åæã«ããœãªã¥ãŒã·ã§ã³ã¯å€ãã®é«ãèŠä»¶ãæºããå¿ èŠããããŸãïŒäŒæ¥ã®ããžãã¹ããã»ã¹ã®ç¶ç¶æ§ã確ä¿ããå³æ Œãªã»ãã¥ãªãã£åºæºãæºãããé«ãITã€ã³ãã©ã¹ãã©ã¯ãã£ããã©ãŒãã³ã¹ãç¶æããçµç¹ã®æé·ã«å¿ããŠå¿ èŠãªæ¡åŒµãããã«ç¢ºå®ã«ããããã«ç°¡åã«æ¡åŒµã§ããããã«ããããã
éå»æ°å¹Žã«ããã£ãŠãç¹å®ã®ã¿ã€ãããã³ããŒãžã§ã³ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®ã¿å®è¡ããã倧容éã§éãã¢ããªã±ãŒã·ã§ã³ã®ãã®åããšã³ã¿ãŒãã©ã€ãºãã©ãããã©ãŒã ã¯ã軜éã§ã¹ã±ãŒã©ãã«ãªã¯ãã¹ãã©ãããã©ãŒã Webã¢ããªã±ãŒã·ã§ã³ã«å€ãããŸããã ç§ã¯ã倧èŠæš¡ãªWebãããžã§ã¯ãããã©ãŒã©ã ããã®ä»ã®ãã蚪ãããªãœãŒã¹ã«ã€ããŠã ã話ããŠããã®ã§ã¯ãããŸããã çŸä»£ã®ããžãã¹ã§ã¯ãCRMãERPããã®ä»ã®SAPããã³1Cã«äŒŒããã©ãããã©ãŒã ãWebäžã§ç¿»èš³ããŠããŸãã ãã®çç±ã¯èª°ã«ã§ãæããã ãšæããŸãã ããããçŸä»£ã®ããžãã¹ããã°ãã°ç¡èŠããå°ããªåºç€ã1ã€æ®ã£ãŠãããããããäŒæ¥å šäœãæ¥åãåæ¢ããææªã®å Žåãæ©å¯æ å ±ã®æŒæŽ©ãŸãã¯æ倱ãçºçããããšãæãåºãããŸãã
ç§ã®å Žåããã©ãããã©ãŒã ã¯DDoSæ»æãåããäŒæ¥å šäœã®ä»äºãšã¯ã©ã€ã¢ã³ãã®ä»äºã麻çºãããããã顧客ã¯åå1æã«åé¡ã解決ããããã«ç§ã«ç®ãèŠãŸããŸããã èšäºãæžãããã®äž»ãªå©ããšãªã£ããNetscalerã®ä»çµã¿ã«é¢ãã説æã説æã¯ãããŸããã
ãã¹ãŠã®å§ãŸã
ã客æ§ã®ãŠã§ããã©ãããã©ãŒã ã§æåã«è¡ããªããã°ãªããªãã£ãã®ã¯ãå€éšãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹ãéããããšã§ããã ã©ããããããè² è·ã軜æžããã«ã¯ãå€éšããã®ã¢ã¯ã»ã¹ãšãã¹ãã®ããã«IPã¢ãã¬ã¹ã®ããŒã«ãç»é²ããå¿ èŠããããŸããã 次ã«ãåæã»ãã·ã§ã³ãšãªã¯ãšã¹ãã®æ°ãå¶éããããã«WebãµãŒããŒãæ§æããŸããã ããã«ãGeoIPãéããŠãåœã¯åŸã ã«éããå§ããŸããã 次ã«ãæ»æãæéããããã®æ©èœãè¿œå ããããã«WebãµãŒããŒãåã³ã³ãã€ã«ããå¿ èŠããããŸããã failtobanãæ§æãããåŸãcronçšã®ã¹ã¯ãªããã®æ°åè¡ãèšè¿°ãããŸããã 16ã20æéããããŸããããå€ãã®ããããããäºãã«è¡çªããã·ã¹ãã å šäœã«ãæ£ãã°ã£ãŠãããããšãæ°ã®ãããããã§ããã ããã«ãããããããæ»æã¯ç¶ç¶ããã·ã¹ãã ã¯503ãšã©ãŒã§å¿çãç¶ãããããäºé²çãè¬ããè ã¯èª°ãããªãã£ããããå³åº§ã«å¯Ÿå¿ããå¯èœæ§ã¯ãããŸããã§ããã ããã¯ãCitrix Netscalerã§ãã¹ãŠã1ã€ã®å Žæã«æèŠãšæèŠã§èšå®ããããã®äžæçãªæ段ãšããŠè¡ãããŸããã
Netscalerã¯ãã»ãšãã©ã®ãããã¯ãŒã¯ã®åé¡ãŸãã¯ããã«ããã¯ã解決ããå€æ©èœãã©ãããã©ãŒã ã§ãã ãã®è£œåã¯ãã¬ãŽãã¶ã€ããŒãšæ¯èŒã§ããŸããã¬ãŽãã¶ã€ããŒã®ããŸããŸãªéšåãããŠãããŒãµã«ãã©ã³ã¹ãã©ãŒããŒãæ§æã§ããŸããã³ã³ãã¯ãã§ãããªããããã©ãã£ãã¯ãåŠçããããã«å¿ èŠãªãã¹ãŠã®ããŒã«ãåããŠããŸãã Netscalerã¯ãææ°ã®ãã¹ãŠã®ãã€ããŒãã€ã¶ãŒã®ä»®æ³VPXããã€ã¹ãšããŠããç©çããã€ã¹ãšããŠã䜿çšã§ããŸãã
