ãããã¯ãŒã¯æ§é
Windows Server 2008 StdïŒãŸã 泚æãæã£ãŠããŸããïŒã«åºã¥ãå°çšãµãŒããŒãšãã·ã³ãã«ãªã«ãŒã¿ãŒã䜿çšããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãåãã10å°ã®Windows 7/8ã¯ã©ã€ã¢ã³ãã®å°èŠæš¡ãããã¯ãŒã¯ã VPNãµãŒããŒã®å ŽåãWindows 7 Proã®ãã·ã³ã®1ã€ã匷調衚瀺ããŸããã Windows 7 Proã§L2TP / IPsecãµãŒããŒãäœæãã2ã€ã®æ¹æ³ã以äžã«èª¬æããŸãã
蚌ææžã䜿çšããWindows 7 L2TP / IPsec AES 128ããã
- ãŸããVPNãµãŒããŒã§ã³ã³ãã¥ãŒã¿ãŒãšãŠãŒã¶ãŒèšŒææžãçæããå¿
èŠããããŸãã
ãããè¡ãã«ã¯ãç¡æã®Simple AuthorityãŠãŒãã£ãªãã£ã䜿çšããŸãã
ã€ã³ã¹ããŒã«ãå®è¡ã ããã°ã©ã ã¯ããã«ã³ã³ãã¥ãŒã¿ãŒèšŒææžã®çæãææ¡ããŸãã ãã£ãŒã«ãã«å ¥åããŸãã ããŒããŒããã©ã³ãã ã«ã¯ãªãã¯ããŠãä¹±æ°ãçæããŸãã ãã¹ã¯ãŒããå ¥åããŸãïŒã§ããã°8æåããé·ããããã§ãªãå Žåã¯ã°ãªãããçºçããå¯èœæ§ããããŸãïŒã³ã³ãã¥ãŒã¿ãŒèšŒææžïŒCAïŒã®æºåãã§ããŸããã ãŠãŒã¶ãŒãè¿œå ãããŠããªãå Žåã¯ãè¿œå ããŸãã å³åŽã§ãå¿ é ãã£ãŒã«ãã«å ¥åããŸãã ãæ°ãã蚌ææžããã¯ãªãã¯ããŸãã ãã®åŸã* .cerããã³* .p12æ¡åŒµåãæã€2ã€ã®èšŒææžãã¡ã€ã«ããã¹ã¯ãããã«è¡šç€ºãããŸã - VPNãµãŒããŒã«èšŒææžãã€ã³ã¹ããŒã«ããŸãã
ãããè¡ãã«ã¯ãWin + RïŒãå®è¡ãïŒãå®è¡ããmmcãšå ¥åããŠEnterããŒãæŒããŸãã ã³ã³ãœãŒã«ãéããŸãã
ã¹ãããã€ã³ãè¿œå ããŸãïŒ[ãã¡ã€ã«]-> [ã¹ãããã€ã³ã®åé€]ãè¿œå ïŒã ã蚌ææžããéžæããŸãã ãè¿œå ããã¯ãªãã¯ããŸãã ãã®ã¹ãããã€ã³ã蚌ææžã管çããå Žæãå°ãããããããã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ããé ç®ãéžæããŸãã 次ã«ããå人ã->å³ã¯ãªãã¯->ãã¹ãŠã®ã¿ã¹ã¯->ã€ã³ããŒã->æ¡åŒµåã* .p12ã®èšŒææžãã¡ã€ã«ãéžæããŸãïŒããã§å®äºã§ãïŒã ãã¹ã¯ãŒããå ¥åããããã®ããŒããšã¯ã¹ããŒãå¯èœãšããŠããŒã¯ãããããã¯ã¹ããã§ãã¯ããŸãã 2ã€ã®èšŒææžã[å人]ã«ããŽãªã«è¡šç€ºãããŸãã ãçºè¡è ããã£ãŒã«ããšãçºè¡è ããã£ãŒã«ããåäžã®èšŒææžã¯ãã«ããŽãªãä¿¡é Œãããã«ãŒãèªèšŒå±ãã«è»¢éããå¿ èŠããããŸãã - ProhibitIpSec = 1ãã©ã¡ãŒã¿ãŒãæ¬ èœããŠããããšã確èªããå¿
èŠããããŸã ã
