã¯ããããã¯æ»æãæéããŸãããæ»æè ãèŠã€ããŠçœ°ããããšã¯ã§ããŸããïŒããžã·ã§ãã³ã°ã·ã¹ãã ã䜿çšããªãå ŽåïŒã ãããŠããªãŒãã³ãããã¹ãããã«ã€ããŠäœãèšããŸããïŒ
ãããã£ãŠããããªãã¯ãããã¯ãŒã¯ã§ã¯ãããã«ã®ãããã¯ãŒã¯ã®ããã«PSKã§ä¿è·ãããŠããŠããæ»æè ã¯ã»ãšãã©åžžã«çœ°ããããŸããã
ãã1ã€ã¯ãCaptive PortalïŒè³¢æã«äœ¿çšããã ãïŒãŸãã¯802.1xã䜿çšããããšã§ãïŒåæã«ãã©ãã£ãã¯æ³šå ¥ã®åé¡ã解決ããŸããããããªãã¯ãããã¯ãŒã¯ã§ã¯802.1xã®äœ¿çšã¯å°ãè€éã§ãïŒã åãŠãŒã¶ãŒã¯ããã°ã€ã³ã«é¢é£ä»ããããMACã¢ãã¬ã¹ã«é¢é£ä»ããããåã ã®ååãšãã¹ã¯ãŒããåãåããŸããã¢ã«ãŠã³ãã¯éãããæéã ãæ©èœããŸãïŒããã«ã·ã¹ãã ã§ã¯ãèªååã¯ãã§ãã¯ã€ã³/ãã§ãã¯ã¢ãŠãã¹ããŒãã¡ã³ãã«ãªã³ã¯ããããã«æ§ç¯ãããŸãïŒã ãããã£ãŠã誰ãããã§éãã§ããã®ãããŸãã¯å°ãªããšã誰ãä»ããŠèå¥ããŒã¿ã®æŒæŽ©ãçºçããã®ããåžžã«ææ¡ã§ããŸãã
ãããã®ãã¥ã¢ã³ã¹ã¯äž¡æ¹ãšãã責任ãå€ãããããªå±éºã§ãšããµã€ãã£ã³ã°ãªã²ãŒã ã«ãããŠéåžžã«éèŠã§ãã ãŠãŒã¶ãŒåææžã«å 責äºé ãå«ãŸããŠããªãå ŽåïŒåžžã«ãããè¡ãããšãã§ããªãå Žåãããã«ããŠãŒã¶ãŒããããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããããªãœãŒã¹ã䜿çšããããã®ã«ãŒã«ã«åæã§ããªãå ŽåïŒããããã³ã°ããã«ãã人皮差å¥/æŽåãªã©ã®ãããã¬ã³ãããããŠããªãã極端ãèŠã€ããããšãã§ããªãå Žå-極端ã¯ããªããä»»åœããŸãã ãã®ããããšãŒãããã®ãããã¹ãããã§æšªè¡ããŠãããã£ãã·ã³ã°ã®çµæãšããŠã圌ãã¯ç«æ³ã¬ãã«ã§åãŠãŒã¶ãŒã®å¿ é èå¥ãå°å ¥ããŸããïŒã»ãšãã©ã®å ŽåãSMSã«ã¯åå¥ã®ã¢ã¯ã»ã¹ã³ãŒããä»å±ããæºåž¯é»è©±çªå·ãå ¥åããå¿ èŠããããŸãïŒã ãããé ãããšãã§ããããšã¯æããã§ããããã®æ¹æ³ã§ã¯ããããã¹ããããããã€ããŒãSIMã«ãŒããããã€ããŒã«è²¬ä»»ã移ããŸãã èªèšŒã䜿çšããªããŠãããã£ããã£ãããŒã¿ã«ã¯ãã¢ã¯ã»ã¹ãèš±å¯ããŠããããªãœãŒã¹ã䜿çšããããã®ã«ãŒã«ããå«ãã¹ãã©ãã·ã¥ã¹ã¯ãªãŒã³ã衚瀺ãããŠãŒã¶ãŒã«ãæ¡ä»¶ã«åæããããã§ãã¯ããã¯ã¹ãã¯ãªãã¯ããããšã匷å¶ã§ããŸããå¥çŽã衚瀺ãããŸããã§ããïŒã ãã®ãããCaptive Portalã䜿çšãããªãŒãã³ãããã¯ãŒã¯ã¯ãPSKã䜿çšããã¯ããŒãºããããã¯ãŒã¯ãããå®å šãªå ŽåããããŸã-ææè ã«ãšã£ãŠã¯:)