ä»®æ³ãã·ã³ãã€ã³ã¹ããŒã«ããŠæ§æãã
ãŸããcitrix.comã«ç»é²ããå¿ èŠããããŸãã äŒç€Ÿã§ãã§ã«Citrixã䜿çšããŠããå Žåã¯ãæ¢åã®ã¢ã«ãŠã³ãã§è£œåãããŠã³ããŒãã§ããŸãã ããã§ãªãå Žåã¯ã[顧客ã¢ã«ãŠã³ãã®äœæ]ãéžæããå¿ èŠãªãã£ãŒã«ãã«å ¥åãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããéžæããŸããã¢ã«ãŠã³ãã§æ¢ã«ãã°ã€ã³ããŠããŸããã¡ãŒã«ã¢ãã¬ã¹ã確èªããå¿ èŠã¯ãããŸããã
Netscalerã®ããŠã³ããŒããã€ã³ã¹ããŒã«ãæ§æ
1. [ ããŠã³ããŒã]ã»ã¯ã·ã§ã³ã«ç§»åããŸãã
2. NetScaler ADCãéžæããããããããŠã³ã¡ãã¥ãŒããè©äŸ¡çãšè©ŠçšçãœãããŠã§ã¢ãéžæããŠãæ€çŽ¢ãã¿ã³ãã¯ãªãã¯ããŸãã
3. ãã¹ãŠã®NetScalerã«ã¹ã¿ããŒãã©ã€ã¢ã«ã衚瀺ãããªãªãŒã¹ã®ã»ã¯ã·ã§ã³ãå±éããŸãã
4. [ç¡æã§è©Šã]ãéžæããŸãã
5.ãã©ãŒã ã«å ¥åãã[ç¶è¡]ãã¯ãªãã¯ããŠããŠã³ããŒãããŸãã
6.ããŠã³ããŒãããŒãžã§ãããŸããŸãªãã€ããŒãã€ã¶ãŒã®ã€ã¡ãŒãžãå©çšå¯èœã«ãªããŸããèªåã«åã£ããã®ãéžæããŠãã ããã
7.ãã€ããŒãã€ã¶ãŒã«Netscalerãã€ã³ã¹ããŒã«ããŸãã
8.ã³ã³ãœãŒã«ã®æåã®èµ·åæã«ãèšå®ãŠã£ã¶ãŒãããããŸãã ããŒã¿ãæäŸããå¿ èŠããããŸãã Netscalerã¯DHCPãåãå ¥ãããè€æ°ã®ç©çãŸãã¯ä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹ãæã€ããšãã§ãããšããäºå®ã«ãããããããè«ççã«1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãæã£ãŠããŸãã DMZãŸãŒã³ã§äœ¿çšå¯èœãªããŒã«ã«IPã¢ãã¬ã¹ãæå®ããå¿ èŠããããŸãã ç§ã¯172.16.0.100ãåããŸãã
9.ãã©ãŠã¶ã§ããŒãžhttp://172.16.0.100ãéãããŠãŒã¶ãŒå/ãã¹ã¯ãŒãnsroot / nsrootã§ãã°ã€ã³ããŸã
10.ã¿ã€ã ãŸãŒã³ãDNSããã®ä»ã®IPã¢ãã¬ã¹ãæå®ããããæ±ããããŸãã 172.16.0.100ã¯ãNetscalerèªäœã®ã¢ãã¬ã¹ã§ãã ãµããããIP-ä»ã®ãµãŒããŒããã³ãµãŒãã¹ãšé£æºããããã«äœ¿çšãããã¢ãã¬ã¹ã ã€ãŸããå¥ã ã«é£ã³ãŸã-ã«ãã¬ããïŒãµãŒãã¹ãæäœããããã®å¶åŸ¡IPã¯1ã€-ãã1ã€ã§ãã çªç¶ã2ã€ã®DMZãŸãŒã³ãŸãã¯VLANãããã¯ãŒã¯ããŸãã¯ç°ãªããã¹ã¯ãæã€ãããã¯ãŒã¯ããããŸãã ç§ã®å Žåããããã¯ãŒã¯ã¯1ã€ãªã®ã§ã172.16.0.101ãæå®ããŸããã
11. 2ã3åã¯ãªãã¯ãããšã[æ§æ]ã¿ãã衚瀺ãããŸãã
ç»é²ãšã©ã€ã»ã³ã¹
1.次ã«ãã©ã€ã»ã³ã¹ãã¡ã€ã«ãããŠã³ããŒãããå¿ èŠããããŸãã [ãã€ã¢ã«ãŠã³ã]ããŒãžã«ç§»åãã[ã©ã€ã»ã³ã¹ã®ã¢ã¯ãã£ãåãšå²ãåœãŠ]ãéžæããŠãé ã«ãã[ 補åã衚瀺ãããªã ]ãªã³ã¯ãã¯ãªãã¯ããŸãã ã¡ãŒã«ã§åãåã£ãã©ã€ã»ã³ã¹ã³ãŒããå ¥åããŸãã [ç¶è¡]ã2åã¯ãªãã¯ãããšããªã¹ãã«è£œåã衚瀺ãããŸãã ãã®ç¬éãããã©ã€ã»ã³ã¹ã®ã«ãŠã³ãããŠã³ãå§ãŸããŸããã
