å¶ç¶ããæ å ±ã»ãã¥ãªãã£ããšãããããã¯ã«é¢ããé éåŠç¿ã³ãŒã¹ãåè¬ããŸããããã®æåŸã«ãåæ¥äœåãä¿è·ããå¿ èŠããããŸããã ç§ã¯ãã®äœæ¥ã®ãããã¯ãšããŠãã¢ã¹ã¿ãªã¹ã¯ã»ãã¥ãªãã£ããéžæããŸãããããã®ãããã¯ã«é¢ããŠå€ãã®èšäºãåºçç©ãæžãããŠããŸãããç§ã®æèŠã§ã¯ããããã¯å®å šã§ã¯ãªããããã®ãããã¯ãå®å šã«ã«ããŒããŠããªããããã®åé¡ã®é¢é£æ§ã®å åã¯ãããŸãã ç§ã¯ããã¹ãŠãã1ã€ã®ææžã«ãŸãšããèªç±ãåãããããæçµçãªææããããããŸããã 圌ã¯èªåèªèº«ãå®ããåæ¥èšŒæžãåãåã£ã-ãã®äœåãã³ãã¥ããã£ãšå ±æããããšã決ããã
1.ã¢ã¹ã¿ãªã¹ã¯IP-PBXã«é¢é£ãããªã¹ã¯
æ å ±æè¡ã®æ代ã«ã¯ãæ»æè ïŒããã«ãŒïŒã®è¡åãçµç¹ã«å€§ããªæ倱ãããããããšã¯èª°ããç¥ã£ãŠããŸãã ååãšããŠãæãçã¿ã䌎ãæ»æã¯ãçµç¹ã«æ害ãäžããããè³éãçŽæ¥çãããšãç®çãšãããã®ã§ãã ã¢ã¹ã¿ãªã¹ã¯ã¯ã³ã³ãã¥ãŒã¿ãŒãã©ãããã©ãŒã ã«åºã¥ããé»è©±äº€æã§ãããéä¿¡ãã£ãã«ã¯ã€ã³ã¿ãŒããããçµç±ããïŒäžéšã®ã·ã¹ãã ãµãŒãã¹ã¯å€éšã«å ¬éãããŠããïŒãããããã«ãŒã¯ã·ã¹ãã ãžã®äžæ£ã¢ã¯ã»ã¹ãååŸã§ããŸãã
IPãã¬ãã©ããŒãœãªã¥ãŒã·ã§ã³çšã®ã»ãã¥ãªãã£ã·ã¹ãã ãæ§ç¯ããå Žåãé¢é£ãããªã¹ã¯ãèªèããããšãéèŠã§ãã äžè¬çã«ããããã¯æ¬¡ã®ããã«åºå¥ã§ããŸãã
1.æ©å¯æ§ã®äŸµå®³ããã³ã³ã³ãã³ãã®æªã¿ã ååã»ãã·ã§ã³ã
2. IPãã¬ãã©ããŒã®å±éäžã«åºçŸããè匱æ§ãä»ããçµç¹ã®ãããã¯ãŒã¯ãžã®äŸµå ¥ã
3.ãµãŒãã¹ã®å£åãç®çãšããã¢ã¯ã·ã§ã³ïŒDosæ»æïŒã
4.å販ãã©ãã£ãã¯ïŒToll-FraudïŒã
å販ãã©ãã£ãã¯ã¯ãããã«ãŒããéã皌ãããã®æã䟿å©ãªæ¹æ³ã®1ã€ã§ãã ã¹ããŒã·ã§ã³ããããã³ã°ããé«äŸ¡ãªåœéçãªç®çå°ã«é»è©±ãããããšãããã«ãŒã¯èªåã®é»å財åžã«å¯Ÿããäžå®ã®å ±é ¬ãåãåããçŸéåãããŠå®éã®ãéãåãåããŸãã äžè¬çãªãã©ãã£ãã¯å販ã¹ããŒã ããã詳现ã«æ€èšããŠãã ããã
ãã©ãã£ãã¯ã転売ããããšã§ãéã皌ãããããã«ãŒãããŸãã 圌ã¯æ氎管亀ææã«è¡ããå°æ¥åœŒãèå¥ããããšãã§ããæ°ã®ããŒã«ãç»é²ããŠåãåããŸãã 次ã«ãããã€ãã®åœãµãŒããŒãä»ããŠãIP-ATCãµãŒããŒãçºèŠãããå€æããå Žåããããã³ã°ãããŸãã ããã«ããã®æ°åã¯ãæ氎管ã®äº€æã§ããã«ãŒã«æäŸãããæ°åã«ç§»åãå§ããŸãã é話ã¯ææã§ãã é話æéã10ã«ãŒãã«ã ãšããŸãããã ïŒãªãã¬ãŒã¿ãŒãžã®è¢«å®³è ã®æ¯æãïŒã ãã®åŒã³åºãã¯ãéåžžã¯æµ·å€ïŒéåžžã¯ãã¥ãŒãããã¬ã¹ãããã«ãŒããã¢ãã©ããã¢ãªã©ïŒã§ããµã€ããŒç¯çœªã«ååãªæ³šæãæãããŠããªãåœãã€ãŸããã®çš®ã®ããžãã¹ãè¡ãæ©äŒãããåœã«éä¿¡ãããŸãã ãããã£ãŠã被害è ã¯OSïŒéä¿¡äºæ¥è ïŒã«1åããã10ã«ãŒãã«ãæ¯æããŸãã OSã¯ãOMTïŒåœéãã©ãã£ãã¯ã®ãªãã¬ãŒã¿ãŒïŒãä»ããŠåœéç·ã«è¡ãã8ã«ãŒãã«ã®å°åã§æ¯æããŸãã 1åããããOMTã¯å°å ã®ãªãã¬ãŒã¿ãŒïŒãã¥ãŒãããã¬ã¹ãããªã©ïŒã«åŒã³åºããéä¿¡ããŸãããªãã¬ãŒã¿ãŒã¯é³å£°ãã©ãã£ãã¯ã®ãæŽæµãã«åŸäºãã6ã«ãŒãã«ãæ¯æããŸãã æ¯åããã®ãªãã¬ãŒã¿ãŒã¯å ±æããã圌ã¯æ¬¡ã®ããã«ãéãåé ããŸã-ãéã®äžéšã¯ãµãŒãã¹ã®æ¯æãã®ããã«åœŒã«è¡ããŸãïŒããã°ããã®éé¡ã皌ããŸã-圌ã®ã¢ã«ãŠã³ãã«æ®ããŸãïŒããããŠãéã®åèªã¯ããã«ãŒãç»é²ãããŠããæ氎管ååŒæã«éãããŸãã ããã«ã亀æã¯1ã«ãŒãã«ã®ãŸãŸã§ãããã«ãŒã«2ãæ¯æããŸãã ç®ã«èŠãããå³ã¯å³1ã«ç€ºãããŠããŸãã
å³1 Voip Traffic Resale Scheme

æ¹åãé«äŸ¡ã«éžã°ããåŒã³åºãã®æµããæ¿ããããšãèãããšãããã«ãŒã¯è¯ãå©çãäžããŸãã ãŸããã·ã¹ãã ãé©åã«ä¿è·ãããŠããªãå Žåããããããæéãšè²»çšã®ããããã®ãªãã§ãããã³ã°ãè¿ éã«çºçããŸããã¢ã¹ã¿ãªã¹ã¯ã¯ãèµ€ãåžãã«ãªããŸãã ãŸãããã¹ãŠã®æäœã®åŸã被害è ã¯é»è©±ã§å€§ããªè«æ±æžïŒ10ã100,000ã«ãŒãã«ïŒãåãåããŸãã
