Cisco SD-Accessã®åºç€ãšãªãäž»èŠãªã³ã³ããŒãã³ããšãã¯ãããžãŒãããã³ãããã®æ©èœã«ã€ããŠèª¬æããŸãã
ç¹å®ã®ãµã³ãã«ã·ããªãªãäŸãšããŠäœ¿çšããŠãSD-Accessãã¡ã¯ããªãŒãšITãããžãã¹ã«ããããå©ç¹ã詳现ã«åæããŸãã
1.解決ãããŠããåé¡ãšãã®çç±
äŒæ¥ã®ITãµãŒãã¹ã¯ã岩ãšå³ããå Žæã®éãã§ãã
äžæ¹ã§ã¯ãããžãã¹ã§ã¯é«ããããã¯ãŒã¯å¯çšæ§ã確ä¿ããå¿ èŠããããäŸå€ãªããããã¯ãŒã¯ãåžžã«æ©èœããããšãæåŸ ããŠããŸãïŒ ããã¯æããã§ãã ITã§ã¯ãããžãã¹ããã»ã¹ã«ã¢ã¯ã»ã¹ã§ããªãããšä»¥äžã«ããžãã¹ãå¿é ãããã®ãèŠã€ããããšã¯å°é£ã§ã ã ããããããžã¿ã«ãã¯ãããžãŒã®éçºã«ãããããžãã¹ããã»ã¹ã®ãããã¯ãŒã¯ãžã®äŸåã¯ãŸããŸã倧ãããªã£ãŠããŸãã
äžæ¹ããŠãŒã¶ãŒïŒããã³æ¬è³ªçã«åãããžãã¹ïŒã¯ãæ°ãããµãŒãã¹ãæ°ããçš®é¡ã®ããã€ã¹ãæ°ããçš®é¡ã®ãŠãŒã¶ãŒïŒã²ã¹ããããŒãããŒãå«ãïŒãªã©ã®ãµããŒããå¿ èŠãšããŸãã ãããã¯ãã¹ãŠããããã¯ãŒã¯ããé©åãªãµããŒããè¿ éã«æäŸããå¿ èŠããããŸãã ããã«ãISãµãŒãã¹ã®èŠä»¶ãèæ ®ããå¿ èŠããããŸãã
ãã ããæ°ãããµãŒãã¹ãå°å ¥ããé«å¯çšæ§ã確ä¿ããããã®èŠä»¶ã¯ãååãšããŠçžåããŸãã å®éãé«å¯çšæ§ã¯äž»ã«ãããã¯ãŒã¯ã®å®å®æ§ãæå³ããŸããããã¯ãå°éæç®ïŒPiedadãFloydãMichael Hawkinsãªã©ïŒã§ç¥ãããŠããŸããé«å¯çšæ§ïŒèšèšãæè¡ãããã³ããã»ã¹ããããŠãäžè¬çãªååãäŸãã°ãKISSïŒKeep it Simple StupidïŒããåäœãã-觊ããªãããªã©
ãŸããå®çŸ©ã«ãã£ãŠæ°ãããããã¯ãŒã¯ãµãŒãã¹ãå°å ¥ãããšããããã¯ãŒã¯ã«æ°ããäœãããããããããå€æŽãå¿ èŠã«ãªãããããã®å®å®æ§ã«éåããŸãã ãããã®å€æŽã¯ãå€ãã®å Žåãè€éã§åºç¯ãªãã®ã§ããããšãã°ããã«ãã¡ãã£ã¢ã³ã©ãã¬ãŒã·ã§ã³ãœãªã¥ãŒã·ã§ã³ãšQoSã¡ã«ããºã ã®å°å ¥ãã»ãã¥ãªãã£ãã¯ãããžãŒãã»ã°ã¡ã³ããŒã·ã§ã³ãªã©ã§ãã ã茞éãã®åé¡ã解決ããããšããå°é£ãªå ŽåããããŸããããšãã°ããã£ã³ãã¹ãããã¯ãŒã¯ã®ç°ãªãéšåã«ãããã€ã³ãAãšBã®éã«ã¬ãã«2ã§æ¥ç¶ãæäŸããå Žåã§ãã
ãã®çµæããµãŒãã¹ã®å°å ¥ã¯ãããã¯ãŒã¯ãè€éã«ããå€ãã®æéãå¿ èŠãšããæã«ã¯å®å šã«è¡ãããªãããšããããŸãã
é«å¯çšæ§ã確ä¿ããããšãšæ¥åžžã®ããžãã¹äžã®åé¡ã解決ããããšãšã®éã«ççŸã«ã¯å¥ã®åŽé¢ããããŸãã éåžžãããžãã¹ã¿ã¹ã¯ã§ã¯ããã€ã³ãAãããã€ã³ãBã«ãã±ããã転éããã ãã§ãªããããŸããŸãªçš®é¡ã®ããªã·ãŒãå®è£ ããããã«ãããã¯ãŒã¯ãå¿ èŠã§ãã ããªã·ãŒã¯ç¹å®ã®èŠä»¶ã«å€æãããŸããããšãã°ãã»ãã¥ãªãã£ã®ç¢ºä¿æ¹æ³ãããŸããŸãªã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã£ãã¯ã®è»¢éæ¹æ³ãåŠçæ¹æ³ãªã©ã§ãã èªæã§ãªãããªã·ãŒã¯ããããã¯ãŒã¯ã®å®è£ ãšéçšã®è€éããå¢ããŸãã
ããã«ãããªã·ãŒã§ã¯å®è£ ããã®ã«ååã§ã¯ãããŸããã ãŸããããããå€æŽããããã«ãããããææ°ã®ç¶æ ã«ç¶æããå¿ èŠããããŸãã äŒæ¥ãããã¯ãŒã¯ã®èŠæš¡ã®ãã®ãããªå€æŽãç¹ã«æåã§å®è¡ãããå€æŽã¯ãéåžžããªãœãŒã¹ã倧éã«æ¶è²»ããé·ãããšã©ãŒã«å¯ŸããŠéåžžã«è匱ã§ãã ãã®çµæããããã¯ãŒã¯ã®å¯çšæ§ã¯åã³äœäžããåŸåããããŸãããéçšã³ã¹ãã¯å¢å ããŸãã
ãããã£ãŠãå žåçãªãå€å žçãªãäŒæ¥ãããã¯ãŒã¯ã§ã¯
- ãµãŒãã¹ã®å¯çšæ§ãšå®è£ ãé«ããããã®èŠä»¶ã¯äºãã«ççŸããŠããŸãã
- ããªã·ãŒã®å®è£ ã¯å°é£ã§ãã
- ããªã·ãŒãå®è£ ããŠææ°ã®ç¶æ ã«ä¿ã€ã¿ã¹ã¯ã«ããããããã¯ãŒã¯ã®é«å¯çšæ§ã確ä¿ããããšãé£ãããªããŸãã
ãããã®èª²é¡ã¯ã©ãã§ãITãµãŒãã¹ã«çŽé¢ããŠããŸãã ããããããžãã¹ã¯ITã®åé¡ã«é¢å¿ããããŸããã äŒæ¥ã¯ãããžãã¹ããã»ã¹ã確å®ã«æ©èœãããè¿ éã«å®è£ ããããšã«é¢å¿ãæã£ãŠããŸãã
2.ãããã¯ãŒã¯ãã¡ã¯ããªïŒäžé©åãªçµå
ITãçŽé¢ãããããã®çžåããè€éãªèª²é¡ãã©ã®ããã«è§£æ±ºããŸããïŒ è€éãªåé¡ã解決ããå®èšŒæžã¿ã®æ¹æ³ã¯ã1ã€ã®ã¿ã¹ã¯ãããã€ãã®åçŽãªã¿ã¹ã¯ã«åå²ãããããããã§ã«è§£æ±ºããããšã§ãã ããç¥ãããŠããäŸã¯ããããã¯ãŒã¯çžäºäœçšã®åé¡ã解決ãã7ã¬ãã«ã®OSIã¢ãã«ãŸãã¯4ã¬ãã«ã®DoDã¢ãã«ã§ãã
å³ 1.ãããã¯ãŒã¯ãã¡ã¯ããªã®æŠå¿µïŒãªãŒããŒã¬ã€ïŒ
ç§ãã¡ã®å Žåããããã¯ãŒã¯ãã¡ã¯ããªãŸãã¯ãªãŒããŒã¬ã€ã®æŠå¿µã圹ç«ã¡ãŸãïŒå³1ãåç §ïŒã ãªãŒããŒã¬ã€ã¯ãåºã«ãªããããã¯ãŒã¯ïŒã¢ã³ããŒã¬ã€ïŒã®äžã«æ§ç¯ãããè«çããããžã§ãã ãªãŒããŒã¬ã€ã¯ãããã¯ããŒã³ãããã¯ãŒã¯ãä»ããäŒéã«äœããã®åœ¢åŒã®ãã©ãã£ãã¯ã«ãã»ã«åã䜿çšããŸãã ãªãŒããŒã¬ã€ã®æŠå¿µã¯ããããã¯ãŒã¯ç®¡çè ã«ããç¥ãããŠããŸãã ãããã¯ãŒã¯äžã«ãã³ãã«ãæ·èšããããšã«ããã管çè ã¯ãªãŒããŒã¬ã€ãäœæããŸãã å žåçãªäŸã¯ãIPSecãGREãCAPWAPãVXLANãOTVãªã©ã§ãã
ãããã¯ãŒã¯ãã¡ã¯ããªãããã¯ã©ã·ãã¯ãããã¯ãŒã¯ãã§ã¯è§£æ±ºã§ããªãåè¿°ã®åé¡ãå æããã®ã«åœ¹ç«ã€ã®ã¯ãªãã§ããïŒ
ãå€å žçãªãããã¯ãŒã¯ãã§ã¯ããããã®å°é£ã¯æ ¹æ¬çãªçç±ã§è§£æ±ºãããŸãã-競åããèŠä»¶ãåããªããžã§ã¯ãã«èª²ãããããã§ãã
ãããã¯ãŒã¯ãã¡ã¯ããªã®å ŽåãèŠä»¶ãæ瀺ããããªããžã§ã¯ãã¯2ã€ã«åå²ãããŸãã 1ã€ã®ãããã¯ãŒã¯ããããžã¯2ã€ã«åå²ãããŸãã
æåã®åºç€ãšãªãããããžã¯ãã«ãŒãã£ã³ã°ããããããã¯ãŒã¯ã«åºã¥ããŠä¿¡é Œã§ãããã©ã³ã¹ããŒããæäŸããŸãã ããã圌女ã®å¯äžã®ä»äºã§ãã ãµãŒãã¹ãšããªã·ãŒãå®è£ ããŸãã-ãããç®çãšããŠããŸããã
ãµãŒãã¹ãšããªã·ãŒãå®è£ ããã¿ã¹ã¯ã¯ã2çªç®ã®ãªãŒããŒã¬ã€ãããã¯ãŒã¯ããããžã«ãã£ãŠæ±ºå®ãããŸãã ããšãã°ãOSIã¢ãã«ã®ç°ãªãã¬ãã«ã®ãããã³ã«ãäºãã«åé¢ãããŠãããããåºç€ãšãªãããããžããåé¢ãããŠããŸãã
2ã€ã®ãããã¯ãŒã¯ããããžã®åºçŸãšã競åããèŠä»¶ã®è§£æ±ºçãæäŸããŸãã ããã¯ããã¯ã©ã·ãã¯ãããã¯ãŒã¯ããšãããã¯ãŒã¯ãã¡ã¯ããªã®æ ¹æ¬çãªéãã§ãã ããã«ããããããã¯ãŒã¯ãã¡ã¯ããªã¯ãå€å žçãªãããã¯ãŒã¯ãã§ã¯å¯ŸåŠã§ããªãå°é£ãå æã§ããŸãã
3. Cisco SD-Accessãšã¯äœã§ããïŒ
ãããã¯ãŒã¯ãã¡ã¯ããªã®æŠå¿µã®å®è£ ã¯ãå€ãã®äŒæ¥ãããã¯ãŒã¯ã§æ¢ã«è¡ãããŠããŸãã ããšãã°ãCAPWAPãã³ãã«ãã¡ã¯ããªã®ã¢ã€ãã¢ã¯ãéäžåãšã³ã¿ãŒãã©ã€ãºã¯ã€ã€ã¬ã¹LANã¢ãŒããã¯ãã£ã«é·ãéå®è£ ãããŠããŸããã å¥ã®äŸã¯ãCisco Application Centric InfrastructureïŒACIïŒãœãªã¥ãŒã·ã§ã³ã®ããŒã¿ã»ã³ã¿ãŒãããã¯ãŒã¯ã®å·¥å Žã§ãã å·¥å Žã¯ãç¹ã«Cisco IWANãªã©ãSD-WANãã¯ãããžãŒã®åœ¢ã§å°ççã«åæ£ãããããã¯ãŒã¯ã«åºãã£ãŠããŸãã
