ããªãã®å€ãã¯ããNetworks for the Youngestããšããäžè¬çãªã¿ã€ãã«ã§åªããè³æãèŠããèªãã ãããŠããŸãã å®éãç§ã¯ææ¡æš¹ã®ãµããããã€ããã¯ãããŸããããã·ã¹ã³ã®æ©åšã«åºã¥ãããããã¯ãŒã¯ã»ãã¥ãªãã£ã®åéã§äŒŒããããªãã®ãæžãããšã«ããŸããã
æåã®è³æã¯ãBaseLine / L2 Securityãã€ãŸã IOSãå®è¡ããŠããL2ã¹ã€ãããšåæ§ã«ãããã€ã¹ã®åæèšå®ã§äœ¿çšã§ããã¡ã«ããºã ã
èå³ã®ããçãããè¡ããïŒ
æ°åã®[ã¹ã€ãã/ã«ãŒã¿ãŒ]ããããšããŸããæåã®ç« ã§ã¯éèŠã§ã¯ãããŸããã ã³ã³ãœãŒã«ã¯ã€ã€ã䜿çšããŠæ¥ç¶ããŸãïŒ æå°ã®ããŒã1ãããã¯ãŒã¯ã«ã€ããŠè©³ãã説æããŸãïŒã ãªããªã ããŒãã«ã®äžã«éçã眮ããããïŒãã§ã«ã©ãã¯ã«èšçœ®ãããŠããå ŽåïŒãµãŒããŒã«ãŒã ã§ç«ã£ãŠåçµããããªãå Žåã¯ãããã«ãªã¢ãŒãã³ã³ãããŒã«ãèšå®ããŸãã
ãªã¢ãŒãå¶åŸ¡ãšè³æ Œæ å ±
ãªã¢ãŒãã§æ¥ç¶ããã«ã¯ãç¬èªã®è³æ Œæ å ±ãå¿ èŠã§ãã ã³ã³ãœãŒã«ãä»ããŠæ¥ç¶ãããšãå¶éãªãã§ç¹æš©ã¢ãŒãã«å ¥ãããšãã§ããŸãã ãåç¥ã®ããã«ãããã¯ç¹ã«å®å šã§ã¯ãããŸããããæ»æè ãæ¢ã«éçã«ç©ççã«ã¢ã¯ã»ã¹ã§ããå ŽåãååãšããŠã©ã®ãããªã»ãã¥ãªãã£ã«ã€ããŠè©±ãããšãã§ããŸã...ããããå€å±€é²åŸ¡ã¢ãããŒããèæ ®ããŠããã¹ã¯ãŒããç¹æš©ã¢ãŒãã«èšå®ããããšã¯ãŸã 䟡å€ããããŸãã
IOSã«ã¯ããã¹ã¯ãŒãã¹ãã¬ãŒãžã¬ãã«ã®4ã€ã®ãªãã·ã§ã³ããããŸãïŒ0ã4ã5ã7ïŒ
- 0ã¬ãã«ïŒãã¹ã¯ãŒããæå¹ã«ããQwertyïŒ23-ã¯ãªã¢ããã¹ãã§ã®ããŒã¿ã¹ãã¬ãŒãžã
- ã¬ãã«4ïŒã·ãŒã¯ã¬ããQwertyïŒ23ãæå¹ã«ãã-IOS 15ã§ã®SHA256æå·åãžã®ããŒã¿å€æ ãæ°ããæå·åãžã®å€æŽãmd5ã¯éããªãå»æ¢ãããå¯èœæ§ããããŸããã
- ã¬ãã«5ïŒã·ãŒã¯ã¬ããQwertyãæå¹ã«ããŸãïŒ23-MD5ããã·ã¥ãžã®ããŒã¿å€æã
äŸãšããŠãã©ã¡ãŒã¿ãŒã䜿çšããŠenableã³ãã³ãã䜿çšããŠãããããæ€èšããŠãã ããã
