é«æ§èœæ
å ±ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®äžççãªãŒããŒãšããŠããã©ãŒãã£ãããã¯ãå°çšãããã»ãããé«éã³ã³ãã³ãåæããã»ããµãç¬èªã®ãããã¯ãŒã¯ãã©ãã£ãã¯åŠçãªã©ã®ããã©ãŒãã³ã¹ã®åé¡ã«ã€ã㊠ã FortiASICãšçµã¿åãããŠFortiOSã«äŸåããŠããŸãã ãã®èšäºã§ã¯ããããã®ããã»ããµãŒã®åäœã«ã€ããŠè©³ãã説æããŸãã ããã±ãŒãžã®åŠç/åæãé«éåããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ãã©ã«ãã£ã¢ã·ãã¯
ã»ãšãã©ã®FortiGateã¢ãã«ã«ã¯ããã©ãã£ãã¯ã®åŠçãšã¬ã€ãã³ã·ãŒã®åæžã®ããã®FortiASICïŒç¹å®çšéåãéç©åè·¯ïŒå°çšããŒããŠã§ã¢ã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ããããã¡ã€ã³ããã»ããµïŒCPUïŒãã¢ã³ããŒãã§ããŸãã
-ãããã¯ãŒã¯ããã»ããµïŒNPïŒ-ãããã¯ãŒã¯ãã©ãã£ãã¯ã®åŠççš
-ã³ã³ãã³ãããã»ããµïŒCPïŒ-ã»ãã¥ãªãã£æ©èœçš
-System-on-a-Chip ProcessorïŒSOC2ïŒ-ã»ãã¥ãªãã£æ©èœãšãã©ãã£ãã¯åŠçã®ã³ã©ãã¬ãŒã·ã§ã³çš
ãã©ãŒãã£ãããã¯ãFortiGate補åã©ã€ã³ã3ã€ã®ã«ããŽãªã«åé¡ããŠããŸãã
-ãšã³ããªãŒã¬ãã«ïŒãã¹ã¯ãããïŒ
-ãããã¬ã³ãž
-ãã€ãšã³ã
åã«ããŽãªã§ã¯ãç°ãªãCPUãšFortiASICãããã³ãããã®ç°ãªãæ°ã䜿çšãããŸãã
ãããã¯ãŒã¯ããã»ããµãŒ
NPãããã¯ãŒã¯ããã»ããµã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¬ãã«ã§åäœããã¡ã€ã³ããã»ããµãããã©ãã£ãã¯ããªãããŒãããããšã§ãã©ãã£ãã¯ãå éããŸãã ææ°ã®ã¢ãã«ã«ã¯NP4ãšNP6ãå«ãŸããŠããŸãã å€ãFortiGateã¢ãã«ã«ã¯ãNP1ïŒFortiAccelãŸãã¯FA2ãšãåŒã°ããŸãïŒããã³NP2ãå«ãŸããŸãã
çŸåšãNP6ããã»ããµã¯ææ°ã®éçºã§ããã次ã®ãã©ãã£ãã¯ãšãµãŒãã¹ããªãããŒãã§ããŸãã
-IPv4ããã³IPv6ãã©ãã£ãã¯ãNAT64ããã³NAT46ãã©ãã£ãã¯
-ãªã³ã¯ã¢ã°ãªã²ãŒã·ã§ã³ïŒLAGïŒïŒIEEE 802.3adïŒãã©ãã£ãã¯
-TCPãUDPãICMPãããã³SCTP
-IPsec VPNãã©ãã£ãã¯ãããã³IPsecæå·å/埩å·åïŒSHA2-256ããã³SHA 2-512ãå«ãïŒ
-æå·åãããŠããªãIPsecãã©ãã£ãã¯
-ç°åžžããã§ãã¯ãµã ãªãããŒããããã³ãã±ãããã©ã°ã¡ã³ããŒã·ã§ã³ã«åºã¥ãIPS