æ®å¿µãªããããããã®çš®é¡ã®åé¡ã¯æè¿é »ç¹ã«ãªã£ãŠããŸãã ãããã£ãŠãå€ãã®äººãã¢ã¹ã¿ãªã¹ã¯ã¯å®å šã§ãªãã·ã¹ãã ã§ãããšèããŠããŸãã ããããç§ã¯ãã®è«æã«ææŠãããã ãŸããã¢ã¹ã¿ãªã¹ã¯èªäœã®æ©èœã«ã€ããŠè©±ããšãã»ãã¥ãªãã£ã確ä¿ããããã®éåžžã«è±å¯ãªããŒã«ã»ããããããŸãã ã¢ã¹ã¿ãªã¹ã¯ããŒã«ã¯ãå€ãã®ç«¶åä»ç€Ÿããã匷åã§ãã ãã ããã¢ã¹ã¿ãªã¹ã¯ã¯éåžžã«é »ç¹ã«ãããã³ã°ãããŸãã ã©ãããŠïŒ ãªããã ãã®ã·ã¹ãã ã®ç®¡çè ããã¹ãŠã§ãã ã¢ã¹ã¿ãªã¹ã¯ã»ãã¥ãªãã£ãã¢ã¯ãã£ãã«ããããã®åäžã®ãã§ãã¯ã¯ãããŸããã ã¢ã¹ã¿ãªã¹ã¯ã»ãã¥ãªãã£ãšã¯ãäžè¬ã«ç®¡çè ãå¿ããå€æ°ã®å æ¬çãªæ段ã®æ¡çšã§ãããããã«ããã¢ã¹ã¿ãªã¹ã¯ãè åšã«ããããŸãã
2. IP-PBXã¢ã¹ã¿ãªã¹ã¯ã®ãã«ãã¬ãã«ä¿è·
äžè¬ã«IP-ATCãœãªã¥ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã«ã€ããŠèšãã°ãã»ãã¥ãªãã£ã¯ã¢ã¹ã¿ãªã¹ã¯èªäœã®ã»ãã¥ãªãã£ã«åºã¥ããŠããã ãã§ãªããã¢ã¹ã¿ãªã¹ã¯ã®ã»ãã¥ãªãã£ãšç°å¢ã確ä¿ããããšãå¿ èŠã§ããããšãç解ããå¿ èŠããããŸãã
IP-ATCä¿è·ã·ã¹ãã ã¯ãããã€ãã®ã¬ãã«ã§æ§ç¯ãããŠããŸãã
1.ãããã¯ãŒã¯ä¿è·ã
2.ãããã¯ãŒã¯èšèšã
3.ãã°åæã
4.ã¢ã¹ã¿ãªã¹ã¯æ§æã
5.ä¿è·èšç»ã®ã³ãŒã«ã«ãŒãã£ã³ã°ïŒãã€ã€ã«ãã©ã³ïŒã
6. Linuxã®æ§æã
7.åšèŸºæ©åšã®ä¿è·ã
8.管çæªçœ®ã
ã»ãã¥ãªãã£ã®é¢ã§ã¢ã¹ã¿ãªã¹ã¯ã®åé¡ãã°ããŒãã«ã«å€æããå Žåãäžèšã®ããã«-ãã®åé¡ã¯ã¢ã¹ã¿ãªã¹ã¯ã®ç®¡çè ã®èœåã§ã¯ãããŸããã
ãããã¯ã¹ãœãªã¥ãŒã·ã§ã³ããã€ã³ã¹ããŒã«ãããŠæ©èœããŠãããšããäºå®ã«ãããé©åãªã»ãã¥ãªãã£èšå®ãšå¿ èŠãªç®¡çè ã®è³æ Œãæããªãéåžžã«å€ãã®ã€ã³ã¹ããŒã«ãããã¢ã¹ã¿ãªã¹ã¯ãµãŒããŒãååŸããŸãã ç¡èœãªã€ã³ãã°ã¬ãŒã¿ãŒããµãŒããŒãé©åã«ã€ã³ã¹ããŒã«ããªãã£ããããæ¯æãåŸã«æ¶ããŸãã ãããŠãã¯ã©ã€ã¢ã³ãã¯åŸã«é»è©±ã§å·šé¡ã®è«æ±æžãåãåããããªãã¬ãŒã¿ãŒãæ瀺ããããã¯ããŸãã
åå¿è ã®ã¢ã¹ã¿ãªã¹ã¯ç®¡çè ãç¯ããå žåçãªééããèŠãŠã¿ãŸãããã
1.å éšçªå·ã®åŒ±ããã¹ã¯ãŒãïŒãã¹ã¯ãŒãããªãããã¹ã¯ãŒãã¯extãšåãã§ãïŒã
2.ãã¡ã€ã¢ãŠã©ãŒã«ã®æ¬ åŠïŒiptablesã®æ¬ åŠãiptablesããªãã«ãªã£ãŠããããæ£ããæ§æãããŠããªãïŒã
3.å€ããã£ã¹ããªãã¥ãŒã·ã§ã³ãšãœãããŠã§ã¢ïŒå€ããœãããŠã§ã¢ã«ã¯è匱æ§ãå«ãŸããå ŽåããããŸããã·ã¹ãã ã®å®æçãªæŽæ°ãå¿ èŠã§ããäŸãšããŠãtrixboxã¯ãµããŒããããªããªããæŽæ°ãããŸãã-è匱æ§ããããŸãïŒã
4.æšæºã®ãã°ã€ã³ãšãã¹ã¯ãŒãïŒWebã€ã³ã¿ãŒãã§ã€ã¹ãSQLãæ©åšïŒã
5.ãããã¯ãŒã¯èšèšïŒã¢ã¹ã¿ãªã¹ã¯ãšå€éšã¢ãã¬ã¹ã§åäœããæ©åšããã ãä¿è·ãªã-ããã¯ããã«ãŒã«ãšã£ãŠã¯ã¡ãã£ãšãã話ã§ãïŒã
6.æ§æã®ãšã©ãŒã
7.ã·ã¹ãã ã®å¶åŸ¡ã®æ¬ åŠïŒèšå®ããŠå¿ããããã°ã®å¶åŸ¡ãªãïŒã
2.1ãããã¯ãŒã¯ä¿è·
ã·ã¹ãã ãå±éãããšãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããããšãéèŠã§ãã Linuxã«ã¯ãã³ãã³ãé§ååã®åŒ·åã§æè»ãªIPTablesããŒã«ããããŸãã ããã©ã«ãã§ã¯ãIPTablesã¯æ¬¡ã®ããã«æ§æãããŸãã
-A INPUT âm state âstate ESTABLISHEDãRELATED âj ACCEPT ïŒæ¢ã«ç¢ºç«ãããæ¥ç¶ã®ãã±ãããèš±å¯ããŸãïŒ
-A INPUT âp icmp âj ACCEPT ïŒicmpãããã³ã«ãã±ãããèš±å¯ïŒ
-A INPUT âi lo âj ACCEPT ïŒloã€ã³ã¿ãŒãã§ãŒã¹ããã®ãã©ãã£ãã¯ãèš±å¯ïŒ
-A INPUT âmç¶æ --state NEW âm tcp âp tcp âdport 22 âj ACCEPT ïŒæ°ããsshæ¥ç¶ãèš±å¯ïŒ
-A INPUT -j REJECT --reject-with icmp-host-prohibited ïŒä»ã®ãã¹ãŠã®çä¿¡æ¥ç¶ãçŠæ¢ïŒ
-A FORWARD âj REJECT-reject-with icmp-host-prohibited ïŒãã¹ãŠã®äžç¶æ¥ç¶ãçŠæ¢ïŒ
ã³ããã
ãã®ãæ§æãã¯ãéå§ããæ¥ç¶ãèš±å¯ããsshãé€ããã¹ãŠã®çä¿¡æ¥ç¶ãæåŠããŸãã 次ã«ãã¿ã¹ã¯çšã«æ§æããŸãã æ§æã¯/ etc / sysconfig / iptablesã«ãããŸãã IPTablesãæ§æããããã«ç解ãã¹ãäž»ãªããšã¯ããã®ããŒã«ã®å²åŠã§ãã ã«ãŒã«ãèšè¿°ããããšã®æ¬è³ªã¯ããã©ãã£ãã¯ãç¹å®ã®åé¡åïŒ-s sourceã-p protocolã-i interface ... ..ïŒã«åŸã£ãŠé§åãããããã§ãŒã³ããäœæããããšã§ããããã§ããã©ãã£ãã¯ã«å¯Ÿããã¢ã¯ã·ã§ã³ãè¡ãããŸã-èš±å¯ããããçŠæ¢ããããå¥ã®ãã©ãã£ãã¯ã«è»¢éããŸããã§ãŒã³ã ãã©ãã£ãã¯ããã¹ãŠã®ãã§ãŒã³ãééããã«ãŒã«ïŒæªå®çŸ©ã®ãã©ãã£ãã¯ïŒè€æ°ã®åé¡åãæ©èœããªãã£ãïŒïŒã«è©²åœããªãå Žåããã©ãã£ãã¯ã¯çŠæ¢ãããŸãã ã€ãŸããããšãã°ãå éšãããã¯ãŒã¯ããã®IPé»è©±ãšãœãããã©ã³ãAsteriskãµãŒããŒã«æ¥ç¶ããã«ã¯ãã«ãŒã«ãèšè¿°ããå¿ èŠããããŸã
