äŒç€Ÿãã©ã¹ã³ã«ãã®åµèšã®æŽå²ã¯ãããããããããã¹ã¯éå€ã®å°ããªå·¥å Žã§ãæ®éã®ã¢ã€ã¹ã¯ãªãŒã -ã¯ããã«ã«ãããšã¢ã€ã¹ãã£ã³ãã£ãŒã®ã¢ã€ã¹ã¯ãªãŒã ã®çç£ãã1997幎1æã«å§ãŸããŸããã çŸåšããŠã¯ã©ã€ãã®å€§æã¢ã€ã¹ã¯ãªãŒã ã¡ãŒã«ãŒã§ãã
äŒç€ŸãLasunkaãã«ã¯ããWhite BirchãããWeaselãããLasunkaããªã©ã®ããã€ãã®ãã©ã³ãããããäž»ãªçç£ã¯ã¢ã€ã¹ã¯ãªãŒã ã§ãã Lasunkaã®éçºæŠç¥ã«ããã°ãäž»ãªæè³ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®éçºãšé«ãå質åºæºã®ç¶æã«åããããŠããŸãã
çŸåšãå瀟ã«ã¯26ã®ååŒæããããäŒç€Ÿã¯æ¡å€§ããäºå®ã§ãã çç£ã¯ãã«ããã«ãšãããŽã©ã°ã©ãŒãã«ãããæ¬ç€Ÿã¯ããããããããã¹ã¯ã«ãããŸãã ãã®ãããªäŒæ¥ã®ITã€ã³ãã©ã¹ãã©ã¯ãã£ã¯è€éã§ãããäŒæ¥ã®ãªãã£ã¹éã§å®å šã«æ å ±ã亀æããå¿ èŠããããŸãã
ä»å¹Žã®åãã«ããã©ãŒãã£ãããã²ãŒããŠã§ã€ãäŒæ¥ã«ã€ã³ã¹ããŒã«ããå§ããããããã®ãœãªã¥ãŒã·ã§ã³ãã¯ã©ã€ã¢ã³ãã§ã©ã®ããã«æ©èœãããã調ã¹ãããšã«ããŸããã
å®éããšã³ã¿ãŒãã©ã€ãºã®ããŒãITã¹ãã·ã£ãªã¹ãã«æ©åšã®æäœã«é¢ãããã£ãŒãããã¯ãæ±ããå¿ èŠããããŸãããšEugeneã®TMâ Lasunkaâã®ITãã£ã¬ã¯ã¿ãŒã¯èšããŸãã
UPDïŒ
å
責äºé
ã¯ã©ã€ã¢ã³ãã¯å人çãªçµéšãå
±æããŸããæãããªçç±ã«ããããããã¯ãŒã¯ãã©ã®ããã«æ§æãããŠãããããã¹ãŠäŒããããšã¯ã§ããŸããã ã³ã¡ã³ãã¬ãã¥ãŒã¯ãã¯ã©ã€ã¢ã³ãã®èšèã«ã§ããã ãè¿ã圢ã§èšè¿°ãããŸããå¿
èŠã«å¿ããŠèšé²ãæäŸã§ããŸãã CIOã¯ããã®ã¬ãã¥ãŒã§èšãããšãã§ãããã¹ãŠã®ããšã«ã€ããŠãã§ããã ãå€ã話ããŸãã-ããã¯å®å
šã§ã¯ãªããããäžå¯èœã§ãã
-ãã¹ãŠã®ããžãã¹æ å ±ã¯ãæ¬ç€Ÿã®ããããããããã¹ã¯ã«ãããŸãã ãªã¢ãŒããªãã£ã¹ã®ã»ãšãã©ã®åŸæ¥å¡ã¯ã¿ãŒããã«ãµãŒããŒãä»ããŠäœæ¥ãããããå®å®ããäœæ¥ãã£ãã«ãå¿ èŠã§ãã åœç€Ÿã®ã€ã³ã¿ãŒããããã£ãã«ã¯ã100Mbit / sã®é床ã§æ§ç¯ãããŠããŸãã ããã«ãã»ã³ãã©ã«ãªãã£ã¹ã«ã¯2ã€ã®ãã£ãã«ããããŸãã1ã€ã®ãã£ãã«ã®é床ã¯1ã®ã¬ããã/ç§ã2çªç®ã®ããã¯ã¢ããã¯100ã¡ã¬ããã/ç§ã§ã誀åäœã®å Žåãèªåçã«åãæ¿ãããéä¿¡ã®åé¡ãåé¿ããŸãã
