
ããã«ã¡ã¯ãHabrïŒ æšç§ãCisco ASAãã¡ã€ã¢ãŠã©ãŒã«ã«FirePOWERãµãŒãã¹ãå®è£ ããçµéšãå ±æããŸããã æ°å¹Žã®ãã©ãã·ã¥ããã¯ã§ã¯ã FirePOWERããŒãžã§ã³6.0ã«ã€ããŠèšåããŸããããã®ããŒãžã§ã³ã§ã¯ãäž»ãªé©æ°ã®1ã€ãASDMã䜿çšãããã¹ãŠã®ãµãŒãã¹ã®ç®¡çã§ããã ã·ã¹ã³ã®é²æ©ã¯ãŸã æ¢ãŸã£ãŠãããããã®æ¥ã Cisco Firepower 4100ããã³9300ã®æ°ããã©ã€ã³ã¢ãããçºè¡šãããŸããã å®éããããã¯5585-Xã«äŒŒãåãã¢ãžã¥ã©ãŒASAã§ãããæ°ããååïŒããŒã±ãã£ã³ã°éšéïŒãããæŽç·Žããããããå¹ççãªæ°ããéäžç®¡çãœãããŠã§ã¢Firepower Threat DefenseïŒFTDïŒãåããŠããŸãã FTDã¯ãæ°ããã¢ãã«ç¯å²ã®ããã€ã¹ã ãã§ãªãã5585-Xãé€ããã¹ãŠã®ASA 5500-Xã¢ãã«ã§ãïŒå°ãªããšãçŸæç¹ã§ã¯ïŒèµ·åã§ããŸãã ãã®èšäºã§ã¯ãã·ã¹ã³ã®ãã®æ°ãããœãããŠã§ã¢ã«ã€ããŠèª¬æããŸãã
èæ¯ã®ãããã FirePOWERããŒãžã§ã³5.4ã§ã¯ããã¹ãŠããã·ã³ãã«ãã§ãããASASSDïŒãŸãã¯å¥ã®ããŒããŠã§ã¢ããŸãã¯ä»®æ³ãã·ã³ïŒã«ã»ã³ãµãŒããããFireSIGHT Management CenterïŒå¥åDefense CenterïŒã管çãããœãããŠã§ã¢ããããŸããã ASAã«ã¯ãCLI / ASDMã«ããå¶åŸ¡ãåããç¬èªã®æšæºIOSã€ã¡ãŒãžããããŸããã ã»ã³ãµãŒã«ã¯ãåãCLI ASAïŒãŸãã¯mgmtããŒããžã®SSHïŒãä»ããŠã¢ã¯ã»ã¹ãããç¬èªã®ã€ã¡ãŒãžãå¿ èŠã§ããã ããŠãFireSIGHTãžã®ã¢ã¯ã»ã¹ã¯ãã©ãŠã¶ãä»ããŠè¡ãããŸããã ããã«ã¯ãASAã®åå¥ã®ã©ã€ã»ã³ã¹+ã¹ããŒãããããFireSIGHTã®ã»ã³ãµãŒãšã¹ããŒããããã®åå¥ã®ãµãã¹ã¯ãªãã·ã§ã³ãè¿œå ããå¿ èŠããããŸãã èšããŸã§ããªãããã¹ãŠã®ãµãŒãã¹ã管çããããã®ãã®ãããªåæ£ã¢ãããŒãã¯ãå€ãã®äººã«é©ããŠããªãã FirePOWERããŒãžã§ã³6.0ã®ãªãªãŒã¹ã«ãããASDMã䜿çšããŠãã¹ãŠã®ãµãŒãã¹ã管çã§ããããã«ãªããŸããã ASDMèªäœã«ãã£ãŠèª²ããããå€ãã®å¶éãç°ãªãã»ã³ãµãŒã«ãããããªã·ãŒã®äžå åãããé åžã®æ¬ åŠãããã³ä»ã®ããã€ãã®æ©èœã¯èª°ãã奜ããã®ã§ã¯ãªãã£ããããå€ãã¯ãŸã ãã¹ãŠãäžå 管çããå®å šãªãœãªã¥ãŒã·ã§ã³ãåŸ ããªããã°ãªããŸããã
ãããã ãŽã·ãã
Tsiskaã«ãããšãCisco ASAåãã®æ°ããASDMã®éçºã¯æ¬æ Œçã§ãããHTML 5ã§èšè¿°ãããäºå®ã§ãã ããããšã
FTDã®ãªãªãŒã¹ã«ãããã»ã³ãµãŒãœãããŠã§ã¢ãšCisco ASAãœãããŠã§ã¢ãå転ãã1ã€ã®ã€ã¡ãŒãžãéäžç®¡çãããŸããã ã©ã¡ããFirepower Management Centerã§ç®¡çãããŸãïŒFMCã¯FireSIGHTãåãååã®3çªç®ã®ååã§ããä»ããåæ¢ããŠãã ããïŒã ãããŠããã¹ãŠã¯åé¡ãããŸããããASDMã®å Žåã«FPãµãŒãã¹ã®å¶éãåããå ŽåãASAã®æ©èœãšèšå®ã«å¶éãããããŸãã äž»ãªå¶éã¯ããæ©èœããªããVPNã§ãã ãããŠããããæ©èœããªãããã§ã¯ãªããéåžžã®æ段ã䜿çšããŠèšå®ããããšã¯ã§ããŸããã çŸåšããµã€ãéVPNããªã¢ãŒãã¢ã¯ã»ã¹VPNãæ§æã§ããŸããã
ãµã€ãéVPNã«ã€ããŠ
ãµã€ãéVPNã®å Žåããã¹ãŠãããªãææ§ã§ãïŒ ããŒãžã§ã³6.0.1ã®ãªãªãŒã¹ããŒãã§ã¯ãçœé»ã§èšè¿°ãããŠããŸãïŒãFirepower Threat Defenseãå®è¡ããŠããããã€ã¹ã¯ãããŒãžã§ã³6.0.1ã§ã¯VPNæ©èœããµããŒãããŸããããã¹ã€ããã³ã°ããã³ã«ãŒãã£ã³ã°æ©èœããµããŒãããŸãã ãããããåæã«ãFMC 6.0.1ã®æ§æã¬ã€ã ïŒpdf圢åŒïŒã¯åãããã«èªã¿ãŸãã Firepower Threat Defenseã¢ãã©ã€ã¢ã³ã¹ã¯ãçµ±åããã次äžä»£ãã¡ã€ã¢ãŠã©ãŒã«ãšæ¬¡äžä»£IPSããã€ã¹ãæäŸããŸãã ãFirepowerãœãããŠã§ã¢ã¢ãã«ã§å©çšå¯èœãªIPSæ©èœã«å ããŠããã¡ã€ã¢ãŠã©ãŒã«ããã³ãã©ãããã©ãŒã æ©èœã«ã¯ããµã€ãéVPN ãå
ç¢ãªã«ãŒãã£ã³ã°ãNATãã¯ã©ã¹ã¿ãªã³ã°ïŒFirepower 9300çšïŒãããã³ã¢ããªã±ãŒã·ã§ã³æ€æ»ãšã¢ã¯ã»ã¹å¶åŸ¡ã«ããããã®ä»ã®æé©åãå«ãŸããŸããã FMCãããµã€ãéVPNãæ§æããè©Šã¿ã倱æããããããªãªãŒã¹ããŒãã®ããŒãžã§ã³ã«åŸåããŠããŸãã
FTDã®ã€ã³ã¹ããŒã«
FTDã€ã¡ãŒãžã¯ããã¹ãŠã®ASA 5500-Xããã³FP 4100/9300ãã©ãããã©ãŒã ã«ã€ã³ã¹ããŒã«ã§ããŸãã ä»®æ³å®è¡ãªãã§ã¯ãªã-vFTDãããã«åºã¥ããŠãäž»ã«ããããªããã¬ãŒã·ã§ã³ãæ§ç¯ãããŸãã
æåã®FTDã€ã¡ãŒãžã¯ããŒãžã§ã³6.0.1ãåãåããŸããã FTDãFMCã«æ¥ç¶ã§ããããã«ããã«ã¯ãFireSIGHTãããŒãžã§ã³6.0.1ã«æŽæ°ããå¿ èŠããããŸãïŒFMCã®èŠä»¶ã¯ã補åã®ä»¥åã®ããŒãžã§ã³ã®èŠä»¶ãšåãã§ãïŒã FTDã€ã¡ãŒãžã®ã€ã³ã¹ããŒã«ãšFMCãžã®æ¥ç¶ã䜿çšããŠä»®æ³ç°å¢ãŸãã¯Cisco ASAãæºåããããã»ã¹ã¯ãã¯ã€ãã¯ã¹ã¿ãŒãã¬ã€ãïŒ VMware ã Cisco ASAããã³Firepower 4100 ã Firepower 9300ã®å ŽåïŒã§è©³çŽ°ã«èª¬æãããŠãããããããã§ã¯è©³ãã説æããŸããã ããã«ãASAãšVMwareã®ãã®ããã»ã¹ã¯ããããã®ãã©ãããã©ãŒã ã«å¥åã®FPã»ã³ãµãŒãã€ã³ã¹ããŒã«ããããšãšå€§å·®ãããŸããã æçµçã«ãæ¥ç¶ãããFTDïŒãã®å Žåã¯vFTDïŒã®ç»åã¯æ¬¡ã®ããã«ãªããŸãã