-A INPUT âs xxx.xxx.xxx.xxx/24 âj ACCEPT
ãã®ã«ãŒã«ã§ã¯ããããã¯ãŒã¯xxx.xxx.xxx.xxx \ 24ããã®çä¿¡æ¥ç¶ãèš±å¯ããŸãã ããã±ãŒãžã¯äžããäžã®èŠåã«åŸããããçŠæ¢èŠåãããäžã«èšè¿°ããå Žåããã®èŠåãæ©èœããããšãç解ããå¿ èŠããããŸãã ãããã£ãŠãAsteriskãæå³çã«ä¿¡é ŒããŠãããããã®æ¹åãšããã±ãŒãžã®ã¿ã«ãµãŒãã¹ãæäŸããããã«ãã¡ã€ã¢ãŠã©ãŒã«ãæ§æã§ããæ»æè ããµãŒããŒã«ã¢ã¯ã»ã¹ããããšã¯ã»ãšãã©äžå¯èœã§ãã ãã¡ã€ã¢ãŠã©ãŒã«ããžãã¯ãããæè»ã«æ§æã§ããŸã-åã°ã«ãŒãã®ãã±ããïŒç®¡çè ãSIPãIAX2 ...ïŒã«ç¬èªã®ã«ãŒã«ã䜿çšããŠç¬èªã®ãã§ãŒã³ãäœæããã¡ã€ã³ã®INPUTãã§ãŒã³ã§ã¯ãã«ãŒã«ã«åŸã£ãŠããã±ããããã§ãŒã³ã§éä¿¡ãããé©åãªã¢ã¯ã·ã§ã³ãå®è¡ãããŸãã
2.2ãããã¯ãŒã¯èšèš
ã·ã¹ãã ãèšèšããã³å®è£ ãããšãã¯ããããã¯ãŒã¯èšèšã«æ³šæãæãå¿ èŠããããŸãã
å€ãã®å Žåãã¢ã¹ã¿ãªã¹ã¯ã¯ãå³1ã«ç€ºãæãè匱ãªã¹ããŒã ã«åŸã£ãŠãããã¯ãŒã¯ã«æ¥ç¶ãããŸãã 2ã
å³2ã ã¢ã¹ã¿ãªã¹ã¯å€éšæ¥ç¶ã¹ããŒã ã¯æšå¥šãããŸãã

ã¢ã¹ã¿ãªã¹ã¯ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœã§ãããšããäºå®ã¯ãã·ã¹ãã å šäœã®äž»èŠãªã»ãã¥ãªãã£ãªã¹ã¯ã§ãã æ»æè ã¯ãAsteriskãœãŒã¹ã³ãŒãã®è匱ãªãã¹ã¯ãŒããŸãã¯è匱æ§ã䜿çšããŠãPBXãžã®äžæ£ã¢ã¯ã»ã¹ãååŸããAsteriskãµãŒããŒãææããäŒç€Ÿãç ç²ã«ããŠé»è©±ããããããšãã§ããŸãã æè¯ã®ã·ããªãªã§ã¯ãæ»æè ã¯ãµãŒãã¹æåŠãæšçã«ããããšãã§ããŸãã
匷åãªãã¹ã¯ãŒããšå®æçãªæŽæ°ã¯ãã¡ããããªã¹ã¯ã軜æžããŸãã ããã«åŒ·åãªä¿è·æ段ãã€ãŸããã¡ã€ã¢ãŠã©ãŒã«ïŒMEïŒã«ãã£ãŠåæžããããšãã§ããŸãã å³ã«ç€ºãããã«ã¢ã¹ã¿ãªã¹ã¯ãæ¥ç¶ããå Žåã 3ããµãŒããŒã¯ããŒã«ã«ãããã¯ãŒã¯ã®å¢çã®èåŸã§å®å šã«éããããŸãã
å³ 3. MEã䜿çšããæšå¥šã¢ã¹ã¿ãªã¹ã¯æ¥ç¶ã¹ããŒã

MEã¯çºä¿¡ãã©ãã£ãã¯ãAsteriskãµãŒããŒããSIPãããã€ããŒã«æž¡ãããã€ãããã¯NATã«ãŒã«ãä»ããŠæ»ããŸãã ãŸãããªã¢ãŒããªãã£ã¹ã®ãŠãŒã¶ãŒãæ¥ç¶ããæ©èœã¯ãVPNãã³ãã«ãä»ããŠæäŸãããŸãã ãŠãŒã¶ãŒã¯ãæåã«VPNãä»ããŠãšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ã«æ¥ç¶ãã次ã«ä»®æ³ãã£ãã«ãä»ããŠã¢ã¹ã¿ãªã¹ã¯ãµãŒããŒã«æ¥ç¶ããŸãã ã¢ã¹ã¿ãªã¹ã¯ã¯å€éšãããã¯ãŒã¯ããèŠããªããªããæ»æè ã¯å©çšã§ããŸããã
ãŸãã泚æãå¿ èŠãªãã1ã€ã®éèŠãªåŽé¢ã¯ãããŒã¿ã®åé¢ã§ãã Vlanã®æ§ç¯ãéããŠé³å£°ãšããŒã¿ãåé¢ããããšãéèŠã§ãã ã³ã³ãã¥ãŒã¿ãŒããµãŒããŒããã®ä»ã®ãããã¯ãŒã¯æ©åšã¯1ã€ã®VLANã«å±ããã¢ã¹ã¿ãªã¹ã¯ã§åäœããæ©åšïŒãµãŒããŒèªäœãã²ãŒããIPé»è©±ãªã©ïŒã¯å¥ã®VLANã«ãªããã°ãªããŸããã ããã¯ããŠãŒã¶ãŒèªèº«ãããã³ãŠãŒã¶ãŒãã·ã³ã§çºçããå¯èœæ§ã®ãããŠã€ã«ã¹ãIP-ATCã«æªåœ±é¿ãäžãããããã®éãèµ·ãããããªãããã«ããããã§ãã Vlanã®ã¹ããŒã ãå³ã«ç€ºããŸãã 4ã
å³ 4.é³å£°ãšããŒã¿ãç°ãªãVLANã«åé¢ããŸãã

2.3ãã°åæ
IP-ATCã·ã¹ãã ã®åäœäžãã¢ã¹ã¿ãªã¹ã¯èªäœãšä»ã®ã¢ããªã±ãŒã·ã§ã³ã¯ããã¹ãŠã®ã¢ã¯ãã£ããã£ãèšé²ããŸãã ãã°ã«ã¯èš±å¯ãããã¢ã¯ã·ã§ã³ãšèš±å¯ãããŠããªãã¢ã¯ã·ã§ã³ã®äž¡æ¹ã®ããŒã¿ãå«ãŸããŠãããããã€ã³ã·ãã³ããå®æçã«ç¢ºèªããããšãéåžžã«éèŠã§ãã æ¥ç¶ã®ç£èŠããã¹ã¯ãŒãã®éžæã®å¶åŸ¡ãè€æ°ã®æ¥ç¶è©Šè¡ã®ç£èŠãèšç»å€ã®ã¢ã¯ãã£ããã£ã®å¶åŸ¡ãå¿ èŠã§ãã