ãã£ã³ãã¹ãããã¯ãŒã¯ã«ãããã¯ãŒã¯ãã¡ã¯ããªãŒãç»å Žãããšããæ¥ãŠããŸãïŒå³2ãåç §ïŒã
å³ 2. Cisco SD-Accessãããã¯ãŒã¯ãã¡ã¯ããªã¢ãŒããã¯ãã£
Cisco Software-Defined AccessïŒSD-AccessïŒã¯ãéäžç®¡çãèªååããªãŒã±ã¹ãã¬ãŒã·ã§ã³ãããã³ç£èŠãšåæãåãããã£ã³ãã¹ãããã¯ãŒã¯ãã¡ã¯ããªã³ã³ã»ããã®ã·ã¹ã³ã«ããå®è£ ã§ãã
ãããã®ããŒã«ã¯ããœãªã¥ãŒã·ã§ã³ã®äž»èŠã³ã³ããŒãã³ãã§ããCisco DNA Center Controllerã«ãã£ãŠæäŸãããŸãã DNA Centerã¯ãWebããŒã¹ã®ç®¡çãšAPIãæäŸããŸãã
ããã«ãDNAã»ã³ã¿ãŒã¯åæãµãŒãã¹ãå®è£ ããå·¥å Žã®ããã€ã¹ãããµãŒãã¹æ å ±ãšãã¬ã¡ããªãŒãåä¿¡ããŠââåæããŸãã DNA Centerã¯ã倧éã®ç°çš®ããŒã¿ãç¹å®ã®çµè«ãšå®éçãªæšå¥šäºé ã«å€æããåé¡ã解決ããŸãã ãã®ãããªçµè«ãšæšå¥šäºé ã¯ããããã¯ãŒã¯ã®çŸåšã®ç¶æ ããã®ãµãŒãã¹ãšã¢ããªã±ãŒã·ã§ã³ãããã³çŸåšã®ã€ã³ã·ãã³ãã«é¢é£ããŠããŸãã ããŒã¿ã®åæã«åºã¥ããŠãã³ã³ããã¹ãã®ç¥èãèæ ®ããŠãDNAã»ã³ã¿ãŒã¯ããããã¯ãŒã¯ãµãŒãã¹ã«å¯Ÿããã€ã³ã·ãã³ãã®åœ±é¿ã®å¯èœæ§ã«ã€ããŠã¢ããªã¹ããæäŸããã€ã³ã·ãã³ããæé€ããããã®ç¹å®ã®æ段ãæšå¥šããåŸåãåæãããããã¯ãŒã¯å®¹éãèšç»ããããã®æšå¥šãè¡ããŸãã ããã¯ãç£èŠãè¿ éãªãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®ããã®éåžžã«éèŠãªæ©èœã§ãã æçµçã«ã¯ãå·¥å Žã§å®è¡ãããããžãã¹ããã»ã¹ã®é«å¯çšæ§ã確ä¿ããã®ã«åœ¹ç«ã¡ãŸãã
DNA Centerã¯ã Cisco Identity Service Engine ïŒISEïŒã¢ã¯ã»ã¹å¶åŸ¡ãµãŒããŒãšé£æºããŠåäœããŸãã ISEã¯ãå·¥å Žã«èªèšŒãæ¿èªãã¢ã¯ã»ã¹å¶åŸ¡ïŒAAAïŒãµãŒãã¹ãæäŸããå·¥å ŽãŠãŒã¶ãŒãã°ã«ãŒãã«åçã«é 眮ããã°ã«ãŒãéã®çžäºäœçšã®ããªã·ãŒã管çããæ段ãæäŸããŸãã ISEã¯ãå·¥å Žã§çµç¹ã®ã»ãã¥ãªãã£ããªã·ãŒãå®è£ ããããã«å¿ èŠã§ãã
ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®èŠ³ç¹ããèŠããšãå·¥å Žã¯æ¬¡ã®äž»èŠãªåœ¹å²ãå®è¡ããããã€ã¹ã§æ§æãããŠããŸãã
ã³ã³ãããŒã«ãã¬ãŒã³ããŒãã¯ãå·¥å Žå ã®ã¯ã©ã€ã¢ã³ãããã€ã¹ã®çŸåšã®å Žæã远跡ããŸãã ããã¯ããŠãŒã¶ãŒã«å²ãåœãŠãããããªã·ãŒãç¶æããã¢ããªãã£ã確ä¿ããªãããå·¥å Žå ã§ãŠãŒã¶ãŒãèªç±ã«ç§»åãããããã«å¿ èŠã§ãã
å·¥å Žãå€ã®äžçã«æ¥ç¶ããã«ã¯ã ãã¡ããªãã¯ããŒããŒããŒããå¿ èŠã§ãã å·¥å Žã®äžéšã§ã¯ãªããããã¯ãŒã¯ãžã ããšãã°ãSD-Accessãã¡ã¯ããªãã€ã³ã¿ãŒããããªã©ã«åºã¥ããŠæ§ç¯ãããŠããªãããŒã¿ã»ã³ã¿ãŒãããã¯ãŒã¯ãäŒæ¥ãããã¯ãŒã¯ã®ä»ã®éšåã䜿çšã§ããŸãã
ãã¡ããªãã¯ãšããžããŒãã¯ãã¯ã©ã€ã¢ã³ãããã€ã¹ãšå·¥å Žãžã®ç¡ç·ã¢ã¯ã»ã¹ãã€ã³ãã®æ¥ç¶ãæäŸããŸãã
ãã¡ããªãã¯ã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã¯ãå·¥å Žã§æ§ç¯ãããã¯ã€ã€ã¬ã¹LANã³ã³ãããŒã©ãŒã§ãã
äžéããŒãã¯ãäžèšã®ããã€ã¹éã®æ¥ç¶ãæäŸããŸãã ãããã¯ãªãŒããŒã¬ã€æ©èœãå®è¡ãããåºç€ãšãªãåºç€ã®ãããã¯ãŒã¯ããããžã®ã¿ãå®è£ ããŸãã
ãã¯ãããžãŒã®èŠ³ç¹ããèŠããšãCisco SD-Accessãã¡ã¯ããªã®ããŒã¿ãã¬ãŒã³ã¯ãä»®æ³æ¡åŒµLANïŒVXLANïŒã«ãã»ã«åã«åºã¥ããŠããŸãã ã³ã³ãããŒã«ãã¬ãŒã³ãªãŒããŒã¬ã€ã¯ãLocator / ID Separation ProtocolïŒLISPïŒã䜿çšããŸãã ããªã·ãŒã¯ãCisco TrustSecãã¯ãããžãŒã®ã¹ã±ãŒã©ãã«ã°ã«ãŒãã¿ã°ïŒSGTïŒã«åºã¥ããŠå®è£ ãããŸãã æåŸã«ããªãŒããŒã¬ã€ã¯ã«ãŒãã£ã³ã°ãããããã¯ããŒã³ã®äžã§å®è¡ãããŸãã ãããã®ãã¯ãããžãŒããã詳现ã«æ€èšããŠãã ããã
3.1ã ããŒã¿ãã¬ãŒã³ãªãŒããŒã¬ã€ïŒVXLAN
Cisco SD-Accessãã¡ã¯ããªã®ããŒã¿ãã¬ãŒã³ã¯ã ã°ã«ãŒãããªã·ãŒãªãã·ã§ã³ ïŒVXLAN-GPOïŒã䜿çšããVXLANã«ãã»ã«åã«åºã¥ããŠããŸãã VXLANã®éèŠãªå©ç¹ã¯ãå ã®ã€ãŒãµããããã¬ãŒã ããããŒãä¿æããããšã§ãã ãã®çµæãå·¥å Žãã¹ãã®ã¢ããªãã£ã¯ã¬ãã«3ã ãã§ãªããã¬ãã«2ã§ãä¿èšŒãããŸããããã«ãããæè»ã§æ±çšæ§ã®é«ããã©ã³ã¹ããŒããæäŸãããŸãã ã¢ããªã±ãŒã·ã§ã³ã®èŠä»¶ãäœã§ãããå·¥å Žã¯ããã¹ããšå·¥å Žå ã®ãã¹ãéã®çžäºäœçšã®æ¹åã«é¢ä¿ãªããããããçš®é¡ã®ãã©ã³ã¹ããŒãïŒã¬ãã«3ããã³2ïŒãæäŸã§ããŸãã
å³ 3.ãããã¯ãŒã¯ãã¡ã¯ããªSD-Accessã§ã®ã«ãã»ã«å
å·¥å ŽããŒã¿ãã¬ãŒã³ãã©ãã£ãã¯ïŒã¬ã€ã€ãŒ2ãã¬ãŒã ïŒã¯VXLANãã±ããã«ã«ãã»ã«åãããUDPããã³IPãä»ããŠãããã¯ãŒã¯çµç±ã§éä¿¡ãããŸãïŒå³3ãåç §ïŒã å·¥å Žã®äžéããã€ã¹ã®èŠ³ç¹ããããããã¯ããŒã4789ã«ã¢ãã¬ã¹æå®ããããã¹ããããUDPã»ã°ã¡ã³ããæã€æšæºIPãã±ããã§ããUDPãœãŒã¹ããŒãçªå·ã¯ããœãŒã¹ãã±ããã®ã¬ã€ã€ãŒ2ã3ãããã³4ã®ããããŒã®ããã·ã¥ã«ãã£ãŠæ±ºå®ããããããåçã«å€æŽãããŸã ããã¯ãã³ã¢ãããã¯ãŒã¯ã®ã·ã¹ã³ãšã¯ã¹ãã¬ã¹ãã©ã¯ãŒãã£ã³ã°ïŒCEFïŒãã¯ãããžãŒã䜿çšããé©åãªããŒããã©ã³ã·ã³ã°ã«ãšã£ãŠéèŠã§ãã è² è·åæ£ã§ã¯ãå®å šãªCEFæ¹åŒã¯IPã¢ãã¬ã¹ãšãã©ã³ã¹ããŒãå±€ããŒãã®ããã·ã¥å€ã䜿çšããŠç¹å®ã®éä¿¡ãã£ãã«ãéžæããŸãã ãããã£ãŠãUDPéä¿¡å ããŒãã®å€æ°å€ã¯ã CEFå極ãšæŠãããã®è¿œå ã®æ¹æ³ã䜿çšããªããŠããç°ãªãéä¿¡ãã£ãã«éã®ããŒããã©ã³ã·ã³ã°ã«ã€ãªãããŸãã
VXLANãã³ãã«ã«ã¯ãäºåã®æ¥ç¶ãã€ãŸã ã¹ããŒãã¬ã¹ãã³ãã«ã§ãã
ãªãŒããŒã¬ã€ã¯ããã©ã³ã¹ããŒãã«åºç€ãšãªããããã¯ãŒã¯ïŒã¢ã³ããŒã¬ã€ïŒã䜿çšãããããè¿œå ã®ããããŒã衚瀺ãããŸãã ããã¯ã8ãã€ãã®VXLANããããŒã8ãã€ãã®UDPããããŒã20ãã€ãã®IPããããŒãããã³14ãã€ãã®MACããããŒïŒãªãã·ã§ã³ã§è¿œå ã®4ãã€ãïŒã§ãåèš50ã54ãã€ãã§ãã
Cisco SD-Accessãœãªã¥ãŒã·ã§ã³ã§ã®VXLANãã±ããã®ãã©ãã£ãã¯ã®ã«ãã»ã«åã¯ãå·¥å Žã®ãšããžããã€ã¹ã«ãã£ãŠå®è¡ãããŸãã å€éšãããã¯ãŒã¯ãã©ãã£ãã¯ã®å Žåãããã¯æç·ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ã®ãã¡ããªãã¯ããŒããŒããŒã-ãã¡ããªãã¯ãšããžããŒãã§ãã
SD-Accessã䜿çšãããšãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãå·¥å Žã«çµ±åããããšãã§ããŸãïŒå³4ïŒã ãã®åäœã¢ãŒãã¯ãFabric Enabled WirelessïŒFEWïŒãšåŒã°ããŸãã éäžåWLANã¢ãŒããã¯ãã£ãšã¯ç°ãªããFEWã¢ãŒãã§ã¯ãWLANãŠãŒã¶ãŒãã©ãã£ãã¯ã¯CAPWAPãã±ããã§ã¯WLANã³ã³ãããŒã©ãŒã«ãã³ããªã³ã°ãããŸããããVXLANãã±ããã§ã¯ãšããžããŒãã¢ã¯ã»ã¹ã¹ã€ããã«ãã³ããªã³ã°ãããŸãã ãã®ããã«ããŠãæç·ãšç¡ç·ã®äž¡æ¹ã®ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ããšããžããŒãã¹ã€ããã«çŽæ¥æµããŸãã