èšå®ãèŠãŠã¿ãŸããããåããã¹ã¯ãŒããèšå®ããããšã¯ã§ããŸããã§ããïŒIOUã¹ã€ããã«ããŒãžã§ã³15.1ããããã¬ãã«4ã䜿çšãããŠããããïŒã
ã¬ãã«7ïŒãµãŒãã¹ãã¹ã¯ãŒãæå·åããã®ã³ãã³ããå ¥åãããšãCiscoæå·åãããã³ã«ã䜿çšããŠ0ã¹ãã¬ãŒãžã¬ãã«ã®ã¿ã7ã«å€æãããŸãã
ã¬ãã«7ã¯ã»ãã¥ãªãã£ã®èŠ³ç¹ãã4ããã³5ããä¿¡é Œæ§ãé«ããšæ³å®ã§ããŸãããããã¯ããã§ã¯ãªããããšãã°ãã®è³æã§èªãããšãã§ããŸãã
ããã€ã¹ãžã®å®å šãªæ¥ç¶ã¬ãã«ãããã«é«ããããã«ã次ã®ã³ãã³ããå°å ¥ããŸãïŒããã§ãã³ãã³ãã¯IOSããŒãžã§ã³15.4ã䜿çšããŠã«ãŒã¿ãŒã«å ¥åãããŸããã¹ã€ããã§å¿ èŠãªã³ãã³ãã¯ãªãªãŒã¹æ©èœã«ãããã®ã§ã¯ãªãããã§ãïŒã
圌ããããããšïŒåœŒãã¯10æåã®æå°ãã¹ã¯ãŒãé·ã®èŠä»¶ãèšå®ããæ倧ç¹æš©ã¬ãã«ãæã€ãŠãŒã¶ãŒãäœæãã圌ã«ãNotAdminããšããååãä»ããŸããã
ciscoãadminãrootãªã©ã®ãŠãŒã¶ãŒåã䜿çšããŸãã æšå¥šãããŸããã ã芧ã®ãšãããQwertyïŒ23ã®ãã¹ã¯ãŒãã¯é·ãã®å¶åŸ¡ã®ããããŸããããŸããã§ããïŒãã¹ã¯ãŒãã«åé¡ãããå Žåã¯ããã®ç·Žç¿ããäœãè©ŠããŠã¿ãŠãã ããïŒãã¹ã¯ãŒããæãåºããŸãã!! CNrmpãããŒãºä»ãã¯ã©ãŒã¿ãŒããŠã³ããŒ= .25ïŒerwchzããã¹ã¯ãŒããäœåºŠãå€æŽããå¿ èŠããããŸããïŒ= hmtdïŒn2cmpïŒïŒæ¬¡ã«ãå®å šãªæ¥ç¶ã®ããã®ããŒãçæããsshã®ã¿ã䜿çšããŠæ¥ç¶ãã©ã¡ãŒã¿ãŒãèšå®ããŸãããŸãããã®æ§æã§ã¯ã -åã
ããããã¹ãŠã®ããã«ããŠãŒã¶ãŒåãæã€ããŒã«ã«ããŒã¿ããŒã¹ã䜿çšãããŸãã åæ§ã«ïŒããŒã«ã«ïŒãã³ã³ãœãŒã«ããŒããèšå®ããŸãã ç¹æš©ã¬ãã«ãæå®ãããŠããªãããŸãã¯15æªæºã®å¥ã®ã¢ã«ãŠã³ãã䜿çšããå ŽåïŒããã©ã«ãã§ã¯3ã€ã®ç¹æš©ã¬ãã«ããããŸãïŒ0ã1ã15ïŒãã¢ã«ãŠã³ãã«å ¥ããšããããã³æå¹ã«ããããã«ç¹æš©ã¢ãŒããã¢ã¯ãã£ãã«ãããšãã«ãã¹ã¯ãŒããå ¥åããå¿ èŠããããŸãã
ãã¹ã¯ãŒãã¢ã¯ã»ã¹ãèšå®ãããšãã¯ã passwordã³ãã³ãã䜿çšããªãããšã匷ããå§ãããŸãã