-SITããã³IPv6ãã³ããªã³ã°ã»ãã·ã§ã³
-ãã«ããã£ã¹ããã©ãã£ãã¯ïŒIPsecå
ã®ãã«ããã£ã¹ããå«ãïŒ
-CAPWAPãã©ãã£ãã¯
-ãã©ãã£ãã¯ããã³ãã©ã€ãªãªãã£ãã¥ãŒã€ã³ã°ã®åœ¢æ
-Synãããã·
-Inter-VDOMãªã³ã¯ãééãããã©ãã£ãã¯
-IPS
-ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡
-CASI
-ãããŒããŒã¹ã®ãŠã€ã«ã¹å¯Ÿç
-ãããŒããŒã¹ã®Webãã£ã«ã¿ãªã³ã°
NPã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ã®å€æŽãããã³ã³ãã³ãã®ã¢ã³ããŒãããµããŒãããŠããŸãããã€ãŸããããªã·ãŒã§æ¬¡ã®ã»ãã¥ãªãã£æ©èœãæå¹ã«ãªã£ãŠããå Žåãã»ãã·ã§ã³ã¯ã¢ã³ããŒããããŸããã
-ãããã·ããŒã¹ã®ãŠã€ã«ã¹ã¹ãã£ã³
-ãããã·ããŒã¹ã®Webãã£ã«ã¿ãªã³ã°
-DNSãã£ã«ã¿ãªã³ã°
-DLP
-ã¹ãã 察ç
-VoIP
-ICAP
-Webã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«
-ãããã·ãªãã·ã§ã³
ã³ã³ãã³ãããã»ããµ
CPã³ã³ãã³ãããã»ããµã¯ãCPUã«ãã£ãŠå®çŸ©ãããã¿ã¹ã¯ã䜿çšããŠã·ã¹ãã ã¬ãã«ã§åäœããŸãã æ°ããFortiGateã¢ãã«ïŒ2000Eã2500Eã6040EïŒã«ã¯CP9ãå«ãŸããŠããŸãã å€ãããŒãžã§ã³ã¯CP4ãCP5ãCP6ã§ãããçŸåšã®FortiGateã¢ãã«ã¯CP8ã䜿çšããŠããŸãã
CP8ã¯ã次ã®ã¿ã¹ã¯ããªãããŒãã§ããŸãã
-ãããŒããŒã¹ã®æ€æ»IPSãã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãã¯ã©ãŠãã¢ã¯ã»ã¹ã»ãã¥ãªãã£æ€æ»ïŒCASIïŒãWebãã£ã«ã¿ãªã³ã°ãDLPãããã³ãŠã€ã«ã¹å¯Ÿç
-é«æ§èœVPNãã«ã¯ããŒã¿ãšã³ãžã³
-IPsecããã³SSL / TLSãããã³ã«ããã»ããµ
-FIPS46-3 / FIPS81 / FIPS197ã«æºæ ããDES / 3DES / AES
-RC4ã«æºæ ããARC4
-RFC1321ããã³FIPS180ã䜿çšããMD5 / SHA-1 / SHA256
-RFC2104 / 2403/2404ããã³FIPS198ã«æºæ ããHMAC
-Key Exchange Processorã¯ãé«æ§èœã®IKEããã³RSAèšç®ããµããŒãããŸã
-ããŒããŠã§ã¢CRTããµããŒãããå
¬ééµã¹ãä¹ãšã³ãžã³
-äž»ã«RSAããŒçæã®ç¢ºèª
-èªåããŒãããªã¢ã«çææ©èœä»ããã³ãã·ã§ã€ã¯ã¢ã¯ã»ã©ã¬ãŒã¿
-ANSI X9.31ã«æºæ ããä¹±æ°ãžã§ãã¬ãŒã¿ãŒ
-æ倧4096ãããã®æäœãçŽæ¥ãµããŒããããµãå
¬éããŒãšã³ãžã³ïŒPKCEïŒ