1ã€ã®ãã³ããŒã®ã²ãŒããŠã§ã€ããããããŸãæ©èœããŠããŸããããå éšVPNãã©ãã£ãã¯ã®è² è·ãå¢å ãããšãã³ã°ãå§ãã40 Mbit / sã®æé·äžéã«éããŸããïŒå°ãªããšã130 Mbit / sã®é床ããã³ããŒã®Webãµã€ãã§å®£èšãããŸããïŒ-ãããŠããã ãã§ããããã«-ãŸããããã®é床ãèŠéãå§ããŸããã
æåã¯ããŸãæãã§ããŸããã§ãããã SmartnetããŒãããŒã¯ãã©ãŒãã£ãããã®æ©åšãè©Šãããã«ã¢ããã€ã¹ããŸããããã£ã¹ããªãã¥ãŒã¿ãŒã®ãããã§ããã¹ãçšã®æ©åšãæäŸããŠãããŸããããã¹ãŠã®ãã£ã¹ããªãã¥ãŒã¿ãŒããã¹ãçšã®æ©åšãæäŸããããã§ã¯ãããŸããã§ããã çŸåšããã®ãœãªã¥ãŒã·ã§ã³ã¯ãïŒFortiNetãçŽæããããã«ïŒ100 Mbit / sã®VPNãã©ãã£ãã¯ãæ確ãã€ç¢ºå®ã«ä¿æããŸãã
ãã®ãããªFortiGate 60Cã²ãŒããŠã§ã€ãããã³ã»ãã¥ã¢æ¥ç¶ïŒVPNæ¥ç¶ïŒãæ§ç¯ããããã®FortiGateãã¡ããªã®ä»ã®ã²ãŒããŠã§ã€ã¢ãã«ã¯ãäŒæ¥ã®åå¶æ¥æã«ãããŸãã
æåã«ãæå·åããããã©ãã£ãã¯çšã«è€æ°ã®ã²ãŒããŠã§ã€ãã€ã³ã¹ããŒã«ããŠããããã©ã®ããã«æ©èœãããã確èªããŸãããçŸåšããã®æ©åšã¯åãªãã£ã¹ã«ãããŸãã ç§ãã¡ã®å°åãªãã£ã¹ãšçç£ã¯ãã¿ãŒããã«ã»ãã·ã§ã³ããã®ããŒã¿ãéä¿¡ãããå®å šãªãã£ãã«ãä»ããŠã¡ã€ã³ãªãã£ã¹ã«æ¥ç¶ãããŠããŸãããã¡ãããããžãã¹ããã»ã¹ã®ç¶ç¶æ§ã¯æ¥ç¶ã«äŸåãããããæ¥ç¶ãäžæãããªãããšãéåžžã«éèŠã§ãã -æ¬çªç°å¢ã§ã®äœæ¥ã¯å€ã«æ¢ãŸããŸããã ãããŠãå€éã«ã²ãŒããŠã§ã€ãããªãŒãºããå Žåã誰ããããã«äžæºãæã£ãŠããŸãããŸããç§ã®ç®¡çè :)ã圌ãã¯ç·æ¥ã«éä¿¡ãå埩ããå¿ èŠããããŸãã ãã©ãŒãã£ãããã§ã¯ããã®ãããªåé¡ã¯ãããŸããã
ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®æå·åãããVPNãã©ãã£ãã¯ãšé³å£°ãã©ãã£ãã¯ã¯çŽ90ïŒ ãå ããŠããŸãã äžåºŠã«æ倧400ã®ã¿ãŒããã«ã»ãã·ã§ã³ãå¯èœã§ãããã£ãã«ã«åé¡ã¯ãããŸããã
-ãããã¯ãŒã¯ã§ãµãŒãããŒãã£ã®å¹²æžãçºçããé »åºŠã¯ã©ããããã§ããïŒ
ç§ãã¡ã¯å®æçã«DDoSæ»æãã¡ãŒã«ãµãŒããŒã«å¯Ÿããã¹ãã æ»æããã®ä»ã®æ»æã競åä»ç€ŸããŸãã¯ã¹ããŒãã®å©çã®ããã«ãããã¯ãŒã¯ã«äŸµå ¥ããããšãã誰ããæ»æããŠããŸãããã©ãŒãã£ãããã²ãŒããŠã§ã€ã¯ãããéåžžã«ããŸãè¡ãããšãã§ããŸãã
ã¡ã€ã³ãªãã£ã¹ã«ã¯å¥ã®ãã³ããŒã®ã¡ã€ã³ã«ãŒã¿ãŒããããŸããããã©ãŒãã£ãããã«äº€æããäºå®ã§ãã ãããŠãããã«å¥ã®åœã«ããäŒæ¥ã®æ°ããéèšãããæ¯ç€Ÿã«ãããã¯ãŒã¯ãã»ããã¢ããããããã«ãã©ãŒãã£ãããã®ã²ãŒããŠã§ã€ãèšçœ®ããŸãã