管çãããã¯ãŒã¯ãåå¥ã«å²ãåœãŠãããšãæãŸããäžæ¹ã§ãããã€ã¹ã®IPã¢ãã¬ã¹ããã³ã°ã¢ãããããŸãŸã«ããŸãïŒdgã®å ŽåããããŸãããOOB管çãããã¯ãŒã¯ããããã©ããã«ãã£ãŠç°ãªããŸãïŒã
ãã¹ãŠãããã€ã¹ã¯ãªã¢ãŒãã§äœ¿çšã§ããŸãã
ã¯ããçªç¶ãã¹ã¯ãŒããå¿ããå Žåã¯ã ãã¡ãã«ãã«ãããããŸã ã ãã¡ããã ãµãŒãã¹ãã¹ã¯ãŒãå埩ã䜿çšããŠããªãå Žåã
ããšãã°ãCiscoããã€ã¹ã®ãªã¢ãŒãå¶åŸ¡ã«ã»ãã¥ã¢ãªã¡ã«ããºã ã䜿çšããæ¹æ³ã«ã¯2ã€ã®æ¹æ³ããããŸãã AAAããªããã°ãäžèšã§ç¢ºèªããŸããã çŸåšãAAAã䜿çšããŠããŸãã
AAAãšã¯-èªèšŒãèš±å¯ãã¢ã«ãŠã³ãã£ã³ã°ããŸãã¯å²ãåœãŠããããªãœãŒã¹ã®å¶åŸ¡ã ã芧ã®ãšãããAAAã¯ã¢ã¯ã»ã¹ã®ç¹ã§éåžžã«ãã现ãããã»ãã¥ãªãã£ã®ã¬ãã«ãé«ããã ãã§ãã ãã®äœ¿çšãã©ã®çšåºŠé¢é£ãããã¯ãç¹å®ã®ã¢ãŒããã¯ãã£ã«äŸåããŸãã ãã¹ãŠãåçŽã«ã¢ã¯ãã£ãåãããŸãã
ãã®ãããç»é¢äžã®ã³ãã³ãïŒ2人ã®ãŠãŒã¶ãŒãäœæããAAAãã¢ã¯ãã£ãã«ãããã©ã¡ãŒã¿ãŒã䜿çšããŠ2ã€ã®ã¡ãœããïŒMethod-ListïŒãé©çšããŸãã-ããã©ã«ãã®ããŒã«ã«ãã€ãŸããããŒããŠã§ã¢å šäœã®ããŒã«ã«ããŒã¿ããŒã¹ã¯ãã³ã³ãœãŒã«ããŒãã§ã®èªèšŒãé€ããèªèšŒããã³æ¿èªäžã«ãã§ãã¯ãããŸãããããè¡ãã«ã¯ã aaa authorization consoleãå ¥åããŸãã
å®éã«ã¯ãåæ§ã®æ¹æ³ã§ãã«ã¹ã¿ã Method-ListãäœæããŠvtyã«é©çšã§ããŸãã
ç解ããããã«ãradius / tacacsãµãŒããŒãæ§æããå¿ èŠããããŸãïŒ radius-server host 192.168.1.100 ã
Method-Listã§é åºã確èªããŸãïŒradiusïŒyes / noïŒã䜿çšã§ããªãå Žåã¯ãæå¹ã«ããŸãã Method-Listã®ããžãã¯ã¯ãæåã«ååã·ãŒãããã§ãã¯ãã次ã«ããã©ã«ãã·ãŒãããã§ãã¯ããã ãã§ãã
å¥ã®èå³æ·±ãã»ãã¥ãªãã£ã³ãã³ãïŒ aaaããŒã«ã«èªèšŒã¯max-fail 3ãè©Šè¡ããŸãã ãŠãŒã¶ãŒã3åã®è©Šè¡ãå®è¡ãããšãã¢ã«ãŠã³ãã¯ãããã¯ãããŸãã
æ£çŽãªãšãããå€ãã®ããš...