å³ 4. Cisco SD-Accessãã¡ã¯ããªãžã®ç¡ç·LANçµ±åïŒB-å¢çããŒããC-ã³ã³ãããŒã«ãã¬ãŒã³ããŒãïŒ
ãã®çµæãæç·ããã³ç¡ç·ãŠãŒã¶ãŒã®ãã©ãã£ãã¯ã®åãåŠçãWLANãã©ãã£ãã¯äŒéãã¹ã®æé©åãWLANã³ã³ãããŒã©ãŒãšæç·ãããã¯ãŒã¯ã®çµåã«ç¹æã®æœåšçãªããã«ããã¯ã®æé€ãæäŸãããŸãã
FEWã¢ãŒãã®ã¯ã€ã€ã¬ã¹LANã®ã³ã³ãããŒã«ãã¬ãŒã³ãšç®¡çãã¬ãŒã³ã¯ããã¡ããªãã¯ã¯ã€ã€ã¬ã¹ã³ã³ãããŒã©ãŒã§éäžç®¡çãããŸãã ã³ã³ãããŒã©ã¯LISPã䜿çšããŠãå·¥å Žå ã®ã¯ã€ã€ã¬ã¹ã¯ã©ã€ã¢ã³ãã®çŸåšã®å Žæã«ã€ããŠã³ã³ãããŒã«ãã¬ãŒã³ããŒããšéä¿¡ããŸãã ç¡ç·ã¢ã¯ã»ã¹ãã€ã³ãã¯ãCAPWAPãããã³ã«ã䜿çšããŠã³ã³ãããŒã©ãŒãšéä¿¡ããŸãã
ãããã£ãŠãç¡ç·ãããã¯ãŒã¯ã¢ãŒããã¯ãã£ã¯ãå·¥å Žã«çµ±åããããšãã2ã€ã®äžçã®ãã¹ãããç²åŸããŸãã
3.2ã ã³ã³ãããŒã«ãã¬ãŒã³ãªãŒããŒã¬ã€ïŒLISP
ã¬ãã«2ããã³ã¬ãã«3ã®ãã¹ãã¢ããªãã£ã¯ããã¡ã¯ããªã®äžå¯æ¬ ãªéšåã§ãã ããŒã¿ãã¬ãŒã³ã®èŠ³ç¹ã§ã¯ãVXLANãã¯ãããžãŒã«ãã£ãŠã¢ããªãã£ãæäŸããã Locator / ID Separation Protocol ïŒLISPïŒãã³ã³ãããŒã«ãã¬ãŒã³ãšããŠäœ¿çšãããŸãã
ã¢ãã¬ã¹ãå€æŽããã«ãã¹ãããã¡ã¯ããªå ã§ç§»åã§ããããã«ããã«ã¯ããã¡ã¯ããªãåãã¹ãã®å Žæã远跡ããå¿ èŠããããŸãã åŸæ¥ã®ã«ãŒãã£ã³ã°ãããã³ã«ã䜿çšããŠãã®åé¡ã解決ããã«ã¯ã/ 32ãŸãã¯/ 128ãã¬ãã£ãã¯ã¹ãæã€ãã¹ãåºæã®ã«ãŒãã䜿çšããå¿ èŠããããŸãïŒããããIPv4ããã³IPv6çšïŒã å®çŸ©äžããã¹ãåºæã®ã«ãŒãã䜿çšããããã®èŠä»¶ã§ã¯ãã«ãŒãã®éçŽãé€å€ãããŸããããã«ããããã¡ã¯ããªã¹ã€ããã®ã¡ã¢ãªæ¶è²»ãå¢å ããŸãã ããã«ãå·¥å Žã®ã¹ã€ããéã§ãã¹ãã移åãããã³ã«ã«ãŒãã£ã³ã°ãããã³ã«ãæŽæ°ããããã®ã¹ã€ããã§ãã®ã«ãŒããå¿ èŠãã©ããã«é¢ä¿ãªãããã¹ãŠã®ã¹ã€ããã®CPUã«è¿œå ã®è² è·ãããããŸãã
ãã®çµæããã¹ãã¢ããªãã£ã®å®è£ ã«ãããã³ã³ãããŒã«ãã¬ãŒã³ãªãœãŒã¹ã«å¯ŸããèŠæ±ãé«ããªããŸãã ãŸãããããã®èŠä»¶ã¯å·¥å Žã®ãšããžã¹ã€ããã«é©çšãããŸããã¢ã¯ã»ã¹ã¹ã€ããã¯ãéåžžã匷åãªã³ã³ãããŒã«ãã¬ãŒã³ãåããŠããŸããã
ãã®åé¡ã解決ããããã«ãCisco SD-Accessã¯LISPã䜿çšããŸãã ãã¹ãã¢ããªãã£ã«æé©åãããéåžžã«å¹ççãªãããã³ã«ã§ãã ãã¡ã¯ããªã«ã¯ãã³ã³ãããŒã«ãã¬ãŒã³ããŒãã®åœ¹å²ãæã€ããã€ã¹äžã§å®è¡ãããéäžåãã¹ããã©ããã³ã°ããŒã¿ããŒã¹ïŒHTDBïŒãŠãŒã¶ãŒããŒã¿ããŒã¹ãå«ãŸããŠããŸãã HTDBã¯ãã¯ã©ã€ã¢ã³ããã¹ãïŒãšã³ããã€ã³ãIDïŒã®ãã¡ã¯ããªå ã®çŸåšã®å Žæãžã®å¯Ÿå¿ã«é¢ããæ å ±ãšãããã€ãã®è¿œå å±æ§ãæ ŒçŽããŸãã
å·¥å Žåºè·æã®ãšããžããã€ã¹ã¯ãLISPãããã³ã«ã䜿çšããŠãäžæãªå Žæã®ã¯ã©ã€ã¢ã³ããã¹ãã«ãã±ããã転éããå¿ èŠãããå Žåã«HTDBããŒã¹ãç §äŒãããã®æ å ±ãããŒã«ã«ãã£ãã·ã¥ã«ä¿åããŸãã
ã¯ã©ã€ã¢ã³ããã¹ããæ¥ç¶ããŠç§»åãããšãå·¥å Žã®å¢çããã€ã¹ããããŒã¿ããŒã¹ã«æ å ±ãå±ããŸãã
ãããã£ãŠãCisco SD-Accessã䜿çšãããšããã¹ãã¯ã¢ãã¬ã¹ãå€æŽããã«å·¥å Žå ãèªç±ã«ç§»åã§ããã¢ããªãã£ãæäŸãããŸãã
3.3ã ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãšã»ã°ã¡ã³ããŒã·ã§ã³ïŒTrustSec
ãã®å·¥å Žã¯ããªãœãŒã¹ã»ã°ã¡ã³ããŒã·ã§ã³ããã³ãŠãŒã¶ãŒã»ã°ã¡ã³ããŒã·ã§ã³ãšãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãå®è£ ããããã®æè»ã§ã¹ã±ãŒã©ãã«ãªããŒã«ãæäŸããŸãã
ãããŸã§ãIPã¢ãã¬ã¹ã«åºã¥ãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒã¯ãã¢ã¯ã»ã¹å¶åŸ¡ã®åé¡ã解決ããããã«äœ¿çšãããŠããŸããã ããã¯ãIPãã±ããããããŒã«ãIPãã±ãããšãŠãŒã¶ãŒéã®è«çæ¥ç¶ã確ç«ããããã«äœ¿çšã§ããä»ã®ããŒã¿ãå«ãŸããŠããªãããã«çºçããŸããã
ãã®ãããªãœãªã¥ãŒã·ã§ã³ã§ã¯ããããã¯ãŒã¯å ã®å€ãã®å Žæã§ACLã倧èŠæš¡ã«å®è£ ããããããææ°ã®ç¶æ ã«ä¿ã¡ãå€æŽãå ããå¿ èŠããããŸãã ãŸãããã®ãããªå€æŽã«ã¯å€ãã®çç±ãèããããŸããããšãã°ãã»ãã¥ãªãã£ããªã·ãŒã®æ°ããèŠä»¶ããŠãŒã¶ãŒã®æ§æã®å€æŽããªãœãŒã¹ããããã¯ãŒã¯ããããžãæç·ããã³ç¡ç·ãããã¯ãŒã¯ã®ãŠãŒã¶ãŒã¢ããªãã£ã§ãã ãããã£ãŠããã®ã¢ãããŒãã«ã¯æéãšã¹ã¿ããã®å€å€§ãªæè³ãå¿ èŠã§ãã ããã«ããšã©ãŒã«å¯ŸããŠéåžžã«è匱ã§ãã ãã®çµæããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ãšã¹ã±ãŒã©ããªãã£ãããžãã¹ããŒãºã«å¯ŸããITã®å¿çé床ãããã³ããžãã¹ããã»ã¹ã®å¯çšæ§ã«åœ±é¿ããããŸãã
ãŠãŒã¶ãŒã»ã°ã¡ã³ããŒã·ã§ã³ã¯ãVLANãVRFãMPLS VPNããã³ãã«ãããã³ãã®ä»ã®åæ§ã®ããŒã«ããçµã¿ç«ãŠãããä»®æ³ããããžã䜿çšããŠé·ãéå®è£ ãããŠããŸããã ãŸãããã®ã¢ãããŒãã¯éåžžã«ãªãœãŒã¹éçŽåã§ãããã»ã°ã¡ã³ããŒã·ã§ã³ç°å¢ã®ãã€ããã¯ã¹ãããå€ããªãããã®ã»ã°ã¡ã³ããŒã·ã§ã³ã现ãããªãã°ãªãã»ã©æªåããŸãã
ãããã£ãŠãä»®æ³ããããžã¯ç¹ã«ãŠãŒã¶ãŒã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã«ã¯ããŸãé©ããŠããªããããçŸä»£ã®ããžãã¹ã®ããžã¿ã«åãã»ãã¥ãªãã£ã®è åšïŒãããã¯ãŒã¯æå·åã¯ãŒã ã®å€§èŠæš¡ãªæ¡æ£ãå«ãïŒã®é²åã«é¢é£ããŠããŸããŸãé »ç¹ã«å¿ èŠãšãããŠããŸãã
ã¢ã¯ã»ã¹å¶åŸ¡ãšãŠãŒã¶ãŒã»ã°ã¡ã³ããŒã·ã§ã³ã®èª²é¡ã«å¯ŸåŠããããã«ãã·ã¹ã³ã¯TrustSecãã¯ãããžãŒãéçºããŸããã TrustSecã¯ãã°ã«ãŒãããŠãŒã¶ãŒã°ã«ãŒãã«å±ããããã®åºæºãšããŠãIPã¢ãã¬ã¹ã®ä»£ããã«ã¹ã±ãŒã©ãã«ã°ã«ãŒãã¿ã°ïŒSGTïŒã䜿çšããŸãã ãã®ã¢ãããŒãã«ãããã¢ãã¬ã¹æå®ãã¢ã¯ã»ã¹å¶åŸ¡ããåé¢ããSGACLå°çšã®ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãã䜿çšããŠã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãå®è£ ãããããã¯ãŒã¯ã«æè»æ§ãšã»ãã¥ãªãã£ããªã·ãŒã®èªååãæäŸã§ããŸãã
