å·äžé¢ã®ä»£è¡šè ãèšã£ãããã«ãæ³åŸã«ã¯äŒæ¥ã®ç®çã®ããã«ãããã¯ãŒã¯æå·åã䜿çšããããšãã§ãããšããäºçŽããããŸãã ããã¯ãVPNæ¥ç¶ã®ç¢ºç«ãäºå®äžïŒå Žåã«ãã£ãŠã¯ïŒç¡æã§ãããããäŒæ¥ã¯ãªãã£ã¹éã§å€é¡ã®è²»çšããããŠãã©ã€ããŒããããã¯ãŒã¯ãæ§ç¯ããå¿ èŠããªãããšãæå³ããŸãã ãããã£ãŠãæ¬æ¥ãäŒæ¥ãããã¯ãŒã¯äžã§VPNæ¥ç¶ãæ§æãã2ã€ã®æ¹æ³ãšãããã«äœ¿çšãããããã€ãã®ãããã³ã«ãæ€èšããããšã«ããŸãããPPTPãL2TP / IPsecãSSTPãããã³OpenVPNã§ãã
/ Flickr / ãšããã¹ãŠã§ãŒã㌠/ cc
PPTP
PPTPä»æ§ã¯ãMicrosoftããã€ã€ã«ã¢ããVPNãç·šæããããã«èšç«ããã³ã³ãœãŒã·ã¢ã ã«ãã£ãŠéçºãããŸããã ãã®ãããPPTPã¯äŒæ¥ãããã¯ãŒã¯ã®æšæºãšããŠé·ãé䜿çšãããŠããŸããã åãçç±ã§ãMicrosoft Point-to-Point EncryptionïŒ MPPE ïŒæå·åãããã³ã«ã䜿çšããŸãã
VPN察å¿ãã©ãããã©ãŒã ã§ã¯ãããã©ã«ããã§ãããè¿œå ã®ãœãããŠã§ã¢ãªãã§ç°¡åã«æ§æã§ããŸãã PPTPã®ãã1ã€ã®å©ç¹ã¯ããã®é«ãããã©ãŒãã³ã¹ã§ãã ããããæ®å¿µãªãããPPTPã¯ååã«å®å šã§ã¯ãããŸããã 90幎代åŸåã«Windows 95 OSR2ã«ãããã³ã«ãå«ãŸããŠä»¥æ¥ãããã€ãã®è匱æ§ãæããã«ãªããŸããã
æãæ·±å»ãªã®ã¯ãã«ãã»ã«åãããŠããªãèªèšŒMS-CHAP v2ã®å¯èœæ§ã§ãã ãã®ãšã¯ã¹ããã€ãã«ããã2æ¥éã§PPTPããããã³ã°ãããŸããã ãã€ã¯ããœããã¯PEAPèªèšŒãããã³ã«ã«åãæ¿ããããšã§ç©ŽããããããããŸãããã圌ãèªèº«ã¯L2TP / IPsecãŸãã¯SSTP VPNãããã³ã«ã䜿çšããããšãææ¡ããŸããã ãã1ã€ã®ãã€ã³ã-ãããã³ã«ã¯1ã€ã®ããŒãçªå·1723ã§åäœãã GREãããã³ã«ã䜿çšãããããPPTPæ¥ç¶ã¯ç°¡åã«ãããã¯ã§ããŸã ã
VPNãã³ãã«ãã€ã³ã¹ããŒã«ããããšãPPTP 㯠2çš®é¡ã®ã¡ãã»ãŒãžããµããŒãããŸãããããã¯ãVPNæ¥ç¶ãç¶æããã³åæããããã®å¶åŸ¡ã¡ãã»ãŒãžãšãããŒã¿ãã±ããèªäœã§ãã
L2TPããã³IPsec
ã¬ã€ã€2ãã³ããªã³ã°ãããã³ã«ïŒ L2TP ïŒã¯ãã»ãšãã©ãã¹ãŠã®ææ°ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ååšããVPNããèªèãã§ãããã¹ãŠã®ããã€ã¹ã§åäœããŸãã