å³1-FMCã³ã³ãœãŒã«ã§ã®vFTDã®è¡šç€º
ããã§æ³šæãã¹ãããšïŒ
1.ã©ã€ã»ã³ã¹
ã©ã€ã»ã³ã¹ã¯ãã¹ããŒãã©ã€ã»ã³ã¹ããã°ã©ã ãçµç±ããããã«ãªããŸãããããã¯ãã·ã¹ã³ããã®æ°ããã©ã€ã»ã³ã¹ã¹ããŒã ã§ãã
ãããã ãŽã·ãã
Tsiskaã¯ã é ãå°æ¥ããã®ã¹ããŒã ã¯ãæè¿å°å
¥ãããCisco ONEã¹ããŒã ãå«ãããã¹ãŠã®åŸæ¥ã®ã©ã€ã»ã³ã¹ã¹ããŒã ã眮ãæãããšèšããŸãã
ãã®ã¹ããŒã ã®äž»ãªã¡ãã»ãŒãžã¯ãããã€ã¹ã«ãããµãã¹ã¯ãªãã·ã§ã³/ã©ã€ã»ã³ã¹ã®é¢é£æ§ã®èªåç£èŠïŒããã€ã¹ã¯ãã€ã³ã¹ããŒã«ãããã©ã€ã»ã³ã¹ãé¢é£ãããã©ãããããã³ã«ã¹ã¿ã æ©èœããµãã¹ã¯ãªãã·ã§ã³æ¡ä»¶ã«äžèŽãããã©ãããã·ã¹ã³ã«å®æçã«ç¢ºèªããŸãïŒãããã³ãã®ããã«äœæãããSmart Software ManagerããŒã¿ã«ãéããŠãã¹ãŠã®ãµãã¹ã¯ãªãã·ã§ã³/ã©ã€ã»ã³ã¹ãéäžç®¡çããæ©èœã§ã