-ã¡ãã»ãŒãžèªèšŒã¢ãžã¥ãŒã«ã¯ã4Gãã€ããŸã§ã®ããŒã¿ã®SHA256 / SHA1 / MD5ãèšç®ããããã®é«æ§èœæå·ãšã³ãžã³ãæäŸããŸãïŒå€ãã®ã¢ããªã±ãŒã·ã§ã³ã§äœ¿çšãããŸãïŒ
-PCI Express Gen 2 4ã¬ãŒã³ã€ã³ã¿ãŒãã§ã€ã¹
-ãããæ¡åŒµçšã®ã«ã¹ã±ãŒãã€ã³ã¿ãŒãã§ã€ã¹
ã·ã¹ãã ãªã³ãããããã»ããµ
SOCããã»ããµã¯ããšã³ããªã¬ãã«ïŒãã¹ã¯ãããïŒã«ããŽãªã®è¥ãã¢ãã«ã§äœ¿çšãããŸãã SoCã¢ãŒããã¯ãã£ã®ç®çã¯ãè€æ°ã®ããã»ããµã1ã€ã®ãããã«çµåããŠãããŒããŠã§ã¢å
šäœã®èšèšãç°¡çŽ åããããšã§ãã SOCã¯ãCPãNPãRISCããŒã¹ã®CPUããã»ããµãçµã¿åããããã®ã§ãã
çŸåšãNPããã³CPã»ã¯ã·ã§ã³ã§èª¬æãããŠãããã©ãã£ãã¯ããªãããŒãããSOCããŒãžã§ã³2ãé¢é£ããŠããŸãã
SOCã¢ãŒããã¯ãã£
ãªãããŒã
ã»ãã·ã§ã³ã®ã¢ã³ããŒãããã»ã¹ã¯ãããã€ãã®æ®µéã§è¡ãããŸãã æ°ããã»ãã·ã§ã³ã®æåã®ãã±ããã¯åžžã«CPUã«å°çããŸãã å®è¡ããå¿
èŠãããèŠæ±ãããã»ãã¥ãªãã£æ©èœãNPããµããŒãããŠããå ŽåãCPUã¯ãã®ã»ãã·ã§ã³ãåŠçã§ãããšããæ瀺ãNPã«éä¿¡ããŸãã ãé«éãã¹ãã»ãã·ã§ã³ã®åŸç¶ã®ãã±ããã¯ãã¹ãŠNPã«ãªãã€ã¬ã¯ããããŸãã æåŸã«ãæåŸã®TCPãã±ããã®åŸããFINãïŒçµäºïŒãŸãã¯ãRSTãïŒãªã»ããïŒNPãã»ãã·ã§ã³ãCPUã«è¿ããã»ãã·ã§ã³ãéããŸãã ãã以å€ã®å ŽåãNPãåŠçãå¿
èŠãªèŠæ±ãããã»ãã¥ãªãã£æ©èœããµããŒãããŠããªãå Žåããã®ã»ãã·ã§ã³ã®ãã¹ãŠã®ãã±ããã¯CPUã«ãã£ãŠåŠçãããå¿
èŠããããŸãã
ã¢ã³ããŒããããã»ãã·ã§ã³ã®ããã±ãŒãžãã¹
ãªãããŒããããã»ãã·ã§ã³ã®æåã®ãã±ããã®ãã¹
ã¢ã³ããŒããããã»ãã·ã§ã³ã®åŸç¶ã®ããã±ãŒãžãã¹
2ã€ä»¥äžã®NP6ãåããFortiGateãã€ãšã³ãã¢ãã«ã¯ãIntegrated Switch FabricïŒISFïŒãä»ããŠç©ççã«æ¥ç¶ãããŸããããã«ããããã¹ãŠã®ã€ã³ã¿ãŒãã§ã€ã¹ãšNP6ããã»ããµéã®éä¿¡ãäžå€®ããã»ããµããã€ãã¹ã§ããŸãã ãã®ããã«ããŠãå
¥åããŒããšåºåããŒããè€æ°ã®NPããã»ããµã«å±ããŠããå Žåã§ãããã©ãã£ãã¯ã¯ã¢ã³ããŒããããŸãã
çµ±åã¹ã€ãããã¡ããªãã¯
NTurboã¢ã¯ã»ã©ã¬ãŒã·ã§ã³
NTurboã®ã¢ã¯ã»ã©ã¬ãŒã·ã§ã³æ©èœã«ãããNPããã»ããµãééããUTM / NGFWã»ãã·ã§ã³ãã¢ã³ããŒãã§ããŸãã