AsteriskããŒã«ãããã«ã¯ãç¹å®ã®æ¡ä»¶äžã§æ¥ç¶ã«å¯ŸããŠäœããã®ã¢ã¯ã·ã§ã³ãå®è¡ãããã°ã¢ãã©ã€ã¶ãŒãªã©ã®ããŒã«ã¯ãããŸããã AsteriskãµãŒããŒããããã³ã°ããå¯èœæ§ãé²ãããã«ç£èŠããããšãéèŠãªèšç»å€ã®ã¢ã¯ãã£ããã£ããããŸãããã®ãããªã¢ã¯ãã£ããã£ã®1ã€ã¯ããã¹ã¯ãŒãã®éžæïŒèŸæžå ã®ãã¹ã¯ãŒãã®åæïŒã§ãã Asteriskã«ã¯ãã«ãŒããã©ãŒã¹ãã¹ã¯ãŒããé²ããããªããŒã«ã¯ãããŸãããããã¯ã»ãã¥ãªãã£ã®éèŠãªãã€ã³ãã§ãããããAsteriskãApacheãsshãftpãªã©ã®å€ãã®ãµãŒãã¹ãšé£æºã§ããå€éšFail2BanãµãŒãã¹ã䜿çšããããšãææ¡ãããŠããŸãã ãã®ãµãŒãã¹ã®åäœã¯ããæ€åºãšåé€ããšãã1ã€ã®ååã«åºã¥ããŠããŸãããµãŒãã¹ã¯ãã°ããèªã¿åãããåæããè€æ°ã®ãã°ã€ã³è©Šè¡ãæ€åºãããšãIPTablesã¬ãã«ã§ãã®æ¥ç¶ããããã¯ããŸãã å³5ã¯ãFail2BanãµãŒãã¹ã®åäœã瀺ããŠããŸãã
å³ 5. Fail2Banã®åäœåç

ã·ã¹ãã å ã®ã€ãã³ãã«é¢ãããã°ïŒãã°ïŒããªã¢ãŒãã«ä¿åãããããªã¢ãŒããªãœãŒã¹ã«çµ¶ããã³ããŒããããšããå§ãããŸãã ããã¯ãæ»æè ãããã€ã¹ïŒç¹ã«IP PBXïŒã«ã¢ã¯ã»ã¹ãããšããã°ãã¡ã€ã«ãããã¹ãŠã®ã€ãã³ããåé€ããããšã«ãããèªåã®ååšãšã¢ã¯ã·ã§ã³ãé ãããšããããã§ãã ãã°ããªã¢ãŒããµãŒããŒã«éä¿¡ããããšããã°ã®ååšãé ãããšãå°é£ãŸãã¯äžå¯èœã«ãªããŸãã
2.4ã¢ã¹ã¿ãªã¹ã¯æ§æ
ãã®ç« ã§ã¯ãã¢ã¹ã¿ãªã¹ã¯æ§æã¬ãã«ã§ã®ã·ã¹ãã ã»ãã¥ãªãã£ã«ã€ããŠèª¬æããŸãã ãããã£ãŠãã¢ã¹ã¿ãªã¹ã¯èªäœã§æ§æããå¿ èŠãããã®ã¯ãIP-ATCã®ã»ãã¥ãªãã£ã匷åããããšã§ãã
ã¢ã¹ã¿ãªã¹ã¯ãå€éšã¢ãã¬ã¹ã«ã座ã£ãŠããããIPTablesã䜿çšããæ¹æ³ããªãå ŽåïŒåçIPã¢ãã¬ã¹ã§ããã€ã¹ãæ¥ç¶ããå¿ èŠãããç¶æ³ïŒãŸãã¯vpnã䜿çšãããŠããªãå Žåãæåã«è¡ãããšã¯æšæºããŒã5060ïŒsipïŒãä»»æã«å€æŽããããšã§ãå¥ã®ãã®ã ãããã£ãŠãã¢ã¹ã¿ãªã¹ã¯ãµãŒããŒããã以äžæ»æããªããšããç念ãåé¿ããŸãã å€éšããã®BruteForceæ»æããä¿è·ããŸãããã
ãããè¡ãæ¹æ³ã sip.confãã¡ã€ã«ãç·šéããŸã
[äžè¬]
; bindport = 5060 ; æšæºãã©ã¡ãŒã¿ãŒãã³ã¡ã³ãåããŸããã
bindport = 9060 ; ã»ãã¥ãªãã£äžã®çç±ãããããã©ã«ãã®ããŒããå¥ã®ç©ºãããŒãã«å€æŽããŸãã
æšæºããŒããå€æŽããããŒãã端æ«ããã€ã¹ã§ç€ºãããšãå¿ããªãã§ãã ããã ããã©ã«ãã§ã¯ãããã€ã¹ã¯ããŒã5060ã§ã¢ã¹ã¿ãªã¹ã¯ã«æ¥ç¶ããããšãããããäœãæ©èœããŸããã
sip.confæ§æã¬ãã«ã§ã·ã¹ãã ã®ã»ãã¥ãªãã£ãé«ããããã«ä»ã«ã§ããããšã¯äœã§ããã
[äžè¬]
alwaysauthreject = yes ; æ°å€ã«ããåæãããµãŒããŒãä¿è·ããŸãã å€ãnoã®å ŽåããµãŒããŒã¯ãã®ãããªãµãã¹ã¯ã©ã€ããŒãååšããªãããšãå¿ å®ã«å¿çããæ»æè ãæ¢åã®extãæšæž¬ãããŸã§ããµãŒããŒã¯ãã¹ã¯ãŒããééã£ãŠãããšå¿çããŸãã ãããã£ãŠãæ»æè ã¯å éšçªå·ã®ååšã«ã€ããŠåŠç¿ãããã¹ã¯ãŒããèŠã€ããããã ãã«æ®ããŸãã 次ã«ãéåžžã«å ·äœçãªå ç·çªå·ã®ãã¹ã¯ãŒãæ€çŽ¢ããããŸãã yesãªãã·ã§ã³ã¯ãååšããªããŠãŒã¶ãŒãšåãçç±ã§ãæ¢åã®ãŠãŒã¶ãŒã®èªèšŒèŠæ±ãæåŠããŸãã ããã«ãããè©æ¬ºåž«ãæ¢åã®å ç·çªå·ãææ¡ããããšãé£ãããªããŸãã
allowguest = no ; é»åã¡ãŒã«ã§å å ¥è ã«é»è©±ããããããšãã§ããå Žåããã€ã¬ã¯ãã²ã¹ãã³ãŒã«ã¢ãŒããããããã²ã¹ãã³ãŒã«ã§ã®ãµãŒããŒãžã®æ¥ç¶ãçŠæ¢ããŸãã
bindaddr = xxx.xxx.xxx.xxx ; ã¢ã¹ã¿ãªã¹ã¯ã¯ãsipãããã³ã«ã䜿çšããŠãã©ã®ã¢ãã¬ã¹ã§ãããã¯ãŒã¯æ¥ç¶ããªãã¹ã³ããŸãã ããã¯ããµãŒããŒãããŸããŸãªãããã¯ãŒã¯ã«æ¥ç¶ãããŠããå Žåãsipãåãå ¥ãããããã¯ãŒã¯ãæ瀺çã«æå®ããããšããå§ãããŸãã
[1000]
æåŠ= 0.0.0.0 / 0.0.0.0 ; ãã¹ãŠã®ã¢ãã¬ã¹ããã®æ¥ç¶ãçŠæ¢ããŸã
èš±å¯= xxx.xxx.xxx.xxx / 24 ; ãããã¯ãŒã¯xxx.xxx.xxx.xxxããã®æ¥ç¶ãèš±å¯ããŸã
secret = bdDfg12312fc ; æšæºçãªãã®ïŒadminãextã1000ãpassword ...ïŒä»¥å€ã®åŒ·åãªãã¹ã¯ãŒããå¿ èŠã§ãã
call-limit = 2 ; ãµãã¹ã¯ã©ã€ããŒã®åæåç·æ°ã«å¶éãèšå®ããŸããã
2.5ã³ãŒã«ãã©ã³ä¿è·ïŒãã€ã€ã«ãã©ã³ïŒ
é©åã«äœæããããã€ã€ã«ãã©ã³ïŒé話ã«ãŒãã£ã³ã°ãã©ã³ïŒã䜿çšãããšãã»ãã¥ãªãã£ãå€§å¹ ã«åäžããŸãã æåã«æšå¥šãããã®ã¯ããµãã¹ã¯ã©ã€ããŒãç¬èªã®ã«ãŒãã£ã³ã°ã«ãŒã«ãæã€ã³ã³ããã¹ãã«åé¢ããããšã§ãã