L2TPã¯ãééãããã©ãã£ãã¯ãæå·åããæ¹æ³ãç¥ããªãããã IPsecãšçµã¿åãããŠäœ¿çšââãããããšããããããŸãã ãã ããããã¯æªåœ±é¿ããããããŸããããŒã¿ã®äºéã®ã«ãã»ã«åãL2TP / IPsecã§çºçããããã©ãŒãã³ã¹ã«æªåœ±é¿ãåãŒããŸãã L2TPã¯ã500çªç®ã®UDPããŒãã䜿çšããŸããããã¯ãNATã®èåŸã«ããå Žåããã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠç°¡åã«ãããã¯ãããŸãã
L2TP / IPsecã¯ã 3DESãŸãã¯AESæå·ã§æ©èœããŸãã æåã®ãã®ã¯ã meet-in-the-middleãsweet32ãªã©ã®æ»æã«å¯ŸããŠè匱ã§ãããããä»æ¥ã§ã¯å®éã«ã¯ã»ãšãã©èŠãããŸããã AESæå·ã䜿çšããå Žåã倧ããªè匱æ§ã¯äžæã§ãããããçè«çã«ã¯ããã®ãããã³ã«ã¯å®å šã§ããå¿ èŠããããŸãïŒæ£ããå®è£ ãããŠããå ŽåïŒã ãã ããElectronic Frontier Foundationã®åµèšè ã§ããJohn Gilmoreã¯ã圌ã®æçš¿ã§IPSecãç¹ã«åŒ±äœåããå¯èœæ§ããããšææããŸããã
L2TP / IPsecã®æãæ·±å»ãªåé¡ã¯ãå€ãã®VPNãµãŒãã¹ãååã«å®è£ ããŠããªãããšã§ãã ãµã€ãããããŠã³ããŒãã§ããäºåå ±æããŒïŒPSKïŒã䜿çšããŸãã PSKã¯æ¥ç¶ã確ç«ããããã«å¿ èŠã§ãããããããŒã¿ãå±éºã«ãããããŠããAESã«ãã£ãŠä¿è·ããããŸãŸã§ãã ãã ããæ»æè ã¯PSKã䜿çšããŠVPNãµãŒããŒã«ãªãããŸããæå·åããããã©ãã£ãã¯ãçèŽããããšãã§ããŸãïŒæªæã®ããã³ãŒããæ¿å ¥ããããšããå¯èœã§ãïŒã
SSTP
Secure Socket Tunneling ProtocolïŒ SSTP ïŒã¯ãMicrosoftãéçºããVPNãããã³ã«ã§ãã SSLã«åºã¥ããŠãããWindows Vista SP1ã§æåã«èµ·åãããŸããã çŸåšããã®ãããã³ã«ã¯ãRouterOSãLinuxãSEILãMac OS Xãªã©ã®OSã§äœ¿çšã§ããŸãããWindowsãã©ãããã©ãŒã ã§ã®äž»èŠãªã¢ããªã±ãŒã·ã§ã³ã¯ãŸã èŠã€ãã£ãŠããŸãã SSTPã¯Microsoftãææããç¬èªã®æšæºã§ããããã®ã³ãŒãã¯å ¬éãããŠããŸããã
SSTPèªäœã«ã¯ã1ã€ã®æ©èœãé€ããæå·åæ©èœããããŸãããMITMæ»æããä¿è·ããæå·åãã€ã³ãã£ã³ã° ïŒæå·åãã€ã³ãã£ã³ã°ïŒã«ã€ããŠè©±ããŸãã ããŒã¿æå·åã¯SSLãå®è¡ããŸãã VPNæ¥ç¶ã確ç«ããæ¹æ³ã®èª¬æã¯ãMicrosoft Webãµã€ãã«ãããŸãã
Windowsãšã®ç·å¯ãªçµ±åã«ããããããã³ã«ãç°¡çŽ åããããã®ãã©ãããã©ãŒã ã§ã®å®å®æ§ãåäžããŸãã ãã ããSSTPã¯SSL 3.0ã䜿çšããŸããããã¯ãçè«äžã¯VPNãããã³ã«ã®ã»ãã¥ãªãã£ã«åœ±é¿ããPOODLEæ»æã«å¯ŸããŠè匱ã§ãã