å³2-vFTDã®ã¹ããŒãã©ã€ã»ã³ã¹
2.ä»®æ³FTDã®ã«ãŒãããã¢ãŒã
ä»®æ³FPã»ã³ãµãŒãšã¯ç°ãªããvFTDã¯ã«ãŒãã£ã³ã°ã¢ãŒãã§åäœã§ããŸãã ããã¯ãFTDå ã«ASAãœãããŠã§ã¢ã€ã¡ãŒãžãããããã§ãã ãŸããä»®æ³åã®å Žåã¯ãäœãã§å®è¡ããå¿ èŠããããŸããããã¯ãã¡ãããASAvãããå ·äœçã«ã¯ASAv30ã§ãã vFTDãããŒãããããã»ã¹ã§ã¯ãã³ã³ãœãŒã«ã«ASAvã®èµ·åã«é¢ããã¡ãã»ãŒãžãåžžã«è¡šç€ºãããŸãããŸãã¯ãã©ã®ã€ã¡ãŒãžãããŒãããããå°ããŸãã

å³3-vFTDã®ããŠã³ããŒãã ASAvã®ã€ã¡ãŒãžã®éžæ
ãšããã§ãvFTDã®ããŒãæã®ã³ã³ãœãŒã«ã¯ãASAvèªäœã®çŸåšã®ã©ã€ã»ã³ã¹ãèŠãããšãã§ããå¯äžã®å Žæã§ãã

å³4-ã¢ã¯ãã£ãåããã3des-aesãšAnyconnectãªãã®ã©ã€ã»ã³ã¹ãVPN Premiumã
ããã¯vFTDãåããASAv30ã§ããããããã³ããŒã®ããŒã¿ã·ãŒãã®æ°å€ïŒ ASA 5500-X ã ASAv pdfïŒããå€æãããšãéASA 5525-Xã«å¹æµããããã©ãŒãã³ã¹ãåŸãããŸãã ãã¡ãããFPã®æ©èœãèæ ®ããŠã©ã®ãããªããã©ãŒãã³ã¹ãããã®ãââã¯ãŸã æ確ã§ã¯ãããŸããããããã§ããªãçŽ æŽãããã§ãã
ã«ãŒãããã¢ãŒããšãã©ã³ã¹ãã¢ã¬ã³ãã¢ãŒãã«ã€ããŠ
ããã¥ã¡ã³ãã«ãããšãééã¢ãŒãã¯FTDã§ã䜿çšã§ããŸãããvFTDã®å Žåãã«ãŒãã£ã³ã°ã¢ãŒãã®ã¿ã䜿çšå¯èœã§ãã
FTDã»ããã¢ãã
FTDã»ããã¢ããã¯ã3ã€ã®ãã€ã³ãã«åããããšãã§ããŸãã
- ã·ã¹ãã èšå®
- ã«ãŒãã£ã³ã°èšå®ã
- ãµãã¹ã¯ãªãã·ã§ã³ïŒNGFWãNGIPSãAMPïŒã«ããæ©èœã®ã«ã¹ã¿ãã€ãºã
ã·ã¹ãã èšå®
ãããã®èšå®ã¯ã[ããã€ã¹]-> [ãã©ãããã©ãŒã èšå®]ã¿ãã§æ§æ/ç·šéãããŸãã 次ã®ããã«ãªããŸãã