sip.confã§
[1000]
ã³ã³ããã¹ã= from_chef
[1001]
ã³ã³ããã¹ã= from_it
[1002]
ã³ã³ããã¹ã= from_fin
ã³ã³ããã¹ãã«ããåé¢ã¯ãé»è©±éä¿¡ã«å¯Ÿããå å ¥è ã®ããŸããŸãªæš©å©ãäžããæ©äŒãäžããŠãããŸãã 誰ããåœéçãªç®çå°ã«é»è©±ããããå¿ èŠããããšã¯éããªããããããã¯éèŠã§ãã 次ã«ãã«ãŒã«ãã³ã³ããã¹ãã«å²ãåœãŠãŸãã æ¡åŒµåã§ã conf
[èš±å¯]
exten => _ X.ãnãDialïŒSIP / operator / $ {EXTEN}ïŒ ; ãªãã¬ãŒã¿ãŒãä»ããåŒã³åºããèš±å¯ããŸã
exten => _ [12] XXXãnãDialïŒSIP / $ {EXTEN}ïŒ ; å éšæ¥ç¶ãèš±å¯ããŸã
[from_chef]
exten => _XããnãGotoïŒallowã$ {EXTEN}ã1ïŒ ; ãã¹ãŠã®åŒã³åºããã³ã³ããã¹ãã«éä¿¡ããŸã[èš±å¯]
[from_it]
exten => _9810ããnãHungupïŒïŒ ; åœéçãªç®çå°ãå¶éããŸã
exten => _XããnãGotoïŒallowã$ {EXTEN}ã1ïŒ ; ãã¹ãŠã®åŒã³åºããã³ã³ããã¹ãã«éä¿¡ããŸã[èš±å¯]
[from_fin]
exten => _9810ããnãHungupïŒïŒ ; åœéçãªç®çå°ãå¶éããŸã
exten => _989ããnãHungupïŒïŒ ; æ¹åãæºåž¯é»è©±ã®æ¹åã«å¶éããŸãã
exten => _XããnãGotoïŒallowã$ {EXTEN}ã1ïŒ ; ãã¹ãŠã®åŒã³åºããã³ã³ããã¹ãã«éä¿¡ããŸã[èš±å¯]
ãããã£ãŠãéèéšéã¯ãåœéçãªç®çå°ãã¢ãã€ã«ã®ç®çå°ãžã®é話ãçŠæ¢ãããŠããŸãã åœéçãªç®çå°ã®ã¿ãçŠæ¢ããŸãã ãŸããé ã¯ãã¹ãŠã®æ¥ç¶ãèš±å¯ãããŠããŸãã
é»åã¡ãŒã«ã®çŠæ¢ãããåŒã³åºãã«é¢ããæ å ±ãåä¿¡ããããã«ãéåã«ã€ããŠäŒèšããããã¢ã¹ã¿ãªã¹ã¯ã«æããŸãã ãã®ããã«ãå¥ã®ã³ã³ããã¹ã[ã¢ã©ãŒã ]ãè¿œå ããŸãã
[ã¢ã©ãŒã ]
exten => _9810Xãã1ãåçïŒzapreshenoïŒ ; ç§ãã¡ã¯ã圌ããã®æ¹åã§çŠæ¢ãããŠããããšãå å ¥è ã«ç¥ãããŸãã
exten => _9810XããnãSystemïŒecho "To" $ {EXTEN} "Ext" $ {CALLERIDïŒnumïŒ} | mail -s "8-10 ALARM" it_admin@list.ruïŒ ; åœéé»è©±ãããå Žåã¯ãFiscalitããéµéããŸãã
exten => _9810XããnãHangupïŒïŒ ; é»è©±ã眮ããŸãã
ãããŠããã®ã³ã³ããã¹ãã«çŠæ¢ãããåŒã³åºããéä¿¡ããŸã
[èš±å¯]
exten => _ X.ãnãDialïŒSIP / operator / $ {EXTEN}ïŒ ; ãªãã¬ãŒã¿ãŒãä»ããåŒã³åºããèš±å¯ããŸã
exten => _ [12] XXXãnãDialïŒSIP / $ {EXTEN}ïŒ ; å éšæ¥ç¶ãèš±å¯ããŸã
[from_chef]
exten => _XããnãGotoïŒallowã$ {EXTEN}ã1ïŒ ; ãã¹ãŠã®åŒã³åºããã³ã³ããã¹ãã«éä¿¡ããŸã[èš±å¯]
[from_it]
exten => _9810ããnãGotoïŒalarmã$ {EXTEN}ã1ïŒ ; ã³ã³ããã¹ãã«åœéé»è©±ããããŸã[ã¢ã©ãŒã ]
exten => _XããnãGotoïŒallowã$ {EXTEN}ã1ïŒ ; ãã¹ãŠã®åŒã³åºããã³ã³ããã¹ãã«éä¿¡ããŸã[èš±å¯]
[from_fin]
exten => _9810ããnãGotoïŒalarmã$ {EXTEN}ã1ïŒ ; ã³ã³ããã¹ãã«åœéé»è©±ããããŸã[ã¢ã©ãŒã ]
exten => _989ããnãHungupïŒïŒ ; æ¹åãæºåž¯é»è©±ã®æ¹åã«å¶éããŸãã
exten => _XããnãGotoïŒallowã$ {EXTEN}ïŒ ; ãã¹ãŠã®åŒã³åºããã³ã³ããã¹ãã«åããŸã[èš±å¯]
ãããã£ãŠãçŠæ¢ãããæ¹åããããã¯ããã ãã§ãªããã€ã³ã·ãã³ããçºçããå ŽåãïŒextïŒãééããããšããŠããã¡ãã»ãŒãžãååŸããŸãã ãããã£ãŠããããŠãµãŒããŒããããã³ã°ãããããšãç解ã§ããããã«ãªããå·šé¡ã®éä¿¡æéãçºçãããšãã§ã¯ãªããªããŸãã
ãããã¢ã¹ã¿ãªã¹ã¯ã®å©ç¹ã§ããdilplanã䜿çšãããšãã«ãŒãã£ã³ã°ãæè»ã«æ§æã§ããŸããããŸããŸãªãã©ã¡ãŒã¿ãŒã«åŸã£ãŠæ¹åãçŠæ¢ãããããµãã¹ã¯ã©ã€ããŒã®æš©å©ãåºå¥ããããçŠæ¢ãããé話ã«é¢ããéç¥ãèšå®ããããé話ã®å¶éæéãèšå®ãããããã³ã³ãŒãé話ãªã©ãèšå®ãããããŠãIP-ATCã»ãã¥ãªãã£ãåäžãããããšãã§ããŸããåçIPã¢ãã¬ã¹ãæã€ãªã¢ãŒããŠãŒã¶ãŒã«ã¯PINã³ãŒãã䜿çšããããšããå§ãããŸããèš±å¯/æåŠãšiptablesãå¶éããããšã¯ã§ããªãããã§ãããã®å Žåãåœéçãªå®å ãéããæšæºããŒãïŒ5060ïŒãå¥ã®ãã®ã«å€æŽããé話ãã«ãŒãã£ã³ã°ããããšããå§ãããŸããã³ã³ãŒãã«ãã£ãŠã