ç§ãã¡ããã©ãŒãã£ãããã®åã«æã£ãŠããæ©åšã«ã€ããŠæªãããšãèšãããã¯ãããŸããããããã®è§£æ±ºçã¯è¯ãã§ãããç§ãã¡ã¯ãããããæé·ããŸããã ãŸãããã©ãŒãã£ãããã§ã¯ãå·®ãè¿«ã£ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®åé¡ã解決ããã ãã§ãªããå°æ¥ã«åããŠéåžžã«åªããäŸçµŠãæäŸããŠããŸãã
ã¯ããå ¬å¹³ã«èšãã°ããã©ãŒãã£ãããã®æ©åšã¯ããé«äŸ¡ã§ãããšèšããªããã°ãªããŸãããããã®å Žåã¯éåžžã«æçãªæè³ã§ãã éä¿¡ã¯ITã®å質ã«äŸåãããããITã€ã³ãã©ã¹ãã©ã¯ãã£ãç¯çŽããããšã¯ã§ããªããšèããŠããŸããä»æ¥ã®ããããããžãã¹ã§ã¯ãé«å質ã§å®å šãªéä¿¡ããã¹ãŠã§ãã
ãã§ã«èšã£ãããã«ãæã£ãŠããæ©åšãäžè¶³ããŠããã®ã§ãæ¥å¹Žäœããå€æŽããå¿ èŠããªãããã«ããã©ãã£ãã¯ã®ããã«ãã£ãã«åž¯åå¹ ãäžè¶³ããã®ãåŸ ããã«æ±ºå®ããŸãã5幎éããŸãã¯10幎éã§ååãªä»£æ¿ãšãªãé·æçãªãœãªã¥ãŒã·ã§ã³ãæ¢ãããã«ãå°æ¥é¢é£ããå¯èœæ§ã®ãããã¹ãŠã®ãã©ã¡ãŒã¿ãŒã«å¯ŸããŠãããŒãžã³ã®ãããœãªã¥ãŒã·ã§ã³-ãã©ãŒãã£ããããéžæããŸãã
å®éãç§ãã¡ã®ITéšéã®åã§ã¯ãæ°ããã¿ã¹ã¯ãåžžã«æ瀺ãããŠããŸãã ãããŠãITã¹ãã·ã£ãªã¹ããšããŠãç§ãã¡ã®ããžãã¹ãã1幎ã2幎ã§ç§ãã¡ã«ã©ããªæ°ããã¿ã¹ã¯ãæ¥ãã®ããæšæž¬ã§ããŸãïŒç§ã¯ããã§17幎éITãã£ã¬ã¯ã¿ãŒãšããŠåããŠããŸããïŒ-ããããã¹ãŠã®æºåãã§ããŠããçç±ã§ã:) ãããŠããã©ãŒãã£ããããäžå€®ãªãã£ã¹ã§æäŸããã°ããã¹ãŠãéåžžã«é©åã«äŸçµŠã§ãããšä¿¡ããŠããŸãããŸãããããã¯ãŒã¯ãæ¡å€§ããäŒæ¥ãæ¡å€§ããŸãã
ãŸãããã¹ã段éã§ã¯ããã©ãŒãã£ããããšåãäŸ¡æ Œåž¯ã§ãå¥ã®ãããã¯ãŒã¯ãã³ããŒã®æ©åšã䜿çšããããšã«ã泚æããŠãã ããã ã¯ããããã¯å©ç¹ããããŸãããç§ãã¡ã¯ãã©ãŒãã£ããããã¯ããã«å¥œãã§ããšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ã«ã¯ããã«ããçµ±åããããã©ãŒãã³ã¹ã®é¢ã§ã¯æ©èœæ§ãšçç£æ§ã®é¢ã§ç«¶åä»ç€Ÿããã®ããŸãã
äœãèµ·ãã£ãã®ããä»äœãèµ·ãã£ãŠããã®ããæ¯èŒãããš ãã©ãŒãã£ãããã¯å¹ åºãèšå®ã«éåžžã«æºè¶³ããŠããããã¹ãŠã®ãã©ãã£ãã¯ãããŒãéåžžã«æè»ãã€æ£ç¢ºã«èšå®ã§ããèšå®ãã©ã³ããå€æ°ãããŸãã ä»ã®æ©åšãã€ãŸããã©ãŒãã£ãããã§ã¯æ§æã§ããªããã®ã¯ç°¡åã§ãã ã€ãŸãããã©ãŒãã£ãããã¯ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãã©ãã£ãã¯ã«ã¢ããªã·ãã¯ã«ã¢ãããŒãããã®ã§ã¯ãªããäŒæ¥ã®ãã©ãã£ãã¯ã¯éåžžã«å€§ããç°ãªãå¯èœæ§ãããããšãç解ããŠãããèªåã§èšå®ã§ããç¬èªã®åå¥ã®èšå®ãå¿ èŠãªãã¹ãŠã«ã€ããŠãç§ãèšããããšã¯éåžžã«äŸ¿å©ã§ãïŒ