ã¬ãžã¹ããªã«ç§»åããŸãïŒWin + R-> regeditïŒã HKLM \ System \ CurrentControlSet \ Services \ Rasman \ Parametersãã©ã³ããæ¢ããŠããŸãã äžèšã®ãã©ã¡ãŒã¿ãŒãååšããªããã0ã§ããå Žåããã¹ãŠæ£åžžã§ãã ãã以å€ã®å Žåã¯ä¿®æ£ããŸãã - çä¿¡æ¥ç¶ãäœæããŸã ã
[ãããã¯ãŒã¯ãšå ±æã»ã³ã¿ãŒ]-> [ã¢ããã¿ãŒèšå®ã®å€æŽ]ã«ç§»åããŸãã AltããŒãæŒããšãã¡ãã¥ãŒãããããã¢ãŠãããŸãã 次ã®ãã¡ã€ã«->ãæ°ããçä¿¡æ¥ç¶ãã å¿ èŠãªãŠãŒã¶ãŒãéžæããŠããThrough the Internet ... VPNããå ¥åããŸãã å¿ èŠãªãããã³ã«ãéžæããŸãã TCP / IP v4->ã§ã¯ããããŒã«ã«ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããããå ¥åããã¯ã©ã€ã¢ã³ãã«çºè¡ãããã¢ãã¬ã¹ã®ããŒã«ãå¿ ãèšå®ããŸãã æ¥ç¶ãäœæããããå¿ ããã®ããããã£ãéãã[ãŠãŒã¶ãŒ]ã¿ãã§[ãŠãŒã¶ãŒã¯ãã¹ã¯ãŒããç§å¯ã«ããå¿ èŠããã]ãã§ãã¯ããã¯ã¹ãååšããããšã確èªããŸã - å¿ èŠãªããŒããéããŠãããã©ããã確èªããŠãã ãã ã ã³ãã³ãã©ã€ã³ãéãã netstat / a / p udpã³ãã³ãã䜿çšããŠãUDP 1701 UDP 4500 UDP 500ãéããŠãããã©ããã確èªããŸãã
ãã®ã¡ãœããã®ã¯ã©ã€ã¢ã³ãæ¥ç¶ãäœæãã
- VPNã¯ã©ã€ã¢ã³ãã«èšŒææžãã€ã³ã¹ããŒã«ããŸãã åã«äœæãã蚌ææžãVPNãµãŒããŒããã³ããŒããŸãã ãµãŒããŒãšãŸã£ããåãæ¹æ³ã§ã€ã³ã¹ããŒã«ããŸãã
- VPNæ¥ç¶ãäœæããŸãã ããããã¯ãŒã¯ãšå ±æã»ã³ã¿ãŒãã«ç§»å->æ°ããæ¥ç¶ãŸãã¯ãããã¯ãŒã¯ãæ§æããŸãã 次ã«ããè·å Žãžã®æ¥ç¶ã->ã€ã³ã¿ãŒãããæ¥ç¶ã䜿çšããŸãã VPNãµãŒããŒã®ã¢ãã¬ã¹ãå ¥åããŸãã æ¥ç¶ã®æºåãã§ããŸããã
- VPNæ¥ç¶ãã»ããã¢ããããŸãã ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã¯ã質åãåŒãèµ·ãããªããšæããŸãã [ã»ãã¥ãªãã£]ã¿ãã§ãL2TP / IPsec VPNã¿ã€ããéžæããè¿œå ã®ãã©ã¡ãŒã¿ãŒã§[蚌ææžã䜿çšãã]ãéžæãã[蚌ææžåã®å±æ§ã確èªãã]ããªãã«ããŸãã æå·åãå¿ èŠã§ãã次ã®ãããã³ã«ãèš±å¯ãããèªèšŒãèšå®ããŸãïŒMS-CHAPv2ã 次ã«ã[ãããã¯ãŒã¯]ã¿ã-> [TCP / IPv4ããããã£]-> [詳现]-> [ããã©ã«ãã²ãŒããŠã§ã€ã䜿çšãã]ã®ãã§ãã¯ãå€ããŸãã
