VPNãããã€ããŒã¯éåžžãããã€ãã®æ¥ç¶ã¿ã€ãã®éžæãæäŸããŸããç°ãªãæéãã©ã³ã®äžéšãšããŠããŸãå Žåã«ãã£ãŠã¯åäžã®æéãã©ã³ã®äžéšãšããŠæäŸããŸãã ãã®èšäºã®ç®çã¯ãå©çšå¯èœãªVPNãªãã·ã§ã³ã確èªãã䜿çšãããŠãããã¯ãããžãŒã®åºæ¬ãç解ããã®ã«åœ¹ç«ã¡ãŸãã
æå·åããŒã®é·ãã«é¢ãã泚æ
倧ãŸãã«èšãã°ãæå·ã®äœæã«äœ¿çšãããããŒã®é·ãã¯ãçŽæ¥åæã䜿çšããŠã¯ã©ãã¯ããã®ã«ãããæéã決å®ããŸãã é·ãããŒãæã€æå·ã¯ãçããã®ãããåæã«ããªãé·ãæéãå¿ èŠã§ãïŒããã«ãŒããã©ãŒã¹ããšã¯ãæ£ããçµã¿åãããèŠã€ãããŸã§ãã¹ãŠã®å¯èœãªçµã¿åãããåæããããšãæå³ããŸãïŒã
çŸåšã128ãããæªæºã®é·ãã®ããŒã䜿çšããŠVPNæå·åãèŠã€ããããšã¯ã»ãšãã©äžå¯èœã§ãããææ¡ãããŠããOpenVPNãœãªã¥ãŒã·ã§ã³ã§256ãããã®æå·åãèŠã€ããããšã¯ãŸããŸãå°é£ã«ãªã£ãŠããŸãã ãããããããã®æ°åã¯å®éã«ã¯ã©ãããæå³ã§ããã256ãããæå·åã¯128ãããããæ¬åœã«å®å šã§ããïŒ
ç°¡åãªçãã¯ãå®éã«ã¯ãããŸããã 256ãããããŒããããã³ã°ããã«ã¯ã128ãããããŒããããã³ã°ããããã2128é«ãèšç®èœåãå¿ èŠã«ãªãã®ã¯äºå®ã§ãã ããã¯ã3.4x10 ^ 38ã®æäœïŒ128ãããããŒã®çµã¿åããã®æ°ïŒãå¿ èŠã§ããããšãæå³ããŸããããã¯ãæ¢åã®ã³ã³ãã¥ãŒã¿ãŒã«ãšã£ãŠããè¿ãå°æ¥ã«ãããŠãåæ¥ã§ãã æéã®ã¹ãŒããŒã³ã³ãã¥ãŒã¿ãŒã䜿çšããå ŽåïŒ2011ã«ããã°ããã®èšç®é床ã¯10.51ãã¿ããããã¹ã§ãïŒãåæã«ãã£ãŠ128ãããAESããŒãã¯ã©ãã¯ããã«ã¯1.02x10 ^ 18ïŒçŽ10åïŒå¹ŽããããŸãã
å®éã«ã¯ã128ãããæå·ã¯ãã«ãŒããã©ãŒã¹ã«ãã£ãŠè§£èªã§ããªãããããã®é·ãã®ããŒã§ã»ãšãã©ã®ã¢ããªã±ãŒã·ã§ã³ã«ååã§ãããšèšãã®ã¯æ£ããã§ãããã çã®åå·çè ïŒããšãã°ãä»åŸ100幎以äžç§å¯ã«ãã¹ã極ç§ææžãæ±ãæ¿åºè·å¡ïŒã®ã¿ã256ãããæå·åã䜿çšã§ããŸãïŒããšãã°ãç±³åœæ¿åºã¯NISTèªå®ã®256ãããAESæå·ã䜿çšããŸãïŒ ïŒ
ã§ã¯ããªãVPNãããã€ããŒã256ãããæå·åïŒ2048ãããã¯èšããŸã§ããªãïŒãæäŸããããšããŸããŸãäžè¬çã«ãªã£ãŠããã®ã§ããããïŒ ç¹ã«ã256ããã以äžã®ããŒã§æå·åã䜿çšãããšãããå€ãã®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ãå¿ èŠã«ãªãããšãèæ ®ããå Žåã çãã¯ç°¡åã§ã-ããŒã±ãã£ã³ã°ã é·ãæå·åããŒã䜿çšããŠVPNãµãŒãã¹ã販売ããæ¹ãç°¡åã§ãã
倧äŒæ¥ãæ¿åºã¯ãé·ãããŒã«ãã£ãŠæäŸãããè¿œå ã®ã»ãã¥ãªãã£ãå¿ èŠã«ãªãå ŽåããããŸãããå¹³åçãªããŒã ãŠãŒã¶ãŒã«ãšã£ãŠã¯ã128ãããVPNã§ååã§ãã
ããŸããŸãªæå·ã«ã¯è匱æ§ãããããããã䜿çšããŠãã°ããã¯ã©ãã¯ããããšãã§ããŸãã ããŒãã¬ãŒãªã©ã®ç¹å¥ãªããã°ã©ã ã䜿çšã§ããŸãã èŠçŽãããšã128ããããè¶ ããããŒã§ã®æå·åã®äœ¿çšã¯ãå®éã«ã¯ã»ãšãã©ã®ãŠãŒã¶ãŒã«ãšã£ãŠã»ãšãã©æå³ããªããšèšããŸãã