2.6 Linuxã®æ§æ
AsteriskèªäœãšLinux OSèªäœã®äž¡æ¹ã«ãããã©ã«ãã§èµ·åããããµãŒãã¹ããããŸãããäœæ¥ã«ã¯å¿ èŠãããŸããããããã£ãŠãæšå¥šäºé ã®1ã€ã¯ãAsteriskãšLinuxã®äž¡æ¹ã§æªäœ¿çšã®ãµãŒãã¹ïŒã¢ãžã¥ãŒã«ïŒãç¡å¹ã«ããå¿ èŠãããããšã§ãã
ã¢ã¹ã¿ãªã¹ã¯ã¯ãããŸããŸãªã³ãŒããã¯ãã³ãã³ããããŒã¿ããŒã¹ãæäœããããã®ããŒã«ããã£ãã«ãªã©ãååçã«ã¯åœ¹ã«ç«ããªãå¯èœæ§ã®ããå€æ°ã®ã¢ãžã¥ãŒã«ãããŒãããŸããäžèŠãªã¢ãžã¥ãŒã«ãç¡å¹ã«ãããšãã¡ã¢ãªã解æŸãããã ãã§ãªããIP-ATCã®è匱æ§ãäœããªããŸããç§ãã¡ãç®æããŠããã®ã¯ããããŠãããã§ããããã§ãã
autoload = yesãã©ã¡ãŒã¿ãŒã¯/etc/asterisk/modules.confãã¡ã€ã«ã§æå®ãããŸããããã«ãããèµ·åæã«/ usr / lib / asterisk / modulesãã©ã«ããŒã«ãããã¹ãŠã®ãµãŒãã¹ã匷å¶çã«åæåããã³éå§ãããŸãã 1ã€ãŸãã¯å¥ã®äžèŠãªãµãŒãã¹ã®éå§ãçŠæ¢ããã«ã¯ã
/ etc / asterisk / modules.confãã¡ã€ã«ã«æ¬¡ã®è¡ãèšè¿°ããå¿ èŠããããŸãnoload => chan_gtalk.so ; Gtalkãã£ãã«ã¢ãžã¥ãŒã«ã
noload => app_morsecode.so ;ã¢ãŒã«ã¹ç¬Šå·ã§äžããããæååã®éä¿¡ã
noload => cdr_pgsql.so ; PostgreSQLããŒã¿ããŒã¹ã«CDRããŒã¿ãä¿åããããã®ã¢ãžã¥ãŒã«ã
ãã®ä»ã¯ãå¿ èŠãªã¢ãžã¥ãŒã«ãšå¿ èŠã§ãªãã¢ãžã¥ãŒã«ã«ãã£ãŠç°ãªããŸãã
ãŸããLinuxèªäœã«çŽæ¥èªã¿èŸŒãŸããŠãããµãŒãã¹ããããŸãããIP-ATCãæ©èœããããã«å¿ èŠã§ã¯ãªãå¯èœæ§ããããŸããç¡å¹ã«ããããšããå§ãããŸãã chkconfig âlistã³ãã³ãã䜿çšããŠãå®è¡äžã®ãµãŒãã¹ã確èªããã©ã®ãµãŒãã¹ãåé·ã§ããããå€æã§ããŸãã CentOS 5ã§ããã©ã«ãã§bluetoothãµãŒãã¹ãããŒããããŠãããšä»®å®ããŸããAsteriské»è©±äº€ææ©ã§ã¯ãã®ãµãŒãã¹ã¯äžèŠã§ããchkconfigbluetooth offã³ãã³ãã§èµ·åããåé€ããŸããä»ã®äžèŠãªãµãŒãã¹ã«ã€ããŠãåãããšãè¡ããŸãããããã®æäœã¯ãã¹ãŠãéåžžã«æ éãã€ææ ®æ·±ãè¡ããªããã°ãªããŸãããããã§ãªããã°ãOSèªäœãšã¢ã¹ã¿ãªã¹ã¯ãµãŒããŒã®äž¡æ¹ãã眮ããããšãã§ããŸãã
OSãšã¢ã¹ã¿ãªã¹ã¯ã管çããã«ã¯ãIP-ATC管çè ããªã¢ãŒãã¢ã¯ã»ã¹ãå¿ èŠãšããŸããæå·åãªãã®ãªã¢ãŒãã¢ã¯ã»ã¹ã«ãããã³ã«ïŒtelnetãªã©ïŒã䜿çšããããšã¯ãå§ãã§ããŸãã; SSHïŒSecure SHellïŒã䜿çšããããšããå§ãããŸãããµãŒããŒãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã«äœ¿çšãããSSHãµãŒãã¹ã¯ãPBXã³ã³ãããŒã«ã»ã³ã¿ãŒã®ã¡ã€ã³ãã¢ã§ããã»ãã¥ãªãã£ã¬ãã«ãäžããã«ã¯ãPBX管çè ã次ã®å¯Ÿçãå®è¡ããããšããå§ãããŸãã
1.ããŒãã®å€æŽãããã©ã«ãã®SSHããŒãã¯22çªç®ã§ããå€ãã®ããã«ãŒã¯ãããŒã22ãéããŠãããµãŒããŒã«ã€ããŠã€ã³ã¿ãŒããããã¹ãã£ã³ããããããã¯ã©ãã¯ããããšããŸãã 1ã65535ã®ç¯å²ã®å¥ã®ããŒããäœæããPortãã£ã¬ã¯ãã£ãã§æå®ããŠsshãæ§æããå¿ èŠããããŸãã
ãŸãããµãŒããŒã«æ¥ç¶ãããšãã«ã¯ã©ã€ã¢ã³ãã§ãã®ããŒããæå®ããããšãå¿ããŠããŸãã
2. [AllowUsers]ãã£ã¬ã¯ãã£ãã§SSHãããã³ã«çµç±ã§ã·ã¹ãã ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã®æ瀺çãªãªã¹ããã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãå€ãã®ãããã·ã«æäŸããå¿ èŠãããå Žåã¯ããããããªã¹ãããŸãã
3. SSHãããã³ã«ããŒãžã§ã³2ã®ã¿ã䜿çšããããšããå§ãããŸã
ã4.çŽæ¥ã«ãŒãã¢ã¯ã»ã¹ãæåŠããŸãã rootãŠãŒã¶ãŒã¯æ£ãããã¹ã¯ãŒããå ¥åããããšããŠãã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãæåŠããããããããã¯éåžžã«è€éã«ãªãããã¹ã¯ãŒãã®ç·åœããæ»æãäžå¯èœã«ããŸããå¿ èŠã«å¿ããŠãéç¹æš©ã¢ã«ãŠã³ãã§ã®ãªã¢ãŒããã°ã€ã³åŸã«ã®ã¿ãsudoãµãã·ã¹ãã ã䜿çšããŠã«ãŒãã¢ã¯ã»ã¹ãååŸããŸãã
5.ãã¹ã¯ãŒããŸãã¯èšŒææžã®å ¥åã«æéå¶éã䜿çšããŸãããã¹ã¯ãŒããå ¥åããããã«å¯èœãªæå°æéïŒ1ç§ãªã©ïŒãèšå®ãããšãæ»æè ãæ··ä¹±ãããå¯èœæ§ããããŸãã