2. Netscaler Webã€ã³ã¿ãŒãã§ã€ã¹ã®[æ§æ]ããŒãžãããã¹ãIDãããã¡ãŒïŒããã¯Netscalerã®MACã¢ãã¬ã¹ã§ãïŒã«ã³ããŒããã©ã€ã»ã³ã¹ãããŠã³ããŒãããå¿ èŠããããµã€ãã«æ»ããŸãã
3. [ãã¹ãID]ãã£ãŒã«ãã«MACã¢ãã¬ã¹ãæ¿å ¥ãã[ç¶è¡]ã[確èª]ã[OK]ã®é ã«ã¯ãªãã¯ãããšãLICæ¡åŒµåã§ãã¡ã€ã«ã®ããŠã³ããŒããéå§ãããŸãã
4.å®äºãããã¯90æ¥éã®ã©ã€ã»ã³ã¹ã§ãã
5. Netscalerã€ã³ã¿ãŒãã§ãŒã¹ããŒãžïŒä»¥éNSïŒãæŽæ°ãããã°ã€ã³ãããšãå床ã©ã€ã»ã³ã¹ãæå®ããããæ±ããããŸãã ãã¡ã€ã«ãéžæããŠããŠã³ããŒãããŸããããŠã³ããŒããæåããããã·ã¹ãã ãåèµ·åããå¿ èŠããããŸããããã¯ãŠã£ã³ããŠã«è¡šç€ºãããŸãã
6.åèµ·ååŸã[ã©ã€ã»ã³ã¹]ã¿ãã«90æ¥é䜿çšå¯èœãªãã®ãäžèŠ§è¡šç€ºãããŸãã
ãµãŒããŒããµãŒãã¹ãããªã·ãŒãããªã·ãŒããã³ã«ãŒã«ã®æ§æ
1.ããã«ã以åã®ããŒãžã§ã³ãç¡æãã©ã€ã¢ã«ã§å©çšå¯èœã§ããããšãæ確ã«ããå¿ èŠããããŸãã æ®å¿µãªãããGUIã«ããå®å šãªç®¡çãšæ§æã«ã¯ãJavaããŒãžã§ã³7/45 x86ãå¿ èŠã§ãã NSã®æ°ããããŒãžã§ã³ã§ã¯ãJREã®ææ°ããŒãžã§ã³ã䜿çšã§ããŸãã ããŠã³ã°ã¬ãŒããè¡ããããªãå Žåã¯ãã³ãã³ãã©ã€ã³ã䜿çšã§ããŸãã å¿ èŠãªã³ãã³ãã¯ãã¹ãŠã»ã¯ã·ã§ã³ã®æåŸã«ãããŸãã ãããè¡ãã«ã¯ãNSãŠãŒã¶ãŒå/ãã¹ã¯ãŒãnsroot / nsrootã§NSã®IPãžã®ã¿ãŒããã«SSHã»ãã·ã§ã³ãéããŸãã
2.ãããããä¿è·ãããWebãµã€ãããããŸãã 圌ã«ã¯èªåã®ãã¡ã€ã³åããããIPã¢ãã¬ã¹ãå²ãåœãŠãããŠããŸãã 圌ã®ãã€ãã£ãIPã¢ãã¬ã¹ã¯æ®ããŸãããNSã«ä»®æ³ãµãŒããŒãç»é²ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãVIPãšåŒã°ããç¡æã®IPã¢ãã¬ã¹ãå¿ èŠã§ãããã®IPã¢ãã¬ã¹ãä»ããŠããŠãŒã¶ãŒã¯å®éã®WebãµãŒããŒã«ã¢ã¯ã»ã¹ããŸãã WebãµãŒãã¹ãå€éšã®å ŽåãIPã¯å€éšã§ãïŒå éšãããããã®å ŽåïŒã äŸãšããŠ172.16.0.102ãåãäžããŸãã
3. [ãã©ãã£ãã¯ç®¡ç]ã«ç§»åãã[ä»®æ³ãµãŒããŒ]ã§[è¿œå ]ãã¿ã³ãã¯ãªãã¯ããŸãã
ååãèãåºããHTTPãããã³ã«ãéžæããVIPïŒä»®æ³IPïŒãšãã®ä»®æ³ãµãŒããŒãåäœããããŒããæå®ããŠã[äœæ]ãã¯ãªãã¯ããŠãã[éãã]ãã¯ãªãã¯ããŸãã
4. [ãµãŒããŒ]ã«ç§»åãã[è¿œå ]ãã¯ãªãã¯ããŠãWebãµãŒããŒã®ããŒã¿ãæå®ããŸãã å®éãååãä»ããIPã¢ãã¬ã¹ãŸãã¯ååã瀺ãå¿ èŠããããŸãã ãµãŒããŒã¯å¥ã®ããŒãã§ä»ã®ãµãŒãã¹ã䜿çšããå ŽåããããããããŒãã¯å¿ èŠãããŸããã
5.ããã§ãä»®æ³ãµãŒããŒãç¹å®ã®ãµãŒãã¹ã®åœ¢åŒã§å®éã®ãµãŒããŒã«æ¥ç¶ããå¿ èŠããããŸãã [ãµãŒãã¹]ã«ç§»åããããäžåºŠ[è¿œå ]ãã¯ãªãã¯ããŠååãä»ãããµãŒããŒãæ¥ç¶ãåãå ¥ãããããã³ã«ããµãŒãã¹ãããŒããéžæããŸãã
6.äœæãããµãŒãã¹ãä»®æ³ãµãŒããŒã«è¿œå ããŸãã [ä»®æ³ãµãŒããŒ]ã«ç§»åãã[éã]ãã¯ãªãã¯ãã[ã¢ã¯ãã£ã]åã«ãã§ãã¯ãå ¥ããŠ[OK]ã確èªããŸãã ãã®åŸãä»®æ³ãµãŒããŒãèµ·åããŠå®è¡ãããŸãã