ACLã䜿çšããŠvtyãä»ãããªã¢ãŒãå¶åŸ¡ãå¶éããããšãã§ããŸãïŒæåã®ãªã³ã¯ã§ãNATãšACLã«é¢ããéšåã§ACLãšã¯äœãïŒãããã¯æ¬¡ã®ããã«è¡ãããŸãïŒ
ååãšããŠãå¶åŸ¡ãããã¯ãŒã¯ãä»ã®ããŒã¿ãããã¯ãŒã¯ããåé¢ããããšããå§ãããŸãã
ã³ãã³ããå ¥åããã«ã¯ãæªäœ¿çšã®ç®¡çããŒããç¡å¹ã«ããå¿ èŠããããŸãã
line aux 0 no exec no transport input no transport output
ããã«ãã€ã³ã¿ãŒãã§ãŒã¹ã®ã¢ã€ãã«æéãèšå®ããããã«ïŒ exec-timeout 10 0 ã
å¥ã®è¯ãç¿æ £ã¯ãããŸããŸãªæ å ±ã¡ãã»ãŒãžãã€ã³ã¹ããŒã«ããããšã§ã-ãããŒã äœã®ããã«ïŒ ããŠãããšãã°ãããã«ã€ããŠéçã®å¶åŸ¡ã€ã³ã¿ãŒãã§ãŒã¹ã«å°éãããå¶ç¶ã管çè ã«éç¥ããããã«ïŒ
banner login c Warning! Non Authorization Access Is Restricted c
ã·ã¹ã³ã«ã¯CDPãªã©ã®åªãããããã³ã«ããããæ å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ãããã°ããŒãã«ã«cdpãå®è¡ããªãããã€ã³ã¿ãŒãã§ã€ã¹interface <interface-id>ãno cdp enableã«åå¥ã«é 眮ããå¿ èŠããããŸãã Cisco VoIPã䜿çšããŠããå Žåã¯ã次ã®ããã«åæã«æ³šæããŠãã ããã CDPã¯èšå®ãé»è©±ã«è»¢éããŸãã
管çã®ããã«ïŒå¯èœã§ããã°ïŒHTTPã䜿çšãããHTTPSã®ã¿ã䜿çšããŸãã
no ip http server ip http secure-server
Gratuitous ARPãç¡å¹ã«ããŸã-ããã¯ãåŸ æ©ããŸããã§ãããã圌ã¯ãã³çãããŸããããšããã«ããŽãªã®ãã®ã§ãããã®ãããªããã±ãŒãžã¯ã no ip gratuitous-arpsã³ãã³ãã§ç¡å¹ã«ããAPR Poisoningã§äœ¿çšã§ããŸãã
IOSã«ã¯èªåã»ãã¥ãªãã£æ§æããããŸãã èªåä¿è· -åºæ¬çãªã»ãã¥ãªãã£èšå®ãæ§æãããŠã£ã¶ãŒãã
ãŸããç¡å¹ã«ããããšãæãŸãããã©ã¡ãŒã¿ãŒãæ€æ»ããå¿ èŠããããŸãïŒIOSã®æè¿ã®ããŒãžã§ã³ã§ã¯ãããã©ã«ãã§ç¡å¹ã«ãªã£ãŠãããã»ãšãã©ã®å ŽåL3ã«é¢é£ããŠããŸã ïŒïŒ TCP / UDP Small-ServersãFingerãIdentificationïŒauthïŒProtocolãPADãAutoloading Device ConfigurationãIPãœãŒã¹ã«ãŒãã£ã³ã°ãIPãã€ã¬ã¯ããããŒããã£ã¹ã