å³5-vFTDã®ãã©ãããã©ãŒã èšå®
ååãšããŠãååããäœãåå ã§ããããæ確ã§ãããããããã§ã¯ãå€éšèªèšŒ+ã»ãã¥ã¢ã·ã§ã«/ HTTPã®1ã€ã ããåãäžããŸãã
ãã®ãããªãã³ãã«ã¯ãASAvã³ã³ãœãŒã«ã«çŽæ¥ã¢ã¯ã»ã¹ã§ããããã«ããããã«å¿ èŠã§ãã ããŒã«ã«ã¢ã«ãŠã³ãã¯äœæã§ããªããããèªèšŒã«ã¯LDAPãŸãã¯RADIUSïŒå€éšèªèšŒïŒã䜿çšããå¿ èŠããããŸãã ãã¹ãŠããã€ãã®ããã«èŠããŸããæåã«èªèšŒæ¹æ³ãèšå®ãã次ã«ã©ã®ã¢ãã¬ã¹ãããã©ã®ã€ã³ã¿ãŒãã§ãŒã¹ãšãããã³ã«ã«ã¢ã¯ã»ã¹ã§ããããèšå®ããŸãã ãããŠããã¹ãŠãSSHã§ããŸãããã°ãHTTPã¯æããã«ãæªæ¥ã®ããã«ãäœãããŸãã Cisco ASAäžã®HTTPã¯éåžžãASDMçµç±ã§ã¢ã¯ã»ã¹ããããã«èšå®ãããŠããŸããããã®å ŽåãASDMã€ã¡ãŒãžã¯ASAvã§å©çšã§ãããFMCã§ããŠã³ããŒãããã³èšå®ãããªãã·ã§ã³ããªãããããã©ãŠã¶ããã¢ã¯ã»ã¹ãããšããããã³ASDMçµç±ã§æ¥ç¶ãããšãã«404ãšã©ãŒãçºçããŸããããã€ã¹ãããŒãžã£ãŒãèµ·åã§ããŸãããïŒ

å³6-HTTPãä»ããFTDãžã®æ¥ç¶
SSHçµç±ã§ã³ã³ãœãŒã«ã«ã¢ã¯ã»ã¹ãããšãæåã«èŠãã®ã¯show versionã§ãã

å³7-SSHçµç±ã§ããŒãžã§ã³ã衚瀺
ããã¯ãvFTDããŒãžã§ã³ãšASAvã®ãœãããŠã§ã¢/ããŒããŠã§ã¢ã«é¢ããæ å ±ã§ãã CLIã«ã€ããŠå°ã調ã¹ããšãããç£èŠãšãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®ç®çã ãã®ããã«äœæããããšããçµè«ã«éããŸããã showã«ããŽãªã®ã»ãšãã©ã®æšæºã³ãã³ãã¯ãããã«ãASAv / ASAã®åãã³ãã³ããšéãã¯ãããŸããã ãã£ããã£ããã±ãããã¬ãŒãµãŒããããã°ããã¹ããªã©ã®ã³ãã³ãããããŸãã æ§æã¢ãŒãïŒ conf t ïŒã¯ãããŸããã ã€ããŒãã«ã¢ãŒãããèšå®ã§ããå¯äžã®ãã®ã¯ãåãCLIã«å¯ŸããŠãŠãŒã¶ãèªèšŒããaaa-serverã§ãã ãŸãã2ã€ã®ãªãã·ã§ã³ããããŸãããããã¯ã¢ã«ãŠã³ãã¢ã¯ã»ã¹å¶éããŸãã¯ãã®ãããªASAvã€ã¡ãŒãžã®ããããã§ãããååã¯éåžžã«æšæºçã§ãïŒ asa961-smp-k8.bin ïŒã ããã§ãã衚瀺ãããæ§æãæ éã«æ€èšãããšã2çªç®ã®ãªãã·ã§ã³ã®åŸåãçŸããŸãããæåã®ãªãã·ã§ã³ãé¢äžããªãããã§ã¯ãããŸããã
ã«ãŒãã£ã³ã°èšå®
å®éãããã¯FMCãä»ããASAæ©èœã®ãŸãã«èšå®ã§ãã ãã¹ãŠã®èšå®ã¯ã[ããã€ã¹]-> [ããã€ã¹ç®¡ç]ãš[ãªããžã§ã¯ã]ã¿ãã®2ã€ã®ã¿ãã§å®è¡ãããŸãã [ãªããžã§ã¯ã]ã¿ãã§ãBGPã®SLAãã«ãŒãããããACLããã³[ASãã¹ãã³ãã¥ããã£ãªã¹ããããªã·ãŒãªã¹ã]ã®æšæºã®ASAèšå®ã確èªã§ããŸãã