7.ãã¹ãŠã®å€æŽåŸããããããŒãã£ã¹ã¯ã®åœ¢ã®ã¢ã€ã³ã³ãã¯ãªãã¯ããŠãçŸåšã®æ§æãä¿åããå¿ èŠããããŸãã
8.ãã©ãŠã¶ã§ããŒãžhttp://172.16.0.102ãéããåºæ¥äžããããµã€ããéããŸãã æåããããããã©ã®ããã«æ©èœãããã¯å®å šã«ã¯æããã§ã¯ãªããããç§ãã¡ã¯äœãããããåæããŸãã
aïŒ80çªç®ã®ããŒããä»ããŠHTTPãããã³ã«çµç±ã§ä»®æ³IPã¢ãã¬ã¹ã§åäœããä»®æ³ãµãŒããŒãäœæããŸããã
bïŒå®ãµãŒããŒã«é¢ããããŒã¿ãè¿œå ããŸãã
cïŒãµãŒããŒã®ããŒã80ã«HTTPãµãŒãã¹ãããããšã瀺ãã
dïŒä»®æ³ãµãŒããŒãç¹å®ã®ãµãŒãã¹ã®ããŒã¿ãåŠçããããšãææ¡ãã
eïŒèšå®ãä¿åããŸããã
9.ã³ãã³ãã©ã€ã³çµç±
add lb vserver CRM-virtual-server HTTP 172.16.0.102 80 add server CRM-server 172.16.0.10 add service CRM-service CRM-server HTTP 80 bind lb vserver CRM-virtual-server CRM-service save config
å§çž®ãšãã©ãã£ãã¯ã®å§çž®
ä»®æ³ãµãŒããŒã¯æ©èœããŠããŸãã å®ãµãŒããŒãæ¡ä»¶ä»ããªã³ã¯ã䜿çšããŠHTMLã³ã³ãã³ããäœæããå Žåã¯ããµãŒãã£ã³ããããšãã§ããŸããããã§ãªãå Žåããªã³ã¯ããã¡ã€ã³åãæãå Žåã¯ããã¹ãŠã®å®å šãªã³ã¯ãæ¡ä»¶ä»ãã«å€æŽããããDNSãµãŒããŒãå€æŽããå¿ èŠããããŸãã <a href='http://www.domain.com/page1'>ãªã³ã¯</a>ãªã©ã®å®å šãªãªã³ã¯ãç»é²ãããŠããWebãµã€ããããå Žåãããã<a href='/page1'>ãªã³ã¯ã«å€æããå¿ èŠããããŸã</a>ã
ããã«ããçŽãæ¹æ³ããªãå Žåã¯ãDNSã§Aã¬ã³ãŒããwwwã«ãããããã¡ã€ã³ãä»®æ³ãµãŒããŒã®IPã¢ãã¬ã¹ãã€ãŸã172.16.0.102ã«åå²ãåœãŠããŸãã
æåã«æŽçã§ããã®ã¯ãGZIPå§çž®ã§ãã ãã®å Žåãå®ãµãŒããŒã§ã®å§çž®ãç¡å¹ã«ããããšãã§ããŸãã ããããNSã¯ãã©ãã£ãã¯ãã¢ã³ããã¯ããã³åããã¯ããŸããããããã»ããµãªãœãŒã¹ãåé¢ããããã«ãWebãµãŒããŒã«ãã¹ãããšããããŸã-å®æããã³ã³ãã³ããé ããŸãã
1. [ã·ã¹ãã ]> [èšå®]> [åºæ¬æ©èœã®èšå®]ã¡ãã¥ãŒã§ã[HTTPå§çž®]ãã§ãã¯ããã¯ã¹ããªã³ã«ããŸãã
2. Webã€ã³ã¿ãŒãã§ã€ã¹ã§ã[ãã©ãã£ãã¯ç®¡ç]> [è² è·åæ£]> [ãµãŒãã¹]ã«ç§»åãããµãŒãã¹ãéžæããŠ[éã]ãã¯ãªãã¯ãã[詳现èšå®]ã¿ãã«ç§»åããŠããã©ãã£ãã¯ãå§çž®ããããšãéžæããŸãã ãŸããã¯ã©ã€ã¢ã³ããšãªã¯ãšã¹ãã®æ倧æ°ãªã©ãä»ã®ãã©ã¡ãŒã¿ãŒãæå®ããããšãã§ããŸãã
3.ãã以éããã©ãã£ãã¯ã¯æšæºNSèšå®ã«åŸã£ãŠå§çž®ãããŸãã ãããããã¹ãŠãå§çž®ãããŠããããã§ã¯ãããŸããã äžéšã®WebãµãŒããŒã®MIMEèšå®ã§ãtext / javascriptã®ä»£ããã«jsæ¡åŒµã®application / x-javascriptãããããæå®ãããšãå§çž®ã¯çºçããŸããã ãã®ç¶æ³ãä¿®æ£ããã«ã¯ãããªã·ãŒãè¿œå ããŸãã
ã¡ãã¥ãŒã®[æé©å]> [HTTPå§çž®]> [ããªã·ãŒ]ã«ç§»åããŠã[è¿œå ]ãã¯ãªãã¯ãã[ã¯ã©ã·ãã¯æ§æã«åãæ¿ãã]ãã¯ãªãã¯ããŠæ°ããã«ãŒã«ãè¿œå ããŸãã
