äžèšã®ããã«ãIPAMãç»å Žããåã«ãå³åžã®ããŒã«ã䜿çšããŠãããã¯ãŒã¯äžã®IPã¢ãã¬ã¹ã管çããå¿ èŠããããŸããããµãŒãããŒãã£ã®ããŒã«ããExcelããŒãã«ã®ã¢ãã¬ã¹ãªã¹ããŸã§ã ãã®çµæããããã¯ãŒã¯ç®¡çã®çç£æ§ãäœäžããã³ã¹ããå¢å ããã ãã§ããã ããã«ãå©çšå¯èœãªããŒã«ã¯ãçæçã«ãããã¯ãŒã¯ã¢ãã¬ã¹ã管çããåé¡ã解決ããã®ã«é©ããŠããŸããã ãããããããã¯ãŒã¯ãæé·ããäœæ¥æéãé·ããªãã°ãªãã»ã©ããã®äœæ¥ã¯é¢åã«ãªããŸããã
Windows Server 2012ã®ãªãªãŒã¹ã«äŒŽãããããã¯ãŒã¯IPã¢ãã¬ã¹ã管çããããã®å éšããŒã«ã§ããIPAMãç»å ŽããŸããã IPAMïŒIPã¢ãã¬ã¹ç®¡çïŒã¯ãWindows Server 2012ããã³Windows Server 2012 R2ã§åããŠå°å ¥ãããIPã¢ãã¬ã¹ç®¡çãµãŒãã¹ã§ãã ããã«ã Windows Server vNextã§IPAMå€æŽã®åŒ·åãæåŸ ã§ããŸãã IPAMã¯ãçµç¹ã®ãããã¯ãŒã¯å ã®IPã¢ãã¬ã¹ç©ºéãæ€åºãç£èŠã管çãããã³ç£æ»ããããã®ãã©ãããã©ãŒã ã§ãã
IPAMã®äž»ãªæ©èœã«ã¯æ¬¡ã®ãã®ããããŸãã
- IPã€ã³ãã©ã¹ãã©ã¯ãã£ã®èªåæ€åº
- IPã¢ãã¬ã¹ç©ºéã衚瀺ã管çãå ±åããããã®äŸ¿å©ã§æè»ãªæ段
- DHCPããã³IPAMãµãŒãã¹ã®æ§æå€æŽã®ç£æ»
- DHCPããã³DNSãµãŒãã¹ã®ç£èŠãšç®¡ç
- IPãªãŒã¹ãã©ããã³ã°
IPAMã®äž»ãªå©ç¹ã¯ããã©ã¬ã¹ãå ã®ãã¹ãŠã®DNSããã³DHCPãµãŒãã¹ã®æ§ææ å ±ãæäŸããåäžã®ã³ã³ãœãŒã«ãæäŸããããšã§ãã ãã®ã³ã³ãœãŒã«ã䜿çšããŠãããšãã°ã1ã€ãŸãã¯è€æ°ã®DHCPãŸãŒã³ã®èšå®ãå€æŽã§ããŸããããã«ãããã·ã¹ãã 管çè ãè¿œå ã®ã¹ã¯ãªãããèšè¿°ããããåDHCPãµãŒããŒãæåã§æ§æãããããå¿ èŠããªããªããŸãã 次ã«ãäŸã§ãã®ãããªèšå®ã確èªããŸãã
ããããæåã«ãIPAMãµãŒãã¹ãå±éããããã䜿çšããŠDNSããã³DHCPãµãŒãã¹ãç£èŠããæ¹æ³ã確èªããŸãã
IPAMãµãŒããŒãå±éãã
IPAMãµãŒããŒã§ã®äœæ¥ãéå§ããã«ã¯ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸã-IPAMã¯ãããã©ã«ãã§ã€ã³ã¹ããŒã«ããããµãŒãã¹ã»ããã«å«ãŸããŠããŸããã ã€ã³ã¹ããŒã«ã«ã¯2ã€ã®æ¹æ³ããããŸãã 次ã®PowerShellã³ãã³ãã䜿çšã§ããŸãã
Install-WindowsFeature IPAM âIncludeManagementTools
ãŠã£ã¶ãŒãã䜿çšããŠã圹å²ãšãµãŒããŒã³ã³ããŒãã³ããã€ã³ã¹ããŒã«ããããšãã§ããŸãã