TrustSecãã¡ã€ã³å ã§ã©ãã«ã転éããåºæ¬çãªæ¹æ³ïŒã€ã³ã©ã€ã³æ¹æ³ïŒã¯ããã¬ãŒã ã®ããããŒãŸãã¯ãã©ãã£ãã¯ãã±ããïŒCisco Meta Dataãã£ãŒã«ãå ïŒã«ã©ãã«ãã«ãã»ã«åããããšã§ãã ãŸããCisco SD-Accessãã¡ã¯ããªã§ã¯ãã©ãã«å€ã¯VXLANãªãŒããŒã¬ã€ããããŒã®äžéšãšããŠæž¡ãããŸãã VXLANããããŒã«ã¯ãVN IDããã³ã»ã°ã¡ã³ãIDãã£ãŒã«ãïŒãããã24ãããããã³16ãããïŒãå«ãŸããŠããŸããå³ãåç §ããŠãã ããã 3.ãããã®ãã£ãŒã«ãã¯ãç¹å®ã®ä»®æ³ãããã¯ãŒã¯VNïŒ1600äžãè¶ ããVRFã«å¯Ÿå¿ïŒããã³TrustSecãã¯ãããžã®SGTã°ã«ãŒãïŒ64,000ãè¶ ããã¿ã°ã«å¯Ÿå¿ïŒã«å±ãããã±ããã«é¢ããæ å ±ã転éããããã«äœ¿çšãããŸãã ãããã£ãŠãTrustSecã¯æåã¯å·¥å Žã®äžå¯æ¬ ãªæ©èœã§ãã ããã«ãVXLANããããŒã«SGTã©ãã«ãã«ãã»ã«åãããšãTrustSecã®å®è£ ã容æã«ãªããŸããçµå±ãã³ã¢ãããã¯ãŒã¯ã®äžéããã€ã¹ã¯ã©ãã«ã䜿çšããå¿ èŠããããŸããã
Cisco SD-Accessãã¡ã¯ããªã䜿çšãããšã2ã¬ãã«ã®ãŠãŒã¶ãŒã»ã°ã¡ã³ããŒã·ã§ã³ãå®è£ ã§ããŸãïŒé«ã¬ãã«ã®å€§ãŸããªã»ã°ã¡ã³ããŒã·ã§ã³çšã®VRFïŒããšãã°ãçµç¹ãŸãã¯éšéã®åé¢çšïŒãšãã·ã³ã»ã°ã¡ã³ããŒã·ã§ã³çšã®SGTã°ã«ãŒãïŒããšãã°ãçµç¹ããå°ããªã¯ãŒã¯ã°ã«ãŒããŸã§ã®ã¬ãã«ïŒã SD-Accessãã¡ã¯ããªã®æåã®ãªãªãŒã¹ã§ã¯ãSGTã¯VNå ã§äžæã§ãããååãšããŠãç°ãªãVNã«ååšããããããVN-Agnosticã°ã«ãŒããå¯èœã§ãã SGTã¯IPã¢ãã¬ã¹ããã³VRFããç¬ç«ããŠããŸãã
SGTãšããçšèªèªäœã¯å¥ã®èª¬æã«å€ããŸãã 圌ã¯TrustSecãã¯ãããžãŒã®éçºéçšã«ç»å Žããå ã ã¯ãœãŒã¹ã°ã«ãŒãã¿ã°ãšåŒã°ããŠããŸããã ããŒã±ãã£ã³ã°æ åœè ã®åªåã«ããããã®çšèªã¯ã»ãã¥ãªãã£ã°ã«ãŒãã¿ã°ãæå³ããããã«ãªããŸããã TrustSecã®å ŽåãSGTãã»ãã¥ãªãã£ããªã·ãŒã®å®è£ ã«äœ¿çšããããããããã¯æ£åœåãããŸããã ããã§ããSGTã¯åãªãã©ãã«ã§ããããã±ãããåºå¥ããããã®æ°åã§ãã ãŸãããã®çªå·ã¯ãCisco SD-Accessã§è¡ãããã»ãã¥ãªãã£ã ãã§ãªããããããããªã·ãŒã®å®è£ ã«é©ããŠããŸãã ãã®çµæãSGTã¯çŸåšãScalable Group Tagã®ç¥ã§ãã
ã¢ã¯ã»ã¹ããªã·ãŒã®ã¢ã¯ã»ã¹å¶åŸ¡ãèšå®ãããã³å®è£ ã¯ãCisco SD-Accessãœãªã¥ãŒã·ã§ã³ã«çµ±åãããCisco ISEãµãŒãã§å®è¡ãããŸãã ãã®çµæãSD-Accessã¯ãçµç¹ã®ã¢ã¯ã»ã¹å¶åŸ¡ããªã·ãŒãããã³ãŠãŒã¶ãŒã»ã°ã¡ã³ããŒã·ã§ã³ãšãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãå®è£ ããããã®æ¢è£œã®èªååããŒã«ãæäŸããŸãã
3.4ã ã³ã¢ãããã¯ãŒã¯
å·¥å ŽããèŠãã³ã¢ãããã¯ãŒã¯ã®äž»ãªã¿ã¹ã¯ã¯ããªãŒããŒã¬ã€ãã©ãã£ãã¯ã®è»¢éãä¿èšŒããããšã§ãã ãªãŒããŒã¬ã€ã®å Žåãåç §ãããã¯ãŒã¯ã¯ééçã§ãã ãããã£ãŠãé©åãªã¬ãã«ã®å¯çšæ§ãšããã©ãŒãã³ã¹ãæäŸããææ°ã®äŒæ¥ãããã¯ãŒã¯ãããã¯ããŒã³ãããã¯ãŒã¯ãšããŠäœ¿çšã§ããŸãã ãã¡ããªãã¯ãšããžããŒããããŒããŒããŒããã³ã³ãããŒã«ãã¬ãŒã³ããŒããIPéä¿¡ãªã©ã®å·¥å Žãšããžããã€ã¹ãæäŸããå¿ èŠããããŸãã
äžè¬ã«ãã³ã¢ãããã¯ãŒã¯ã¯ã¬ã€ã€ãŒ2ããã³3ãã¯ãããžãŒã®ä»»æã®çµã¿åããã«åºã¥ããŠæ§ç¯ã§ããŸãããã·ã¹ã³ã§ã¯ããã€ã³ãããŒãã€ã³ãæ§æã®å®å šã«ã«ãŒãã£ã³ã°å¯èœãªãããã¯ãŒã¯ïŒã¢ã¯ã»ã¹ã¹ã€ããã«ã«ãŒãã£ã³ã°ãããïŒããã³éä¿¡ãã£ãã«ãæ§ç¯ããããšããå§ãããŸãã ã«ãŒãã£ã³ã°ãããã³ã«ãä»»æã§ããæšå¥šãªãã·ã§ã³ã¯IS-ISã§ããããã¯ãã¬ãã«3ã¢ãã¬ã¹ããã®ç¬ç«æ§ãé«éã³ã³ããŒãžã§ã³ã¹ãããã³TLVãã©ã¡ãŒã¿ãŒã®ååšã«ãããå·¥å Žã®ã³ã¢ãããã¯ãŒã¯ã®äºå®äžã®æšæºãšãªã£ãŠããŸãã
ãªãŒããŒã¬ã€ã®VXLANã«ãã»ã«åã«ãããå°ãªããšã9,100ãã€ãã®MTUå€ãæã€ãžã£ã³ããã¬ãŒã ãã³ã¢ãããã¯ãŒã¯ã§éä¿¡ããããšããå§ãããŸãã å·¥å Žå ã®ãã±ãã転éé 延ïŒRTTïŒã¯100ããªç§ãè¶ ããŠã¯ãªããŸããã
ã³ã¢èŠä»¶ã®è©³çŽ°ã«ã€ããŠã¯ã ã Cisco SD-Access Design Guideããåç §ããŠãã ããã
ããã¯ããŒã³ãããã¯ãŒã¯ã®æ©åšãšããŠããããã®èŠä»¶ãæºããæ©åšã¯ãã·ã¹ã³ãšä»ã®ã¡ãŒã«ãŒã®äž¡æ¹ãé©ããŠããŸãã æ¢åã®äŒæ¥ãããã¯ãŒã¯ã䜿çšã§ããŸãã ããã«ãããå·¥å Žã§ãµããŒããããŠããªãå Žåã§ããæ¢åã®ãããã¯ãŒã¯ã®æ©åšãžã®æè³ãä¿è·ãããŸãã ãã®å Žåãã³ã¢ãããã¯ãŒã¯ã¯æåã¢ã³ããŒã¬ã€ã«ãªããŸãã å·¥å ŽããèªåŸçã«ç®¡çãããŸãã
é©åãªã·ã¹ã³æ©åšã䜿çšããå Žåããã¡ã¯ããªããŒã«ã䜿çšããŠããã¯ããŒã³ãããã¯ãŒã¯ã®å¶åŸ¡ãèªååããããšãã§ããŸãïŒCisco SD-Access 1.0ã¯ãCatalyst 3850/3650ããã³9000ã·ãªãŒãºã¹ã€ããã«åºã¥ããŠæ§ç¯ãããããã¯ããŒã³ãããã¯ãŒã¯ã®èªååãæäŸããŸãïŒã ããã¯èªåã¢ã³ããŒã¬ã€ã¹ã¯ãªããã§ãã ãã®å Žåãã³ã¢ãããã¯ãŒã¯ããããžã§ãã³ã°ã¯DNA Centeræ©èœã«ãã£ãŠå®è¡ãããŸãã ã³ã³ãããŒã©ã¯ãCisco Validated Designã®æšå¥šäºé ã«åºã¥ããŠäºåãã¹ãæžã¿ã®æ§æãã³ã¢ãããã¯ãŒã¯ããã€ã¹ã«ããŠã³ããŒãããŸãã å·çæç¹ã§ã®èªåã¢ã³ããŒã¬ã€ã¢ãŒãã§ã®ããã€ã¹æ§æã®æåç·šéã¯èš±å¯ãããŠããŸãããããã®æ©èœã¯å°æ¥çã«äœ¿çšãããäºå®ã§ãã
æè³ã®ä¿è·ã«å ããŠãããã¯ããŒã³ãããã¯ãŒã¯ã®SD-AccessèŠä»¶ã®æè»æ§ã«ããå®è£ ã容æã«ãªããŸãããã€ããããããžã§ã¯ãããå§ããæ¢åã®ããã¯ããŒã³ãããã¯ãŒã¯ããã©ã³ã¹ããŒããšããŠäœ¿çšããŠå°ããªå·¥å ŽãäœæããåŸã ã«æ¬æ Œçãªãœãªã¥ãŒã·ã§ã³ã«ç§»è¡ã§ããŸãã
4.ãªãCisco SD-Accessããžãã¹ïŒå žåçãªã·ããªãª
Cisco SD-Accessãœãªã¥ãŒã·ã§ã³ã®äž»èŠãªã³ã³ããŒãã³ããšååãæ€èšããŸããã 次ã«ãç¹å®ã®ã·ããªãªã䜿çšããŠãITããã³ããžãã¹åããœãªã¥ãŒã·ã§ã³ã®å®éçãªäŸ¡å€ãåæããŸãã
ITã«å žåçãªããã€ãã®ã¿ã¹ã¯ãæ€èšãã2ã€ã®æ¡ä»¶ä»ããããã¯ãŒã¯ãæ¯èŒããŸãããã¯ã©ã·ãã¯ããšSD-Accessãã¡ã¯ããªãŒã«åºã¥ããããã¯ãŒã¯ïŒä»¥äžãSD-Accessãããã¯ãŒã¯ãšåŒã³ãŸãïŒã
ãã®æ¯èŒã®å€å žçãªãããã¯ãŒã¯ãšã¯ãã¢ã¯ã»ã¹ã¬ãã«ãã¹ã€ãããããã³ã¢ãã«ãŒãã£ã³ã°ããããã£ã³ãã¹ãããã¯ãŒã¯ãæå³ããŸãã ãã®ãããªãããã¯ãŒã¯ã®ã¢ã¯ã»ã¹å¶åŸ¡ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒã䜿çšããŠå®è£ ãããã»ãšãã©ã®æ§æããã©ãã«ã·ã¥ãŒãã£ã³ã°ãããã³ãã©ãã«ã·ã¥ãŒãã£ã³ã°æäœã¯æåã§å®è¡ããããšæ³å®ããŠããŸãã ãããã¯ãŒã¯ã¯RADIUSãµãŒããŒã䜿çšããŠãŠãŒã¶ãŒã¢ã¯ã»ã¹ãå¶åŸ¡ããŸãã
SD-Accessãããã¯ãŒã¯ãšã¯ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãDNA Centerã³ã³ãããŒã©ãŒãããã³Cisco ISEã¢ã¯ã»ã¹ã³ã³ãããŒã«ãµãŒããŒãå«ãCisco SD-Accessãã¡ã¯ããªãŒã«åºã¥ããŠæ§ç¯ããããããã¯ãŒã¯ãæå³ããŸãã
4.1ã ãããã¯ãŒã¯ãè¿ éã«éçšããæ¹æ³