Openvpn
OpenVPNã¯ãOpen SSLã©ã€ãã©ãªãTLSãããã³ä»ã®å€ãã®ãã¯ãããžãŒã䜿çšãããªãŒãã³ãœãŒã¹ãããžã§ã¯ãã§ãã çŸåšãåçšVPNãµãŒãã¹ã®æ¥çæšæºã§ããããµãŒãããŒãã£ãœãããŠã§ã¢ã䜿çšããä»»æã®ãã©ãããã©ãŒã ã«å®è£ ãããŠããŸãã å€ãã®ãããã€ããŒã¯ã«ã¹ã¿ã OpenVPNã¯ã©ã€ã¢ã³ããæäŸããŠããŸããããããžã§ã¯ãéçºè ã¯ã³ã¢ã³ãŒãã§äœæ¥ããŠããŸãã
OpenVPNã®å©ç¹ã®äžã§ããã«ã¹ã¿ãã€ãºæ§ãéç«ã£ãŠããŸãã ä»»æã®ããŒãã§åäœããããã«æ§æã§ããŸãã ããã«ãããããŒã443ã§ãã©ãã£ãã¯ãéä¿¡ããŠHTTPSãšããŠããã¹ã¯ãã§ããããããã³ã°ãè€éã«ãªããŸãã
ãã ãããã®VPNãããã³ã«ã®æè»æ§ã¯ãããçšåºŠã®æ¬ ç¹ãšèŠãªãããšãã§ããŸãã ç¹ã«ãWindowsã®æšæºã¯ã©ã€ã¢ã³ãã䜿çšããå Žåãè¿œå ã®æ§æãã¡ã€ã«ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã ãã ãããã®åé¡ã¯ãäžéšã®ãããã€ããŒãå®è£ ããäºåæ§ææžã¿ã®VPNã¯ã©ã€ã¢ã³ãã䜿çšããããšã§è§£æ±ºã§ããŸãã
ãã®ãããã³ã«ã®ãã1ã€ã®å©ç¹ã¯ãOpenSSLã©ã€ãã©ãªã§ãã å€ãã®æå·åã¢ã«ãŽãªãºã ããµããŒãããŠããŸã-ãããã¯3DESãCAST-128ãCameliaãAESãBlowfishã§ãã æåŸã®2ã€ã¯ãå®éã«æããã䜿çšãããŸãã
OpenVPNã®ãã1ã€ã®å©ç¹ã¯ãå®æçãªç£æ»ã§ãã æåŸã®ãã§ãã¯ã§ã¯ ããŠãŒã¶ãŒããŒã¿ã®ã»ãã¥ãªãã£ã«åœ±é¿ãããç©Žã ã¯æããã«ãªããŸããã§ãã ã ãã®åŸãæ»æè ã«DDoSæ»æãå®è¡ããèœåãäžããããã€ãã®è匱æ§ãçºèŠãããŸããããéçºè ã¯ããŒãžã§ã³OpenVPN 2.4.2ã§ãããã«ããããé©çšããŸããã
OpenVPNã¯ãä»æ¥å©çšå¯èœãªæãä¿¡é Œæ§ã®é«ãVPNãããã³ã«ã®1ã€ãšèããããŠãããVPNæ¥çã§åºããµããŒããããŠããŸãã OpenVPNã¯ã«ãŒãã¢ã¯ã»ã¹ãªãã§ã¯ã¢ãã€ã«ãã©ãããã©ãŒã ã§ã¯åäœããŸããã§ããããä»æ¥ã§ã¯ãã®ã誀解ããä¿®æ£ãããµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ããããŸãã
/ Flickr / ã¢ã³ããªã¥ãŒããŒã / CC
VPNæ¥ç¶ã¿ã€ã