4.ã«ãŒã«ã¯äœæãããŸããããä»ã®ãšããã¢ã¯ãã£ãã§ã¯ãªããæ©èœããŸããã ã«ãŒã«ãå³ã¯ãªãã¯ããŠã[ããªã·ãŒãããŒãžã£ãŒ]ãéžæãã[å¿ç]ã¿ããéžæããŠããã[ããã©ã«ãã°ããŒãã«]ã[ããªã·ãŒã®æ¿å ¥]ãã¯ãªãã¯ããã«ãŒã«ãéžæããŠãæé«ã®åªå 床ãèšå®ããŸãã
5.ãã®ãããªã«ãŒã«ã¯ãpdfãjsonãããã³ãã®ä»ã®ã¿ã€ãã§ãèšå®ã§ããŸãã å§çž®ããæå°ãµã€ãºããµããããããã©ãŠã¶ãªã©ãæå®ããããšãã§ããŸãã ãªã© ã«ãŒã«ã¯ã°ããŒãã«ã§ã¯ãªããç¹å®ã®ãµãŒãã¹ã«å¯ŸããŠäœæã§ããŸãã
6.ã³ãã³ãã©ã€ã³çµç±ïŒ
enable ns feature cmp set service CRM-service -CMP yes add cmp policy ns_cmp_javascript -rule "RES.HTTP.HEADER Content-Type CONTAINS javascript" -resAction COMPRESS add cmp policy ns_cmp_json -rule "RES.HTTP.HEADER Content-Type CONTAINS json" -resAction COMPRESS add cmp policy ns_cmp_pdf -rule "RES.HTTP.HEADER Content-Type CONTAINS application/pdf" -resAction COMPRESS bind cmp global ns_cmp_javascript -priority 10001 -state ENABLED bind cmp global ns_cmp_json -priority 10002 -state ENABLED bind cmp global ns_cmp_pdf -priority 10003 -state ENABLED save config
ããŒã¿ä¿è·
ãã ããäœïŒããšããªãã¯èšããŸãã ãããŠãããªãã¯æ£ããã§ãããã äžèšã®ãã¹ãŠã¯ãæšæºã®WebãµãŒããŒã§å®è¡ã§ããŸãã ããŒã¿ããããã³ã°ããä¿è·ããããã«ãæšæºãµãŒããŒããã¬ãŒãã³ã°ããæ¹æ³ã¯ãããŸããã ããªãã¯åžžã«ãœãŒã¹ã³ãŒãã®æ£ç¢ºãã«é Œããªããã°ãªããŸãããã»ãšãã©ã®å Žåãç§ãã¡ã¯ãããæžããŸããã§ããã ãŸããå®è¡å¯èœã³ãŒãã«ãšã©ãŒãæ¬ ç¹ããªãããšãä¿èšŒããããšã¯ã§ããŸããã
ãã€ãŠãå°ããªããŒã ã§å€§èŠæš¡ãªã€ã³ã¿ãŒããããããžã§ã¯ããéçºããŠãããšããSQLã€ã³ãžã§ã¯ã·ã§ã³ããã®ä¿è·ã«æžæããããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããããã®APIãäœæããŸããã ç§ã®ããŒã ã®ããã°ã©ããŒãäœãããŠãããããã§ãã¯ãå§ãããŸã§ãç§ã¯ãããžã§ã¯ãã«ã€ããŠèœã¡çããŠããŸããã ãªã³ã¯ã«ãã£ãŠå€ãæž¡ãã®ã§ã¯ãªããSQLã¯ãšãªãç¿æ £ãããã¢ã»ã³ãã«ãããã¯ãšãªãæååå€æ°ãšæ°å€å€æ°ãšé£çµããŸãããšã¹ã±ãŒãã ãã§ãªããå€ã®åŠ¥åœæ§ã«ã€ããŠå€æ°ããã§ãã¯ããããšãå¿é ããŸããã 10ã15åã§ããã€ãã®SQLè匱æ§ãçºèŠãããªã³ã©ã€ã³ãã³ã¯ã®ãµã€ãã«ã€ããŠäœãšèšããŸããã ãŸããããã«å ããŠãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãCookieåœé ãæªæã®ããJSONããã³XMLèŠæ±ã®åœ¢æãªã©ããããŸãã
å¬ããããšã«ãNetscalerã¯ããã«éåžžã«æåããŠããŸãã
1. [ã·ã¹ãã ]> [èšå®]> [åºæ¬æ©èœã®èšå®]ã¡ãã¥ãŒã§ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã確èªããŸãã