NTurboã®ãããã§ãNPããIPSãšã³ãžã³ãžããŸãã¯ãã®éã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ãããããã®ç¹å¥ãªãããŒã¿ãã£ãã«ããäœæãããŸãã ã¢ã³ããŒãæé ïŒ
1.NPã¯ãã±ãããåä¿¡ããå¿
èŠãªã¢ã¯ã·ã§ã³ãå®è¡ããŸãã
1.1ãã±ãããæå·åãããŠããå Žåããã±ããã¯CPããã»ããµã«éä¿¡ãããŸãã
1.2 CPã䜿çšãã埩å·åã
1.3CPã¯ãNPããŒã¿ãããã»ããµã«è»¢éããŸãã
2.ãããŒããŒã¹ã®UTM / NGFWæ€æ»ã®å ŽåãNPã¯IPSãšã³ãžã³ã§ããŒã¿ãã£ãã«ãäœæãïŒCPUã§åŠçïŒãããŒã¿ãéä¿¡ããŸãã
3. IPSãšã³ãžã³ã¯ãããŒã¿æ€æ»ã®ã¿ã¹ã¯ãCPã«è»¢éããŠãCPãé«éåããŸãã
4.CPã¯ãIPSãšã³ãžã³ã«ããŒã¿ãè¿ããŸãã
5. IPSãšã³ãžã³ã¯ãNPããŒã¿ãããã»ããµã«è¿ããŸãã
6.ããŒã¿ã埩å·åãããŠããå Žåãæå·åã®ããã«CPã«éä¿¡ãããŸãã
7. CPã䜿çšããæå·åã
8.CPã¯NPããŒã¿ãããã»ããµã«è»¢éããŸãã
9.NPããã»ããµã¯CPUãã±ãããéä¿¡ããŸãã
NTurboã¯NP4ãšNP6ããµããŒãããŠããŸãã
IPSAãªãããŒãã䜿çšããNTurboã»ãã·ã§ã³
IPSAã¢ã¯ã»ã©ã¬ãŒã·ã§ã³
IPSAãã¯ãããžãŒã¯ãNTurboããã³æšæºã®ãã¡ã€ã¢ãŠã©ãŒã«ã»ãã·ã§ã³ã§å©çšå¯èœãªFlowããŒã¹ã®UTM / NGFWæ€èšŒã®ããã¿ãŒã³ãããã³ã°ãæ¡åŒµæ©èœããªãããŒãããŸãã IPSAã¯CP7ãCP8ããã³CP9ããµããŒãããŠããŸãã
IPsecæå·å/埩å·å
IPsecãã³ãã«ãNPãããã¯ãŒã¯ããã»ããµã§ãµããŒããããæå·åããã³ããã·ã¥ã¢ã«ãŽãªãºã ã䜿çšããå ŽåãIPsecãŠãŒã¶ãŒããŒã¿åŠçããªãããŒãããŠããã©ãŒãã³ã¹ãåäžãããããšãã§ããŸãã ãã®å ŽåãNPã¯ãã©ãã£ãã¯ã®åŸ©å·åã®ã¿ãè¡ããCPã¯æå·åãè¡ããŸãã
IPsecæå·å/埩å·å
CPã䜿çšãããããŒããŒã¹ããã³ãããã·ããŒã¹ã®æ€æ»ã®é«éå
ãããŒããŒã¹ã®UTM / NGFWæ€æ»ã¯ãã·ã³ã°ã«ãã¹ã¢ãŒããã¯ãã£ã䜿çšããŠã»ãã·ã§ã³ã§ãã±ãããååŸããããšã«ããããªã¢ã«ã¿ã€ã ã®ã»ãã¥ãªãã£è
åšãæ€åºããã³ãããã¯ããŸããããã«ã¯ãå¯èœæ§ã®ããæ»æãŸãã¯è
åšãèå¥ãããã€ã¬ã¯ããã£ã«ã¿ãŒã¢ãããŒãïŒDFAïŒãã¿ãŒã³ãããã³ã°ãå«ãŸããŸãã
ãã§ãã¯ããåã«ãIPSãšã³ãžã³ãããã€ãã®ãã³ãŒããŒã䜿çšããŠé©çšãããã±ãããããã³ã«ãšããªã·ãŒèšå®ã«å¿ããŠé©çšãããé©åãªã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ã決å®ã§ããŸãã ããã«ãSSLãã±ããã埩å·åãããŸãã SSL埩å·åã¯ãCP8ãŸãã¯CP9ããã»ããµãŒã«ãã£ãŠãªãããŒããããå éãããŸãã