å³8-ASAã¯ã©ã·ãã¯èšå®ã®ã³ã³ããŒãã³ã
[ãªããžã§ã¯ã]ã¿ãã®ãã¹ãŠã®ã«ã¹ã¿ã ããªããžã§ã¯ããã¯ãããŸããŸãªããªã·ãŒãç¹ã«[ããã€ã¹ç®¡ç]ã¿ãã§ããã€ã¹ã«é©çšãããããªã·ãŒã§ããã«äœ¿çšããããã«äœæãããŸãã
CLIã®ãªããžã§ã¯ã
FMCã«1ã€ãŸãã¯å¥ã®ããªããžã§ã¯ããã®èšå®ãååšããã©ã®ããªã·ãŒã§ã䜿çšãããŠããªãå Žåã§ãããã®ãããªããªããžã§ã¯ããã¯CLIã«è¡šç€ºãããªããšããäºå®ãèæ
®ãã䟡å€ããããŸãã
[ããã€ã¹ç®¡ç]ã¿ãã®ããªã·ãŒèšå®ã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
1.ã»ã¯ã·ã§ã³ããã€ã¹ã
å¥ã®FPã»ã³ãµãŒãã»ããã¢ããããå Žåãåæ§ã§ãã

å³9-ããã€ã¹ã»ã¯ã·ã§ã³
2.ã«ãŒãã£ã³ã°ã
éçããã³åçïŒ

å³10-ã«ãŒãã£ã³ã°ã®ã»ããã¢ãã
ãŸããSLAããªããžã§ã¯ãããéçã«ãŒãã«é©çšããCLIã§è¡šç€ºããäŸã次ã«ç€ºããŸãã

å³11-SLAã»ããã¢ããã®äŸ
3. NATã
ããã§ã¯ããã¥ã¢ã³ã¹ãšå¶éãªãã§ãNATã«ãŒã«ã®ãã¹ãŠã®ããªã¢ã³ãã䜿çšã§ããŸãã

å³12-å€æã«ãŒã«ã®èšå®
4.ã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æã

å³13-ã€ã³ã¿ãŒãã§ã€ã¹ã®æ§æ
ã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯ã1ç¹ãé€ããŠãã¹ãŠãéåžžã«æšæºçã§ããéåžžã®ã»ãã¥ãªãã£ã¬ãã«ã¯èšå®ã§ããããã¹ãŠã®ã€ã³ã¿ãŒãã§ãŒã¹ã«ã¯ãŒãã»ãã¥ãªãã£ã¬ãã«ãèšå®ãããŠããŸãã ãã ããæ§æã«åãã¬ãã«ã®ã»ãã¥ãªãã£ïŒ åãã»ãã¥ãªãã£ãã©ãã£ãã¯èš±å¯ã€ã³ã¿ãŒã€ã³ã¿ãŒãã§ã€ã¹ ïŒã®ã€ã³ã¿ãŒãã§ã€ã¹éã§ãã©ãã£ãã¯ãæž¡ãèš±å¯ããªããšããäºå®ã«ããããããããã¹ãŠãæ£åžžã«æ©èœããŸãã
åãã»ãã¥ãªãã£ãã©ãã£ãã¯ã®ã€ã³ã¿ãŒãã§ã€ã¹éã¢ã¯ã»ã¹èš±å¯
firepower# sh run inter g0/0 ! interface GigabitEthernet0/0 description inside interface nameif inside security-level 0 ip address 192.168.20.254 255.255.255.0 firepower# sh run inter g0/1 ! interface GigabitEthernet0/1 description outside interface nameif outside security-level 0 ip address 192.168.200.251 255.255.255.128 firepower# sh run same-security-traffic ^ ERROR: % Invalid input detected at '^' marker. firepower# sh run | i same firepower#
5.ã€ã³ã©ã€ã³ã»ããã®ã»ããã¢ããã
ã¿ããã¢ãŒã -ãã¹ãŠã®ãã©ãã£ãã¯ãã»ã³ãµãŒã«æž¡ãã®ã§ã¯ãªãããã©ãã£ãã¯ã®ã³ããŒã®ã¿ãã»ã³ãµãŒã«å°éãããããã¢ã¯ãã£ããªã¢ã¯ã·ã§ã³ã¯ãã©ãã£ãã¯ã«é©çšãããŸããã ãã ããåæã«ã€ãã³ãïŒIPSã€ãã³ããªã©ïŒãçæãããŸãã éžæãããã€ã³ã¿ãŒãã§ã€ã¹ãã¢ã®ãã©ãã£ãã¯ã®äžçš®ã®ç£èŠã¢ãŒãïŒåå¥ã®FPã»ã³ãµãŒãšæ¯èŒããå Žåã®ãã¹ãã³ã¢ãŒããïŒã ãªã³ã¯ç¶æ ã®äŒæ -ãã€ãã¹ã¢ãŒãããã§ãã¯ããã«ãã¹ãŠã®ãã©ãã£ãã¯ãã¹ããããããã¢ã®ã€ã³ã¿ãŒãã§ã€ã¹ã®1ã€ãããŠã³ç¶æ ã§éä¿¡ãããå Žåã2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ãåãããšãèµ·ãããŸãïŒåé¡ã®ããã€ã³ã¿ãŒãã§ã€ã¹ãã¢ããç¶æ ã«æ»ããšããã«ã2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ãèªåçã«ç«ã¡äžãããŸãïŒã å³å¯ãªTCPåŒ·å¶ -TCPã»ãã·ã§ã³ã®ããªãã«ãã³ãã·ã§ã€ã¯å¶åŸ¡ãæå¹ã«ããŸãã Tapã¢ãŒããšStrict TCP Enforcementãåæã«æå¹ã«ããããšã¯ã§ããŸããã