2. [ã»ãã¥ãªãã£]> [ã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«]ã¡ãã¥ãŒã§ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ãŠã£ã¶ãŒããèµ·åããŸãã
3.æ§æã®ååãéžæããWeb 2.0ãšå ¥åããŸã
4. [ã«ãŒã«ã®æå®]ã§ããã¹ãŠããã®ãŸãŸã«ããŠ[次ãž]ãã¯ãªãã¯ããŸã
5.次ã®ãã€ã¢ãã°ã§ãWebãµãŒããŒãäœã«åãçµãã§ãããã確èªããŸãã
6. [眲åã¢ã¯ã·ã§ã³ã®éžæ]ã§ããã¹ãŠããã®ãŸãŸã«ããŸãã
7. [æ·±ãä¿è·ã®éžæ]ã§ãæåã®4ã€ã®ãªãã·ã§ã³ããã§ãã¯ããŸãã HTMLã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ã§ã¯ãããã©ã«ãã§HTMLã¿ã°ãGETããã³POSTãªã¯ãšã¹ãã§éä¿¡ãããããšãçŠæ¢ããŠããããšã«æ³šæããŠãã ããã ä»»æã®ã«ãŒã«ã«ãã£ã«ã¿ãŒãšæ¡ä»¶ãèšå®ã§ãããããããã¯æãããšã§ã¯ãããŸããã
8. [ãã£ãŒãã¢ã¯ã·ã§ã³ã®éžæ]ã§ããããã¯ãããªãã·ã§ã³ããã§ãã¯ããå¿ èŠããããŸãã åæ段éã§ã¯ããããã¯ããã®ã§ã¯ãªãããµã€ããæ©ãåããèãããããã¹ãŠã®ãŠãŒã¶ãŒã®è¡åãã¹ããŒãžã³ã°ããçµ±èšãåéããããããããã¯ãããã®ãšè¿œå ã«ãŒã«ãäœæããå Žæã決å®ããããšããå§ãããŸãã ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãé€ããã¹ãŠãããã«ãããã¯ã§ããŸãã
9.ã«ãŒã«ãäœæããããã«ãŒã«ãéããŠè¿œå ã®èšå®ãè¡ãå¿ èŠããããŸãã
aïŒãšã³ã³ãŒãã£ã³ã°ãèšå®ããŸã
bïŒãããã³ã°ã®è©Šã¿ããã£ãå Žåã«ãŠãŒã¶ãŒããªãã€ã¬ã¯ããããããŒãžãäœæããŸãã ããã¯éåžžããŒã ããŒãžã§ãããã¢ã¯ã·ã§ã³ãçããããšæãããæ å ±ãå«ãå¥ã®ããŒãžãäœæãã管çè ãããã³å¿ èŠã«å¿ããŠæ管å®åºã«éä¿¡ããããšãã§ããŸãã
cïŒä»ã®å€ãã®åŸ®åŠãªèšå®ããã®èª¬æã¯ããã¥ã¡ã³ãã«ãããŸãã
10.次ã«ããµã€ãã«ã¢ã¯ã»ã¹ãããããŒSQLã€ã³ãžã§ã¯ã·ã§ã³http://172.16.0.102/?Search=00&q=CB506-67902 'UNION SELECT aaa FROM aaaã䜿çšããŠããŒãžãéããã¡ã€ã³ããŒãžã«ã©ã®ããã«ã¹ããŒããããã確èªããŸãã
11. Cookieã®ç·šéãã«ããã«ã®ä¿®æ£ãããŒãžã®æŽæ°ãå¯èœã«ãããã©ã°ã€ã³ããã©ãŠã¶ãŒã«é 眮ããŸãã ããªãã®åŽã®ã¯ãããŒã¯å€æŽãããŸãããããŠã§ããµãŒããŒã«éä¿¡ãããŸããã NSã¯ãå ã®ãµãŒããŒãã¹ãã¬ãŒãžã«æž¡ãããã¹ãŠã®Cookieããã£ãã·ã¥ããŸãã 次ã®REQèŠæ±ã§ãNSã以åã«èšå®ãããCookieã®äžäžèŽãæ€åºããå ŽåãNSã¯åã«ãããããããã¯ããŸãã
12. [ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°]ã»ã¯ã·ã§ã³ã§[ãããã¯]ããªã³ã«ããå ŽåãGETãŸãã¯POSTãªã¯ãšã¹ãã䜿çšããŠHTMLãéä¿¡ãããšãã¡ã€ã³ããŒãžã«ããªãã€ã¬ã¯ããããŸãã