ITã®å žåçãªã¿ã¹ã¯ã®1ã€ã¯ãæ¢åã®ãããã¯ãŒã¯ã®è¿ä»£åã ãã§ãªãããããã¯ãŒã¯ã®æ°ããéšåãŸãã¯æ°ãããµã€ãã§ã®ãããã¯ãŒã¯ã®ã³ããã·ã§ãã³ã°ã«é¢é£ããŠããŸãã
å€å žçãªãããã¯ãŒã¯ã®å Žåã®ãã®åé¡ã®è§£æ±ºçã¯ãå€ãã®å Žåãæäœæ¥ãšç°çš®èªååããŒã«ã®è€éãªçµã¿åããã«ãã£ãŠå®çŸãããŸãã
ãã®ãããªã¢ãããŒãã§ã¯ãå®è£ äžãç¹ã«å€æŽãé¿ããããªãéçšäžã«äžè²«ããæ©åšæ§æã確ä¿ããããšã¯å°é£ã§ãã ãã®ããã»ã¹ã¯ãã人çèŠå ãã«ãããšã©ãŒããååã«ä¿è·ãããŠããŸããã ãããŠæåŸã«ãèšèšããã³æ§æã®éçºãæ©åšã®æ³šæãšç©ççãªé éãæ§æã®ã¹ããŒãžã³ã°ãšå®è£ ãå«ãå®è£ äœæ¥äžã«ãããžãã¹ã®å€æŽã«æè»ã«é©å¿ããããšã¯ã§ããŸãã-ããžãã¹ã®ããŒãºã®å€æŽãçºçããå®è£ ãããæ§æãå€ããªãå¯èœæ§ããããŸããããã¯ãŒã¯ãéçšããåã«ïŒ
è±å¯ãªéäžç®¡çããŒã«ãšè¿œå ã®ããŒã«ããã®åé¡ã解決ããã¯ãã§ãã ããããäŒæ¥ãããã¯ãŒã¯äžã§å€æŽã®çŽ90ïŒ ããŸã æåã§è¡ãããŠããã·ã¹ã³ã®èª¿æ»ããã®ããŒã¿ã¯ãå察ã瀺åããŠããŸãã
SD-Accessãããã¯ãŒã¯ã¯ãããã»ã¹ãæé©åããã³èªååããããã®ããŒã«ãæäŸããŸãã Cisco DNA Centerã䜿çšãããšãå°ççãªå Žæã«ãªã³ã¯ãããçµç¹ãµã€ãã®éå±€æ§é ãäžå çã«å®çŸ©ã§ããŸãã éå±€ãªããžã§ã¯ãã®å Žåãããšãã°AAAãNTPãDNSãµãŒããŒãNetFlowãSyslogããã³SNMPããŒã¿ã³ã¬ã¯ã¿ãŒã®ã¢ãã¬ã¹ããã¹ã¯ãŒããªã©ã®ãã©ã¡ãŒã¿ãŒå€ãéäžçã«æå®ã§ããŸãã ãããã®ãã©ã¡ãŒã¿ãŒã¯ãä»ã®ãµã€ãã®ãããã¯ãŒã¯ã«ãã£ãŠéå±€ã§ç¶æ¿ã§ããåå¥ã«èšå®ã§ããŸãã ããã«ãDNA Centerã䜿çšãããšããããã¯ãŒã¯ã§ããã«æ¿èªããã³å®è£ ããããã®æ§æãã³ãã¬ãŒããäœæã§ããŸãã ããã«ãDNAãããã¯ãŒã¯ã¯ãæ°ããããã€ã¹ãéå±€ãµã€ãã«ãã€ã³ããããããã¯ãŒã¯ããã€ã¹å šäœã«æ§æãäžå çã«é åžããæ©èœã«ãããæ°ããããã€ã¹ãå·¥å Žã«èªåçã«æ¥ç¶ãããã©ã°ã¢ã³ããã¬ã€ïŒPnPïŒããŒã«ãæäŸããŸãã
ãã®çµæãSD-Accessãããã¯ãŒã¯ã¯ä»¥äžãæäŸããŸãã
- èªååã«ãããããã¯ãŒã¯å±éãå€§å¹ ã«å éããŸãã
- äžè²«æ§ã®ããé©åãªããã€ã¹æ§æã®èªåã¡ã³ããã³ã¹ã«ãããããã¥ãŒãã³ãã¡ã¯ã¿ãŒãã«é¢é£ãããªã¹ã¯ã軜æžããŸãã
4.2ã ã¯ã©ã€ã¢ã³ãããã€ã¹ãè¿ éãã€å®å šã«æ¥ç¶ããæ¹æ³
ããžã¿ã«åã®åŸåã«ããããããã¯ãŒã¯ã«æ¥ç¶ãããŠããããã€ã¹ã®æ°ãšçš®é¡ãå€§å¹ ã«å¢å ããŠããŸãã ãããã¯ããã¹ã¯ãããã³ã³ãã¥ãŒã¿ãŒãšã©ããããããã¹ããŒããã©ã³ãšã¿ãã¬ãããããªã³ã¿ãŒãCCTVã«ã¡ã©ãã»ã³ãµãŒããã®ä»ã®ã¢ãã®ã€ã³ã¿ãŒãããïŒIoTïŒãªã©ã®ããã€ã¹ã§ãã
ãããã¯ãŒã¯IPã¢ãã¬ã¹èšç»ãå¿ èŠãªãã¹ãŠã®ããã€ã¹ãæ¥ç¶ããæºåãã§ããŠããããšã確èªããã ãã§ãªããé©åãªã»ãã¥ãªãã£ããªã·ãŒãé©çšããå¿ èŠããããŸãã
åŸæ¥ã®ãããã¯ãŒã¯ã§ã¯ããã®åé¡ã解決ããããã«ããªãã®åªåãå¿ èŠã§ãã ãŸããIPã¢ãã¬ã¹ã¯éåžžãã¢ãã¬ã¹æå®ã ãã§ãªããããªã·ãŒã®é©çšåºæºãšããŠã䜿çšããããããã¢ãã¬ã¹æå®èšç»ã¯è€éã§ãããã¢ãã¬ã¹æå®ã®å€æŽã¯éåžžã«å°é£ã«ãªããŸãã 第äºã«ãããªã·ãŒã®å®è£ ã®é£ããã¯ãå€ãã®å Žåãæç·ãããã¯ãŒã¯ã®å éšå¢çãä¿è·ããããã»ãã¥ãªãã£ããªã·ãŒãæ¥ç¶ãããããã€ã¹ã«é©çšãããªãããŸãã¯æè¯ã®å Žåãåºæ¬çãª802.1xæ©èœãé©çšããããšããäºå®ã«ã€ãªãããŸãã
SD-Accessãããã¯ãŒã¯ã«ã¯ãIPã¢ãã¬ã¹ããŒã«ã管çããããã®äžå åãããæ©èœããããŸãã InfobloxãµãŒãã¹ãšã®çµ±åã ããã«ããããããã¯ãŒã¯ã®ã¢ãã¬ã¹æå®ãå€§å¹ ã«ç°¡çŽ åãããŸãã ããã«ããããã¯ãŒã¯ãã¡ã¯ããªèªäœã®ã¢ãŒããã¯ãã£ã¯ãæå³ããç®çã«ã®ã¿ã¢ãã¬ã¹ã䜿çšã§ãããããIPã¢ãã¬ã¹ã®å€§å¹ ãªç°¡çŽ åã«è²¢ç®ããŸãã ããªã·ãŒããã¹ãããã³ãµããããã¢ãã¬ã¹ã«ããã€ã³ããããå¿ èŠã¯ãªããªããŸããã ããã«ãã¢ããªã±ãŒã·ã§ã³ãã¯ã©ã€ã¢ã³ãããã€ã¹ã®èŠä»¶ã«ããããã£ã³ãã¹å šäœã«ãæ¡åŒµããããIPãµãããããå¿ èŠãªå Žåã§ãããªãŒããŒã¬ã€ã«ããããããŒããã£ã¹ãã¹ããŒã ãã¬ãã«2ãã¡ã€ã³ã®ä»ã®ãã©ãã«ã®ãªã¹ã¯ãªãã«ãã«ãŒãã£ã³ã°ãããã³ã¢ãããã¯ãŒã¯ã®èšèšãæãªãããšãªãããã®åé¡ã解決ã§ããŸãããã®çµæãSD-Accessãããã¯ãŒã¯ã¯ããµããããæ°ã®æå°èŠä»¶ãåããããŸããŸãªã¿ã€ãã®ããã€ã¹ã®æ倧æ°ãæ¥ç¶ããæºåãã§ããŠããŸãã
ãããã¯ãŒã¯å¢çä¿è·ã¯ãCisco ISEããã³Active Directoryãšã®çµ±åã«ããå®çŸãããIPã¢ãã¬ã¹ã«ãã€ã³ãããããšãªããã»ãã¥ãªãã£ããªã·ãŒãåçãã€è©³çŽ°ã«é©çšã§ããŸãã
ãããã£ãŠãSD-Accessãããã¯ãŒã¯ã¯ä»¥äžãæäŸããŸãã
- IPã¢ãã¬ã¹ç®¡çã®ç°¡çŽ åãã¢ãã¬ã¹ã®å¹ççãªäœ¿çšãããã³æè»ãªãã©ã³ã¹ããŒãã¬ãã«2ããã³3ã«ãããããŸããŸãªã¿ã€ãã®ããã€ã¹ã®å€§éæ¥ç¶ã®æºåãã§ããŠããŸãã
- IPã¢ãã¬ã¹ç®¡çã«è²»ããããæéãšåŽåã®å€§å¹ ãªæé©åã
- IPã¢ãã¬ã¹ã«çžãããããšãªããåçã§è©³çŽ°ãªã»ãã¥ãªãã£ããªã·ãŒãç°¡åã«é©çšã§ãããããããã€ã¹ãå®å šã«å±éã§ããŸãã
4.3ã æ¢åã®ãµãŒãã¹ãšããªã·ãŒãæ°ããããžãã¹èŠä»¶ã«è¿ éã«é©åãããæ¹æ³ã¯ïŒ
æè¿ã§ã¯ããŠãŒã¶ãŒãã€ã³ã¿ãŒããããé»åã¡ãŒã«ãããã³äŒæ¥ã®ããŒã¿ã»ã³ã¿ãŒã§å®è¡ãããŠããäžé£ã®ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ããããã«ããããã¯ãŒã¯ã«å¿ èŠãªãã®ã¯ã»ãšãã©ãããŸããã§ããã
ãããããããã¯ãŒã¯èŠä»¶ã¯æ¥éã«æé·ããŠããŸããããžã¿ã«åã®åŸåã¯å¢ããå¢ããŠããŸããããããžã§ãã³ã°ãæ§æãç£èŠããã©ãã«ã·ã¥ãŒãã£ã³ã°ãå¿ èŠãªãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£èŠçŽ ã®æ°ã¯å¢ãç¶ããŠããŸãããããã¯ãŒã¯æ¥ç¶ã®æ°ã¯æ¥éã«å¢å ããŠããããŠãŒã¶ãŒïŒã³ã³ãã¥ãŒã¿ãŒãé»è©±ãã¿ãã¬ãããªã©ã®å ŽåïŒãšãã·ã³ïŒèªååã·ã¹ãã ãããžã¿ã«ãµã€ã³ãã»ã³ãµãŒããã®ä»ã®ã¢ãã®ã€ã³ã¿ãŒãããããã€ã¹ïŒ IoTïŒãããã®ãã¹ãŠã®ããã€ã¹ã¯ãå¿ èŠãªã¬ãã«ã®ãµãŒãã¹ãšé©åãªã»ãã¥ãªãã£æš©éãæã€ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããå¿ èŠããããŸãã
ååãšããŠããã€ã³ãAãšBéã®æ¥ç¶ãåã«æäŸããã ãã§ã¯äžååã§ããæ¿æ²»å®¶ãå¿ èŠã§ããããªã·ãŒã¯ããã©ã³ã¹ããŒãïŒãããã¯ãŒã¯ãšãªã¢éã®çžäºäœçšã®å¯èœæ§ãå®çŸ©ãäŒéãã¹ã®èŠä»¶ïŒãã»ãã¥ãªãã£ããªã·ãŒïŒã¢ã¯ã»ã¹å¶åŸ¡ãä¿¡é Œæ§ãæŽåæ§ãéä¿¡ããŒã¿ã®æ©å¯æ§ãå®çŸ©ïŒããµãŒãã¹ããªã·ãŒïŒãããã¯ãŒã¯æ©èœã«ãããã©ãã£ãã¯ãããŒã®åŠçãå®çŸ©ïŒã«åé¡ã§ããŸãã