PPTP
ãã€ã³ãããŒãã€ã³ããã³ããªã³ã°ãããã³ã«ïŒãã€ã³ãããŒãã€ã³ããã³ããªã³ã°ãããã³ã«ïŒã¯ããã€ã€ã«ã¢ããã¢ã¯ã»ã¹ãããã¯ãŒã¯ãä»ããŠVPNãç·šæããããã«Microsoftã«ãã£ãŠéçºããããããã³ã«ã§ãã PPTPã¯ãé·å¹Žã«ããã£ãŠVPNãæ§ç¯ããããã®æšæºãããã³ã«ã§ãã ããã¯VPNãããã³ã«ã«éãããã»ãã¥ãªãã£ïŒMS-CHAP v.2ã§æããã䜿çšãããïŒã®ããã«ããŸããŸãªèªèšŒæ¹æ³ã«äŸåããŠããŸãã VPNããµããŒãããã»ãšãã©ãã¹ãŠã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšããã€ã¹ã§æšæºãããã³ã«ãšããŠäœ¿çšã§ãããããè¿œå ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããå¿ èŠãªããVPNã䜿çšã§ããŸãã PPTPã¯ãäŒæ¥ãšVPNãããã€ããŒã®äž¡æ¹ã§åŒãç¶ã人æ°ã®ããéžæè¢ã§ãã ãŸããã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ã®äœ¿çšéãå°ãªããããé«éã§ãããšããå©ç¹ããããŸãã
PPTPã¯éåžž128ãããã®æå·åã§äœ¿çšãããŸããã1999幎ã«ãã®ãããã³ã«ãWindows 95 OSR2ã«å«ãŸããåŸãä»åŸæ°å¹Žéã§å€ãã®è匱æ§ãçºèŠãããŸããã æãæ·±å»ãªã®ã¯ãèªèšŒãããã³ã«MS-CHAP v.2ã®è匱æ§ã§ããã ãã®è匱æ§ã䜿çšããŠãPPTPã¯2æ¥ã§ã¯ã©ãã¯ãããŸããã Microsoftã¯ãã®ãšã©ãŒãä¿®æ£ããŸãããïŒMS-CHAP v.2ã§ã¯ãªãPEAPèªèšŒãããã³ã«ã䜿çšïŒãVPNãšããŠäœ¿çšããããã«L2TPãŸãã¯SSTPãã³ã¯ãæšå¥šããŠããŸããã
é·æïŒ
- PPTPã¯ã©ã€ã¢ã³ãã¯ãã»ãŒãã¹ãŠã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«çµã¿èŸŒãŸããŠããŸã
- èšå®ãéåžžã«ç°¡å
- éãåäœããŸã
çæïŒ
- å®å šã§ãªãïŒè匱ãªèªèšŒãããã³ã«MS-CHAP v.2ããŸã å€ã䜿çšãããŠããŸãïŒ
L2TPããã³L2TP / IPsec
ã¬ã€ã€2ãã³ãã«ãããã³ã«ã¯ãããèªäœãééãããã©ãã£ãã¯ã®æå·åãšæ©å¯æ§ãæäŸããªãVPNãããã³ã«ã§ãã ãã®ãããéåžžãã»ãã¥ãªãã£ãšãã©ã€ãã·ãŒã®ããã«IPsecæå·åãããã³ã«ã䜿çšãããŸãã
L2TP / IPsecã¯ãææ°ã®ãã¹ãŠã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšVPNäºæããã€ã¹ã«çµ±åãããŠãããPPTPãšåãããã«ç°¡åã«æ§æã§ããŸãïŒéåžžã¯åãã¯ã©ã€ã¢ã³ãã䜿çšãããŸãïŒã L2TPã¯UDPããŒã500ã䜿çšãããããåé¡ãçºçããå¯èœæ§ããããŸããUDPããŒã500ã¯ãNATã®èåŸã«ããå Žåããã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠãããã¯ãããå¯èœæ§ããããŸãã ãã®ãããã«ãŒã¿ãŒã®è¿œå æ§æïŒããŒã転éïŒãå¿ èŠã«ãªãå ŽåããããŸãã ã¡ãªã¿ã«ãããšãã°SSLã¯TCPããŒã443ã䜿çšããŠãéåžžã®HTTPSãã©ãã£ãã¯ãšåºå¥ã§ããŸããã