ã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ïŒIPSãã¢ããªã±ãŒã·ã§ã³ã³ã³ãããŒã«ãCASIããããŒããŒã¹ã®Webãã£ã«ã¿ãªã³ã°ããããŒããŒã¹ã®DLPãã£ã«ã¿ãªã³ã°ïŒã®ã¢ããªã±ãŒã·ã§ã³ã¯ã1ã€ã®ã¢ãããŒãã§åæã«çºçããCP8ããã³CP9ããã»ããµã«ãã£ãŠå éãããŸãã CASI眲åã¯ãæ€èšŒã®ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡éšåã§äœ¿çšãããŸãã ãããŒããŒã¹ã®ã¢ã³ããŠã€ã«ã¹ã¯ããããã³ã«ã®ãã³ãŒãäžã«ãã¡ã€ã«ããã£ãã·ã¥ããã¹ãã£ã³ããŸãã SSLãã±ããã®å Žåããã§ãã¯ã®æåŸã«æå·åããããããCP8ããã³CP9ããã»ããµãŒã¯ãã®ããã»ã¹ãå éããŸãã
ãããŒããŒã¹ã®æ€æ»ã®æ®µé
ãããã·ããŒã¹ã®UTM / NGFWæ€æ»ã¯ãããã«æ€èšŒããããã«ãã¡ã€ã«ãæœåºããŠãã£ãã·ã¥ããŸãã
æåã«ããã±ããã¯IPSãšã³ãžã³ã«å
¥ãããã®ã¢ãŒãã§ã®ã¿åäœããã»ãã¥ãªãã£æ©èœïŒã·ã³ã°ã«ãã¹IPSãã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãCASIïŒã§ãããŒããŒã¹ã®æ€æ»ãåãããããCP8ããã³CP9ã䜿çšããŠãã©ãã£ãã¯ãå éãããŸãã ãã®åŸããã±ããã¯FortiOS Proxy-serverã«éããããããã·ããŒã¹ã¢ãŒãã§ã»ãã¥ãªãã£æ©èœããã§ãã¯ãããŸãã ãŸãããããã·ã¯SSLãã©ãã£ãã¯ãæ€åºããŸãã SSLãã±ããã¯CP8ãŸãã¯CP9ã䜿çšããŠåŸ©å·åãããIPSãšã³ãžã³ã«å床éä¿¡ãããŠããã§ã«åŸ©å·åããããã©ãã£ãã¯ã®ãããŒããŒã¹ã®ã»ãã¥ãªãã£æ©èœïŒã·ã³ã°ã«ãã¹IPSãã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãããã³CASIïŒãåãã§ãã¯ãããŸãã 次ã«ããã©ãã£ãã¯ã¯ãããã·ãµãŒããŒã«å°éããããã§ãããã·ããŒã¹ã®ã»ãã¥ãªãã£æ©èœãé©çšãããŸãã æ€æ»ã¯æ¬¡ã®é åºã§è¡ãããŸãã
â¢VoIPã€ã³ã¹ãã¯ã·ã§ã³
â¢DLP
â¢ã¢ã³ãã¹ãã
â¢Webãã£ã«ã¿ãªã³ã°
â¢ã¢ã³ããŠã€ã«ã¹
â¢ICAP
埩å·åãæ€èšŒããããšãSSLãã©ãã£ãã¯ãæå·åãããŸãã è
åšãèŠã€ãããªãå Žåããããã·ãµãŒããŒã¯ãã¡ã€ã«ãå®å
ã«è»¢éããŸãã è
åšãèŠã€ãã£ãå Žåããããã·ãµãŒããŒã¯ãã¡ã€ã«ããããã¯ããããã«å¿ããŠãããã¯ã®çç±ã«é¢ããã¡ãã»ãŒãžãéä¿¡ã§ããŸãã
ãããã·ããŒã¹ã®æ€æ»æé