ãããŠãã1ã€ïŒäžèŠãªãµãŒãã¹ãšãããã³ã«ããã¹ãŠç¡å¹ã«ããæªäœ¿çšã®ã€ã³ã¿ãŒãã§ã€ã¹ã管çäžç¡å¹ã«ããNTPïŒntpãµãŒããŒïŒããã®ã³ã°ãããŒã¹ã©ã€ã³èšå®ãå¿ããªãã§ãã ããïŒ
service tcp-keepalives in service tcp-keepalives in out snmp-server enable traps cpu threshold ......... service timestamps log datetime secure boot-image secure boot-config
ç§ãäœããå¿ããå Žåãããã¯ãã¹ãŠã®ããã§ããå°ãªããšãJDimaã®ã³ã¡ã³ãã§éäŒããŠãã ãããåžžã«äŸ¡å€ã®ããã³ã¡ã³ããããŠãã ããã
L2ã»ãã¥ãªãã£
å®å šãªã¢ã¯ã»ã¹ãèŠã€ããããL2æ å ±ã»ãã¥ãªãã£ãªã¹ã¯ã®è»œæžã«é²ã¿ãŸãããã ãã®ãããªææžããããŸãïŒCISCO LAYER 2 ATTACKSïŒMITIGATION TECHNIQUESãããã¯æ¬¡ãåæ ããŠããŸãïŒ
ãã®ãããã¹ã€ãããšã¯äœããã©ã®ããã«æ©èœãããããããŒããã£ã¹ããã¡ã€ã³ãVLANãããã³ãã®ä»ã®åºæ¬çãªçè«çéšåã¯ããã¯ããã¯ããã¯ããã§çªç¶èª¬æãããŠããŸãã ããŒã2.åãæ¿ãã
VLANãããã³ã°-ããŒãã®åäœã¢ãŒãã匷å¶ããå Žåãªã©ãæ»æè ãVLANã«ã¢ã¯ã»ã¹ããå Žåã®æ»æã®ã¿ã€ãã ãã®ãŠãŒãã£ãªãã£ã䜿çšããŠãããè¡ãããšãã§ããŸã ;ããã¯ã«ãŒãªãŒã«ããããŸãã äžè¬ã«ãæ°ããã¹ã€ããã§ã¯ããã¯ããŸãããŸããããŸããããåé¡ã®æ¬è³ªã¯èªåããã©ã«ãã¢ãŒãã®DTPã«ãããŸãã ãã ãããŠãŒã¶ãŒããŒãã§switchport mode accessã³ãã³ããå ¥åãããšïŒãã©ã³ã¯DTPã§åäœããã¯ãã§ãããŽã·ãšãŒããªã ïŒãæ»æè ã¯ã¢ãŒããããŽã·ãšãŒãã§ããŸããã
ãŸãããã¹ãŠã®æªäœ¿çšããŒããäžéšã®VLAN 2451ã«è»¢éããVLAN1 ã€ã³ã¿ãŒãã§ã€ã¹ ïŒ ã€ã³ã¿ãŒãã§ã€ã¹vlan 1ãã·ã£ããããŠã³ ïŒã䜿çšãŸãã¯ç¡å¹åãããããã©ã«ãã§ãã€ãã£ãvlanãid = 1ã§ããããããã©ã³ã¯ããŒããããšãã°ãã€ãã£ãvlan 20ãèšå®ããŸã
vlan dot1q tag nativeã³ãã³ãã¯ãã°ããŒãã«æ§æã¢ãŒããšåãããšãè¡ããŸãããç§ã¯æã£ãŠããŸããã§ãã...