çµæã«ãããšãé床ã®åäžãšãã£ãã«ã®å®å®æ§ãåŸãããŸããã çŸåšãçç£äŒæ¥ããã©ãŒãã£ãããã«ç§»ç®¡ããŠããŸãããã§ã«ããããã©ãã移管ããŠããããã«ããã«ãšããããããããã¹ã¯ãèšç»ããŠããŸãã çŸåšããã¹ãŠã®æ°ããéšéã§ãããã«ãã©ãŒãã£ãããã®ãœãªã¥ãŒã·ã§ã³ã®ãããã¯ãŒã¯ãæ§ç¯ããããã«ãããè¡ãäºå®ã§ãã
å€ãã®ãã©ãã£ãã¯ãéãè² è·ããã£ãã«äºçŽãå¿ èŠãªè£œé äŒæ¥-ãã©ãŒãã£ãããã¯åªãããœãªã¥ãŒã·ã§ã³ã§ãããéåžžã«æºè¶³ããŠããŸãïŒ
ä»ã®äŒæ¥ãšåæ§ã«ãWebã³ã³ãã³ãã®ã»ãã¥ãªãã£ãšå¶éã«é¢ãã質åãåžžã«ãããŸãããããã¯ãŒã¯ã§ã¯ããã¹ãŠã®ãã©ã³ãããã®ãã¹ãŠã®ãã©ãã£ãã¯ãã»ã³ãã©ã«ãªãã£ã¹ã§ã©ãããããå¶éã¯ãã§ã«ããã§èšå®ãããŠããŸããFortiGateã¯éåžžã«åœ¹ç«ã¡ããã£ã«ã¿ãªã³ã°èšå®ãéåžžã«æè»ã§ãã httpsãã©ãã£ãã¯ããã¬ã³ããããã¯ãŒã¯ãªã©ã«èªç±ã«å¯Ÿå¿ããŸãã
FortiGateã®èšå®ã®æè»æ§ã¯Linuxãšæ¯èŒã§ããŸãããã¯ãã«ã«ãµããŒããµãŒãã¹ã¯å€ãã®ã¿ã¹ã¯ãåŠçã§ããã«ãŒã¿ãŒãžã®ãã«ã¢ã¯ã»ã¹ãæäŸããå¿ èŠããªãããã管çã泚ç®ã«å€ããŸããç¹å®ã®èšå®ã»ã¯ã·ã§ã³ã§ååã§ãããFortiNetãããã«å¯Ÿå¿ããŸãã
ããªãã¯ãŸã ãããã話ãããããšãã§ããŸãããè©ŠããŠã¿ãæ¹ãè¯ãã§ãïŒ
äžèšã§èšãã°-ã¢ã€ã¹ã¯ãªãŒã ã¯ä¿è·ãããŠããŸã:)
ããŒããŠã§ã¢æè¡æ å ±
FortiGateã¯ãå æ¬çãªãããã¯ãŒã¯ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ã§ãã L2 / L3ã«ãŒã¿ãŒããã¡ã€ã¢ãŠã©ãŒã«ãVPNã³ã³ã»ã³ãã¬ãŒã¿ãŒããŠã€ã«ã¹å¯Ÿçãã¹ãã 察çãã£ã«ã¿ãŒãWeb /ã³ã³ãã³ããã£ã«ã¿ãŒãäŸµå ¥æ€ç¥ã·ã¹ãã ïŒIPSïŒã®æ©èœãããã³è¿œå ã®ãŠãŒã¶ãŒèªèšŒãä»®æ³åããã©ãŒã«ããã¬ã©ã³ã¹ãœãªã¥ãŒã·ã§ã³ãå«ãŸããŠããŸãã
ã«ãŒãã£ã³ã° -ããã€ã¹ã¯ãéçãåçã«ãŒãã£ã³ã°ïŒRIPãOSPFãBGPïŒããªã³ããã³ãã«ãŒãã£ã³ã°ïŒããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ïŒãããã³ãã«ããã£ã¹ããã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ããµããŒãããŸãã