13.ããã¯çŽ æŽãããããšã§ã¯ãããŸãããïŒ èšå®ã詳ãã調ã¹ãŠã¿ããšãèªåã«ãšã£ãŠèå³æ·±ãæçšãªãã®ãããããèŠã€ãããŸãã NSã¯WebãµãŒããŒã«ããŒãæž¡ãåã«ããŒããã³ãŒããããããCookieã¯ããŠãŒã¶ãŒããã®ããã«åœé ã§ããªãããã«ãã»ãã¥ãªãã£ã匷åããããã«ãšã³ã³ãŒãã§ããŸãã æ€èšŒãŸãã¯ãšã¹ã±ãŒãã®ããã«ãã¿ã€ãã®æ£èŠè¡šçŸãŸãã¯ãã£ãŒã«ãåã®åœ¢åŒã§ããŒã¿åœ¢åŒãæå®ã§ããŸãã HTMLãŸãã¯SQLããã§ãã¯ããããã«ãç¹å®ã®ããŒãžãŸãã¯ãã£ãŒã«ãã«äŸå€ãäœæã§ããŸãã NSãé©åã«æ§æãããšããµã€ãã®ã»ãã¥ãªãã£ãæ°çŸåã«åäžããŸãã
14.ã³ãã³ãã©ã€ã³çµç±
enable ns feature AppFW add appfw profile crm-appfw-profile -type HTML XML set appfw profile crm-appfw-profile -cookieConsistencyAction block log stats learn set appfw profile crm-appfw-profile -bufferOverflowAction block log stats set appfw profile crm-appfw-profile -crossSiteScriptingAction log stats learn set appfw profile crm-appfw-profile -SQLInjectionAction block log stats learn set appfw profile crm-appfw-profile -startURLAction log stats learn set appfw profile crm-appfw-profile -defaultCharSet utf-8 add appfw policy crm-appfw-policy true crm-appfw-profile bind appfw global crm-appfw-policy 10 save config
DDoDæ»æãåæ ãã
æåŸã«ãç§ãã¡ã¯ããããã¹ãŠã§ãããã€ã³ãã«æ¥ãŸããã ä¿è·ã®ä»çµã¿ã詳ãã調ã¹ãªãããã«ãDDoSãšæŠãããã®èšäºnginxã¢ãžã¥ãŒã«ãèªãããšãã§ããŸãã ååã¯äžå¯Ÿäžã§ãããå®éã®ç¶æ³ã§ãã®ã¢ãžã¥ãŒã«ãæ£åžžã«èµ·åããããšã¯ã§ããŸããã§ããã
1.ã¡ãã¥ãŒã®[ã»ãã¥ãªãã£]> [ä¿è·æ©èœ]> [HTTP DoS]ã«ç§»åããŠã[è¿œå ]ãã¯ãªãã¯ããŸãã
2.ååã«å ããŠãå€ã貌ãä»ãã2ã€ã®ãã£ãŒã«ãããããŸãã ããããæ°ããæ¹æ³ãç解ããŸãããã
æåã®ããã¥ãŒé ç®æ°ããã£ãŒã«ãã¯ããµãŒããŒã®å¿çãåŸ ã£ãŠãããŠãŒã¶ãŒã®å®éçãªå€ã§ãã
1æ¥ããã86400ã®ãŠããŒã¯ãŠãŒã¶ãŒã1æéããã3500人ã1åããã60人ã1ç§ããšã«1人ã®ãŠããŒã¯ãŠãŒã¶ãŒããããšããŸãã
ãã¡ããã圌ãã¯å€ã§ã¯ãªããæ¥äžã¯ããããããŸãã éèŠåºŠãé«ããããã«10åããŠã1ç§ããã10ãŠãŒã¶ãŒãååŸããŸãã äžè¬çã«ãçµ±èšãèŠãããšãã§ããŸãã
1人ã®ãŠãŒã¶ãŒãå¹³åããŠ1ããŒãžããã5ã10åã®ãªã¯ãšã¹ãïŒhtmlãcssãjsãimgãªã©ïŒãèŠæ±ãã5ã10ç§éããããèŠããšããŸãããïŒã ããAJAXãé§åããŸãïŒã
ã€ãŸããè² è·ã®ããŒã¯æã®ãµãŒããŒã¯ã1ç§ãããæ倧100件ã®å¿çãåŠçããŸãã
WebãµãŒããŒã1ç§ãããæ倧500ã®å¿çãéä¿¡ã§ãããã1ç§ããã10,000ã®èŠæ±ããŸãã¯20å以äžã®èŠæ±ãåä¿¡ã§ãããšããŸãã
çŸåšäœäººã®å®éã®ãŠãŒã¶ãŒãåé¡ãçµéšããŠããŸããïŒ ããã§ããåã10ãæ®ãã¯æ»æã§ãã ãããã¯ãå§ããã®ã¯ãã€ã§ããïŒ 10çŽåŸïŒ ãããã®ã§ãããæå°å€ã¯21ã§ãã®ã§ããã®ãŸãŸã«ããŠãããŸãããã ã€ãŸããããŒã¿ãåä¿¡ããããã®ãã¥ãŒã«21å以äžã®ã»ãã·ã§ã³ããããšããã«ãæ»æã«å¯Ÿããèªåä¿è·ããªã³ã«ãªããŸãã