å³14-ã€ã³ã©ã€ã³ã»ããã®æ§æ
6. DHCPãµãŒãã¹ãæ§æããŸãã
3ã€ã®ãªãã·ã§ã³ïŒDHCPãµãŒããŒãDHCPãªã¬ãŒãããã³DDNSã

å³15-DHCPèšå®
ããããããã ãã§ãã åŸæ¥ã®ãã©ãã£ãã¯æ€æ»ã®ãã©ã¡ãŒã¿ã«é¢ããŠã¯ãå€æŽããããšã¯ã§ããŸããããCLIã§ã¯ipãªãã·ã§ã³ããã³tcpã®è¿œå ãªãã·ã§ã³ãšãã圢ã§è¥å¹²ã®è¿œå ãå ããããŠãããããéåžžã«æšæºçã«èŠããŸãã
åŸæ¥ã®æ€æ»èšå®
firepower# sh run class-map ! class-map inspection_default match default-inspection-traffic ! firepower# sh run policy-map ! policy-map type inspect dns preset_dns_map parameters message-length maximum client auto message-length maximum 512 policy-map type inspect ip-options UM_STATIC_IP_OPTIONS_MAP parameters eool action allow nop action allow router-alert action allow policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp inspect icmp inspect icmp error inspect dcerpc inspect ip-options UM_STATIC_IP_OPTIONS_MAP class class-default set connection advanced-options UM_STATIC_TCP_MAP ! firepower# sh run tcp-map ! tcp-map UM_STATIC_TCP_MAP tcp-options range 6 7 allow tcp-options range 9 255 allow urgent-flag allow !
ãµãã¹ã¯ãªãã·ã§ã³ããªã·ãŒã®æ§æïŒNGFWãNGIPSãAMPïŒ
ãã¹ãŠã®ããªã·ãŒã¯ã以åãšåãæ¹æ³ã§æ§æãããŸãã äž»ãªããšã¯ãããããå±éãããšãã«å¿ èŠãªããã€ã¹ãéžæããããšãå¿ããªãããšã§ãã èå³æ·±ãç¹ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒïŒNGFWïŒã§ããèšå®ããã³é©çšããããã¹ãŠã®ã«ãŒã«ã¯ãCLIã§è¡šç€ºã§ããŸãã CLIã§ã¯ãç¹å®ã®ååãæã¡ãããå ·äœçãªæ§æãæã€ACLãšããŠè¡šç€ºãããŸãã