ãã¡ã€ã¢ãŠã©ãŒã« -ãã©ãã£ãã¯ãããŒã®æ¹åã«å¿ããŠããããã¯ãŒã¯äžã®åãŠãŒã¶ãŒã«å¯ŸããŠåå¥ã«æè»ã«æ§æã§ããããªã·ãŒã«åºã¥ããŸãã
ãŠãŒã¶ãŒèªèšŒ -ããã€ã¹ã¯ããããã¯ãŒã¯ãµãŒãã¹ãæäŸããåã«ãŠãŒã¶ãŒèªèšŒæ©èœããµããŒãããŸãã ããŒã«ã«ãŠãŒã¶ãŒããŒã¹ãLDAPãRADIUSãTACACS +ãããã³ã«ãä»ããå€éšèªèšŒã·ã¹ãã ãšã®çžäºäœçšããµããŒããããŠããŸãã ãŠãŒã¶ãŒèªèšŒãµãŒããŒã®ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒWindows Active Directoryãã¡ã€ã³ã³ã³ãããŒã©ãŒãNovell eDirectoryãªã©ïŒã§ãFortinetã·ã³ã°ã«ãµã€ã³ãªã³ãã¯ãããžãŒã䜿çšãããšãFortiGateã¯ãããã¯ãŒã¯ãã€ã³ã¿ãŒãããã®äŒæ¥ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããšãã«1åéãã®ãŠãŒã¶ãŒèªèšŒãå®è¡ã§ããŸãïŒããšãã°ãã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãã€ã³ã¿ãŒããããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ãªã©ïŒã
VPNãã -IPSecïŒãµã€ãéãããã¢ã³ãã¹ããŒã¯ããã€ã€ã«ã¢ããã¯ã©ã€ã¢ã³ãïŒãSSLïŒWebããŒã¿ã«ã¢ãŒãããã³ãã«ã¢ãŒãïŒãPPTPãL2TPãããã³ã«ã䜿çšããŠããããã¯ãŒã¯ãã±ãŒã·ã§ã³éã®å®å šãªæ¥ç¶ã確ç«ã§ããŸãã æå·åã¢ã«ãŽãªãºã DESã3DESãAESããµããŒããããŠããŸãã
ãŠã€ã«ã¹å¯Ÿç ããã«ãŠã§ã¢å¯Ÿçãã¹ãã€ãŠã§ã¢å¯ŸçãœãããŠã§ã¢-ãŠã€ã«ã¹ãæªæã®ããã³ãŒãããªã¢ã«ã¿ã€ã ã§ã¹ãã£ã³ã§ããŸããWebãã©ãã£ãã¯ïŒHTTPãHTTPSïŒãFTPãé»åã¡ãŒã«ïŒSMTPãPOP3ãIMAPïŒãã€ã³ã¹ã¿ã³ãã¡ãã»ãŒãžã³ã°ãããã³ã«ïŒICQãAIMïŒ ãMSNãYahooãªã©ïŒãP2Pããã¥ãŒã¹è»¢éãããã³ã«ïŒNNTPïŒãªã©ãã»ãšãã©ãã¹ãŠã®äžè¬çãªå§çž®ãã¡ã€ã«åœ¢åŒããµããŒãããŠããŸãã ã¢ã³ããŠã€ã«ã¹çœ²åã¯ããã©ãŒãã£ããããµãŒããŒããèªåçã«æŽæ°ãããŸãïŒæ°ãã眲åããªãªãŒã¹ããããšãã«éç¥ããããã®ããã·ã¥ã¡ã«ããºã ããããŸãïŒã ãã¥ãŒãªã¹ãã£ãã¯åæïŒæªç¥ã®ãŠã€ã«ã¹ã®æ€çŽ¢ïŒã®ã¡ã«ããºã ããããŸãã