IPAMã®ã€ã³ã¹ããŒã«ããã»ã¹ãå®äºããããäœæ¥ã®ããã«æºåããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããµãŒããŒãããŒãžã£ãŒã§[IPAM]ãéžæããIPAMãµãŒããŒãããããžã§ãã³ã°ããŸãã
2ã€ã®æºåæ¹æ³ããéžæã§ããŸãã æåïŒ æå ïŒãŸãã¯ã°ã«ãŒã ããªã·ãŒã« åºã¥ã ïŒ ã°ã«ãŒã ããªã·ãŒ ããŒã¹ ïŒã§ãã ããã2ã€ã®æ¹æ³ã®éãã¯äœã§ããïŒ
管ç察象ãµãŒããŒã®æ°ãå°ãªãå Žå㯠ã IPAM ãµãŒããŒã æåã§æºåããæ¹æ³ããå§ãããŸãã ãã®æºåæ¹æ³ãéžæããå Žåãå管ç察象ãµãŒããŒã®ã¢ã¯ã»ã¹æ¡ä»¶ãæåã§æ§æããå¿ èŠããããšããäºå®ã«åããå¿ èŠããããŸãã ãŸãããã®ãµãŒããŒãŸãã¯ãã®ãµãŒããŒã管çããå¿ èŠããªããªã£ãå Žåã¯ãèšå®ãæåã§åé€ããå¿ èŠããããŸãã æåã®æºåæ¹æ³ãéžæããå Žåã§ããã°ã«ãŒãããªã·ãŒã䜿çšããŠå¿ èŠãªèšå®ã管ç察象ãµãŒããŒã«é©çšã§ããŸããããã¹ãŠã®GPOãæåã§é©çšãŸãã¯åé€ããå¿ èŠããããŸãã IPAMãµãŒããŒãæåã§æºåããæ¹æ³ã¯ããæéãããããè€éã§ãããšããäºå®ã«ãããã°ã«ãŒãããªã·ãŒã䜿çšããæºåæ¹æ³ã䜿çšããããšããå§ãããŸãã
ã°ã«ãŒãããªã·ãŒã䜿çšã ㊠IPAM ãµãŒããŒã æºåããæ¹ ãç°¡åã§ããšã©ãŒãçºçããå¯èœæ§ãäœããªããŸãã ãã®æ¹æ³ã䜿çšãããšã管ç察象ãµãŒããŒã§GPOãèªåçã«é©çšããã³åé€ãããŸãã ãã®æ¹æ³ã¯ãIPAMæºåãŠã£ã¶ãŒãã§ããã©ã«ãã§äœ¿çšãããããšãææ¡ãããŠããŸãã GPOã®ååã®ãã¬ãã£ãã¯ã¹ãå ¥åããå¿ èŠããããŸãã
ããã§ãã°ã«ãŒãããªã·ãŒã䜿çšããŠIPAMãµãŒããŒãæºåããå Žåãæåã®æºåæ¹æ³ã«å€æŽã§ããªãããšã«æ³šæããŠãã ããã ãã ããå察ã®å ŽåãWindows PowerShellã³ãã³ãã¬ããã䜿çšããŠãã°ã«ãŒãããªã·ãŒã䜿çšããæåã®æºåæ¹æ³ãæºåã«å€æŽã§ããŸãã
Set-IpamConfiguration
æºåãŠã£ã¶ãŒãã«æ»ããŸãã ã°ã«ãŒãããªã·ãŒã䜿çšããŠæºåæ¹æ³ãéžæãããšã次ã®ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãã䜿çšããŠèšå®ã管ç察象ãµãŒããŒã«é©çšããããšããã¡ãã»ãŒãžã衚瀺ãããŸãã
- <GPO-prefix> _DHCPïŒãã®GPOã¯ãIPAMããããã¯ãŒã¯äžã®ç®¡çãããDHCPãµãŒããŒããæ å ±ãç£èŠã管çãåéã§ããèšå®ãé©çšããããã«äœ¿çšãããŸã
- <GPO-prefix> _DNSïŒãã®GPOã¯ãIPAMããããã¯ãŒã¯äžã®ç®¡çãããDNSãµãŒããŒããæ å ±ãç£èŠããã³åéã§ããèšå®ãé©çšããããã«äœ¿çšãããŸã