éåžžã®VLANã«å ããŠã次ã®ãããªãã®ããããŸãïŒ Keith Barkerã®èäœæš©ïŒïŒ
ãã®å³ãããããããšïŒ
- VLANã¯ããã©ã€ããªããã³ã»ã«ã³ããªïŒéé¢ãŸãã¯ã³ãã¥ããã£ã§ãã
- VLANã¿ã€ãïŒåé¢ïŒ1ã€ã®ã³ããŒã«ã®ã¿ååšã§ããVLANå ã«ã¯æ¥ç¶ããªããPromiscuousã®ã¿ïŒãã³ãã¥ããã£ïŒå€ãã¯ãVlanå ã«Promiscuousãšã®æ¥ç¶ããããŸãïŒ
- ããŒãã¿ã€ãïŒç¡å·®å¥-ãã©ã€ããªVLANããŒãã¯dgã®ãããªãã®ã§ãéé¢ãããã³ãã¥ããã£ã§ããããŸã
- ãã©ã€ããŒãVLANã«ã¯ãVTPãã©ã³ã¹ãã¢ã¬ã³ããå«ããå¿ èŠããããŸã ïŒ vtp mode transparent ã
ç¹°ãè¿ãã¯ããŸãããããã¹ãŠã¯ãããŸãã¯ããã§è©³ãã説æã ãŸã ã å°ããªäŸïŒ
vlan 101 private-vlan primary vlan 201 private-vlan community vlan 202 private-vlan community vlan 301 private-vlan isolated ........... vlan 101 private-vlan association 201-202,301
é©çšãããã©ããã¯ããªã次第ã§ãã
ãã¹ãŠãæããã§ããããã«èŠããŸãããç¡å·®å¥ããŒããã«ãŒãã£ã³ã°ãããšãå·§åŠã«çŽ°å·¥ããããã±ãããL3ããã€ã¹ã«éä¿¡ããããšã«ãããISOLATEDããä»ã®VLANã«å°éããå¯èœæ§ããããŸãã ãã®ãªãã·ã§ã³ã¯ãã«ãŒã¿ãŒã®ACLã䜿çšããŠéããããŸãã
PVLANãšããžãŸãã¯ä¿è·ããŒããæ§æããå Žåãåé¢VLANã§åæ§ã®æ©èœã䜿çšã§ããŸãã ããã¯ãã³ãã³ãswitchport protectedã䜿çšããŠãåã€ã³ã¿ãŒãã§ã€ã¹ã§åå¥ã«æ§æãããŸãã
ããŠãVLANã®æåŸã«ãVLANã®ACLïŒVLAN ACLïŒVACLïŒãŸãã¯VLANããããšMacSecïŒãæ€èšããŸãã
VLANå ã®ãã©ãã£ãã¯ãå¶åŸ¡ããå¿ èŠãããå Žåã¯ããã©ãã£ãã¯ã決å®ãã次ã®ããã«ç®çã®VLANã§ãã³ã°ãããå¿ èŠããããŸãã
access-list 1 permit 192.168.1.0 0.0.0.255 access-list 2 permit any vlan access-map mymap 10 match ip address 1 action drop exit vlan access-map mymap 20 match ip address 2 action forward exit vlan filter mymap vlan-list 5-10 end
VACLã§äœ¿çšãããéåžžã®ã¢ã¯ã»ã¹ãªã¹ããäœæããŸãã VLANã¢ã¯ã»ã¹ããããå®çŸ©ããŸãã ãã©ãã£ãã¯ããªã¹ãã«äžèŽãããšãã®ã¢ã¯ã·ã§ã³ãå®çŸ©ããŸãã VLANã«é©çšå¯èœã ã¯ã©ã¹1ãã©ãã£ãã¯ã¯åæ¢ããä»ã®ãã¹ãŠã®ãã©ãã£ãã¯ã¯è»¢éãããŸãã