ã¹ãã 察ç *-é»åã¡ãŒã«ïŒSMTPãPOP3ãIMAPïŒã§ã¹ãã ã確èªããŸãã é»åéä¿¡ã®ããŸããŸãªãã©ã¡ãŒã¿ãŒãIPã¢ãã¬ã¹ã®ãã¯ã€ã/ãã©ãã¯ã·ãŒããéä¿¡è /åä¿¡è ã®é»åã¡ãŒã«ã¢ãã¬ã¹ã®å¹æçãªãã¹ãã æ å ±æŒæŽ©é²æ¢ïŒçŠæ¢ãã¬ãŒãºã®ãªã¹ãïŒã Fortinet Global Reputation Databaseã§ã®éä¿¡è è©äŸ¡ã®æ€èšŒã éä¿¡ã®çœ²ååæã
Intrusion Prevention SystemïŒIPSïŒã¯ãFortiGuard Intrusion Prevention Serviceã«åºã¥ãäŸµå ¥æ€ç¥ããã³é²æ¢ã·ã¹ãã ã§ãã 眲åãã©ãã£ãã¯åæããã©ãã£ãã¯ç°åžžã®è¿œè·¡ãšåæãç¬èªã®çœ²åã®äœæã眲åããŸã äœæãããŠããªãæ°ããäŸµå ¥ã®æ€åºã眲åããŒã¿ããŒã¹ã®èªåæŽæ°ã
WEB /ã³ã³ãã³ããã£ã«ã¿ãŒ *-äŒæ¥ãŠãŒã¶ãŒã«ããã€ã³ã¿ãŒãããã®äœ¿çšïŒFortiGuard Web FilteringãµãŒãã¹Webãµã€ãã®ã°ããŒãã«ããŒã¿ããŒã¹åé¡ãšè©å€ââã䜿çšããWebãµã€ãåæïŒãWEBãã©ãã£ãã¯ã®ããããŒãšã³ã³ãã³ãã®ãã§ãã¯ãJavaã¢ãã¬ãããActiveXã³ã³ããŒãã³ããCookieã®ç®¡çã
ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ -FortiGateã«ã¯ãWeb 2.0ããã³ããŒãœãã«ã¢ããªã±ãŒã·ã§ã³ïŒWebã¡ãŒã«ãã€ã³ã¹ã¿ã³ãã¡ãã»ãŒãžã³ã°ïŒIMïŒããã°ã©ã ãç¡æã®VoIPé話ãP2Pããã©ãŠã¶ãŒããŒã«ããŒããã¡ã€ã«å ±æãããŸããŸãªãœãŒã·ã£ã«ã¡ãã£ã¢ãªãœãŒã¹ïŒã転éãããã³ã«ãå¶åŸ¡ããæ©èœããããŸãVoices over IPïŒH.323ãSIPãSCCPïŒã FortiGateã¢ããªã±ãŒã·ã§ã³èå¥ããŒã¿ããŒã¹ã«ã¯çŸåšã18ã®ã«ããŽãªã«1,500ãè¶ ããã¢ããªã±ãŒã·ã§ã³ããã³ãããã³ã«ã®ã·ã°ããã£ãå«ãŸããŠããŸãã
ãã©ãã£ãã¯ã·ã§ãŒãã³ã° -ããã€ã¹ã«ã¯ãã©ãã£ãã¯ãããŒå¶åŸ¡ã®æ©èœããããŸãïŒä¿èšŒ/å¶é/垯åå¹ åªå ïŒã
NATããã³è² è·åæ£-é«åºŠãªã¢ãã¬ã¹å€ææ©èœïŒåçããã³éçNATãããªã·ãŒããŒã¹NATãSIP / H.323 NAT-TraversalïŒããµããŒãããè€æ°ã®ãµãŒããŒéã«è² è·åæ£æ©èœããããŸãã
ä¿è·ãããã¡ã€ã« -ãããã¯ãŒã¯äžã®ãã©ãã£ãã¯ãŸãã¯ãŠãŒã¶ãŒã®çš®é¡ããšã«ãã»ãã¥ãªãã£ãµãŒãã¹ã®ã»ãããå人çã«å²ãåœãŠãïŒæå¹ã«ããïŒããšãã§ããŸãã
VDOM ïŒä»®æ³ãã¡ã€ã³ïŒ-ããã€ã¹ã®ä»®æ³åã åå¥ã®ç®¡çãã»ãã¥ãªãã£ããªã·ãŒãã«ãŒãã£ã³ã°ããŒãã«ãåããè€æ°ã®ä»®æ³ããã€ã¹ãäœæããŸãã 10åã®VDOMã©ã€ã»ã³ã¹ãåºæ¬é ä¿¡ã§ã¢ã¯ãã£ãåãããã©ã€ã»ã³ã¹ã®æ°ãæ¡åŒµã§ããŸãã