ããšãã°ãäŒæ¥ãããã¯ãŒã¯äžã®ããŸããŸãªã«ããŽãªã®ãŠãŒã¶ãŒãšããã€ã¹ãå®å šã«æäœããã«ã¯ãéåžžãé©åãªã¢ã¯ã»ã¹å¶åŸ¡ãå¿ èŠã§ããå Žåã«ãã£ãŠã¯ãããããäºãã«åé¢ããããšãäžè¬çã«ã¯æãŸããã§ã-ããšãã°ãã²ã¹ããŠãŒã¶ãŒã®ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ã®å ŽåãIoTããã€ã¹ã®å°å ¥ãªã©ã
ãã®ä»ã®äŸ-ç¡ç·LANã§å®è¡ããããã«ãã¡ãã£ã¢ã¢ããªã±ãŒã·ã§ã³ãåããé»è©±ãŸãã¯ã³ã³ãã¥ãŒã¿ãŒã®å Žåãã¬ãã«2ããã³3ã§ã®ããŒãã³ã°ãå¿ èŠã«ãªãå ŽåããããŸããã¢ããªã±ãŒã·ã§ã³èŠä»¶ãŸãã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã®çµç¹ãèæ ®ãããšãäŒæ¥ãã£ã³ãã¹ã®ç°ãªãéšåã«åãIPãµãããããååšããå¿ èŠãããã
æ°ãããµãŒãã¹ã®å®è£ ãé ããšãããžãã¹ãã£ã³ã¹ã倱ãããæçµçã«åžå Žã·ã§ã¢ã倱ãããå¯èœæ§ããããŸãããããã£ãŠãããžãã¹ããã»ã¹ã«ãšã£ãŠéèŠãªãããã¯ãŒã¯ãµãŒãã¹ãšããªã·ãŒã¯ãã§ããã ãæ©ãå®è£ ããå¿ èŠããããŸããåé¡ãçºçããŸã-ããžãã¹ã®èŠä»¶ãæºããæ°ãããµãŒãã¹ãšããªã·ãŒã®ç«ã¡äžããä¿èšŒãããããè¿ éãã€ãããã¯ãŒã¯å šäœã§è¡ãæ¹æ³ã¯ïŒ
è¿ä»£çãªç¶æ³ã®å€å žçãªãããã¯ãŒã¯ã¯ãçžäºã«ç¬ç«ããããã€ã¹ã®ã»ããã§ãããããæ°ãããµãŒãã¹ãèµ·åããããªã·ãŒã®å€æŽã«é©å¿ããããã«ããå€ãã®æéãšåŽåãå¿ èŠã§ããããã«ãåŸæ¥ã®ãããã¯ãŒã¯ã®ããã€ã¹ã«ã¯ãç°ãªããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãç®çã®æ©èœãå®è£ ããããŸããŸãªæ¹æ³ãã³ãã³ãã©ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ã§èšå®ããããŸããŸãªæ¹æ³ããããŸãã
éäžç®¡çãåžžã«åœ¹ç«ã€ãšã¯éããŸãããå€ãã®ITããã»ã¹ã«èªååæ©èœãæäŸããŸãããåäžã®èª¿æŽãããããªã·ãŒãäœæããã«ã¯ãæ©èœçãªãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãå¿ èŠã§ãããå®éã«ã¯åŸæ¥ã®ãããã¯ãŒã¯ã«ã¯ãããŸããã
å¥ã®ç¶æ³-æéã®çµéãšãšãã«ãã»ãšãã©ã®äŒæ¥ãããã¯ãŒã¯ã®ããã€ã¹æ§æã¯è¿œå ã®èšå®ãããªã·ãŒã«ãã£ãŠã倧ãããªããããããŸããŸãè€éã«ãªããäžè²«æ§ã倱ãããŸããããã«ãããéäžç®¡çããŒã«ã®äœ¿çšãå°é£ã«ãªããŸãããã®çµæã2016幎ã®ã·ã¹ã³ã®ç€Ÿå 調æ»ã«ãããšãäŒæ¥ãããã¯ãŒã¯ã®å€æŽã®çŽ90ïŒ ã¯äŸç¶ãšããŠæåã§è¡ãããŠããŸãããããŠãããã¯ååãšããŠé·ãã ãã§ãªããã人çèŠå ãã®ããã«å±éºã§ããããŸãã
SD-Accessãããã¯ãŒã¯ã¯ããœãããŠã§ã¢å®çŸ©ã®ãããã¯ãŒã¯ãã¯ãããžãŒãšCisco DNA Centerã³ã³ãããŒã©ãŒã«åºã¥ãããããçŸä»£çãªã¢ãããŒããæäŸããŸããã³ã³ãããŒã©ã¯ãããã¯ããŒã³ãããã¯ãŒã¯ãšãªãŒããŒã¬ã€ããããžã®äž¡æ¹ã管çãããããã¯ãŒã¯å šäœã®å šäœåãææ¡ããŸãã管çè ã¯ãDNA Centerã®ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠããªã·ãŒãèšå®ã§ããŸãã
ãããã¯ãŒã¯ãµãŒãã¹ãšããªã·ãŒã¯ããèªäœã§ã¯ååšããŸããããç¹å®ã®ããžãã¹èŠä»¶ãŸãã¯ãããžãã¹æå³ããæºããããã®ãã®ã§ãã DNA Centerã¯ããããžãã¹æå³ãã®æŠå¿µã«åºã¥ããŠæ§ç¯ãããŠããŸãã管çè ã¯ãŸããé«ã¬ãã«ã®æ§æã®è©³çŽ°ãè«çãŠãŒã¶ãŒã°ã«ãŒãããããã®éã®ç®çã®é¢ä¿ããã©ãã£ãã¯åŠçããªã·ãŒãªã©ãèšå®ãã次ã«ã³ã³ãããŒã©ãŒãç®çã®çµæãåŸãããã«ãããã¯ãŒã¯ãã¡ã¯ããªãŒãããã°ã©ã ããŸããã³ã³ãããŒã©ã¯ãNetconf / YANGãRESTãããã³CLIã®ãµãŠã¹ããŠã³ãAPIãä»ããŠãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãšå¯Ÿè©±ããŸãã
ããã«ãã³ã³ãããŒã©ãŒã«ãããããŒã¹ããŠã³ãREST APIã䜿çšããŠäŒæ¥ãããã¯ãŒã¯ãæœè±¡åãããããã®APIãä»ããŠæ©èœãããããã¯ãŒã¯ããã°ã©ãã³ã°ããŒã«ãé©çšã§ããŸãã
ãã®çµæãSD-Accessãããã¯ãŒã¯ã¯ããããã¯ãŒã¯ãµãŒãã¹ãšããªã·ãŒã®è¿ éãªå®è£ ãä¿èšŒããæçµçã«ã¯ããžãã¹èŠä»¶ãè¿ éã«æºãããŸãã
4.4ããŠãããŒãµã«ãã©ã³ã¹ããŒãã¬ãã«3ããã³2ã®å®è£ æ¹æ³ æç·ããã³ç¡ç·LANãçµ±åããæ¹æ³
ããžãã¹ãç£æ¥ãªã©ã®ããŸããŸãªåéã«ãããè±å¯ãªã¢ããªã±ãŒã·ã§ã³ãšãããã¯ãŒã¯äœ¿çšã·ããªãª ã¬ãã«3ã ãã§ãªãã¬ãã«2ã§ãããã£ã³ãã¹å šäœã§é«éã§ä¿¡é Œæ§ã®é«ã茞éãå¿ èŠã«ãªãå ŽåããããŸãã
ãã®ãããªã·ããªãªã®äŸã¯æ¬¡ã®ãšããã§ãã
- çç£ããŒãºã®å€åã«ãããæç·ãããã¯ãŒã¯ã«æ¥ç¶ãããæ©åšã移åããå¿ èŠãããããã®æ©åšã§ã¯äœ¿çšããã¢ãã¬ã¹ãç°¡åã«å€æŽã§ããªãç£æ¥äŒæ¥ã
- , , , ;
- , IT- ;
- , 2 IP-.
ããã«ãã¯ã©ã€ã¢ã³ãããã€ã¹ã¯ã¢ãã€ã«åãé²ã¿ãæç·ãããã¯ãŒã¯ãšç¡ç·ãããã¯ãŒã¯ã®äž¡æ¹ã«ç§»åããŠæ¥ç¶ã§ããŸãã
ã¬ãã«3ããã³2ã®ãŠãããŒãµã«ãã©ã³ã¹ããŒããæäŸããŠãæç·ããã³ç¡ç·LANãã«ããŒããçµ±åãã©ã³ã¹ããŒãç°å¢ãäœæããæ¹æ³ã¯ïŒ
å€å žçãªãããã¯ãŒã¯ã§ãã®åé¡ã解決ããããšã¯å°é£ã§ãããããè¡ãã«ã¯ãã·ã³ãã«ããä¿¡é Œæ§ãèšèšã®æè»æ§ãç ç²ã«ããŠVLANããã£ã³ãã¹ã«é 眮ãããããããã¯ãŒã¯ãè€éã«ãããã¹ãŠã®çµç¹ã«é©ããŠããªãMPLS VPNãªã©ã®åŸæ¥ã®ãªãŒããŒã¬ã€ããããžã䜿çšããå¿ èŠããããŸãã
æç·ãããã¯ãŒã¯ãšç¡ç·ãããã¯ãŒã¯ã®çµ±åã¯å¥ã®èª²é¡ã§ããçŸä»£ã®ãã£ã³ãã¹ãããã¯ãŒã¯ã§ã¯ãéäžåã¯ã€ã€ã¬ã¹LANã¢ãŒããã¯ãã£ãæãåºã䜿çšãããŠãããWLANãŠãŒã¶ãŒãã©ãã£ãã¯ã¯ç¡ç·ã¢ã¯ã»ã¹ãã€ã³ãããã³ã³ãããŒã©ãŒã«ãã³ããªã³ã°ããããããä»ããŠæç·ãããã¯ãŒã¯ã«å ¥ããŸãããããã£ãŠãæç·ããã€ã¹ãšç¡ç·ããã€ã¹ã®ãã©ãã£ãã¯ã¯ç°ãªãæ¹æ³ã§åŠçãããçµ±äžãããããªã·ãŒãããã«é©çšããããšã¯å°é£ã§ãã
SD-Accessãããã¯ãŒã¯ã¯ãå·¥å Žåºæã®ããããã£ã§ãããªãŒããŒã¬ã€ã§ãã®åé¡ã解決ããŸãããã©ãã£ãã¯ãVXLANãã±ããã«ã«ãã»ã«åãããšãã¬ã€ã€ãŒ3ãšã¬ã€ã€ãŒ2ã®äž¡æ¹ã®ãã©ã³ã¹ããŒããæäŸãããFabric Enabled WirelessïŒFEWïŒãã¯ãããžãŒã«ãããç¡ç·ã¢ã¯ã»ã¹ãã€ã³ããå·¥å Žã«çµ±åãããŸããæç·ãŠãŒã¶ãŒãšç¡ç·ãŠãŒã¶ãŒã®äž¡æ¹ã®ãã©ãã£ãã¯ã¯ãã¢ã¯ã»ã¹ã¹ã€ããïŒãšããžããŒãïŒãä»ããŠå·¥å Žã«å ¥ããåãäžè²«ããããªã·ãŒãé©çšã§ããŸããSD-Accessãããã¯ãŒã¯ã®åã¢ã¯ã»ã¹ã¹ã€ããïŒãšããžããŒãïŒã¯ãLISPãããã³ã«ã«åºã¥ããŠã³ã³ãããŒã«ãã¬ãŒã³ãå®è£ ããL3ãšããŒãã£ã¹ãã²ãŒããŠã§ã€ãæäŸããŸãããã®çµæãSD-Accessã䜿çšãããšãã¯ã©ã€ã¢ã³ãããã€ã¹ã¯ãã£ã³ãã¹å ã移åãããšãã«åãIPã¢ãã¬ã¹ãä¿æã§ããŸãã
ãããã£ãŠãSD-Accessãããã¯ãŒã¯ã¯ä»¥äžãå®è£ ããŸãã
- ã¬ãã«3ããã³ã¬ãã«2ã®çµ±åããã䜿ãããããã©ã³ã¹ããŒãã¡ã«ããºã ã
- .
- , 3 2.
4.5ã ?