å³16-ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒã«ãŒã«ã
ãããŠããã§ã®äž»ãªããšã¯ããã®ãããªACLãã°ããŒãã«ã«é©çšããïŒ ã¢ã¯ã»ã¹ã°ã«ãŒãCSM_FW_ACL_ global ïŒãããã«ãACLã®æåŸã«ã«ãŒã«ãæåŠããã¯ã©ã·ãã¯ãååšããªããšããããšã¯ãå®éã«ååšããªãããšãæå³ããŸãã äœæãããã«ãŒã«ïŒå€åŽããå åŽãžã®æ¹åãå«ãïŒã«è©²åœããªããã¹ãŠã®ãã©ãã£ãã¯ã¯ããããã©ã«ãã¢ã¯ã·ã§ã³ãïŒããã©ã«ãã¢ã¯ã·ã§ã³ãå³16ïŒã«ãã£ãŠåŠçãããŸãã ãããã£ãŠããã¹ãŠã®çä¿¡ãã©ãã£ãã¯ãèš±å¯ãããç¶æ³ãåé¿ããããã«ãã«ãŒã«ã®æºåã«ç¹å¥ãªæ³šæãæã䟡å€ããããŸãã ãã¡ã€ã«ããªã·ãŒãŸãã¯IPSããªã·ãŒã®æ§æã«åŸ®åŠãªéãã¯ãããŸããã§ããã
ãããã«
äžèŠãããŒãžã§ã³6.0.1 FTDã¯
ãµã€ãéVPNã®æ»ç¥
ãµã€ãéVPN æŸèæãèšå®ã§ããŸãã SSHçµç±ã§ã¢ã¯ã»ã¹ã§ããŸããã¯ããæ§æãç·šéããããšã¯ã§ããŸããã ãããããããããŒãããããšãã§ããŸã- ã³ããŒã³ãã³ãã¯å®å
šã«å©çšå¯èœã§ãã å¿
èŠãªããšã¯ãå®è¡ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ãããšãã°tftpãµãŒããŒã«ã¢ããããŒãããŠç·šéããããŒããçŽãããšã ãã§ãã VPNã«å¿
èŠãªãã¹ãŠã®è¡ã¯ãæ§æãã¡ã€ã«ã®æåŸãã2çªç®ã®è¡ãšæåŸã®è¡ïŒCryptochecksumããã³endïŒã®éã®ã®ã£ããã«è¿œå ã§ããŸãã
FTDäžã®èšå®ãã¡ã€ã«ã®å Žæãæ確ã«ç€ºããã³ãã³ãã䜿çšããŠãæºåãããèšå®ãèªã¿èŸŒãå¿ èŠããããŸãã
ãã¡ã€ã«ãã³ããŒãããåŸãSSHæ¥ç¶ãåæããããããåæ¥ç¶ããŠæ§æãä¿åããå¿ èŠããããŸãïŒ ã¡ã¢ãªã®æžã蟌㿠ïŒã å察åŽã§é©åãªæ§æãå®äºãããšãæ¬æ Œçãªåäœãããµã€ãéVPNãåŸãããŸãã
ãããŠããã¹ãŠã¯äœããããŸãããã1ã€ã®ãã¥ã¢ã³ã¹ã§ãªããã°ããæŸèæãã§ã¯ãããŸããããã®æ¹æ³ã§äœæããããã®æå·ã«ãŒãçšã«äœæãããã¢ã¯ã»ã¹ãªã¹ãã¯ãFMCã³ã³ãœãŒã«ã§å€æŽãé©çšãããã³ã«FTDèšå®ããåé€ãããŸãïŒDeployãå®è¡ããŸãïŒ ã ãã®ç¶æ³ã§ã¯ãããŒãžã§ã³9.2ïŒ1ïŒããASAã«è¿œå ãããEmbedded Event ManagerïŒEEMïŒã圹ç«ã¡ãŸãã VPNèšå®ãšåãæ¹æ³ã§ãEEMèšå®ã«è¿œå ããŸãã
ãã®ãããªEEMã¯ãå¿ èŠãªACLã5ç§ããšã«æ§æã«è¿œå ããŸãã ãŸããæ§æããACLãåé€ãããšãã€ã³ãã£ã³ã°ãåé€ããããããACLãã€ã³ãã£ã³ã°ã³ãã³ããæå·ã«ãŒãã«è¿œå ããå¿ èŠããããŸãã ãããã£ãŠãå®å šã«æ©èœããVPNãååŸããŸãã
ãã®ãããªå®è£ ã§ã¯ãFMCããFTDãžã®ããªã·ãŒã®å±éã®ç¬éã«ãã±ããæ倱ãäºæ³ãããŸãã
EEMã®ã€ãã³ãã¿ã€ããŒã®å¯èœãªä»£æ¿æ¹æ³ã¯ãç¹å®ã®IDïŒ ã€ãã³ãsyslog id ïŒãæã€ãã°ã«ã¡ãã»ãŒãžã衚瀺ããããšãã«ã¢ã¯ã·ã§ã³ãå®è¡ããããšã§ãã ãã®ãªãã·ã§ã³ã¯ãã¹ããããŠããªãããããã®æåã«ã€ããŠã¯äœãèšããŸããïŒIDãæ£ããéžæãããŠããå Žåã§ãïŒã
Cryptochecksum:073c34a024b2cff7f7303a5c888c2c61 crypto ikev1 policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 86400 crypto ikev1 enable outside crypto ipsec ikev1 transform-set ESP-AES-SHA esp-aes-256 esp-sha-hmac access-list crypto-acl extended permit ip host 192.168.20.5 host 172.25.25.20 crypto map CMAP 10 match address crypto-acl crypto map CMAP 10 set peer 192.168.200.252 crypto map CMAP 10 set ikev1 transform-set ESP-AES-SHA crypto map CMAP interface outside tunnel-group 192.168.200.252 type ipsec-l2l tunnel-group 192.168.200.252 ipsec-attributes ikev1 pre-shared-key 123456 : end
FTDäžã®èšå®ãã¡ã€ã«ã®å Žæãæ確ã«ç€ºããã³ãã³ãã䜿çšããŠãæºåãããèšå®ãèªã¿èŸŒãå¿ èŠããããŸãã
copy tftp system:running-config
ãã¡ã€ã«ãã³ããŒãããåŸãSSHæ¥ç¶ãåæããããããåæ¥ç¶ããŠæ§æãä¿åããå¿ èŠããããŸãïŒ ã¡ã¢ãªã®æžã蟌㿠ïŒã å察åŽã§é©åãªæ§æãå®äºãããšãæ¬æ Œçãªåäœãããµã€ãéVPNãåŸãããŸãã