- æ¥ç¶ãäžãããªãå Žåã 次ã«ãWindows 8ã§ã¯ããã®ãããªã¬ãžã¹ããªããŒHKLM \ SYSTEM \ CurrentControlSet \ Services \ IPsecãè©Šã䟡å€ããããŸããAssumeUDPEncapsulationContextOnSendRuleãšããååã§å€2ã®DWORDãã©ã¡ãŒã¿ãŒãäœæããŸããWindows7 / Vistaã®å Žåããã®ãã©ã¡ãŒã¿ãŒã¯HKLM \ SYSTEM \ CurrentControlSet \ Services \ PolicyAgent
ãã®æ¹æ³ã®çµæ
Windowsã¯ã©ã€ã¢ã³ãã®å Žåãããã¯L2TP / IPsecãå®è£ ããè¯ãæ¹æ³ã§ãããiOSã¯ã©ã€ã¢ã³ãã®å Žåã¯ã¿ã¹ã¯ãæ¡å€§ããŸãã åé¡ã¯ãiOSã¯äºåã«æºåãããããŒã¯ãŒãïŒäºåå ±æããŒïŒã䜿çšããæå·åã䜿çšããL2TPçµç±ã§ã®ã¿æ¥ç¶ã§ãã蚌ææžã§ã¯Cisco VPNã«ã®ã¿æ¥ç¶ã§ããããšã§ãã 2çªç®ã®æ¹æ³ã¯ããã®åé¡ã解決ããæ¹æ³ã瀺ããŸãã
ESP 3DESæå·åããã³æŽåæ§å¶åŸ¡ãåããWindows 7 L2TP / IPsecäºåå ±æããŒ
- å¥è·¡ã®ãã©ã¡ãŒã¿ãŒProhibitIpSec = 1ã«æ»ããŸããã ã ã¬ãžã¹ããªãHKLM \ System \ CurrentControlSet \ Services \ Rasman \ Parametersãã©ã³ãã«ç§»åããProhibitIpSecãšããååã®DWORDãã©ã¡ãŒã¿ãŒãäœæããŠå€1ãå²ãåœãŠãŸãããã®åŸãOSãåèµ·åããããRemoteAccessããã³RasManãµãŒãã¹ãåèµ·åããå¿ èŠããããŸãã ãã®ã¢ã¯ã·ã§ã³ã§ã¯ãIPsecã®ããŒã«ã«ã®ããã©ã«ãIPã»ãã¥ãªãã£ããªã·ãŒãç¡å¹ã«ããŸãã
- 次ã«ãæ°ããIPã»ãã¥ãªãã£ããªã·ãŒãäœæããŸã ã [å®è¡]-> mmc->ã¹ãããã€ã³ã®è¿œå -> [IPã»ãã¥ãªãã£ããªã·ãŒã®ç®¡ç]ãã¯ãªãã¯ãã[ããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒ]ãéžæããŸãã 次ã«ããIPã»ãã¥ãªãã£ããªã·ãŒãäœæããŸããã ã次ãžã->ååãå
¥å->ãããã©ã«ãã®ã«ãŒã«ã䜿çšããã§ãã¯ããã¯ã¹ãèšå®ããªã->次->ãããããã£ã®å€æŽãããã§ãã¯ããã¯ã¹ããã®ãŸãŸã«ããŸãã æ°ããããªã·ãŒã®ããããã£ãéããŸãã ããã§ãããŠã£ã¶ãŒãã䜿çšãããã³ãè¿œå ããã§ãã¯ããã¯ã¹ãåé€ããŸãã 次ã«ãåã¿ãã«ã€ããŠé çªã«ïŒ
- IPãã£ã«ã¿ãŒã®ãªã¹ãã ååãå ¥åããã䜿çšãããã®ãã§ãã¯ãå€ããŸãã ãã¹ã¿ãŒãããè¿œå ãã éä¿¡å ã¢ãã¬ã¹ïŒä»»æã å®å ã¢ãã¬ã¹ïŒãä»»æãã [ãããã³ã«]ã¿ãã ããããããŠã³ãªã¹ãã§ã[UDP]ãéžæããŸãã ãã®ããŒãããã®ãã±ããïŒ1701ãä»»æã®ããŒããžã®ãã±ããã OKãOKãIPãã£ã«ã¿ãŒã®ãªã¹ãã«æ»ããŸãã ããã§ã¯ãæ°ããäœæãããã£ã«ã¿ãŒã«ããããããä»ããŠã次ã®ã¿ãã«é²ã¿ãŸãã