äžèšã®æšå¥šäºé ã¯ãã¹ãŠãæ§æãã¡ã€ã«/ etc / ssh / sshd_configã«åæ ãããŸãã
ããŒã30222
AllowUsers ats admin
ãããã³ã«2
PermitRootLogin no
LoginGraceTime 1s
蚌ææžã䜿çšããŠSSHãå ¥åããããšããå§ãããŸãã SSHã䜿çšããŠãªã¢ãŒããã¹ãã«é »ç¹ã«æ¥ç¶ããå Žåãæ¥ç¶ã®ã»ãã¥ãªãã£ã確ä¿ãã1ã€ã®æ¹æ³ã¯ããã¹ã¯ãŒãããããã¯ãŒã¯ãä»ããŠéä¿¡ããããã·ã¹ãã ããã«ãŒããã©ãŒã¹æ»æã«èæ§ããããããå ¬é/ç§å¯SSHããŒã䜿çšããããšã§ãã
Linuxã§ã®å ¬é/ç§å¯SSHããŒã®äœæã¯éåžžã«ç°¡åã§ãã
1.ã³ã³ãœãŒã«ã§ãssh-keygen ât rsaãšå ¥åããŸããã®å ŽåãRSAã¯é察称æå·åã¢ã«ãŽãªãºã ã§ãã DSAïŒããžã¿ã«çœ²åã¢ã«ãŽãªãºã ïŒã䜿çšããããšãã§ããŸãã
2.次ã«ãããŒãä¿åããå Žæãæå®ããããšãææ¡ããŸããããã©ã«ãã§ã¯ãããã¯ããŒã ãã£ã¬ã¯ããªã®.sshãã©ã«ããŒã§ããããã©ã«ãèšå®ãåãå ¥ããã«ã¯ããEnterããæŒããŸãã
3.次ã«ããã¹ãã¬ãŒãºã®å ¥åãæ±ããããŸããããã¯ããªã¢ãŒããã¹ãã«æ¥ç¶ããããã®ãã¹ãã¬ãŒãºã§ã¯ãããŸãããããã¯ç§å¯éµã®ããã¯ã解é€ããããã®ãã¹ãã¬ãŒãºã§ãããããç§å¯éµãä¿åãããŠããŠãããªã¢ãŒããµãŒããŒã«ã¢ã¯ã»ã¹ããã®ã«åœ¹ç«ã¡ãŸããããã¹ãã¬ãŒãºã®å ¥åã¯ãªãã·ã§ã³ã§ãã空ã®ãŸãŸã«ããã«ã¯ãEnterããŒãæŒããŸãã
4.ããŒãçæãããŸãã .sshãã©ã«ããŒã®ããŒã ãã£ã¬ã¯ããªã«ç§»åããŸããããŒid_rsaãšid_rsa.pubã¯ããã«ããã¯ãã§ãã
5.次ã«ãæ§æãã¡ã€ã«/ etc / ssh / sshd_configãç·šéããŸã
RSAAuthenticationã¯ã
PubkeyAuthenticationã¯ã
PasswordAuthenticationããã
ãããã£ãŠã蚌ææžã䜿çšããsshãã°ã€ã³ã®ã¿ãèš±å¯ããŸãã
6. id_rsa.pubãã¡ã€ã«ã®å 容ãæ°ããäœæãããauthorized_keysãã¡ã€ã«ã«
ã³ããŒãããŸãcat id_rsa.pub >> authorized_keysã³ãã³ãã䜿çšããŠãã¡ã€ã«ãã³ããŒããã³äœæããŸã
7.ãã¡ã€ã«ã«èªã¿åãæš©éãšæžã蟌ã¿æš©éãèšå®ããŸã
chmod 600 authorized_keys
8ã SSHçµç±ã§ãµãŒããŒã«æ¥ç¶ããŸãã
9.ã¯ã©ã€ã¢ã³ãïŒPuttyïŒããã®ç§å¯éµãç解ã§ããããã«ãputtygenããã°ã©ã ãä»ããŠå®è¡ïŒããŒãïŒããŸããåºåïŒç§å¯ããŒã®ä¿åïŒã§ãç§å¯ããŒïŒ* .ppkïŒãååŸããŸãã
10.次ã«ãããŒãã»ãã·ã§ã³ã«è¿œå ããŸãã PuTTYãèµ·åããå¿ èŠãªã»ãã·ã§ã³ãããŒãããããæ¥ç¶ã®ããŒã¿ãå ¥åããŠãSSH-Authãã«é²ã¿ããputtygenãã®åŠçã§ååŸããç§å¯éµãéžæããŸãã
11. [æ¥ç¶-ããŒã¿]ã¡ãã¥ãŒã«ç§»åãã[èªåãã°ã€ã³ãŠãŒã¶ãŒå]ãã£ãŒã«ãã«ãããŒãçæããããã°ã€ã³ãå ¥åããŸãã
12.ã»ãã·ã§ã³ãä¿åãã/ etc / init.d / ssh reload serverã§SSHãµãŒãã¹ãåèµ·åããŸã
13.æ¥ç¶ããŸãã
ãããã£ãŠãSSHæ¥ç¶ã®ã»ãã¥ãªãã£ã匷åããŸããã
2.7åšèŸºæ©åšã®ä¿è·
éèŠãªãã€ã³ãã®1ã€ã¯ãäœããã®æ¹æ³ã§ã¢ã¹ã¿ãªã¹ã¯ã«æ¥ç¶ãããŠããæ©åšã®ä¿è·ã§ãããã®ãããªæ©åšã¯ãip-phonesãvoip-gateãªã©ã§ãã IP-ATCã·ã¹ãã ã¯ãåšèŸºæ©åšãä¿è·ãããŠããªãéãå®å šã§ã¯ãããŸããããã®æ©åšãä¿è·ããããã«ãããã€ãã®å¯Ÿçãå®è¡ããããšãææ¡ã
ãŸãã1.ããã¯ãæ©åšãœãããŠã§ã¢ã®æŽæ°ã§ãããã®åŽé¢ã«åŸãããšãéèŠã§ãããæ°ããããã¡ãŒã ãŠã§ã¢ããçºçããå Žåã¯ãé©åãªããã€ã¹ã§æŽæ°ããŠãã ãããå€ãã®è匱æ§ã¯æŽæ°ã«ããä¿®æ£ãããŠããŸãã
2.ãã®ç¹ã¯ãã§ã«äžã§è°è«ãããŠããŸããå¯èœã§ããã°ãããŒã¿ãšã¯å¥ã®VLANã«IPæ©åšãé 眮ããŸãã
3.æ©åšããã¡ã€ã¢ãŠã©ãŒã«ã®å åŽã«çœ®ããŸãã IPæ©åšã«å€éšIPã¢ãã¬ã¹ãäžããããšã¯éåžžã«æãŸãããããŸããã
4.è匱æ§ã¯ãæ©åšã®WebããŒã¹ã®ã€ã³ã¿ãŒãã§ãŒã¹ã§ãã Webã€ã³ã¿ãŒãã§ãŒã¹ãä»ãããããã³ââã°ããæ©åšãä¿è·ããããã«ãã»ãã³ãã£ãã¯ã®å€§ããªè² è·ããããªãããããŸãã¯voip-gateã«åŒ·åãªãã¹ã¯ãŒããèšå®ããªããããip-phoneã«å¯ŸããŠç¡å¹ã«ããããšããå§ãããŸãã
5.ãµãŒãã¹ããŒãã®å€æŽã Astersikãšåæ§ã«ãIPé»è©±ãšvoip-gateã§sipããŒãã5060ããä»ã®ããŒãã«å€æŽããããšããå§ãããŸããããã«ãããã¹ãã£ã³ã«å¯Ÿããèæ§ãåäžããŸãã