æè¿èŠ³å¯ããããåäŸã®ãªãæªå åã®æŽ»åã®é¢éžã¯ãå€ãã®è åšãšæ»æãã¯ãã«ãçè«é¢ããå®çšé¢ã«ç§»è¡ããŸãã
ããšãã°ãæ»æè ã¯Targetãã4000äžæ以äžã®æ¯æãã«ãŒãããããŒã¿ãçã¿ããããã¯ãŒã¯ã«æ¥ç¶ããã空調ã·ã¹ãã ãä»ããŠäŒæ¥ãããã¯ãŒã¯ã«äŸµå ¥ããŸããã
WannaCryãPetyaãªã©ã®æå·åã¯ãŒã ã®æµè¡ã¯ãäžçäžã§ããã«å€§ããªè¢«å®³ããããããŠããŸãã
ãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ãå°å ¥ããããšã«ããããã®ãããªã€ã³ã·ãã³ãã®åœ±é¿ãé²ãããå€§å¹ ã«æžããããšãã§ããŸãããããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ã䜿çšãããšããããã¯ãŒã¯ãŠãŒã¶ãŒãåå¥ã®ã°ã«ãŒãã«åå²ããããšãã§ãããã®éã®ãã©ãã£ãã¯ã¯ãã»ãã¥ãªãã£ããªã·ãŒã®èŠä»¶ãšçŸåšã®ç¶æ³ã«å¿ããŠå¶åŸ¡ãŸãã¯ãããã¯ãããŸãã
åŸæ¥ã®ãããã¯ãŒã¯ã«ãããã»ã°ã¡ã³ããŒã·ã§ã³ã®åé¡ã«å¯Ÿãã解決çã¯ãéåžžãä»®æ³è«çããããžïŒããšãã°ãVLANãVRFãMPLS VPNãªã©ã«åºã¥ãïŒãäœæããããã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒã䜿çšããããšã§éæãããŸããã©ã¡ãã®æ¹æ³ããæéãšåŽåã®å€å€§ãªæè³ãå¿ èŠãšãããããã®ã³ã¹ãã¯ãŸããŸã倧ãããªããã»ã°ã¡ã³ããŒã·ã§ã³ç°å¢ã¯ããåçã«ãªããŸãããã®çµæãã»ã°ã¡ã³ããŒã·ã§ã³ããªã·ãŒã®å€æŽã¯é£ãããæéãããããŸããããã«ãä»®æ³ããããžãšACLã䜿çšããã»ã°ã¡ã³ããŒã·ã§ã³ã¯ã©ã¡ããããã¥ãŒãã³ãã¡ã¯ã¿ãŒãã®çºçŸã«å¯ŸããŠè匱ã§ããããã®è匱æ§ã¯ã»ã°ã¡ã³ããŒã·ã§ã³èŠä»¶ããŸããŸãåçã«ãªããŸããå Žåã«ãã£ãŠã¯ããããã®ç¶æ³ã¯äžè¬ã«ãåŸæ¥ã®ãããã¯ãŒã¯ã§ã®ã»ã°ã¡ã³ããŒã·ã§ã³ã®éå®çšæ§ã«ã€ãªããå¯èœæ§ããããŸãã
SD-Accessãããã¯ãŒã¯ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã®åé¡ã解決ããããã®ãã匷åã§æè»ãªããŒã«ãæäŸããŸãã 2ã€ã®ã¬ãã«ã§å®è¡ã§ããŸããæåã®ã¬ãã«ã¯ãVRFã®ã¡ã«ããºã ã䜿çšããä»®æ³ãããã¯ãŒã¯ïŒä»®æ³ãããã¯ãŒã¯ïŒãžã®ã»ã°ã¡ã³ããŒã·ã§ã³ã§ãã 2çªç®ã®ã¬ãã«ã¯ãCisco TrustSecãã¯ãããžãŒã䜿çšããã°ã«ãŒãïŒã¹ã±ãŒã©ãã«ã°ã«ãŒãïŒãžã®ã»ã°ã¡ã³ããŒã·ã§ã³ã§ãã
VRFããŒã¹ã®ã»ã°ã¡ã³ããŒã·ã§ã³ã¯ãæ§æãæ¯èŒçéçãªä»®æ³ãããã¯ãŒã¯ãžã®å€§ãŸããªåé¢ã«æé©ã§ããããšãã°ãäŒæ¥ã®åŸæ¥å¡ãšãã«ã®ãšã³ãžãã¢ãªã³ã°ãµãã·ã¹ãã çšã®åå¥ã®ä»®æ³ãããã¯ãŒã¯ã«ããããšãã§ããŸããå¥ã®äŸã¯ãåãäŒæ¥ã°ã«ãŒãã«å±ããäŒæ¥ã®åå¥ã®ãããã¯ãŒã¯ã§ãã
TrustSecããŒã¹ã®ã»ã°ã¡ã³ããŒã·ã§ã³ã¯ããŠãŒã¶ãŒã°ã«ãŒãã®æ§æãšãããã®çžäºäœçšã®ã«ãŒã«ãé »ç¹ã«å€æŽãããåçç°å¢ã«éåžžã«äŸ¿å©ã§ãã TrustSecã䜿çšãããšãCisco ISEãµãŒããŒã§ãŠãŒã¶ãŒã°ã«ãŒããšçžäºäœçšã«ãŒã«ãäžå çã«èšå®ã§ããŸããããã«ããããã®ã«ãŒã«ã¯ãããã¯ãŒã¯äžã§èªåçã«é åžãããSGTã¿ã°ãšSGACLã¿ã°ã«åºã¥ãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãã«ãã£ãŠå®è£ ãããŸãã
TrustSecã¯éåžžã«é«åºŠãªèªååãæäŸããŸãããã®æè¡ã¯ãåçãªç°å¢ã«æé©ã§ããããŠãŒã¶ãŒãå°ããªã°ã«ãŒãã«çŽ°ååããããã«äœ¿çšã§ããŸãã
TrustSecãã¯ãããžãŒã¯ãå¹ åºãã·ã¹ã³æ©åšã·ãªãŒãºã«å®è£ ãããŠãããSD-Accessãã¡ã¯ããªãšã¯ç¬ç«ããŠäœ¿çšã§ããŸããããããããã«å ããŠãTrustSecã¯å·¥å Žã«æ·±ãçµ±åãããŠãããSD-Accessãããã¯ãŒã¯ã®éçšæã«ç°¡åã«äœ¿çšã§ããçµ±åæ©èœã®1ã€ã§ãã
ããã«ãSGTã¿ã°ã¯VXLANããããŒã®äžéšãšããŠéä¿¡ããããããå·¥å Žå ã®åäžéããã€ã¹ã§TrustSecãã¯ãããžãŒããµããŒãããããSXPãªã©ã®è¿œå ã®ã³ã³ãããŒã«ãã¬ãŒã³ãããã³ã«ã䜿çšãããããå¿ èŠã¯ãããŸãããå·¥å Žã®å¢çããã€ã¹ã§ã®TrustSecã®å®è£ ã¯ååã§ãããæåãããã§ã«ååšããŠããŸãã
ãããã£ãŠãSD-Accessã¯ãTrustSecãã¯ãããžãŒãå·¥å Žã®æ©èœã«çµ±åããããšã«ãããã»ã°ã¡ã³ããŒã·ã§ã³ã®åé¡ã«å¯Ÿãããšã¬ã¬ã³ããªãœãªã¥ãŒã·ã§ã³ãæäŸããŸãã
ãã®çµæãSD-Accessãããã¯ãŒã¯ã¯ä»¥äžãæäŸããŸãã
- çµ±åããã䜿ããããããã¥ãŒãã³ãã¡ã¯ã¿ãŒãã«ããISãªã¹ã¯ãšããžãã¹ããã»ã¹ã®ããŠã³ã¿ã€ã ãå€§å¹ ã«åæžããŸãããVRFããã³TrustSecãã¯ãããžãŒã«åºã¥ãéåžžã«åŒ·åãªã»ã°ã¡ã³ããŒã·ã§ã³ããŒã«ã
- èªååã«ããã»ã°ã¡ã³ããŒã·ã§ã³ã®äººä»¶è²»ã®å€§å¹ ãªæé©åã
- èªååã«ããã»ã°ã¡ã³ããŒã·ã§ã³ã®å®è£ ãå€§å¹ ã«å éããŸãã
4.6ã å šäœçã§äžè²«æ§ã®ããåçãªããªã·ãŒããããã¯ãŒã¯å šäœã«å®è£ ããæ¹æ³ã¯ïŒ
ã»ãã¥ãªãã£ããªã·ãŒããã©ãã£ãã¯åŠçããµãŒãã¹ã®å質ïŒQoSïŒãªã©ãã»ãŒãã¹ãŠã®ææ°ãããã¯ãŒã¯ã«ãããŸãã¯ãã®ããªã·ãŒå®è£ ããããŸãã
ããªã·ãŒã®å®è£ ã¯éåžžã«éèŠã§ãããªããªããæçµçã«ã¯ãããžãã¹ã«å¿ èŠãªãµãŒãã¹ãšå質ããã©ã³ã¹ããŒãç°å¢ã«æäŸããããã§ãã
åŸæ¥ã®ãããã¯ãŒã¯ã§ã¯ãããªã·ãŒã¯è€éãªãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£èšå®ãšããŠå®è£ ãããŸãããå®è£ ãšæäœãå°é£ã§ãã
SD-Accessãããã¯ãŒã¯ã¯ãDNAã»ã³ã¿ãŒã®ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãšå·¥å Žã®ããããã£ãéããŠãçµ±äžãããäžè²«ããããªã·ãŒãå®è£ ããå¯èœæ§ãæäŸããŸããããã«ããã®ãããªæ©èœã¯åçã§ãããããå€åããããžãã¹èŠä»¶ãžã®é©å¿ãšããç¹ã§äŸ¿å©ã§ãã
4.6.1ãã»ãã¥ãªãã£ããªã·ãŒ
äŸãšããŠã¯ã©ã·ãã¯ãããã¯ãŒã¯ã䜿çšããŠã»ãã¥ãªãã£ããªã·ãŒãå®è£ ããããšãæ€èšããŠãã ãããã¢ã¯ã»ã¹å¶åŸ¡-ã»ãã¥ãªãã£ããªã·ãŒã®æãéèŠãªã³ã³ããŒãã³ã-ã¯ã©ã·ãã¯ãããã¯ãŒã¯ã§ã¯ãå€ãã®å Žåã決å®ã®åºæºãšããŠãã¹ããšãµããããã®IPã¢ãã¬ã¹ã«äŸåããŠããŸãã
ããã¯ãç¹å®ã®ã°ã«ãŒãã®ã¡ã³ããŒã·ããã決å®ããããã«ããŠãŒã¶ãŒãèå¥ããããã®ããŒã¿ãIPãã±ããããããŒã«ãªãããã§ãããããã£ãŠã代ããã«ãã¹ããšãµããããã®IPã¢ãã¬ã¹ã䜿çšããå¿ èŠããããŸãã
IPã¢ãã¬ã¹ã«åºã¥ãããªã·ãŒã¯éäžåããããããã€ã¹æ§æã®ãããã¯ãŒã¯äžã§é åžãããŸããæ°åè¡ã®ACLã衚瀺ãããŸãããŠãŒã¶ãŒãšããã€ã¹ã¯VLANããšã«ã°ã«ãŒãåãããŸãããµããããã¯ãããã€ãã®åºæºã«åŸã£ãŠãŠãŒã¶ãŒãšããã€ã¹ãã°ã«ãŒãåããããã«äœ¿çšãããŸããä»®æ³ãããã¯ãŒã¯ããããžã¯ããã©ãã£ãã¯ã»ã°ã¡ã³ããŒã·ã§ã³çšã«äœæãããŸãã IPã¢ãã¬ã¹ã¯ãã»ãã³ãã£ãã¯ããŒãã§åçŽã«ãªãŒããŒããŒããããŸãã
ãã®çµæãããªã·ãŒã®å®è£ ã«å¯Ÿãããã®ã¢ãããŒãã¯ãæéãšåŽåã®å€§ããªæ¯åºã«å ããŠããšã©ãŒã®å¯èœæ§ã®å¢å ã«ã€ãªãããŸãã
ããã«ãããªã·ãŒãé©çšããåºæºãšããŠIPã¢ãã¬ã¹ã䜿çšãããšããããã¯ãŒã¯ã®æè»æ§ã倱ãããŸããã¢ãã¬ã¹æå®ãšã®é¢ä¿ããããããããªã·ãŒã®èŠä»¶ãèæ ®ããã«ãå¿ èŠä»¥äžã®ãµãããããšVLANãäœæããå¿ èŠããããŸãããããã¯ãŒã¯ã«å€æŽãå ããããšã¯ããé·ããããå±éºã«ãªããæäœããã©ãã«ã·ã¥ãŒãã£ã³ã°ããã»ã¹ã¯ããè€éã«ãªãããŠãŒã¶ãŒãã©ãã£ãã¯ããã³ããªã³ã°ããè¿œå ã®æ¹æ³ã䜿çšããªããã¹ãã¢ããªãã£ã¯ãå Žæãå€æŽãããšãµããããã®å€æŽã«ã€ãªããããšãå€ãããå®çšçã§ã¯ãããŸãã
IPã¢ãã¬ã¹ã«åºã¥ããã»ãã¥ãªãã£ããªã·ãŒã®å®è£ ã¯ããããã¯ãŒã¯ç°å¢ã®ãã€ããã¯ã¹ãæªåããã»ã©æªåããŸãããããŠããã®ãããªãã€ããã¯ã¹ã¯éåžžå€ããããæéã®çµéãšãšãã«çŸä»£ã®ãããã¯ãŒã¯ã§ã¯ãŸããŸãå¢ããŠããŸãã
SD-Accessãããã¯ãŒã¯ã«ãããããªã·ãŒãé©çšããããã®åºæºãšããŠãIPã¢ãã¬ã¹ã§ã¯ãªããSGTïŒScalable Group TagïŒã°ã«ãŒãã䜿çšããŠåäžã®çµ±åããªã·ãŒãå®è£ ã§ããŸãããã®æ å ±ã¯ããããã¯ãŒã¯ãã¡ã¯ããªã®VXLANããããŒã«ã«ãã»ã«åãããŸãããŠãŒã¶ãŒã¯ãCisco Identity Services EngineïŒISEïŒã¢ã¯ã»ã¹å¶åŸ¡ãµãŒããŒããŒã¿ããŒã¹ããã³Active Directoryã«é¢ããŠãSGTã°ã«ãŒãã«åçãã€åçã«å²ãåœãŠãããšãã§ããŸããSGTã°ã«ãŒããžã®å²ãåœãŠã¯ããããã¡ã€ãªã³ã°ããã¹ãã£ãªã©ã®è¿œå ã®ã³ã³ããã¹ããèæ ®ããŠè¡ãããŸãã
ãã®çµæãSD-Accessãããã¯ãŒã¯ã¯ãIPã¢ãã¬ã¹ã«é¢ä¿ãªãããããã¯ãŒã¯å šäœã§äžè²«ããäžè²«ããåçãªããªã·ãŒãæäŸããŸãã
4.6.2ããµãŒãã¹å質ïŒQoSïŒããªã·ãŒ
è¿ä»£çãªäŒæ¥ãããã¯ãŒã¯ã®Quality of ServiceïŒQoSïŒããªã·ãŒã¯ãDiffServã¢ãã«ã®ãã¬ãŒã ã¯ãŒã¯å ã§ååãšããŠå®è£ ãããŸãããã®ã¢ãã«ã«ã¯ãDiffServãã¡ã€ã³å¢çã§ã®ã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ã®åé¡ãšã©ããªã³ã°ãå«ãŸããããŒãã³ã°ã«åºã¥ããŠãã¡ã€ã³å ã§ããã«å·®å¥åããããµãŒãã¹ã䜿çšãããŸãã
åŸæ¥ã®ãããã¯ãŒã¯ç°å¢ã§ã®QoSããªã·ãŒã®å šé¢çãªå®è£ ã¯éåžžã«è€éã§ããäž»ãªçç±ã«ã¯ãå°ãªããšã以äžãå«ãŸããŸãã
- QoSæ©èœã®æ§æãšãããã°ã®è€éãã
- QoSããªã·ãŒã®å®è£ ãå€æŽããé£ããã
- QoSæ©èœã®äžäžèŽãããã³ãããã¯ãŒã¯ã圢æããæ©åšã§ã®èšå®æ¹æ³ã®ïŒå Žåã«ãã£ãŠã¯ïŒé¡èãªéãã
- - (, ) (, NBAR2, DPI, DNS-AS, ).