- <GPO-prefix> _DC_NPSïŒãã®GPOã¯ãIPAMã管ç察象ãã¡ã€ã³ã³ã³ãããŒã©ãŒããã³ãããã¯ãŒã¯äžã®ãããã¯ãŒã¯ããªã·ãŒãµãŒããŒïŒNPSïŒããæ å ±ãåéãããããã¯ãŒã¯äžã®DHCPãµãŒããŒãIPã¢ãã¬ã¹ã远跡ã§ããããã«ããèšå®ãé©çšããããã«äœ¿çšãããŸã
ãã®å ŽåãGPOã®ååã¯ããããIPAM_DHCPãIPAM_DNSãããã³IPAM_DC_NPSã«ãªããŸãã IPAMã®æºåãå®äºããã«ã¯ã[æŠèŠ]ã¿ãã®æ å ±ãæ£ããããšã確èªãã[é©çš]ãã¯ãªãã¯ããŸãã æºåããã»ã¹ã«ã¯æéãããããŸãã ãã®çµæãIPAMã®æºåãæ£åžžã«å®äºããããšã瀺ãã¡ãã»ãŒãžã衚瀺ãããŸãã
ããã§ã¯ã次ã®ã¹ãããã«é¢ããã¡ãã»ãŒãžãéèŠã§ãã GPOã¯äœæãããŠããªããããPowerShellã³ãã³ãã¬ããã䜿çšããŠããã«äœæããå¿ èŠããããŸãã
Invoke-IpamGpoProvisioning
ããã¯å°ãåŸã«ãªããŸãã ãããŸã§ã®éããµãŒããŒãããŒãžã£ãŒã«ç§»åããŠãµãŒããŒæ€åºãæ§æããŸãã
衚瀺ããããŠã£ã³ããŠã§ãæ€åºãããã¡ã€ã³ãéžæããŸãã ç§ãã¡ã®å Žåãããã¯mva.comã®ã«ãŒããã¡ã€ã³ã§ãã ãã®ãã¡ã€ã³ãè¿œå ãããããµãŒããŒã®åœ¹å²ã®äžã«ãã¡ã€ã³ã³ã³ãããŒã©ãŒãDHCPãµãŒããŒãããã³DNSãµãŒããŒãããããšã確èªããå¿ èŠããããŸãã OKãã¯ãªãã¯ããŸãã
ãµãŒããŒã®æ€åºãéå§ããŸãããã
ã¿ã¹ã¯ãå®äºããåŸã [IPAM]ã¿ãã®[ãµãŒããŒãããŒãžã£ãŒ]-[ãµãŒããŒã®å転]ã«ç§»åããŸãã dsc01ãµãŒããŒãšDCãµãŒããŒã®å Žåã[管çã¹ããŒã¿ã¹]åã«ã¯[æªå®çŸ©]ã¹ããŒã¿ã¹ã衚瀺ããã[ã¢ã¯ã»ã¹ã¹ããŒã¿ã¹]åã«ã¯[ãããã¯]ãšè¡šç€ºãããŸãã GPOã䜿çšããŠãããã®ãµãŒããŒã管çããã«ã¯ãIPAMã¢ã¯ã»ã¹èš±å¯ãä»äžããå¿ èŠããããŸãã
ããã§ãIPAMã®æºåãå®äºããåŸã«è¡ãããšãæšå¥šããã次ã®ã¹ããããæãåºããŠãã ããã IPAMãµãŒããŒã§ç®¡çè æš©éã§Windows PowerShellãå®è¡ãã次ã®ã³ãã³ãã¬ããã䜿çšããå¿ èŠããããŸã
Invoke-IpamGpoProvisioning âDomain mva.com âGpoPrefixName IPAM âDelegatedGpoUser Administrator âIpamServerFqdn ipam.mva.com
ããã§ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ããäœæãããã°ã«ãŒãããªã·ãŒç®¡çã¹ãããã€ã³ã§ç¢ºèªã§ããŸãã