HA ïŒé«å¯çšæ§ïŒ-ãããã¯ãŒã¯ã®åŸ©å åãé«ããããã®2ã€ã®ããã€ã¹éã®ã³ã©ãã¬ãŒã·ã§ã³ã¢ãŒãã ã¢ã¯ãã£ã/ã¢ã¯ãã£ããã¢ã¯ãã£ã/ããã·ããVRRPã¢ãŒãããµããŒããããŠããŸãã
IPv6-補åã¯IPv6ããµããŒãããŸãã
VLAN -802.1q VLANããµããŒããããŠããŸãã
3G-ããã€ã¹ã¯ãUSBãã©ãŒã ãã¡ã¯ã¿ãŒã®å€éš3GãŸãã¯CDMAã¢ãã ã§åäœããŸãã
管çãšç£èŠã¯ãFortiManagerããã€ã¹ã䜿çšããŠãWEBã€ã³ã¿ãŒãã§ã€ã¹ãCLIïŒsshãtelnetïŒãã³ã³ãœãŒã«ãããã³éäžç®¡çãéããŠå®è¡ã§ããŸãã è€æ°ã®ç®¡çè ã®ããŒã«ç®¡çãã¢ã¯ã»ã¹æš©ã®å·®å¥åãä»®æ³ããã€ã¹ã®ç®¡çã®ããã®VDOMã®äœ¿çšãæäŸãããŸãã ããã€ã¹ã¯syslogãSNMPããµããŒãããã€ãã³ããé»åã¡ãŒã«ã§å ±åã§ããŸãã ãããã¯ãŒã¯ã€ãã³ãã®åéããã®ã³ã°ãã¬ããŒãã¯ãFortiAnalyzerãšå¯æ¥ã«çµ±åãããŠããŸãã
ããŒããŠã§ã¢ã®å®è¡ã«å ããŠãFortiGateãã©ãããã©ãŒã ã¯ä»®æ³ã¢ããªã±ãŒã·ã§ã³-FortiGate-VMãšããŠæäŸãããŸãã FortiGate Virtual Appliancesã¯ãVMwareãœãªã¥ãŒã·ã§ã³äžã«æ§ç¯ãããä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããã«èšèšãããŠããŸãã FortiGate-VMã«ã¯ãåŸæ¥ã®FortiGateããã€ã¹çšã®ã»ãã¥ãªãã£æ©èœã®å®å šãªã»ãããå«ãŸããŠããŸãã
FortiGate-VMã©ã€ã³ã¢ããã¯ã次ã®ããã€ã¹ã§æ§æãããŠããŸãã
ããããã£
| FortiGate-VM00
| FortiGate-VM01
| FortiGate-VM02
| FortiGate-VM04
| FortiGate-VM08
|
ãµããŒããããŠãããã€ããŒãã€ã¶ãŒ
| VMware ESXi / ESX v3.5 / v4.0 / v4.1 / v5.0ã
Citrix XenServer v5.6 SP2 / v6.0ããªãŒãã³ãœãŒã¹Xen v3.4.3 / v4.1ã Hyper-VãKVMãã©ãããã©ãŒã | ||||
ãµããŒããããŠããWirthã®æ°ã ããã»ããµãŒïŒæ倧ïŒ
| 1
| 1
| 2
| 4
| 8
|
ãµããŒãããããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®æ°ïŒæå°/æ倧ïŒïŒ10 GbEã1 GbEïŒ
| 2/10
| 2/10
| 2/10
| 2/10
| 2/10
|
å¿
èŠãªã¡ã¢ãªéïŒæå°/æ倧ïŒ
| 512/512 Mb
| 512/1024 Mb
| 512/3072 Mb
| 512/4096 Mb
| 512/12288 Mb
|
å¿
èŠãªããŒããã£ã¹ã¯å®¹éïŒæå°/æ倧ïŒ
| 30/2048 GB
| 30/2048 GB
| 30/2048 GB