iOSã®èå³æ·±ãæ©èœã¯MacSecã§ãã
ã³ãã³ãã®ã»ããã¯æ¬¡ã®ãšããã§ãïŒããšãã°ã2ã€ã®ããã€ã¹äžïŒïŒ
int gig0/2 cts manual sap pmk Qwerty123
L2ããã€ã¹ã§æ§æãã2ã€ã®ã¹ã€ãããçžäºæ¥ç¶ããããŒãã§ã察称çã«æå·åããããã£ãã«ãååŸããŸãïŒããã€ã¹ã®PMKã¯åãã§ãªããã°ãªããŸããïŒã
ã«ã ä¿è·
macofãŠãŒãã£ãªãã£ïŒKaliã§å©çšå¯èœïŒã䜿çšããŠå®è¡ããã¹ã€ããã«æ¥ç¶ãããã¯ã©ã€ã¢ã³ãããMACã¢ãã¬ã¹ãçæãããšããã°ãããããšã¹ã€ããã®ã¢ãã«ã«å¿ããŠããã«ãªããŸãã ãªãã§ïŒ CAMããŒãã«ã®å Žæãçµäºãããšããäºå®ã®ããã ãããé²ãããã«ãé¢å¿ã®ããã€ã³ã¿ãŒãã§ã€ã¹ã«ããŒãã»ãã¥ãªãã£ã¢ãŒãããããŸãã
ãããŠ
ãã®ã¢ãŒãã¯ãã©ã³ã¯ãŸãã¯ã¢ã¯ã»ã¹ããŒãã§ã®ã¿æ©èœããŸãããåçããŒãã§ã¯æ©èœããŸããã
ã¢ãŒãã«ã¯ãã©ã¡ãŒã¿ãŒããããŸãïŒä¿è·ïŒéåã®å Žåãã±ãããªãããã°ãªãïŒãå¶éïŒéåã®å Žåãã±ãããªãããã°ïŒsnmpãsylogïŒãããŒãã®ã·ã£ããããŠã³ïŒããã©ã«ããæ倧= 1ããã°ïŒsnmpãsylogïŒãVLANã®ã·ã£ããããŠã³ã ã¢ãŒãã«ã¯ãåçïŒæåã®5ã€ã®Macãèšæ¶ïŒãéçïŒå®è¡äžã®æ§æã®éçMACãžã®æåæžã蟌ã¿ïŒãããã³ã¹ãã£ãã㌠ïŒãã©ã³ãã®æ°ãããããã¯ãŒã¯->å®è¡äžã®æ§æã®èªåæžã蟌ã¿ïŒããããŸãã
ãŸããèšå®ã®æåŸã«ãã¢ãŒãèªäœãã¢ã¯ãã£ãã«ããããšãå¿ããªãã§ãã ããã
ã¹ããŒãã³ã°ããŒãã«
dhcpã«å¯Ÿããæ»æãã身ãå®ãããã«ã dhcpã¹ããŒãã³ã°ããŒãã«ã䜿çšã§ããŸã ã èå¿ãªã®ã¯ãã¹ã€ãããæ£åœãªdhcpãµãŒããŒãæã£ãŠããããŒããèšæ¶ããŠãããããã¢ã¯ã»ã¹ããŒãããdhcpæ¯æžæ»æ ïŒãŸãã¯ã誰ããèªå® ããdlinkãæã¡èŸŒãã ïŒãå®è¡ããããšã§ãã
ãã®ã¢ãŒãã¯ãéãšVLANå šäœã«å¯ŸããŠåå¥ã«ãªã³ã«ãªããŸãã
ip dhcp snooping limit rate 20ã³ãã³ãã䜿çšããŠãdhcpèŠæ±ã®æ°ãå¶éã§ããŸãã å¿ èŠã«å¿ããŠãå©çšå¯èœãªæ¥ç¶ã確èªããŸãã
æåããã®ã¢ãŒãã§ã¯ãããã©ã«ãã§ããã¹ãŠã®ããŒããä¿¡é ŒãããŠããŸããã
ãã€
ã¹ããŒãã³ã°ããŒãã«ãDAIã«åºã¥ã-åçarpæ€æ»ãã€ãŸã MAC-IPãåçã«æ¯èŒããARPãã€ãºãã³ã°ãé²ããŸãïŒ ip arp inspection vlan 456 ã
ããã¯ãMACã¢ãã¬ã¹ãå€æŽãããARPãã±ãããéä¿¡ãããæ»æã®äžçš®ã§ãARPããŒãã«ãæŽæ°ããåŸãMITMãå®è¡ãããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã«DHCPããªãå Žåãarp access-listã䜿çšããŠåæ§ã®æ©èœãå®çŸã§ããŸãã