ãµãŒããŒãããŒãžã£ãŒã«æ»ããŸãã [IPAM-ãµãŒããŒã€ã³ãã³ããª]ã¿ãã§ãããããã®ãµãŒããŒãå³ã¯ãªãã¯ãã[ãµãŒããŒã®ç·šé ]ãéžæããŸã ã 衚瀺ããããŠã£ã³ããŠã§ãé ç®ã管çã¹ããŒã¿ã¹ããã管çãã«å€æŽãããOKããã¯ãªãã¯ããŸãã 2çªç®ã®ãµãŒããŒã«ã€ããŠãåãæé ãç¹°ãè¿ããŸãã
ããã§ãã°ã«ãŒãããªã·ãŒã®å€æŽãDCããã³dsc01ãµãŒããŒã§æå¹ã«ããå¿ èŠããããŸãã æéã®æ¹æ³ã¯ãå¿ èŠãªåãµãŒããŒã§æ¬¡ã®PowerShellã³ãã³ãã¬ããã䜿çšããããšã§ãã
gpupdate /force
åãµãŒããŒã§ãã®ã³ãã³ããå®äºãããŸã§åŸ æ©ããŸãã ãµãŒããŒãããŒãžã£ãŒ-IPAM-ãµãŒããŒã€ã³ãã³ããªã§IPAMãµãŒããŒã«æ»ãããIPv4ããæŽæ°ãããããããå³ã¯ãªãã¯ããŠããµãŒããŒã¢ã¯ã»ã¹ã¹ããŒã¿ã¹ã®æŽæ°ããéžæããããšã«ããããµãŒããŒã¢ã¯ã»ã¹ã¹ããŒã¿ã¹ãæŽæ°ããŸãã ãã®çµæããIPAM Access Statusãåã§ãµãŒããŒã®ã¹ããŒã¿ã¹ãUnlockedããååŸããå¿ èŠããããŸãã
次ã«ãIPAM-æŠèŠã¿ãã«æ»ããã管ç察象ãµãŒããŒããããŒã¿ãååŸããããéžæããŠããã®ã¿ã¹ã¯ãå®äºãããŸã§åŸ ã¡ãŸãã
次ã®ããŒã¿åéã¿ã¹ã¯ãèªåçã«èµ·åãããŸãïŒAddressExpiryãAddressUtilicationãAuditãServerAvailabilityãServiceMonitoringãServerConfigurationã
ãã®æ®µéã§ãIPAMãµãŒããŒã®æ§æãå®äºããIPAMãµãŒããŒãå®éã«äœ¿çšããæ¹æ³ã確èªããŸãã äŸãšããŠãIPAMã䜿çšããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç£èŠãšç®¡çãæ€èšããŠãã ããã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç£èŠãšç®¡ç
IPAMã䜿çšãããšããã©ã¬ã¹ãå šäœã§DHCPãµãŒããŒãšDNSãµãŒããŒãç£èŠããé »åºŠãèªååããã³æ§æã§ããŸãã è€æ°ã®ãµãŒããŒã管çããŠèšå®ãèªåçã«é©çšããADãã©ã¬ã¹ãå ã®DHCPãµãŒããŒãšDNSãµãŒããŒãå®æçã«ç£èŠããããšãã§ããŸãã ããã«ãã¯ã³ã¯ãªãã¯ã§è€æ°ã®DHCPãµãŒããŒãšåæ£ãµãŒããŒã®ãšãªã¢èšå®ã管çã§ããŸãã
äŸãšããŠãIPAMã䜿çšããŠDHCPãµãŒããŒãšDNSãµãŒããŒãç£èŠããã³ç®¡çããæ¹æ³ãæ€èšããŠãã ããã
[IPAM-ç£èŠãšç®¡ç-DNSããã³DHCPãµãŒããŒ]ã¿ãã§ãµãŒããŒãããŒãžã£ãŒãéããŸãã [ãµãŒããŒã¿ã€ã]ãã£ãŒã«ãïŒ1ïŒã§ã¯ãDNSãšDHCPã ãã§ãªããDNSã®ã¿ãŸãã¯DHCPã®ã¿ã䞊ã¹æ¿ããããšãã§ããŸãã ãµãŒããŒã®1ã€ãéžæãããšããã®ãµãŒããŒã®ããããã£ããã©ã¡ãŒã¿ãŒãããã³ã€ãã³ãã«ã¿ãã°ã衚瀺ã§ããŸãïŒ2ïŒã