2çªç®ã®ãã£ãŒã«ãã§ãã[ã¯ã©ã€ã¢ã³ãæ€åºç]ã§ã ããã¯ãã·ã©ãããã§ãã¯ãããŠãŒã¶ãŒã®å²åã§ãã æ€èšŒã«1ïŒ ãèšå®ããä¿è·ãèªåçã«ãªã³ã«ãªã£ãŠããå ŽåããµãŒããŒããã®å¿çã®æ°ã¯5ïŒ500 * 0.01ïŒã«ãªãã10,000ã¯é çªã«åŸ æ©ããŸãã ã€ãŸããå®éã®ãŠãŒã¶ãŒã®0.05ïŒ ã ãããã¹ãã«åæ ŒããŸãã ããã§ããã¹ãã£ã³ã¬ãã«ãé«ãå ŽåïŒããšãã°ã10ïŒ ã®å Žåã1000ãªã¯ãšã¹ãã®å€ããã§ãã¯ãããŸãïŒããã¹ãŠã®çºä¿¡ãã©ãã£ãã¯ããã§ãã¯ã§è©°ãŸãããå¯èœæ§ãããããã£ãã«ãçãå Žåã¯ãã§ã«æ»æã§éè² è·ã«ãªã£ãŠããŸãã ãããããã£ãã«ãéåžžã«åããããæ»æããããã«æŠãå§ããããã«30ã35ïŒ ãé 眮ããŸãã ãã®ãã£ãŒã«ãã¯ç©ºçœã®ãŸãŸã«ããããšãã§ããNSã枬å®ã§ãããã£ãã«ã®å¹ ãèŠæ±ãå¿çããã®ä»ã®ã€ã³ãžã±ãŒã¿ã®æ°ã«å¿ããŠãæ€èšŒã®ã¬ãã«ãå€ããããšãã§ããŸãã
3.次ã«ã[ãã©ãã£ãã¯ç®¡ç]> [è² è·åæ£]> [ãµãŒãã¹]ã¡ãã¥ãŒã«ç§»åãã[éã]ãã¿ã³ã䜿çšããŠãµãŒãã¹ãéãã[ããªã·ãŒ/ HTTP DoS]ã¿ãã§ãæ°ããäœæããããªã·ãŒãæ¿å ¥ããŸãã
4.ã³ãã³ãã©ã€ã³çµç±
enable ns feature HttpDoSProtection add dos policy crm-ddos-policy -qDepth 21 -cltDetectRate 33 bind service CRM-service -policyName crm-ddos-policy save config
Netscalerã§ä»ã«ã§ããããš
ãã®ããšãããç¥ã£ãŠããŸãã ãµã€ãã«å¿ èŠãªãã®ãããããã¯æ¬¡ã®ãšããã§ãã
1.éçã³ã³ãã³ããšåçã³ã³ãã³ããåé¢ããŠãè² è·ã軜æžããŸãã
2.éçã³ã³ãã³ãã®ãããã·ã
3.ç¹å®ã®æ¡ä»¶ãŸãã¯æéã«å¿ããŠãåçã³ã³ãã³ãããã£ãã·ã¥ãããã£ãã·ã¥ããã©ãã·ã¥ããŸãã
4.ãµã³ãã«æ°ãæžããããã®mySQLããã³ãã®ä»ã®ãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ã®ãããã·ããã³ãã£ãã·ã¥ã
5.ãããã¯ãŒã¯ã¢ãã¬ã¹ãå°ççäœçœ®ããã®ä»ã®å€ãã®ãã©ã¡ãŒã¿ãŒã«ãããã©ãã£ãã¯ãšã³ã³ãã³ãã®åé¢ã
6.ãã©ãã£ãã¯ã®æå·åã
7. DNSãµãŒããŒãšããŠæ©èœããŸãã
8.ããã©ã«ãã§ã¯ãNSã¯ãã§ã«ICMPãã©ãããªã©ããã®ãããã¯ãŒã¯ä¿è·ããã§ã«æã£ãŠããŸãã
ãããã«
ãã¹ãŠãéåžžã«ç°¡åã«æ§æãããŸãããåžžã«çŽæçã§ã¯ãããŸããã ãã®èª¬æã¯ããã³ããŒã®Webãµã€ãã§å ¥æã§ããŸã ã ãŠã§ããµã€ãhttp://netscaler.kzã®äž»ãªæ©èœã«ã€ããŠãã·ã¢èªã§èªãããšãã§ããŸãã
ãã®ãã©ãããã©ãŒã ã«é¢ãããã·ã¢èªã®æ å ±äžè¶³ã¯ãCISè«žåœã§ã®ãã®æ®åçã«å€§ãã圱é¿ããŸãã ãããã£ãŠãæããã«ãææ°ã®ãããã¯ãŒã¯ç®¡çè ã¯ãã®è£œåã®æ©èœãéå°è©äŸ¡ããŠããŸããã
å®éã2幎åã«ã·ã¹ã³ãACEãã©ã³ãµãŒã®ãããªãéçºãåæ¢ããããšãæ£åŒã«çºè¡šããããšã¯ç¡é§ã§ã¯ãããŸããã§ãããæè¿ã§ã¯ãNetscalerãäžéšã®äžé£ã®Ciscoã¹ã€ããã®äžéšã«ãªã£ãŠããŸãã
ãããããé¡ãããŸãïŒ