å¥ã®æ¹æ³ãšããŠãäžéšã®ãã³ããŒïŒAerohiveãRuckusïŒã¯ãåã¯ã©ã€ã¢ã³ãã«äžæã®ããŒãäžãããããåå¥PSKãã®éæšæºãã¯ãããžãŒãå®è£ ããŠããŸãã ãã®ããã«ããŠãæŒãã®å Žåã®ãŠãŒã¶ãŒèå¥ãšPSKã®è³ªéå€åã®åé¡ã解決ãããŸãã ãã ããCISè«žåœã§ã®å¯çšæ§ã¯éåžžã«éãããŠãããäºææ§ã®åé¡ãæã èŠãããŸãã
ãããã«
ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§ã¯ãã¯ã€ã€ã¬ã¹ãŠãŒã¶ãŒãå®å šã«ã¯ã€ã€ã¬ã¹æ»æããä¿è·ããããšã¯ãæç·ã»ã°ã¡ã³ããä¿è·ããããšãšåããããéèŠã§ãã ããªãåçŽãªæè¡çæ段ã䜿çšããŠãç£æ¥èŠæš¡ããã³ãã®ä»ã®æ»æã§ãã£ãã·ã³ã°ãèšå®ã§ããŸããåäžã®æç·ãã¡ã€ã¢ãŠã©ãŒã«/ IPSã§ã¯åœ¹ç«ã¡ãŸããã
ã¯ã€ã€ã¬ã¹ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ãä»ã®ã¯ã€ã€ã¬ã¹ãŠãŒã¶ãŒã«å¶éããæè¡çãªæ段ããããŸãã
- ãããã®éã®éä¿¡ããŸã£ããçŠæ¢ããŸãïŒã»ãŒãã¹ãŠã®ã¡ãŒã«ãŒã«ãã£ãŠãµããŒããããŠããŸããããããã¯ãŒã¯äžã§åžžã«åãå ¥ãããããšã¯éããŸããïŒ
- ã¯ã€ã€ã¬ã¹ãŠãŒã¶ãŒãéèŠãªãããã¯ãŒã¯ãµãŒãã¹ïŒDHCPãDNSãARPïŒã«åçãéä¿¡ã§ããªãããã«ããŸãïŒã¯ããã«åªããŠããŸããã誰ãããµããŒãããŠããªããããããè€éãªæ»æããæãããšã¯ã§ããŸããïŒ
- ãã£ããã£ãããŒã¿ã«/ 802.1x / PPSKã䜿çšãããšããŠãŒã¶ãŒããŒã¿ã®æ»æãŸãã¯æŒæŽ©ã®åå ãç¹å®ã§ããŸãã
- ç¹æ®ãªã¯ã€ã€ã¬ã¹IPSãä»ã®æ»æã®èåŸã«é ããããšãæ¯æŽ
- ããžã·ã§ãã³ã°ã·ã¹ãã ïŒRTLSïŒã䜿çšãããšããœãŒã¹ã®ããããã®ç©ççäœçœ®ãç¹å®ã§ããŸãã
äžèšã¯ãã¹ãŠãã©ã®ãããã¯ãŒã¯ã«ãé¢ä¿ããŸãïŒã€ã³ãµã€ããŒããã¯ããã£ã³ã»ã«ãã人ã¯ããŸããïŒãããããªãã¯ãããã¯ãŒã¯ïŒãããã¹ããããããã«ãKaBaReãªã©ïŒã®èŠ³ç¹ããã¯ç¹ã«éèŠã§ã
- 顧客åãã®ã¢ãã©ã¯ã·ã§ã³ïŒã圌ãã¯ç§ããããã³ã°ããå人ãããã«é£ããŠè¡ããŸãã-ããããã«ã¯è¡ããŸããããªã©
- çµç¹ã®åé¡ïŒåé¡ããã°ãã解決ããç¯äººãèŠã€ããããšãã§ããŸãã ãããã圌ã®åŸæ¥å¡ã®1人ããäœåãªãéã皌ãããªã©ãšæ±ºããŸããã
- æ³ç質åïŒæŒãããå Žåã責任ãã·ããã§ããŸãã
é¢çœãã£ããšæããŸãã