IPsecã«ã¯çŸåšãé倧ãªè匱æ§ã¯ãªããAESãªã©ã®æå·åã¢ã«ãŽãªãºã ã䜿çšããå Žåãéåžžã«å®å šã§ãããšèããããŠããŸãã ãã ããããŒã¿ã2åã«ãã»ã«åãããããSSLãœãªã¥ãŒã·ã§ã³ïŒOpenVPNãSSTPãªã©ïŒã»ã©å¹ççã§ã¯ãªããããåäœãå°ãé ããªããŸãã
é·æïŒ
- ãšãŠãå®å š
- èšå®ãç°¡å
- ææ°ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§å©çšå¯èœ
çæïŒ
- OpenVPNãããåäœãé ã
- è¿œå ã®ã«ãŒã¿ãŒæ§æãå¿ èŠã«ãªãå ŽåããããŸã
Openvpn
OpenVPNã¯ãOpenSSLã©ã€ãã©ãªãšSSLv3 / TLSv1ãããã³ã«ã䜿çšããéåžžã«æ°ãããªãŒãã³ãœãŒã¹ãã¯ãããžãŒã§ãããä¿¡é Œæ§ã®é«ãVPNãœãªã¥ãŒã·ã§ã³ãæäŸããä»ã®å€ãã®ãã¯ãããžãŒãšãšãã«äœ¿çšãããŸãã ãã®äž»ãªå©ç¹ã®1ã€ã¯ãOpenVPNã®èšå®ãéåžžã«æè»ã§ããããšã§ãã ãã®ãããã³ã«ã¯ã443 TCPããŒããå«ãä»»æã®ããŒãã§åäœããããã«èšå®ã§ããŸããããã«ãããéåžžã®HTTPSïŒGmailãªã©ã䜿çšïŒã§OpenVPNå ã®ãã©ãã£ãã¯ããã¹ã¯ã§ããããããããã¯ããããšãå°é£ã§ãã
OpenVPNã®ãã1ã€ã®å©ç¹ã¯ãæå·åã«äœ¿çšãããOpenSSLã©ã€ãã©ãªãå€ãã®æå·åã¢ã«ãŽãªãºã ïŒAESãBlowfishã3DESãCAST-128ãCameliaãªã©ïŒããµããŒãããããšã§ãã VPNãããã€ããŒã䜿çšããæãäžè¬çãªã¢ã«ãŽãªãºã ã¯ãAESãšBlowfishã§ãã AESã¯æ°ããæè¡ã§ãããäž¡æ¹ãšãå®å šãšèŠãªãããŸãããBlowfishã®ããã«64ãããã§ã¯ãªã128ãããã®ãããã¯ãµã€ãºãæã£ãŠãããšããäºå®ã¯ã倧ããªïŒ1GBãè¶ ããïŒãã¡ã€ã«ãããé©åã«åŠçã§ããããšãæå³ããŸãã ãã ããéãã¯ãããããã§ãã OpenVPNã®åäœé床ã¯ãéžæããæå·åã¢ã«ãŽãªãºã ã«ãã£ãŠç°ãªããŸãããéåžžã¯IPsecãããéãåäœããŸãã
OpenVPNã¯ãVPNã䜿çšããéã«No. 1ã®ãã¯ãããžãŒã«ãªããŸãããæåã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ãµããŒããããŠããŸããã§ãããããã®ãããã³ã«ã¯ãµãŒãããŒãã£ã®ãœãããŠã§ã¢ã§åºããµããŒããããŠããŸãã ããæè¿ããžã§ã€ã«ãã¬ã€ã¯ãšã«ãŒããªãã§iOSããã³Androidã§OpenVPNã䜿çšããããšã¯äžå¯èœã§ãããçŸåšããã®åé¡ãéšåçã«è§£æ±ºãããµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ããããŸãã
å¥ã®OpenVPNã®åé¡ã¯ããã«é¢é£ããŠããŸã-æè»æ§ãèšå®ãäžäŸ¿ã«ããå¯èœæ§ããããŸãã ç¹ã«ãOpenVPNã®å žåçãªãœãããŠã§ã¢å®è£ ïŒããšãã°ãæšæºã®Open Client OpenVPN for WindowsïŒã䜿çšããå Žåãã¯ã©ã€ã¢ã³ãã®ããŠã³ããŒããšã€ã³ã¹ããŒã«ã ãã§ãªããè¿œå ã®æ§æãã¡ã€ã«ã®ããŠã³ããŒããšã€ã³ã¹ããŒã«ãå¿ èŠã§ãã å€ãã®VPNãããã€ããŒã¯ãäºåã«æ§æãããVPNã¯ã©ã€ã¢ã³ãã䜿çšããŠãã®åé¡ã解決ããŸãã