ãã®èšäºã®å·çæç¹ã§ãã·ã¹ã³ã¯DNA Centerã€ã³ã¿ãŒãã§ã€ã¹ã§ã®QoSããªã·ãŒäœææ©èœã«åãçµãã§ããŸãããã®çµæããããã¯ãŒã¯ãµã€ããéžæããå·¥å Žã®ããã€ã¹ã«QoSããªã·ãŒãå®è£ ïŒããã·ã¥ïŒããããšãå¯èœã«ãªããŸãã
éäžãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãšèªååãããQoSã®å®è£ ã¯ãæ§æã®è€éããšããªã·ãŒã®æŽæ°ã®åé¡ã解決ããããã«èšèšãããŠããŸããå·¥å Žã®ã¹ã€ããã§åäžã®ããŒããŠã§ã¢ããŒã¹ïŒUADPéç©åè·¯ãªã©ïŒã䜿çšããå·¥å Žã®ã¹ã€ãããšã«ãŒã¿ãŒã§IOS-XEãœãããŠã§ã¢ãçµ±åãããšãQoSå®è£ ã®äžè²«æ§ãå€§å¹ ã«åäžããŸããæåŸã«ããã¡ã¯ããªã®èŠçŽ ããŒã¹ã¯ãåŸæ¥ã®æ¹æ³ã«å ããŠãNBAR2ã¢ããªã±ãŒã·ã§ã³åé¡ã¡ã«ããºã ããµããŒãããŠããŸãã
ãããã£ãŠãSD-Accessãããã¯ãŒã¯ã¯ãäŒæ¥ç°å¢ã§ã®QoSããªã·ãŒã®å¹æçãªéäžåå®è£ ã®ããã®ããŒã«ãæäŸããŸãã
4.6.3ããã©ãã£ãã¯åŠçããªã·ãŒ
äŒæ¥ãããã¯ãŒã¯ã§ã¯ãããšãã°ãç¹å®ã®ãã©ãã£ãã¯ãšã³ãžãã¢ãªã³ã°ã«ãŒããéžæããå¿ èŠãªãã©ãã£ãã¯ããã©ãŒãªã³ã°ããããã«ããã©ãã£ãã¯åŠçããªã·ãŒãé©çšããå¿ èŠããããŸãã
åŸæ¥ã®ãããã¯ãŒã¯ç°å¢ã§ã¯ããããã®ããªã·ãŒã¯ãããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ïŒPBRïŒãMPLSãã©ãã£ãã¯ãšã³ãžãã¢ãªã³ã°ïŒMPLS TEïŒãé©åãªSPANã¡ãœãããªã©ã®éçããã³åçããŒã«ã䜿çšããŠå®è£ ã§ããŸãã
SD-Accessãããã¯ãŒã¯ã¯ãDNAã»ã³ã¿ãŒãšå·¥å Žã§å®è£ ããããçµ±åãããã¯ããã«ç°¡åãªå®è£ ããã³äœ¿çšã®ãã¹ããªãã¡ã¬ã³ã¹ããã³ãã©ãã£ãã¯ã³ããŒã³ã³ãã©ã¯ãæ©èœãæäŸããŸãã
4.7ã ? ?
ããžãã¹ã®èŠ³ç¹ããããããã¯ãŒã¯ã¯ãããžãã¹ããã»ã¹ã®æé©ãªéçšã«å¿ èŠãã€ååãªã¬ãã«ã®ã¢ã¯ã»ã·ããªãã£ãšãµãŒãã¹å質ãæäŸããå¿ èŠããããŸãã
ãã®åé¡ã®è§£æ±ºçã¯ãçæ³çã«ã¯äºé²çã§ãããã€ã³ã·ãã³ããçºçããåã§ãã£ãŠãäºæž¬ããå¿ èŠããããŸããå®éã«ã¯ãå€å žçãªãããã¯ãŒã¯ã§ã¯ãããã¯ãŸãã§ããã·ã¹ã³ã®èª¿æ»ã«ãããšã調æ»å¯Ÿè±¡ã®äŒæ¥ã®85ïŒ ãããã¢ã¯ãã£ããªã¢ãããŒãã§ã¯ãªãããªã¢ã¯ãã£ããªã¢ãããŒããæ¡çšããŠããŸãã管çè ã¯ããããã¯ãŒã¯ããã€ã¹ããéä¿¡ãããããŸããŸãªããŒã«ã䜿çšããŠããŸããŸãªæ¹æ³ã§åŠçããã倧éã®ç°çš®ããŒã¿ã«å§åãããŸããããã®ããŒã¿ã¯ç¹å®ã®ã¢ã¯ã·ã§ã³ã¬ã€ãã©ã€ã³ãæäŸããŸããããããã¯ãŒã¯ã®å šäœåãææ¡ããããšã¯é£ãããåé¡ã®æ ¹æ¬ãç¹å®ããããšã¯å°é£ã§ãããã®çµæãäºåŸå¯Ÿå¿åã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã§ãããåžžã«è¿ éã«è¡ããããšã¯éãããããžãã¹ã«ãŸããŸãæ £ããªããªããŸãã
SD-Accessãããã¯ãŒã¯ã¯ãDNAã»ã³ã¿ãŒæ©èœã䜿çšããŠãã®åé¡ã®è§£æ±ºçãæäŸããŸããäŒæ¥ãããã¯ãŒã¯ã®å šäœåãæäŸãããããã¯ãŒã¯ããŠãŒã¶ãŒãããã³ã¢ããªã±ãŒã·ã§ã³ã«é¢é£ããã€ã³ã·ãã³ãã«é¢ããæŽå¯ãæäŸããŸãããããã®èª¿æ»çµæã¯ãã€ã³ã·ãã³ãã®åå ã«å¯ŸåŠããããã®å ·äœçãªæé ãå®è¡ããã®ã«åœ¹ç«ã¡ãŸãã
DNA Centerã¯ããããã¯ãŒã¯ã®åŸåãåæãããã®åœ±é¿ã®äºæž¬ãæäŸããŸãããã®æ å ±ã¯ãã€ã³ã·ãã³ãã解決ããããã®äºåŸå¯ŸåŠçãªã¢ãããŒãã§ã¯ãªããäºé²çãªã¢ãããŒãã®å®è£ ã«åœ¹ç«ã¡ãŸãã
ããã«ãDNA Centerã¯ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãšã¬ã¡ã³ãããã¹ããªãŒãã³ã°ãã¬ã¡ããªãåä¿¡ãã管çè ã«æ°ç§åäœã®æ£ç¢ºãªãããã¯ãŒã¯ã€ãã³ãã«é¢ããæ å ±ãæäŸããŸãã
ãã®çµæãSD-Accessãããã¯ãŒã¯ã¯ä»¥äžãæäŸããŸãã
- ã€ã³ã·ãã³ã解決ã®å¹æçãªæ¯æŽã
- .
- -.
- -.
5.
Cisco Software-Defined AccessïŒSD-AccessïŒFactoryã¯ããšã³ã¿ãŒãã©ã€ãºãããã¯ãŒã¯ãæ§ç¯ããããã®æ°ããã¢ãããŒãã§ãããåŸæ¥ã®ãã£ã³ãã¹ãããã¯ãŒã¯ã倧ããæ¹åããŸããéèŠãªç¹ãšããŠããã®æé ã¯ãã³ãã³ãã©ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ãåããã³ã³ãã¥ãŒã¿ãŒããã°ã©ãã£ã«ã«ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ãåããã³ã³ãã¥ãŒã¿ãŒãžã®ç§»è¡ãšæ¯èŒã§ããŸãã
å·¥å Žã¯ãèšèšãå®è£ ãäŒæ¥ãããã¯ãŒã¯ã®éçšãããªã·ãŒã®å®è£ ãããã³ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®åéã§åŒ·åãªæ°ããæ©äŒãITãµãŒãã¹ã«æäŸããŸãããããã®æ©èœã«ãããITã¯ããžãã¹èŠä»¶ãè¿ éãã€å¹ççã«æºããããšãã§ããŸããæ¥åžžæ¥åãæå°éã«æããéçšäž»ã«ãšã£ãŠãã䟡å€ã®ããããæŠç¥çã§éèŠãªã¿ã¹ã¯ã«ããå€ãã®æéãè²»ããæ©äŒããããåŽååžå Žã§ç«¶äºäžã®åªäœæ§ãäžããŸãã
äžæ¹ãããžãã¹ã¯ãã€ãã·ã¢ããã®å®è£ é床ãšãããã¯ãŒã¯ã«åºã¥ãã¿ã¹ã¯ã®ãœãªã¥ãŒã·ã§ã³ã«ãããŠå€§ããªå©ç¹ãåãåããŸããæçµçã«ãå æåžå Žã·ã§ã¢ã®æ¡å€§ãåçã®å¢å ã«åœ¹ç«ã¡ãŸãããŸããCisco SD-Accessã¯ãããã¥ãŒãã³ãã¡ã¯ã¿ãŒãã«é¢é£ããããžãã¹ããã»ã¹é害ã®ãªã¹ã¯ãå€§å¹ ã«åæžããæ å ±ç°å¢ã®æ ¹æ¬çã«æ°ããã¬ãã«ã®ã»ãã¥ãªãã£ãæäŸããŸãã
åç §è³æ
- Cisco SD-Accessã®è©³çŽ°
- ãŠã§ãããŒãCisco Software-Defined Access-Cisco Enterprise Campus Networksã®æ°ããã¢ãŒããã¯ãã£
- ãŠã§ãããŒãCisco SD-Accessã¯ã€ã€ã¬ã¹ãšã³ã¿ãŒãã©ã€ãºã¢ãŒããã¯ãã£
- ãŠã§ãããŒãCisco SD-Accessã¢ãŒããã¯ãã£ã®ãã¬ãŒã ã¯ãŒã¯å ã§äŒæ¥LAN / WLANãããã¯ãŒã¯ãå±éããæ¹æ³ã¯ïŒ-ã©ã€ããœãªã¥ãŒã·ã§ã³ã®ãã¢