ä»æ¥ã®èšäºã§ã¯ãæãäžè¬çã«äœ¿çšããã2ã€ã®ã¿ã€ãã® VPNæ¥ç¶ã«ã€ããŠèª¬æããŸãã ããã¯ãäŒæ¥ãããã¯ãŒã¯ãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ïŒãªã¢ãŒãã¢ã¯ã»ã¹ïŒãšæ¥ç¶ããã€ã³ãããŒãã€ã³ããïŒãµã€ãéïŒã«ã€ããŠã®ãã®ã§ãã
ãªã¢ãŒãã¢ã¯ã»ã¹ã«ãããåŸæ¥å¡ã¯ã€ã³ã¿ãŒããããä»ããŠäŒæ¥ãããã¯ãŒã¯ã«å®å šã«æ¥ç¶ã§ããŸãã ããã¯ãåŸæ¥å¡ããªãã£ã¹ã§åããŠããããã«ãã§ã®Wi-Fiãªã©ã®å®å šã§ãªãã¢ã¯ã»ã¹ãã€ã³ããä»ããŠæ¥ç¶ããå Žåã«ç¹ã«éèŠã§ãã ãã®æ¥ç¶ãæŽçããããã«ããŠãŒã¶ãŒã®ã¬ãžã§ããã®ã¯ã©ã€ã¢ã³ããšäŒæ¥ãããã¯ãŒã¯ã®VPNã²ãŒããŠã§ã€ã®éã«ãã³ãã«ã確ç«ãããŸãã ã²ãŒããŠã§ã€ã¯èªèšŒãè¡ãããããã¯ãŒã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæäŸïŒãŸãã¯å¶éïŒããŸãã
æ¥ç¶ãä¿è·ããã«ã¯ãIPsecãŸãã¯SSLãæãäžè¬çã«äœ¿çšãããŸãã PPTPããã³L2TPãããã³ã«ã䜿çšããããšãã§ããŸãã
/ãŠã£ãã¡ãã£ã¢/ ãã£ãªãããã¬ãã / PD
ãµã€ãéVPN ã¯ãç°ãªãããŒã«ã«ãããã¯ãŒã¯ã®çµã¿åããã§ãã ãã®å ŽåããŠãŒã¶ãŒããã€ã¹ã¯VPNã¯ã©ã€ã¢ã³ããªãã§åäœããŸãâã²ãŒããŠã§ã€ããã¹ãŠã®åäœãå®è¡ããŸãã
ãã®ã¿ã€ãã®æ¥ç¶ã¯ ãäŒç€Ÿã«è€æ°ã®ãªã¢ãŒããªãã£ã¹ãããããããã1ã€ã®ãã©ã€ããŒããããã¯ãŒã¯ã«çµåããå¿ èŠãããå Žåã«äœ¿çšãããŸãã ãŸããçµç¹ã«ãããã¯ãŒã¯ãæ¥ç¶ãå¿ èŠãšããããŒãããŒãããå Žåã«ãã ããã«ãããäŒæ¥ã¯å®å šãªå ±æã¹ããŒã¹ã§å ±åäœæ¥ã§ããŸãã
/ãŠã£ãã¡ãã£ã¢/ ãã£ãªãããã¬ãã / PD
IPsecã¯ããã€ã³ãããŒãã€ã³ãæ¥ç¶ãä¿è·ããããã«æããã䜿çšãããŸãã ãããªãã¯ãããã¯ãŒã¯ã®ãªãMPLSãã£ãªã¢ã¯ã©ãŠãã®ããŒãžã§ã³ã䜿çšãããŸãã ãã®å ŽåãLayer3ïŒMPLS IP VPNïŒãŸãã¯Layer2ïŒVPLSïŒæ¥ç¶ãæŽçããããšãå¯èœã«ãªããŸãã
æåŸã«ãVPNæ¥ç¶ã䜿çšããããã®ãªãã·ã§ã³ãããã€ããããŸãã
- ããŒã¿ã»ã³ã¿ãŒã®2ã€ã®ãµãŒããŒéã®æ¥ç¶ã確ç«ããŸãã äœããã®çç±ã§æšæºçãªäŒæ¥ãããã¯ãŒã¯ã䜿çšããŠå®å šãªãã£ãã«ã確ç«ã§ããªãå Žåã«åœ¹ç«ã¡ãŸãã
- IaaSãµãŒãã¹ãžã®æ¥ç¶ã
- ã¯ã©ãŠãã§VPNã²ãŒããŠã§ã€ããã¹ãããŸãã
次ã®è³æã®ããããã§ãããããšVPLSãã¯ãããžãŒã«ã€ããŠè©³ãã説æããäºå®ã§ãã
PSäŒæ¥ããã°ã§ä»ã«äœãæžããŠããŸããïŒ