ã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠãããœãããã©ã³ã«ã€ããŠè©±ããŠããå Žåãã»ãã¥ãªãã£ã«ã€ããŠè©±ãã®ã¯å°é£ã§ãããã®å Žåã®å¯äžã®å¹æçãªæ段ã¯ãçŠæ¢ãããé»è©±ããããè©Šã¿ã管çè ã«éç¥ããæ©èœãåããéãããã³ã³ããã¹ãã§ãã
2.8管çæªçœ®
äžèšã®ãã¹ãŠã®æšå¥šäºé ã«åŸã£ããšããŠããã·ã¹ãã ã¯äŸç¶ãšããŠãããã³ã°ãããå¯èœæ§ããããŸã-絶察çãªã»ãã¥ãªãã£ã¯ãããŸããããããã£ãŠã管çæªçœ®ãéèŠã§ããããããèæ ®ããŠãã ããã
1.çµç¹ãåœéé»è©±ãå¿ èŠãšããªãå Žåãéä¿¡äºæ¥è ã®ã¬ãã«ã§åœéçãªç®çå°ããããã¯ã§ããŸãããã®ãããªåŒã³åºããéåžžã«å°ãªãå Žåãåœéçãªç®çå°ãžã®åŒã³åºããå€æ°ããå Žåããããã®æ¥ç¶ããããã¯ããããšã§ããã®æ¹åã®ç£èŠã«ã€ããŠãããã€ããŒã«åæã§ããŸãã
2.ã·ã³ãã«ã ãå¹æçãªæ¹æ³ãéžæããããšãã§ããŸã-ããã¯ãéä¿¡äºæ¥è ã¬ãã«ã§ã®è«æ±é¡ãå¶éããããšã§ããé»æ°éä¿¡äºæ¥è ã«å¶éãèšå®ããããäŸé Œããããšãã§ããŸããå¶éã¯ç§ãã¡èªèº«ã決å®ããŸãïŒéä¿¡ã®å¹³åæé¡+ç¹å®ã®å²åïŒãå¶éã«éãããšãéä¿¡ã¯ãããã¯ãããŸãããã®æªçœ®ã¯ãIP-ATCã«éåããå Žåã«æ·±ããã€ãã¹ã«ãªããŸããã
3.ãœãããã©ã³ã«ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ä¿è·ã
4.管çè ãå€æŽãããšãã«ãã¹ã¯ãŒããå€æŽããŸãã
5.ã¹ã¿ããã®æèãé«ããŸãã
6.æãéèŠãªãã€ã³ãã®1ã€-絶察çãªä¿è·ããªãããšãå¿ããªãã§ãã ãããã·ã¹ãã ã®æ°ããè匱æ§ãæ°ãããªã¹ã¯ã®åºçŸãªã©ãåžžã«ç£èŠããã³ç£æ»ããå¿ èŠããããŸããäœããæ€åºãããå Žåã¯ãã·ã¹ãã ã®ã»ãã¥ãªãã£ã·ã¹ãã ã§ãããèæ ®ããŠãã ãããã€ãŸãããã®ã·ã¹ãã ã«é©çšããã«ã¯ãããã³ã°ãµã€ã¯ã«ããå¿ èŠã§ãã
çµè«
ãã®äœæ¥ã«ãããã·ã¹ãã ãæ£ããã»ããã¢ããããããšããã¬ãã©ããŒåéã§åªããæ©èœãåããæãå®å šãªã·ã¹ãã ã®1ã€ã«ã¢ã¹ã¿ãªã¹ã¯ãäœæã§ãããã®ã·ã¹ãã ã¯CiscoãAvayaãªã©ã®äž»èŠãã³ããŒã®æ©èœã«å£ããªããšãã仮説ãæããã«ãããããšãé¡ã£ãŠããŸãã ã
ãŸããçµ±èšã«ãããšã圌ããã¢ã¹ã¿ãªã¹ã¯ãããé »ç¹ã«ãããã³ã°ãããšããäºå®ã¯ãã¢ã¹ã¿ãªã¹ã¯ãä»ã®ã·ã¹ãã ãããã¯ããã«å°ãªããšã³ããªãããå€ãæã£ãŠãããšããäºå®ã«ãã£ãŠæ±ºå®ãããŸããã€ãŸããã€ã³ã¿ãŒãããäžã®ããã€ãã®èšäºãèªãã åŸãããããªã¢ã³ITå°é家ã¯ã¢ã¹ã¿ãªã¹ã¯ãå±éã§ããŸãããè³æ ŒããŸã äžè¶³ããŠãããããã·ã¹ãã ã¯ååãšããŠæ©èœããŸãããè匱ã§ãããŸããåçšãœãªã¥ãŒã·ã§ã³ã®å±éã«ã¯ãã»ãã¥ãªãã£ã®åé¡ã«ååãªæ³šæãæãããã®åéã®å°é家ãå¿ èŠã§ãããã®åçŽãªçç±ã«ãããã¢ã¹ã¿ãªã¹ã¯ã¯ããé »ç¹ã«ãããã³ã°ãããŸãã
IP-ATCã¢ã¹ã¿ãªã¹ã¯ã¯ãæ£ããæ§æãããŠããå Žåãå®å šãªã·ã¹ãã ã§ãã
åèæç®ãªã¹ã
1. Meggelen J.ãMadsen L.ãSmith J. Asteriskâ¢ïŒé»è©±ã®æªæ¥ã第2çã -ãããè±èªãã-ãµã³ã¯ãããã«ãã«ã¯ïŒSymbol-Plusã2009ã-656 pããIllã
2. Platov M. Asterisk and Linux-IPãã¬ãã©ããŒã®äœ¿åœ[ããã¹ã] / M. Platov //ã·ã¹ãã 管çè ã -2005ãNoã31ã-S. 12-19ã
3. Platov M. Asterisk and LinuxïŒIPãã¬ãã©ããŒã®äœ¿åœãã¢ã¯ã·ã§ã³2 [ããã¹ã] / M Platov //ã·ã¹ãã 管çè ã -2005ãNoã32ã-S. 32-38ã
4. Platov M. Asterisk and LinuxïŒIPãã¬ãã©ããŒã®äœ¿åœãã¢ã¯ã·ã§ã³3 [ããã¹ã] / M Platov //ã·ã¹ãã 管çè ã -2005ãNoã33ã-S. 10-19ã
5.ã¢ã¹ã¿ãªã¹ã¯ç¥èããŒã¹[é»åãªãœãŒã¹]ã -ã¢ã¯ã»ã¹ã¢ãŒãïŒasterisk.ru/knowledgebase
6. Voxlinkãã¬ããžããŒã¹[é»åãªãœãŒã¹]ã -ã¢ã¯ã»ã¹ã¢ãŒãïŒwww.voxlink.ru/kb
7. HabrHabrã VoIPãããã¯ãŒã¯ã®ã»ãã¥ãªãã£[é»åãªãœãŒã¹]ã -ã¢ã¯ã»ã¹ã¢ãŒãïŒhabrahabr.ru/post/145206
8. .., .., .. IP-. â.: -, 2003. -252 .: .
9. .., .., .. IP-. âM.: , 2001. -336 .: .
10. CITForum. IP- â . . [ ]. â : citforum.ru/security/articles/ipsec
PS
Voxlink .
, , IP- . , - .