- ãã£ã«ã¿ãŒã¢ã¯ã·ã§ã³ã é¡æšã«ãã£ãŠã ãã¹ã¿ãŒã«ã€ããŠã®ååããè¿œå ãã ãCoordinate SecurityãããAddããéžæããŸãã ãæå·åãšæŽåæ§ããéžæããŸãã ïŒESPïŒãã ããã£ã ã»ãã¥ãªãã£ã¡ãœããã®ãªã¹ãã®äžã«ããŠããªãããšã確èªããŸãã ããã£ã åæ§ã«ããããã§ããŒã¯ãã次ã®ã¿ãã«ç§»åããŸãã
- æ¥ç¶ã®ã¿ã€ãã ãã¹ãŠã®ãããã¯ãŒã¯æ¥ç¶ã
- ãã³ãã«ã®ãã©ã¡ãŒã¿ãŒã ãã®ã«ãŒã«ã¯ãIPsecãã³ãã«ãæå®ããŸããã
- èªèšŒæ¹æ³ Kerberosã«ã¯ãŸã 泚æãæã£ãŠããŸããã[è¿œå ]ãã¯ãªãã¯ããŠãã ããã [Use this lineïŒPre-shared keyïŒ]ãéžæããäºåã«äœæããããŒãå ¥åããŸãã ããã£ã ããã§ãKerberosãåé€ã§ããŸãã åãã¿ãã§ã蚌ææžèªèšŒãè¿œå ã§ããŸãã 蚌ææžã®çæãšã€ã³ã¹ããŒã«ã®ããã»ã¹ã¯ãæåã®æ¹æ³ã§èª¬æãããŠããŸãã
- å¿ ãæ°ããIPã»ãã¥ãªãã£ããªã·ãŒãå²ãåœãŠãŠãã ãã ã ãããå³ã¯ãªãã¯ããŠããå²ãåœãŠãã
ãã®ã¡ãœããã®ã¯ã©ã€ã¢ã³ãæ¥ç¶ãäœæãã
- ããã¯ã蚌ææžã䜿çšãã代ããã«ã...å ±æããŒã䜿çšããããéžæããè¿œå ã®L2TP / IPsecããããã£ã§ã®ã¿ãæåã®æ¹æ³ã§ã¯ã©ã€ã¢ã³ãæ¥ç¶ãäœæããããšãšã¯ç°ãªããŸãã
VPNãµãŒããŒãžã®ã¢ã¯ã»ã¹
ã«ãŒã¿ãŒã§ã¯ãåçDNSãµãŒãã¹ã䜿çšããŸããããªããªãã å€éšIPãã€ãããã¯ã æ¥ç¶ã§ããããã«ããã«ã¯ãããŒãUDP 1701 UDP 4500 UDP 500ãVPNãµãŒããŒã«è»¢éããããŒããäœæããå¿ èŠããããŸãã ããäžã€ã®å€§ããªåé¡ãåŸ ã£ãŠãããã£ããã·ã¥ã¹ããŒãžã«ãã©ãçããŸããã å®éãWindows 7/8ã§ã¯ããªã¢ãŒãã¢ã¯ã»ã¹ã®æ倧æ¥ç¶æ°ã«å¶éãããã1ã§ããWindowsServerã«ã¯ãã®ãããªå¶éã¯ãããŸããã ããã§ãã¬ãŒãºã¯ãå°çã¯ããããã¹ãŠæžããã®ã§ããïŒïŒããšèšããŸãã2ã€ã®è§£æ±ºçããããŸãã æåïŒäžäººã®è¯ã人ãå€ãã®ä»äºãããWindows 7 Pro SP1ã®å¶éãåãé€ãããããæžããŸããã ããã§ã¯ã解決çãèŠã€ããããã»ã¹ã詳现ã«èª¬æãããããããããŸãã 2çªç®ïŒWindows Serverã䜿çšããŸãã ãããããã«ãŒãã£ã³ã°ãšãªã¢ãŒãã¢ã¯ã»ã¹ãã®ãµãŒããŒããŒã«ãå²ãåœãŠãæªéã足ãæãç¹å¥ãªã¹ãããã€ã³ã䜿çšããããšã«ã€ããŠè¿°ã¹ãŠããããäžèšã®æ¹æ³ã䜿çšãããã»ãšãã©ã®èšäºã«æžãããŠããããã«äœ¿çšãããŸããã ç¹å¥ãªåœ¹å²ãå²ãåœãŠãããæ¥ç¶æ°ãå¶éãããããããšãªããWindows Serverã§ããŸãæ©èœããŸãã