次ã«ã[ãµãŒããŒã¿ã€ã]ãã£ãŒã«ãã§[DHCP]ãéžæãã[衚瀺]ãã£ãŒã«ãã§[ã¹ã³ãŒãããããã£]ãéžæããŸãã
MVA DHCP ã¹ã³ãŒã - ã¹ã³ãŒã 1ãå³ã¯ãªãã¯ãã[DHCPã¹ã³ãŒãã®è€è£œ]ãéžæããŸãã 衚瀺ããã[DHCPã¹ã³ãŒãã®è€è£œ]ãã€ã¢ãã°ããã¯ã¹ã§ã[ã¹ã³ãŒãå]ãã£ãŒã«ãã®å€ãå€æŽãã[äžè¬ããããã£]ã»ã¯ã·ã§ã³ã§æ¬¡ã®å€ãå ¥åããŸãã
- éå§IPã¢ãã¬ã¹ïŒ192.168.1.1
- æçµIPã¢ãã¬ã¹ïŒ192.168.1.254
- ãµãããããã¹ã¯ïŒ255.255.255.0
å¿ èŠã«å¿ããŠããšãªã¢ã®ä»ã®ããããã£ãå€æŽã§ããŸãã å¿ èŠãªå€æŽããã¹ãŠè¡ã£ãåŸã[OK]ãã¯ãªãã¯ããŠããªã¹ãã«å¥ã®é åïŒMVA-scope2ïŒã衚瀺ãããŠããããšã確èªããŸãã
DHCPãµãŒããŒDSC01ã®DHCPã³ã³ãœãŒã«ã«åãé åã衚瀺ãããŸãã
IPAMãµãŒããŒã«æ»ããäž¡æ¹ã®DHCPãšãªã¢ãéžæããŠå³ã¯ãªãã¯ãããšãäž¡æ¹ã®ãšãªã¢ã®èšå®ãå€æŽã§ããŸãã
ãã¡ãããIPAMã䜿çšããŠãDNSãµãŒããŒãšDHCPãµãŒããŒäžã®ããŸããŸãªçš®é¡ã®ã€ãã³ããç£èŠã§ããŸããããã«ã¯ããµãŒããŒèªäœãšã¯ã©ã€ã¢ã³ãã®äž¡æ¹ã«é¢ããããŒã¿ãå«ãŸããŸãã ç£æ»ãã°ãšã€ãã³ãã衚瀺ããã«ã¯ãIPAMããã²ãŒã·ã§ã³ã¡ãã¥ãŒã§[ã€ãã³ããã£ã¬ã¯ããª]ïŒã€ãã³ãã«ã¿ãã°ïŒãéžæããŸãã æ¢å®ã§ã¯ãäžéšã®ããã²ãŒã·ã§ã³é åã§[IPAMæ§æã€ãã³ã]ãéžæãããŠããŸãã ä»ã®ã€ãã³ããéžæããŠè¡šç€ºãããããããããã¡ã€ã«ã«ãšã¯ã¹ããŒãããŠããã«è¡šç€ºãããåæãããã§ããŸãã
ãã®èšäºã®æ å ±ãã圹ã«ç«ãŠã°å¹žãã§ãïŒ
䟿å©ãªãªã³ã¯
- Azureã30æ¥éç¡æã§ãè©Šããã ãã ïŒ
- Microsoft Virtual Academy ã³ãŒã¹ãåŠã¶
- äŒæ¥ã®ããã€ã¹ã ããŒã¿ãšã¢ããªã±ãŒã·ã§ã³ãä¿è·ããæ¹æ³
- äŒæ¥ã®ããã€ã¹ã ãã€ããªããè³æ Œæ å ±ã管çããæ¹æ³
- ã³ã³ãã¥ãŒã¿ã»ãã¥ãªãã£ã®åºæ¬
- ãã¡ã€ã³ãããã¯ãŒã¯æ§ç¯ã®åºæ¬
- Windows Server 2012 R2ã䜿çšããŠçµç¹ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãã¢ããã°ã¬ãŒããã
- Windows Server 2012 R2ã©ã€ã»ã³ã¹
- Windows Server 2012 R2ã®è©ŠçšçãããŠã³ããŒããã
- ç¡æãŸãã¯è©Šçšçã®Visual StudioãããŠã³ããŒããã