é·æïŒ
- æè»ãªæ§æå¯èœ
- éåžžã«å®å šïŒéžæããæå·åã¢ã«ãŽãªãºã ã«äŸåããŸããããã¹ãŠå®å šã§ãïŒ
- ãã¡ã€ã¢ãŠã©ãŒã«ãä»ããŠåäœããããšãã§ããŸã
- å¹ åºãæå·åã¢ã«ãŽãªãºã ã䜿çšã§ããŸã
çæïŒ
- ãµãŒãããŒãã£ã®ãœãããŠã§ã¢ãå¿ èŠ
- èšå®ããã«ã¯äžäŸ¿ãããããŸãã
- éãããããŒã¿ãã«ããã€ã¹ã®ãµããŒã
SSTP
Secure Socket Tunneling Protocol-Windows Vista SP1ã§Microsoftã«ãã£ãŠå°å ¥ãããçŸåšLinuxãRouterOSãããã³SEILã§å©çšå¯èœã§ãããWindowsã·ã¹ãã ã§ã®ã¿äœ¿çšãããŠããŸãïŒéåžžã«å°ããªãã£ã³ã¹ããããŸãAppleããã€ã¹ã«è¡šç€ºãããŸãïŒã SSTPã¯SSL v.3ã䜿çšãããããOpenVPNãšåæ§ã®å©ç¹ïŒTCPããŒã443ã䜿çšããŠNATããã€ãã¹ããæ©èœãªã©ïŒãæäŸããŸãããŸããWindowsã«çµ±åãããŠãããããOpenVPNããã䜿ããããå®å®ããŠããŸãã
é·æïŒ
- éåžžã«å®å šïŒæå·åã¢ã«ãŽãªãºã ã«å¿ããŠãéåžžã«åŒ·åãªAESãé垞䜿çšãããŸãïŒ
- Windowsã«å®å šã«çµ±åïŒWindows Vista SP1以éïŒ
- ãã€ã¯ããœããã®ãµããŒãããããŸã
- ãã¡ã€ã¢ãŠã©ãŒã«ãä»ããŠåäœããããšãã§ããŸã
çæïŒ
- Windowsç°å¢ã§ã®ã¿åäœããŸã
ãããã«
PPTPã¯å®å šã§ã¯ãªãïŒMicrosoftã®äœæè ã§ãããæŸæ£ããŠããïŒãããPPTPã®äœ¿çšã¯é¿ããŠãã ããã ã€ã³ã¹ããŒã«ã®å®¹æããšã¯ãã¹ãã©ãããã©ãŒã ã®äºææ§ã¯é åçã§ãããL2TP / IPsecã«ã¯åãå©ç¹ããããããå®å šã§ãã
L2TP / IPsecã¯åªããVPNãœãªã¥ãŒã·ã§ã³ã§ãããOpenVPNã»ã©åªããŠããŸããã ãã ããè¿œå ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããã«VPNããã°ããã»ããã¢ããããã«ã¯ãç¹ã«OpenVPNã®ãµããŒãããŸã äœãã¢ãã€ã«ããã€ã¹ã®å Žåãæåã®ãœãªã¥ãŒã·ã§ã³ã®ãŸãŸã§ãã
OpenVPNã¯ããã¹ãŠã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ãµãŒãããŒãã£ãœãããŠã§ã¢ãå¿ èŠã§ããã«ãããããããæé«ã®VPNãœãªã¥ãŒã·ã§ã³ã§ãã ä¿¡é Œæ§ãé«ããé«éã§å®å šãªãããã³ã«ã§ãããä»ã®ãããã³ã«ãããå°ãæéãããããŸãã
SSTPã¯OpenVPNã®å©ç¹ã®ã»ãšãã©ãæäŸããŸãããWindowsã®ã¿ã§ãã ããã¯ãOSãžã®çµ±åæ§ãé«ãããšãæå³ããŸããããã®ãããVPNãããã€ããŒã«ãããµããŒããäžååã§ãã
ã»ãšãã©ã®ãŠãŒã¶ãŒã¯ããã¹ã¯ãããã³ã³ãã¥ãŒã¿ãŒã§OpenVPNã䜿çšã§ããã¢ãã€ã«ããã€ã¹ã§L2TP / IPsecã䜿çšããŠè£å®ã§ããŸãã