arp access-list NEW-ARP-ACL permit ip host 10.1.1.11 mac host 0011.0011.0011 ip arp inspection filter arpacl vlan 456
ARP Validation Checksãæ¯èŒããããã®æ©èœããããŸãã
IPã¹ããŒãã£ã³ã°/ãœãŒã¹ã¬ãŒã
ç¹°ãè¿ããŸãããã¹ããŒãã³ã°ããŒãã«ã«åºã¥ããŠãIPã¹ããŒãã£ã³ã°/ãœãŒã¹ã¬ãŒãã¯æ©èœããŸãã
IPã¹ããŒãã£ã³ã°æ»æã®é®®æãªäŸã¯ãæ»æè ãç°ãªãIPå®å ããã³åãIPãœãŒã¹ã§ç°ãªããã±ãããçæããå Žåã§ãã æçµçã«ããã¹ãŠã®å®å ã¯ãœãŒã¹ã«å¿çããDDoSãå®è¡ããããšããŸãã
ãã®ã³ãã³ãã»ããã¯ãIPã¹ããŒãã£ã³ã°æ»æããä¿è·ããã®ã«åœ¹ç«ã¡ãŸãã
STP
ãåãã®ããã«ãSTPã®äž»ãªç®æšã¯ãåé·æ¥ç¶ã®ããããããžã®ã«ãŒããæé€ããããšã§ãã ããããæ»æè ãã«ãŒãããªããžã«ãªããåã³MITMãå®è£ ããå Žåããã®ãããªã¹ããŒã ãå®è£ ããããšãå¯èœã§ãã
ãã¹ãŠã®ããŒãã§ä¿è·ãã°ããŒãã«ã«ã¢ã¯ãã£ãã«ããã«ã¯ã spanning-tree portfast bpduguard defaultã³ãã³ãã䜿çšããå¿ èŠããããŸãã
次ã«ãããŒããportfastã¢ãŒãã«ããŠãååŸããŸã... 1000èªã®ä»£ããã«ïŒ
ãããšã¯å¥ã«ãã€ã³ã¿ãŒãã§ã€ã¹äžã§ãããã¯ã³ãã³ãspanning-tree bpduguard enableã䜿çšããŠè¡ãããŸãã
ã¹ããŒã å¶åŸ¡
ããã¯ãSTPãæå¹ãªå Žåã®è»¢éãã±ããã®å¥ã®å¶åŸ¡ã¡ã«ããºã ã§ããã次ã®ãã©ã¡ãŒã¿ãŒããããŸãã
- ç£èŠäžïŒãããŒããã£ã¹ã/ãã«ããã£ã¹ã/ãŠããã£ã¹ã
- ãããå€ãèšå®ãããŸãïŒïŒ / PPS / BPS
- éžæããã¢ã¯ã·ã§ã³ïŒäœé/ã·ã£ããããŠã³
storm-control broadcast pps 500 100 storm-control action shutdown errdisable recovery cause storm-control errdisable recovery interval 60
äžèšã«å ããŠã ã«ãŒãã¬ãŒããEtherChannelã¬ãŒããã«ãŒãã¬ãŒããããŒãããããã³ã°ãªã©ã®ãã¯ãããžãŒããããŸã ã
ãã¹ãŠã®ã·ã ã«ã€ããŠãæåŸãŸã§èªãã§ãããŠããããšãã ãã®æ å ±ãã圹ã«ç«ãŠã°å¹žãã§ãã
PSãã®è³æã®æèã§ã©ã®ãããªã»ãã¥ãªãã£ã¡ã«ããºã ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœ¿çšããŠããã®ããç¥ãããšã¯èå³æ·±ãã§ãããã ã³ã¡ã³ããæžããŠãã ããã