| 30/2048 GB
| 30/2048 GB
|
ããã¯ã¹ ITU垯åå¹
ãMbps
| 500
| 1000
| 1600
| 2000幎
| 4000 2
|
IPSã¹ã«ãŒããããMbps
| 200
| 400
| 600
| 800
| 1000
|
IPsecã¹ã«ãŒãããïŒAES256 + SHA1ïŒãMbps
| 100
| 125
| 150
| 175
| 200
|
ãŠã€ã«ã¹å¯ŸçãMbps
| 100
| 200
| 350
| 500
| 600
|
åæã»ãã·ã§ã³ã®æ倧æ°
| 50äž
| 100äž
| 250äž
| 350äž
| 800äž
|
æ°ããã»ãã·ã§ã³ã®æ°/ç§
| 1äž
| 2äž
| 25000
| 75000
| 10äž
|
FortiAPçªå·
| 32
| 256
| 512
| 512
| 1024
|
ä»®æ³ãã¡ã€ã³ïŒããã©ã«ã/æ倧ïŒ
| 1/1
| 10/10
| 10/25
| 10/50
| 10/250
|
泚ïŒãµããŒãããããŠãŒã¶ãŒã®æ°ã¯ç¡å¶éã§ãããŒããŠã§ã¢ãã©ãããã©ãŒã ã®ã¿ã«äŸåããŸãã
å®éã®ããã©ãŒãã³ã¹ã¯ããã©ãã£ãã¯ã®è² è·ãšã·ã¹ãã æ§æã«äŸåããŸãã
1åFortiGateä»®æ³ã¢ãã©ã€ã¢ã³ã¹ã®æ倧å¯èœvRAMãåããESXi v4.1ã¢ããããŒã1ãå®è¡ããŠããDell PowerEdge R715ãµãŒããŒãã©ãããã©ãŒã ïŒAMD Opteron Processor 6128 CPU 2 GHzã4ç©ç1 GBeã€ã³ã¿ãŒãã§ã€ã¹-2 in / 2 outïŒã§ãã¹ããããããã©ãŒãã³ã¹æž¬å®å€ã
2 Dell M910ãã©ãããã©ãŒã ã§ãã¹ãæžã¿ïŒIntel Xeonããã»ããµE7-4830 CPU 2.13 GHzã2ã€ã®ç©ç10 GBeã€ã³ã¿ãŒãã§ã€ã¹ïŒã
ãŠã¯ã©ã€ã ã ã¢ã«ã¡ã㢠ã ãžã§ãŒãžã¢ ã ã«ã¶ãã¹ã¿ã³ ã ã¢ãŒã«ãã€ãžã£ã³ ã ãã«ã®ã¹ã¿ã³ ã ã¿ãžãã¹ã¿ã³ ã ãã«ã¯ã¡ãã¹ã¿ã³ ã ãŠãºããã¹ã¿ã³ ã CISè«žåœã§ã®ãã©ãŒãã£ããããœãªã¥ãŒã·ã§ã³ã®é åžã
ãã®ãã©ãŒãã£ããããœãªã¥ãŒã·ã§ã³ã®ã€ã³ãã°ã¬ãŒã¿ãŒã¯Smartnet ïŒFortinet Platinum PartnerïŒã§ãã
MUK-Service-ããããçš®é¡ã®ITä¿®çïŒä¿èšŒãéä¿èšŒä¿®çãã¹ãã¢ããŒãã®è²©å£²ãå¥çŽãµãŒãã¹
ã³ã¡ã³ãå ã®ããªããŒã®UPDã ã¯ã©ã€ã¢ã³ãã¯åœŒã®å人çãªçµéšãå ±æããŸããæãããªçç±ã§ã圌ã¯ãããã¯ãŒã¯ãã©ã®ããã«çµç¹ãããŠãããã«ã€ããŠãã¹ãŠã話ãããšãã§ããªãã®ã¯ãªãã§ããïŒ æ¬¡åã¯ééããªããããã³ã°ãããŸããïŒ ã³ã¡ã³ãã¬ãã¥ãŒã¯ãã¯ã©ã€ã¢ã³ãã®èšèã«ã§ããã ãè¿ã圢ã§èšè¿°ãããŸããå¿ èŠã«å¿ããŠèšé²ãæäŸã§ããŸãã åºçç©ãåºåãšããŠèªèãããããšãåŸæããŠãããããã®ãããªèãã¯ãªãã£ãã