ãããŠããã¹ãŠã¯äœããããŸãããã1ã€ã®ãã¥ã¢ã³ã¹ã§ãªããã°ããæŸèæãã§ã¯ãããŸããããã®æ¹æ³ã§äœæããããã®æå·ã«ãŒãçšã«äœæãããã¢ã¯ã»ã¹ãªã¹ãã¯ãFMCã³ã³ãœãŒã«ã§å€æŽãé©çšãããã³ã«FTDèšå®ããåé€ãããŸãïŒDeployãå®è¡ããŸãïŒ ã ãã®ç¶æ³ã§ã¯ãããŒãžã§ã³9.2ïŒ1ïŒããASAã«è¿œå ãããEmbedded Event ManagerïŒEEMïŒã圹ç«ã¡ãŸãã VPNèšå®ãšåãæ¹æ³ã§ãEEMèšå®ã«è¿œå ããŸãã
event manager applet cryptoACL event timer watchdog time 5 action 0 cli command "access-list crypto-acl extended permit ip host 192.168.20.5 host 172.25.25.20" action 1 cli command "crypto map CMAP 10 match address crypto-acl" output none
ãã®ãããªEEMã¯ãå¿ èŠãªACLã5ç§ããšã«æ§æã«è¿œå ããŸãã ãŸããæ§æããACLãåé€ãããšãã€ã³ãã£ã³ã°ãåé€ããããããACLãã€ã³ãã£ã³ã°ã³ãã³ããæå·ã«ãŒãã«è¿œå ããå¿ èŠããããŸãã ãããã£ãŠãå®å šã«æ©èœããVPNãååŸããŸãã
ãã®ãããªå®è£ ã§ã¯ãFMCããFTDãžã®ããªã·ãŒã®å±éã®ç¬éã«ãã±ããæ倱ãäºæ³ãããŸãã

EEMã®ã€ãã³ãã¿ã€ããŒã®å¯èœãªä»£æ¿æ¹æ³ã¯ãç¹å®ã®IDïŒ ã€ãã³ãsyslog id ïŒãæã€ãã°ã«ã¡ãã»ãŒãžã衚瀺ããããšãã«ã¢ã¯ã·ã§ã³ãå®è¡ããããšã§ãã ãã®ãªãã·ã§ã³ã¯ãã¹ããããŠããªãããããã®æåã«ã€ããŠã¯äœãèšããŸããïŒIDãæ£ããéžæãããŠããå Žåã§ãïŒã
UPDïŒ2016幎9æ2æ¥ïŒïŒ
8æ29æ¥ãTsiskaã¯ããŒãžã§ã³6.1ã®ã¢ããããŒãããªãªãŒã¹ããŸããã å ¬åŒWebãµã€ãã®ãªãªãŒã¹ããŒãã«èšèŒãããŠããã¢ããããŒãã®å®å šãªãªã¹ãã
ããããã®ã¢ããããŒããããããããã¯ãã¹ãŠ
- ã¿ãŒããã«ãµãŒããŒçšã®TSãšãŒãžã§ã³ãïŒVDI IDãµããŒãïŒã
ããã§ã端æ«ã®èåŸã«ãããŠãŒã¶ãŒãèªèã§ããããã«ãªããŸããã åäœã®åçã¯ãCheck Pointã§ã®åäœã«äŒŒãŠããŸã-åãŠãŒã¶ãŒãžã®ããŒãç¯å²ã®å²ãåœãŠã ç§ã¯äœãã»ã®ããããŸãããããªãåã«ãããªãã®ã§ããïŒãšã«ãããããã£ãã - KerberosèªèšŒã
ã·ã³ã°ã«ãµã€ã³ãªã³ãæ¯æŽã§ããŸãã 圌ããåŸ ã£ãŠããŸãããããããšãã - ã¬ãŒãå¶éã
ããã§ããããã¯ãŒã¯ããŸãŒã³ããŠãŒã¶ãŒ/ã°ã«ãŒããã¢ããªã±ãŒã·ã§ã³ãããŒããããã³ISEããåä¿¡ãããã©ã¡ãŒã¿ãŒã§åž¯åå¹ ãåæžã§ããŸãã - ãµã€ãéVPNã
ããã§ããŒããªãã§åäœããã¯ãã§ãã - ä»®æ³åãµããŒãã®åŒ·åã
KVMãåŸ ã¡ãŸããHyper-VãåŸ ã¡ãŸãã
ãã¹ãŠãã¯ãŒã«ã«èŠããŸãããå®éã«ã¯ãã¹ããããŠããªããããå®éã®ç¶æ³ã«ã€ããŠã¯äœãèšããŸããã å°ãªããšãä»ã®ãšããã